Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3551.

Solve : Folder Duplicate?

Answer»

My windows folder will duplicate by itself. How to prevent it?Much more info is needed...
What version of Windows is this?
What protection do you have?
When was the last TIME you scanned in Safe Mode?
How does the folder duplicate? Where does it go? Does it contain all of the same files?Is this the same machine that had the other ISSUES ? ?
No right clik FUNCTIONS etc. ? ?
If so i would suggest a format and clean install of XP.O.S. .... XP Profession SP2
Celeron D 2.66Ghz
512 RAM
Duplicate folder is 227kb
AVG Free Edition
Never scan in safe mode

I APOLOGIZE, your post seems to have been overlooked somehow. It can be a bit busy here, as we're understaffed in this section and have a fair amount of people coming in with problems.

If you're still having problems, update your AVG and scan with it in Safe Mode. Once you've done that, download HijackThis and post a log here.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3552.

Solve : SP2 being read as SP1????

Answer»

yes to all three. i'm still trying to see if anyone can get me a windows disc, but no luck so far.wait.

you said that someone gave you that computer?no, i have never said someone gave me this computer. i bought it with my own money..which i'm still paying off actually. i've never been given a computer...

i ran AVG, spybot, and ad-aware two nights ago and they didn't come up with anything.JXY...are you going somewhere with all of these questions?

saytheya, those friends of yours with XP Home/Pro SP2 don't have their CD's? Did you ever try calling Microsoft? You can also ask them about sending you a CD.of course im going somewhere.

saytheya didn't have a windows disc. that happens when someone has given you a computer. and i remember someone saying that they had recieved the computer from someone else. guess i got mixed up with a different topic.

Which brings me to my next question, what type of store did you buy it from.

Because in some places in china, if you buy a computer from a store, it could be just a small street shop.

And unlike larger ELECTRONICS stores, these smaller shops don't give you the windows disc.JXY: as far as i know, new computers aren't given with OS cds anymore. my compaq came with restore cds but no XP cd. i'm usually pretty good about keeping all the papers and cds that come with my computers in a safe spot.

I have never bought a computer "off the street." i don't even trust computer stores to fix my computer..but i also had a bad experience with one so that doesn't help. i bought my compaq from a store similar to walmart and my dell from dell.

CBMatt: i called microsoft to see if they would give me tech support, but i haven't asked them to send me a cd yet. my friend is asking around to see if she can FIND one. so i'm waiting it to be a last resort situation. Quote from: saytheya on August 23, 2007, 05:29:51 PM

CBMatt: i called microsoft to see if they would give me tech support, but i haven't asked them to send me a cd yet. my friend is asking around to see if she can find one. so i'm waiting it to be a last resort situation.
I could be wrong, but I believe they'll ship out the proper CD for only the cost of shipping. Just don't quote me on that one.Quote from: JXY on August 23, 2007, 02:47:37 AM
of course im going somewhere.

saytheya didn't have a windows disc. that happens when someone has given you a computer. and i remember someone saying that they had recieved the computer from someone else. guess i got mixed up with a different topic.

Which brings me to my next question, what type of store did you buy it from.

Because in some places in china, if you buy a computer from a store, it could be just a small street shop.

And unlike larger electronics stores, these smaller shops don't give you the windows disc.
yup because these days all triads are selling computers lol and if you're not careful, you could end up buying a pirated copy of windows.

it happened to me once, and i never bought comps from street shops again.

because you're running a pirated copy of windows, the microsoft support site won't be able to verify whether you're OS is genuine or not. THerefore, all updates will fail. (it happened to me).

and also, things like SP2 won't install properly. (happened to me)

and in the end, i had to re-install windows using a genuine version of windows.

(other SYMPTOMS include : unable to access cmd or task manager).I think thats common sense though ....... i bought parts from street makrets before ..... and let me be the 1st to say its all ripped -off junk ...... if you do regular virus scans etc .... you can actually pick up the patch that cracks x-p , i have about 6 or 7 diffrent x-p serials , that where given to me by a street salesmen ... now they all work , but there not legit ..... they where wrote on a piece of paper etc..... and i know its illegal to sell the codes out side of the microsoft products , he sold me the orginal cd , but the code was on paper ....... he gave me so many because he thought they might not work , that speaks for itself ........W2K has none of these problems. ...except i bought my computer from dell...i've had to have my windows system VERIFIED to even get stuff of the windows website.

no offense, but none of the last few comments have helped along my problem...Dell would be the one to contact for a CD...MS won't as they didn't sell it to you...Quote
no offense, but none of the last few comments have helped along my problem...
Sorry for the input saytheya, I confess to not reading this thread all the way through (it's very long) and I assumed from the previous posts we were dealing with a pirated copy of XP.
I'll keep quiet now but continue to watch
3553.

Solve : help wierd *censored* virus on my computer?

Answer»

Alright there is this virus on my computer, This GUY advertised it as a game CHEAT so i decided to check it out. It added its self on startup and its always running under wpa.dbl.exe in my taskmanager. I try to remove is from startup from typing run and msconfig but no luck the process doesnt show up there or as a service. Now the directory this virus is in is C:\WINDOWS\system32\wpa.dbl.exe . The wierd thing is when i end the process and try to go in that folder its not there. I tried to uncover the hiddin files and again no luck . So i try to delete it with a batch command. It says there is no file in that directory with that name. Now the wierd part is when i try to re start it up with the back command it starts up. Correct me if im wrong but these are the results i get.

BATCH COMMANDS
C:\WINDOWS\system32>DEL wpa.dbl.exe
Could Not Find C:\WINDOWS\system32\wpa.dbl.exe <-----Error

C:\WINDOWS\system32>wpa.dbl.exe <----no running error (it ran successfully.)

C:\WINDOWS\system32>wpa.blahblahblah.exe <---trying a fake file i made up
'wpa.blahblahblah.exe' is not RECOGNIZED as an internal or external command,<--get this error
operable program or batch file.

C:\WINDOWS\system32>

what can i do to get rid of this virus. Im PRETTY sure its a keylogger! its undetectable by all antiviruses.


I've never heard of the Weird *censored* virus, but you do indeed appear to be infected. It appears to be trying to disguise itself as the Windows Protection Activation. Head over to VirusTotal and scan the file by pasting the filepath into the little white text box. Post the results here.

Then download HijackThis to C:\Program Files\HJT and run a scan. Post the log here for us to take a look at.

I'm going to go ahead and move this thread to the appropriate section.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3554.

Solve : huge problem?

Answer»

Well I have these 2 computers in my house that both have this problem. When you turn them on, nothing appears on the monitor. It was only a problem with one of them at first but not neither of them work. I am using 2 different monitors and when i PLUGGED my laptop in to the monitors it worked fine. Does anybody have any idea how to fix this?I think this is going to be an hardware problem.
Just odd that the same thing happens to both the computers.
Do you hear the TESTING of your hard drives when you boot?

Jonas um it makes noises if thats what you mean lol well I downloaded this file on one and it messed up and i downloaded the same thing on the other comuter and that one messed up so i think thats the problemYou downloaded a file and ran it on both computers? If this is the COMMON factor then this was likely EITHER a virus or - seeing as you have not explained well - an incorrect video driver. Though I don't understand why it wouldn't even be displaying the BIOS... It would help a lot if we knew what you downloaded...Porn? XDDue to lack of feedback, I am CLOSING this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3555.

Solve : computer virus problem?

Answer»

Hello. I'm LOOKING for some help.

My computer had a virus of some kind and I called my cable company ( whom I have my internet service through) and they said they had a block on my email becuase it appeared I had a virus. So, that confirmed what I knew from my screens freezing and not being able to access anything.

SO, they recommended I run an anti-virus scan, which I did. I have sophos, and ran it. It said I had viruses and so I had it QUARANTINE them and then remove them.

Now, when I go to run my computer it does seem to be better starting up time and such, but it wont open a browser or let me access the web. In the lower right hand corner, the little computers to show the connection have a yellow triangle over them with an exclamation point over it. so, I need help in what I need to reconfigure now?

any advice is welcome.Alright but would you first post a HijackThis so Chriss (CBmatt) could take a look at it he is much better in that than I am.

Did you try to update the drivers of your Internet connection?
Here is how to do it:
1) Press the Winkey + Pause Break
2) go to hardware then to device manager.
3) go to the network adaptor and right cilck on it and click Update.

Let us know if it worked.

Jonas here's the problem. When I clicked on hijackthis link you had, it wanted to run the program. The computer I am on is my laptop and not my main computer where the problem is. I only hooked this one up so I could get online and get some help for the other computer.

Now what?Instead of clicking on the link, right-click on it and go to Save Target As.for the LIMITED connectivity try going to control panel network connections and right clicking your network adapter then disable it and then reenable it.I hate that *censored* yellow sign. Try right clicking the sign and pressing "Repair". If that doesn't work right-click and "Disable" then "enable" it. And if that still doesn't work go to your modem unplug it and wait about 40 seconds then put it back in and wait.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another MODERATOR and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3556.

Solve : Flashget?

Answer»

Hello again, im using a dell xps 210 vista premium
lately spyware terminater is finding somthing called
flashget HKCU\software\jetcar.....
I have put it in quaretine and nothing seems affectted.
Can anyone tell me what this is please,and should i remove it.
Thanks for your time........Flashget is an FTP connection client, that is if it's legitimate.

Does your protection app give you a registry entry? If so you should post the entire string it gives. What executable is it pointing to? If you can find this executable you should upload it to www.virustotal.com and see what they think of it . . .http://www.safer-networking.org/en/mirrors/index.html

it could be spyware.

download and install spybot S&D.

run a scan and see of ot picks up the flashget entry.

if it does, ask spybot to fix it for you. otherwise, i don't think it's a problem.

did you install flashget?Thanks for your time on this, spybot,avg,adaware se,
none of them detect it only spyware terminater.
ive just removed it and everything seems fine..
cheers..FlashGet is a download accelerator made by Jetcar. I personally don't trust the program much (programs like this just seem iffy to me), but most people seem to think it's relatively safe. In my EYES, the program you should worry about is Spyware Terminator. It's a subpar program (once considered rogue anti-spyware) and anything it picks up has a chance of being no more than a false positive. It's possible that one of the FlashGet files is considered spyware, but there's also a good chance the Spyware Terminator made a mistake. If I were you, I'd stick with Spybot.Thanks CBMatt,for the advice i found flashget
keeps appearing so i just keep removing it,
i have never had any problems with spyware terminator.
it dose seem to find things the others dont??even when
i had my gateway 2core mediacenter..
but cheers again CBMatt for your time..Oh woops, did I say FTP connection client ? ? I meant download accelerator . . . I was thinking of something else, SmartFTP or something, don't KNOW why. Sorry for any confusion. Thats alright DetltaSlaya..no harm done,
the only thing that gets me is your penguin sign!!!
with my Details on it anyone can read that yes??
i must find a way to stop this as it just feeds my
paranioa of on line ID theft and security...
thanks..P...Well your IP and browser information is given to every website you visit, you can't stop this unless you use a proxy. NOONE else can find out this information unless the website decides to broadcast it.

This is how it works with my signature. Your browser is requesting all the images on the PAGE through the URLs, then it sends its request to the site that my signature is from (danasoft.com). This site uses the information sent to it to generate a new image that is then uploaded to your browser. Go to their site for more information.

www.danasoft.comThanks DeltaSlaya, thats reashuring
but now somthing has happend..
new post...cheers.P...Quote from: paul420 on August 26, 2007, 11:44:47 AM

i have never had any problems with spyware terminator.
it dose seem to find things the others dont??even when
i had my gateway 2core mediacenter..
Spyware Terminator has a bad history of leading users astray with false information. But if you wish to keep using it, that's entirely up to you.
3557.

Solve : Tell me the problem?

Answer»

Logfile of HijackThis v1.99.1
Scan saved at 7:04:23 PM, on 7/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\mgrs.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Owner\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jujwakxr.dll",forkonce
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Secondary Logon seclogonSNDSrvc (seclogonSNDSrvc) - Unknown owner - C:\WINDOWS\system32\adsntd.exe (file missing)


In my AVG anti-spyware,I trojans quarantined.But I want to get rid of them.I'm not sure if getting rid of these will mess up my computer.

Here some screenshots of the AVG Infections

http://img72.imageshack.us/my.php?image=avgggqr7.png


http://img187.imageshack.us/my.php?image=avvvddfzv1.png



I see that you have HijackThis running from your desktop. You have it in a permanent location, which is good because it makes important backups that you may end up needing. However, to help you avoid clutter and to help ensure that the backups stay safe, I would like you to MOVE it to a special location.

  • Double-click on My Computer to open it and navigate to C:\Program Files.
  • Right-click on the empty (white) space and go to New > Folder.
  • Name the folder something like HJT and move HijackThis into that new folder.
  • If you would still like to run HijackThis from the desktop for convenience, right-click on HijackThis and click on Create Shortcut. This will create a shortcut to the program; move the shortcut to the desktop.

Looks like you've got yourself some dialers and downloaders. AVG AS appears to have caught most of them, but there are still a few infections on your computer. First, download CCleaner (install without Yahoo! toolbar) and configure it according to this guide.

To delete quarantined items, click on the Infections tab. This will list everything in Quarantine. Click on Select All and then Remove Finally. That will get rid of everything AVG detected. You don't have to WORRY about this messing up your computer. Now...the program you have is very good, but you still need anti-virus. Anti-spyware alone just doesn't cut it. Go ahead and download AVG Free (made by the same people who created your anti-spyware). Update it and scan with AVG Free in Safe Mode. Let it remove whatever it wants. Reboot your computer back into Normal Mode.



Once you have done all of that, post a new HijackThis LOG, as there are still things that need to be taken care of.C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\New Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file)
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jujwakxr.dll",forkonce
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing)
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Secondary Logon seclogonSNDSrvc (seclogonSNDSrvc) - Unknown owner - C:\WINDOWS\system32\adsntd.exe (file missing)

Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet...

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL

O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file)

O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jujwakxr.dll",forkonce

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000

O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab

O23 - Service: Secondary Logon seclogonSNDSrvc (seclogonSNDSrvc) - Unknown owner - C:\WINDOWS\system32\adsntd.exe (file missing)


Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

MyWebSearch
RXToolbar


Please note any other programs that you dont recognize in that list in your next response.

Navigate to and delete the following folder(s) if present...

C:\Program Files\MyWebSearch

Navigate to and delete the following file(s) if present...

C:\WINDOWS\system32\adsntd.exe
C:\WINDOWS\system32\jujwakxr.dll
C:\WINDOWS\system32\svehost.exe
(Do not get this confused with SVCHOST.exe!)

Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any PROBLEMS following my steps.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with INFORMATION about your computer and your problem.
3558.

Solve : Be aware of this {just in case}?

Answer» Alert: I checked with Norton Anti-Virus, and they are gearing up for this virus so I believe this is real. I checked snopes.com and this is for real Get this sent around to your contacts ASAP...we don't need this spreading around.



You should be alerted during the next days: Do not open any message with an attached filed called "INVITATION", REGARDLESS of who sent it. It is a virus that opens an Olympic Torch which "burns" the whole hard disc C of your computer.. This virus will be received from someone who has your e-mail address in his/her contact list, that is why you should send this e-mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it.

If you receive a mail called "invitation", THOUGH sent by a friend, do not open it, and shut down your computer immediately. This is the worst Virus announced by CNN. It has been classif ied by Microsoft as the most destructive virus ev er. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus. This virus simply destroys the ZERO Sector of the Hard Disc, where the vital information is kept.



I got this from an email/ friend not sure if this is valid
I doubt very much so that this is true . . .

"It is a Virus that opens an Olympic Torch which "burns" the whole hard disc C of your computer".

If Norton had a copy of this then it would be spreading, therefore it would already be a PROBLEM, not wait a couple of days.

"This virus simply destroys the Zero Sector of the Hard Disc, where the vital information is kept."

Whats this so-called "Zero sector"? Is there even such a thing? And even if there was, there is no 'vital' information stored on the hard drive. They come blank, generally.It appears that email is remarkably similar to this: http://www.hoax-slayer.com/olympic-torch-virus-hoax.html

??good- find*

thanks for disproving the email, I told my friend to quit FORWARDING them to me in the future, THANKS
3559.

Solve : Help!! I think theres something wrong with my Computer!!?

Answer»

I recently had my computer scanned using Avast Home edition and I got a bunch of viruses most of them Trojans and spywares. after that I was getting some error message saying "Error Message,"Duplicate name exists."" even though Im not connected to a network and it also shows a massage saying "limited or no connectivity" whats worst is I cant access other website such as pldtplay.com(philippine game servers) and I also cant sign in on my yahoo MESSANGER. is there something wrong with my PC? can anyone help...?get superantispyware run it in safe mode(along with any other protections) and dl hijackthis and post log, it might take more then one postthanks, I think Ill try that
I already used system restore but I still get the error but not as alwayswell the superantispyware together with system restore was able to fix things... "kinda"
some of my software was not working "correctly" like my yahoo massager for example some of the pictures and plug ins on it was missing, my browser(firefox and internet explorer both have the same problems) has a big space on the bottom part of it which is very annoying since i cant see most of the contents of a website. some of my files and previously installed PROGRAMS was missing.

I'm thinking of reformatting my PC since i have already backed up all my files.
but i was wondering... can frequent re-formatting(using windows xp installer) damage your hardrive? try windows updates and uninstall firefox and reinstall it

and for the reformatting im not sure someone with more hardware experence might be able to help or google might have the answer i reformat every 3 months and my computers are doing fine. ive had my laptop for over a yr soQuote

my browser(firefox and internet explorer both have the same problems) has a big space on the bottom part of it which is very annoying since i cant see most of the contents of a website.
Got a screen shot of this big space?

Quote
i reformat every 3 months and my computers are doing fine.
Why would you do that UW?because i like to make sure i don't have anything. and i like a fresh start several times during the yearQuote
Got a screen shot of this big space?
well I've already reinstall firefox just like what unlovedwarrior suggested and the bottom thing was gone. but the other bug are still there.
I'm still wondering if frequent re-formatting can damage a hardrive...
MAYBE I'll try to find some other source. but if anyone know something fell free to post hereNo frequent formatting wont damage a hard drive. It is no DIFFERENT than other write operations a hard drive perform.
3560.

Solve : Oh My God... Incredibly Evil Virus PLEASE HELP?

Answer»

Ok, well yesterday night whilst I was on MSN Messenger.. and suddenly the internet stopped working although Windows Vista said it was online.... so I tried opening Windows Media Player to listen to some music from my library and I got an error message saying "wmplayer.exe not FOUND" followed by various messages saying that "explorer.exe" not found and others which I cannot remember.... So I thought best thing to do would be restarting the computer.. as soon as I clicked on restart I got a message saying "SystemUI.exe not found" followed by a blue screen... Now each time I boot before I even have a chance to press F8 it tells me Boot\BCD not found and restarts.... constantly.

I can assume the OS has been destroyed but I suspect my personal files are still there so I tried CREATING a bootable version of Windows XP on my UFD using BartPE on annother computer.... although my BIOS is configured properly and I follow all steps completely the computer refuses to boot the UFD....

Windows Repair is not an option as my DVD-RW drive is bust and IT IS a laptop... I got an external DVD-RW but I have it in my other house in annother country.

Annother problem is the fact that I cannot get it repaired in any shop due to the high costs of the service (all wanted €200 or more) which I cannot afford....


Any help please??


Extra Info:
OS: Microsoft Windows Vista Home Basic
Antivirus: AVG Free + AVG AntiRootkit
AntiSpyware: Windows Deffender + AVG AntiSpyware
Firewall: Windows Firewall
RAM: 1024 (128 Graphics) CPU: AMD Turion 64 X2 (1.6GHz)
HDD: 100GB GFX: nVidea GeForce Go! 6150Did you try using the floppy you made on another good machine? If it works on a good 'puter then you really have no other option than replacing the broke DVD-R/W-do you?
What is it you want to accomplish here...
Retrieve your data ?
Repair install so you can use the machine ?
A clean start ?Quote from: patio on July 16, 2007, 07:51:46 PM

What is it you want to accomplish here...
Retrieve your data ?
Repair install so you can use the machine ?
A clean start ?

Most importantly retrieving my data.... I know how to do a clean start. I would hook up that drive as a slave in a working machine...run a virus scan on the drive, actually all your protection apps...you have a well balanced arsenal there BTW.

Then copy/burn the data you need from that HDD and do a full format on it.

It should then be clean enough for a clean install.

p,s. You may want to add AdAware and Spybot to your package...

p.s.s. Before copying /using any of that data on the new build re-scan the CD just in case.Quote from: patio on July 17, 2007, 02:16:05 PM
I would hook up that drive as a slave in a working machine...run a virus scan on the drive, actually all your protection apps...you have a well balanced arsenal there BTW.

Then copy/burn the data you need from that HDD and do a full format on it.

It should then be clean enough for a clean install.

p,s. You may want to add AdAware and Spybot to your package...

p.s.s. Before copying /using any of that data on the new build re-scan the CD just in case.

That is exactly the problem.... it is a laptop &GT;_


About 10 bucks at any computer store...lets you connect a laptop HDD to any desktop machine with an available IDE connection.

Handy for quicker backups as well.Quote from: patio on July 17, 2007, 04:40:34 PM
Then grab one of these...



About 10 bucks at any computer store...lets you connect a laptop HDD to any desktop machine with an available IDE connection.

Handy for quicker backups as well.

I NEVER knew that existed... I'll go to PC World and to the small shop next 2 my house later to find out if they got them.

Thank you so much you are a real life saver =)As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3561.

Solve : Can a keylogger log your clipboard??

Answer»

I've recently become paranoid after I fell victim to a keylogger last week having a very important password stolen and decided to manually copy and paste my passwords from a notepad document from then on. Might be important to note that since that time I had NEVER typed the password, EVEN to initially create it. Thought I was safe and was surprised to have the same password stolen again. I have run hijackthis, avg, trojan remover, trendmicro online scan, adaware, and win security task manager(actually a safe program believe it or not) and my system turned up clean. I even ran them all in safe mode to be sure. I have a router and use the xp FIREWALL as well. I just don't get it. The only possible way that that password could have been stolen again is if the keylogger is somehow recording my clipboard, which I have began deleting after I paste the password. Is this possible? Is there any way to prevent it happening in the future?can you post the hijackthis log for us to look at?Quote from: endezeichen on August 23, 2007, 12:41:58 AM

The only possible way that that password could have been stolen again is if the keylogger is somehow recording my clipboard, which I have began deleting after I paste the password. Is this possible?
Yes
Quote from: endezeichen on August 23, 2007, 12:41:58 AM
Is there any way to prevent it happening in the future?
Get rid of the keylogger. As unlovedwarrior said a hijackthis log would be good place to start. Sorry, I didn't post my hijackthis log because I didn't think it would be necessary. I've done extensive cleaning with many programs as well as manually. This really is one heck of a trojan.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:23:21 AM, on 8/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Just took a nice look into this one and noticed there was a bogus exe in the folder that was not recognized by google or licensed. Deleted the whole folder, could care less about winmsngr... that could be what I had missed
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Services (NOD32kren) - Nero AG - (no file)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 2626 bytes

Thanks
You could have just uploaded the file to http://www.virustotal.com/, it can tell you, from numerous scanners whether a file is malcious or not..Do you download warez by any chance?

One thing you can try... Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. GO ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.

You could also try running a full-system scan with SUPERAntiSpyware in Safe Mode.

I'm not sure how much this will help, though. When it comes to this sort of breach of security, I think it's best to back up all important personal files (not programs; download them again later) and then reformat. Keyloggers can be pretty sneaky and even when you remove one, it's sometimes hard to trust that your computer truly is clean again.Well I must say, combofix is a pretty interesting and useful program. Never even heard of it so thanks for that. Got a bit weary when zonealarm told me it was launching cmd.exe...that was a high risk alert. Did a little reading up and apparently combofix was infected a few months ago. I just assumed that was a clean version and the cmd.exe part was just part of the process. Oh yeah- Wwwwinnnantispyware... the most annoying piece of crap I've ever had on my computer. Apparently I didn't get rid of it as I thought I did.

C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor
C:\Program Files\Common Files\curity~1
C:\Program Files\Common Files\winantispyware 2007
C:\Program Files\Common Files\winantispyware 2007\err.log
C:\Program Files\Common Files\WinAntiSpyware 2007\err.log
C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe
C:\Program Files\Common Files\ystem~1
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\WINDOWS\scurit~1
C:\WINDOWS\system32\aeksree.dll
C:\WINDOWS\system32\configs
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\ApiMon.sys
C:\WINDOWS\system32\drivers\fopn.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\F2
C:\WINDOWS\system32\F3
C:\WINDOWS\system32\H1
C:\WINDOWS\system32\mcroso~1.net
C:\WINDOWS\system32\mcroso~1.net\M?crosoft.NET\
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\V1
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\wtsicomsv.exe
C:\WINDOWS\system32\zxdnt3d.cfg
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\wr.txt


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_CMDSERVICE
-------\LEGACY_FOPN
-------\LEGACY_NETWORK_MONITOR
-------\LEGACY_NET_AGENT
-------\LEGACY_WINDOWS_OVERLAY_COMPONENTS
-------\fopn
-------\Net Agent
-------\Windows Overlay Components


((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 )))))))))))))))))))))))))))))))


2007-08-23 13:4351,200--a------C:\WINDOWS\nircmd.exe
2007-08-23 09:22d--------C:\DOCUME~1\ED903B~1.ED-\vw
2007-08-23 09:21d--------C:\Program Files\Visual IP Trace 2007
2007-08-23 07:28512--a------C:\ScanSectorLog.dat
2007-08-23 07:195,664--AHS----C:\WINDOWS\system32\drivers\fidbox2.dat
2007-08-23 07:191,720,352--ahs----C:\WINDOWS\system32\drivers\fidbox.dat
2007-08-23 07:19d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\MailFrontier
2007-08-23 07:0775,512--a------C:\WINDOWS\zllsputility.exe
2007-08-23 07:074,212---h-----C:\WINDOWS\system32\zllictbl.dat
2007-08-23 07:0711,264--a------C:\WINDOWS\system32\SpOrder.dll
2007-08-23 07:071,087,216--a------C:\WINDOWS\system32\zpeng24.dll
2007-08-23 07:07d--------C:\WINDOWS\system32\ZoneLabs
2007-08-23 07:06d--------C:\WINDOWS\Internet Logs
2007-08-23 04:50d--------C:\WINDOWS\CSC
2007-08-21 04:46d--------C:\DOCUME~1\ED903B~1.ED-\AIMPro
2007-08-21 04:45d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\AIMPro
2007-08-21 04:45d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\acccore
2007-08-21 04:305,632--a------C:\WINDOWS\system32\ptpusb.dll
2007-08-21 04:30159,232--a------C:\WINDOWS\system32\ptpusd.dll
2007-08-21 04:3015,104--a------C:\WINDOWS\system32\drivers\usbscan.sys
2007-08-21 01:37d---s----C:\DOCUME~1\ED903B~1.ED-\UserData
2007-08-19 00:52d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Ahead
2007-08-19 00:37d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Simply Super Software
2007-08-18 21:16d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Ventrilo
2007-08-17 19:59d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\WinRAR
2007-08-17 19:57d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\vlc
2007-08-17 08:15d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\uTorrent
2007-08-16 15:201,310,720--ah-----C:\DOCUME~1\ED903B~1.ED-\NTUSER.DAT
2007-08-16 13:47d--------C:\WINDOWS\system32\ActiveScan
2007-08-16 03:426,588--a------C:\WINDOWS\system32\bcbeg.ini.ren
2007-08-16 03:426,473--a------C:\WINDOWS\system32\bcbeg.bak1.ren
2007-08-16 03:42243,296--a------C:\WINDOWS\system32\gebcb.dll.ren
2007-08-15 11:536,536--a------C:\WINDOWS\system32\prutv.ini.ren
2007-08-15 11:536,421--a------C:\WINDOWS\system32\prutv.bak1.ren
2007-08-15 11:4852,750--a------C:\WINDOWS\system32\lqdsrngo.exe
2007-08-15 11:4843,542--a------C:\WINDOWS\system32\gebabxw.dll
2007-08-15 11:48192,582--a------C:\WINDOWS\system32\qwinrmdt.exe.ren
2007-08-15 11:48d--------C:\WINDOWS\system32\tmps9
2007-08-15 11:48d--------C:\WINDOWS\system32\ICdll
2007-08-15 11:48d--------C:\WINDOWS\system32\chkconfig
2007-08-15 11:48d--------C:\DOCUME~1\NETWOR~1\APPLIC~1\NetMon
2007-08-05 22:51d--------C:\DOCUME~1\ADMINI~1\APPLIC~1\Simply Super Software
2007-08-05 22:11d--------C:\Program Files\Trend Micro
2007-08-05 21:557,021--a------C:\WINDOWS\system32\ijkmp.ini.ren
2007-08-05 21:556,507--a------C:\WINDOWS\system32\ijkmp.bak1.ren
2007-08-05 21:34d--------C:\WINDOWS\system32\appmgmt
2007-08-05 20:10d--------C:\Program Files\MagicISO
2007-08-05 19:541,404,928--a------C:\WINDOWS\system\nvcpl.dll
2007-08-05 19:07d--------C:\DOCUME~1\ed\APPLIC~1\Help
2007-08-05 19:05d--------C:\Program Files\Security Task Manager
2007-08-05 19:05d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-05 18:5377,312--a------C:\WINDOWS\system32\ztvunace26.dll
2007-08-05 18:5375,264--a------C:\WINDOWS\system32\unacev2.dll
2007-08-05 18:5369,632--a------C:\WINDOWS\system32\ztvcabinet.dll
2007-08-05 18:53162,304--a------C:\WINDOWS\system32\ztvunrar36.dll
2007-08-05 18:53153,088--a------C:\WINDOWS\system32\UNRAR3.dll
2007-08-05 18:53d-a------C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-08-05 18:53d--------C:\Program Files\Trojan Remover
2007-08-05 18:53d--------C:\DOCUME~1\ed\APPLIC~1\Simply Super Software
2007-08-05 18:53d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Simply Super Software
2007-08-05 18:37786,432--ah-----C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-08-05 18:206,467---hs----C:\WINDOWS\system32\efhkj.bak1
2007-08-05 04:0189,088--a------C:\WINDOWS\system32\atl71.dll
2007-08-05 04:01499,712--a------C:\WINDOWS\system32\msvcp71.dll
2007-08-05 04:01348,160--a------C:\WINDOWS\system32\msvcr71.dll
2007-08-05 04:011,060,864--a------C:\WINDOWS\system32\mfc71.dll
2007-08-05 03:346,466---hs----C:\WINDOWS\system32\ttutv.bak1
2007-08-05 03:29169,147--a------C:\WINDOWS\TTC-4444.exe.ren
2007-08-05 03:29d--------C:\Temp
2007-08-05 03:2840,183--a------C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe.ren
2007-08-05 03:28d--------C:\DOCUME~1\ed\APPLIC~1\s?stem32
2007-08-02 23:00d--------C:\Program Files\Lavasoft
2007-08-02 23:00d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-07-30 23:16d--------C:\DOCUME~1\ed\AIMPro
2007-07-30 22:47d--------C:\DOCUME~1\ed\APPLIC~1\AIMPro
2007-07-30 22:47d--------C:\DOCUME~1\ed\APPLIC~1\acccore
2007-07-30 22:46d--------C:\Program Files\Common Files\Nullsoft
2007-07-30 22:46d--------C:\Program Files\AIM
2007-07-30 22:46d--------C:\DOCUME~1\ed\APPLIC~1\AIM
2007-07-27 20:56d--------C:\WINDOWS\ShellNew
2007-07-27 20:56d--------C:\Program Files\AutoIt3(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-23 13:4516292--ahs----C:\WINDOWS\system32\drivers\fidbox.idx
2007-08-23 13:451508--ahs----C:\WINDOWS\system32\drivers\fidbox2.idx
2007-08-20 22:39---------d--------C:\Program Files\World of Warcraft
2007-08-20 21:07---------d--------C:\Program Files\Realtek
2007-08-19 01:38---------d--h-----C:\Program Files\WindowsUpdate
2007-08-18 20:27---------d--------C:\Program Files\uTorrent
2007-08-17 19:59359040--a------C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2007-08-17 19:59359040--a------C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-08-16 02:1514656--a------C:\WINDOWS\gdrv.sys
2007-08-15 12:16---------d--------C:\Program Files\AC3Filter
2007-08-10 15:2116384000--a------C:\WINDOWS\RTHDCPL.exe
2007-08-10 13:524603904--a------C:\WINDOWS\system32\drivers\RtkHDAud.sys
2007-08-05 20:1812528--a------C:\WINDOWS\system32\drivers\secdrv.sys
2007-08-03 13:221826816--a------C:\WINDOWS\SkyTel.exe
2007-08-02 23:00---------d--------C:\Program Files\Common Files\Wise Installation Wizard
2007-07-30 19:1992504--a------C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19549720--a------C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:1953080--a------C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:1943352--a------C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19325976--a------C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19203096--a------C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:191712984--a------C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:1833624--a------C:\WINDOWS\system32\wups.dll
2007-07-26 18:061191936--a------C:\WINDOWS\RtlUpd.exe
2007-07-26 17:09520192--a------C:\WINDOWS\RtlExUpd.dll
2007-07-20 00:2936864--a------C:\WINDOWS\system32\dxinputdll.dll
2007-07-20 00:19---------d--h-----C:\Program Files\InstallShield Installation Information
2007-07-19 01:34---------d--------C:\Program Files\Guitar Pro 5
2007-07-17 00:32---------d--------C:\Program Files\Axon Data
2007-07-13 17:17---------d--------C:\Program Files\Ventrilo
2007-07-10 00:08---------d--------C:\Program Files\Common Files\Ahead
2007-07-10 00:07---------d--------C:\Program Files\Nero
2007-07-09 00:052722--a------C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
2007-07-09 00:048972--a------C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-07-06 21:44---------d--------C:\Program Files\RivaTuner v2.02
2007-07-06 20:40---------d--------C:\Program Files\GIGABYTE
2007-07-06 18:13---------d--------C:\Program Files\Common Files\Blizzard Entertainment
2007-07-05 11:07315392--a------C:\WINDOWS\HideWin.exe
2007-07-05 11:06---------d--------C:\Program Files\Common Files\InstallShield
2007-07-05 10:580-rahs----C:\MSDOS.SYS
2007-07-05 10:580-rahs----C:\IO.SYS
2007-07-05 10:580--a------C:\CONFIG.SYS
2007-07-05 10:580--a------C:\AUTOEXEC.BAT
2007-07-05 10:58---------d--------C:\Program Files\microsoft frontpage
2007-07-05 10:56---------d--------C:\Program Files\Movie Maker
2007-07-05 10:56---------d--------C:\Program Files\Common Files\MSSoap
2007-07-05 10:55---------d--------C:\Program Files\Windows NT
2007-07-05 10:55---------d--------C:\Program Files\Online Services
2007-07-05 10:55---------d--------C:\Program Files\MSN Gaming Zone
2007-07-05 06:50---------d--------C:\Program Files\Common Files\SpeechEngines
2007-07-05 06:50---------d--------C:\Program Files\Common Files\ODBC
2007-07-05 00:38---------d--------C:\Program Files\QuickTime
2007-07-04 23:36---------d--------C:\Program Files\VideoLAN
2007-07-04 23:22---------d--------C:\Program Files\XviD
2007-06-28 16:442165760--a------C:\WINDOWS\MicCal.exe
1997-10-24 13:2025088--a------C:\WINDOWS\inf\regl3acm.exeDoes anyone know of a keylogger that can log a copy & pasted password?
I don't know of one, the log usually comes up as Ctrl C and Ctrl P with no further detail.
Could you be getting directed to a malicious website and pasting your password there?
This is a common problem when clicking on links that COME in emails, very common with banking sites but they play it down because they don't want to admit they're being ripped off.
I have personally reported 2 such misdirections to 2 different banks and neither of them even acknowledged my email.
They're running scared.
3562.

Solve : I've had these trojans for awhile, but my computer is the same.(resolved)?

Answer»

I have about 4 or 5 trojan viruses that I can't REMOVE which really pisses me off. But the thing is my computer has been running the same and nothing seems wrong with it. And I've had these trojans for a couple of months. I'm trying to remove them.

But the question is could they cause really bad damage like severly slow my computer down or make it crash etc?In short, yes.
GET rid of them as soon as you can before they cause more damage.
They've most likely CAUSED a lot of damage already and you just haven't noticed.What have you run to get rid of them /
List all your protection apps.Been working on it after I got a PM from the OP . . . I think we're in the clear, just waiting to hear back on final results.
Can't answer your question as I don't know what ELSE was used, but I suggested AVG Antivirus Free, AVG Anti-Spyware, Adaware 2007, and Spybot Search & Destroy. The HijackThis log suggests TrojanHunter, AOL Anti-Spyware and SpySubtract were also used, or at least installed. The log was clean as far as I am aware except from a Zango toolbar which I gave instructions as to how to remove, and out of date Java (Java 6 Update 1) which gave instructions to update.
Lots of stuff running in the background though, I suspect that the computer is running very slowly because of this.Topic resolved via private messaging, no more Trojans.As this issue appears to be resolved (according to Calum), I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3563.

Solve : wat is qwiz??

Answer»

ok so its the LAST time IM at my cousins and my older cousin mike has something on his startup shield we found wen he just got spy sweeper is anyone FAMILIAR with this program? i know what to do its just that i dont feel safe deleting this programqwix seems to be legit, did you Google it?

3564.

Solve : Please help me i think its a virus.?

Answer» OK i recently was surfin the web and some how i picked up something. I know its not good but it keeps tellin me that i have a virus on my computer but its not my anti-virus program which is mcafee. it keeps putting pop ups of different anti-virus programs and other sites. I have scaned a million times and dont know what to do. Please help as fast as you can.Hi, I think I have the same or a similar problem to you. I was browsing the internet and TRIED to view a video, of an advert, that I need for a research project, I had to download some SOFTWARE to view it. When I did I got next to the clock a new icon, that occassionally sends a message about a system alert about spyware. When I click on the icon it takes me to a webpage for virusprotectpro. I have norton ANTIVIRUS and have scanned my computer but it says my computer is clean, but I cannot remove this icon. When I first try and go online it normally takes me to bbc.co.uk but now it takes me to a security page, saying my computer is at risk and I should download anti-spyware software. I am not sure what is causing all of this but I would like it to stop, if someone could help me it would be appreciated.ok monkeynuts please start your own thread in this section with as much detail as possible, computer specs, symptoms, protection programs( anti-virus and other programs like that..


silence, we need more info on your computer, like OS( what windows do you have?) what scans did you do? did you do them in safe mode? can you post a hijackthis LOG for us to look at also.To avoid confusion, I'm locking this thread. Please refer to the one containing your logs.
3565.

Solve : spywarebomb?

Answer»

how do i get rid of this THING, every two days seems to show up and dont know which software to kill it for good i hope lol

adaware & spybot dont kill it

sytem mechanic says it removes it, but shows up again in two days ?

what am i to do ?

any info plzWhat OS do you have?
Do you have any other protection?

Go ahead and post a HijackThis log and we'll take it from there.have xp home, with system mechanic 6 pro , adaware pro, ETRUST pestpartol 5, REGISTRY mechanic, ashampoo - photo commander, antispyware, winoptimizer & burning studio 6, ms office 2003 pro, aol/yahoo/windows live messengers, winamp & limewire pro

the ashampoo one didnt work either, now trying a-squared anti-malware

i see it in the registry, when i scan with spytron of system mechanic, but can't delete it (dont know which files it is in),
Quote from: CBMatt on July 13, 2007, 11:53:56 AM

Go ahead and post a HijackThis log and we'll take it from there.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 1:33:04 PM, on 7/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\hmsam\Local Settings\Temporary Internet Files\Content.IE5\M72V9DV4\HiJackThis_v2[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [eTrust PestPatrol Active Protection] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe"
O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182927150374
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182927172195
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{7345C513-0818-48BD-A4B4-8AC56A09D709}: NameServer = 204.239.167.3,204.239.167.13
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: Performance Logs and Alerts (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe

--
End of file - 4794 bytes
Quote from: hmsam on July 13, 2007, 12:00:01 PM
have xp home, with system mechanic 6 pro , adaware pro, etrust pestpartol 5, registry mechanic, ashampoo - photo commander, antispyware, winoptimizer & burning studio 6, ms office 2003 pro, aol/yahoo/windows live messengers, winamp & limewire pro

the ashampoo one didnt work either, now trying a-squared anti-malware

i see it in the registry, when i scan with spytron of system mechanic, but can't delete it (dont know which files it is in),


I notice you have Limewire Pro. Did you PURCHASE this? Regardless, downloading files off P2P networks is highly risky and not advised. You should probably uninstall this software so that you are not affected again.

Also, none of the software you have sounds like an AV, correct me if I am WRONG but it is advised, as I am sure Chris will tell you to get - AVG Anti-Virus Free. (Direct .exe Link).Your log looks clean to me. Perform a scan online with Panda ActiveScan and post a log here. Also, download SUPERAntiSpyware and Spybot - Search & Destroy, update them and scan with them in Safe Mode (one at a time!). Let us know the results of your scans.

DeltaSlaya is right...I can't tell you to get rid of it, but you might want to reconsider using LimeWire. The program itself isn't considered malicious, but some of things you download through this client may be unsafe, and are likely contributors to your infection. Many downloads are also considered illegal, as they infringe on copyright laws.




Quote from: DeltaSlaya on July 13, 2007, 06:37:08 PM
Also, none of the software you have sounds like an AV, correct me if I am wrong but it is advised, as I am sure Chris will tell you to get - AVG Anti-Virus Free. (Direct .exe Link).
Actually, they already have Kaspersky, which is a respectable anti-virus. Personally, I prefer AVG, but what they have is sufficient, so there's no need. They could certainly go for some better anti-spyware, though.Sorry, it's just that their AV wasn't mentioned here:

Quote
have xp home, with system mechanic 6 pro , adaware pro, etrust pestpartol 5, registry mechanic, ashampoo - photo commander, antispyware, winoptimizer & burning studio 6, ms office 2003 pro, aol/yahoo/windows live messengers, winamp & limewire pro

and yea now that I look it indeed is in their HJT log.No worries. They probably forgot to mention it.

hmsam, do you update Kaspersky and scan with it on a regular basis?it updates every three hrs and scans constantly by itself, because of kaspersky's antihacker makes it scans from the attacks of the helken attacks

scans full on friday mornings

spybot does not work, never tried superantispyware as mentioned above

oh i also installed the cleaner professiona from moosoft, found nothing tooTry removing SpywareBomb in Safe Mode and then scan with System Mechanic since it seems to be able to detect the program. If it still exists, you should also delete C:\Program Files\SpywareBomb, as well as the various files listed here...
http://www.emsisoft.com/en/malware/?Adware.Win32.SpywareBomb

Use Pocket KillBox if you have to. Once you've done all of this, try the Panda ActiveScan and post your results.RogueRemover is supposed to remove spywarebomb, it on their list.
If it's returning after a couple of days then you should review your downloading habits as antivirus & antispyware programs won't protect you from rogue programs or pups.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3566.

Solve : Rustock.gen!C virus?

Answer»

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 15:28:45, on 2007-08-18
Platform: WINDOWS XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Downloads\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/defaultf.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.fr.msn.ca/0SEFRCA/SAOS01?FORM=TOOLBR
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (USER 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Compagnon d'AOL.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Mini-icône d'AOL 8.0.lnk = C:\Program Files\AOL 8.0\aoltray.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://dominique883.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cabO18 - Protocol: bw+0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw+0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw-0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw-0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw00 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw00s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw10 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw10s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw20 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw20s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw30 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw30s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw40 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw40s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw50 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw50s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw60 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw60s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw70 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw70s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw80 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw80s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw90 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bw90s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwa0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwa0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwb0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwb0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwc0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwc0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwd0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwd0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwe0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwe0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwf0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwf0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwg0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwh0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwh0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwi0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwi0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwj0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwj0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwk0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwk0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwl0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwl0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwm0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwm0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwn0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwn0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)O18 - Protocol: bwo0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwo0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwp0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwp0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwq0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwq0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwr0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwr0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bws0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bws0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwt0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwt0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwu0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwu0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwv0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwv0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bww0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bww0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwx0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwx0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwy0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwy0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwz0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: bwz0s - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O18 - Protocol: offline-8876480 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 UPDATE Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe

--
End of file - 22024 bytes
CB Matt, ComboFix was the only program that COULD pick up the virus.Alrighty, it looks pretty clean to me. You should, however, check those O18 Logitech entries and fix them with HijackThis. The file is gone, but traces of it are still in the registry. You should also download CCleaner (without Yahoo! toolbar) and use the Cleaner and Issues tools to clean up a bit.

Also, that computer still needs a firewall and a newer version of Java. Other than that, things are looking good.

The pe386 driver that ComboFix removed was related to Rustock (a quick search on Google can verify this), so the infection should be gone.
Are you experiencing any problems with that computer?Thanks, CBMatt. She said she will update Java and download Zonealarm. The computer is working fine. If we run Hijackthis again, do we delete anything related to Logictech?Yes, the O18 entries. Make sure that they have reference to Logitech before deleting though.

Great to see your problem has been resolved and if you don't have it already may I also RECOMMEND CCleaner, as has CBMatt..Yeah, like DeltaSlaya said, just focus on the O18 entries. They're the ones that look like this...

O18 - Protocol: bw+0 - {38F58AFF-C4C6-428B-A886-84F284BFDEFF} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll (file missing)

Those are the only ones you need to worry about. Leave everything else alone. If you run CCleaner first, it might automatically clean up a lot of those for you.Thanks for all your help. Problems solved.Awesome, I'm glad to hear it.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3567.

Solve : VIRUS named GONrong.ALP??

Answer»

ok so i was on the internet with my cousins computer and a window pops up saying
system32.exe is know .bat file? i know wat a bat file is and then a download window pops up and it saying ALP casino download start it downloads and i get a new window that pops up and all my files pop UP like every ONE even the stuff like WoW pop up and it says message from user rong PC error my cousins OS is windows XP HE we had a flash file open and the internet his friend says the same thing happend to his PC it came fron something on the intern cus it open up the CONTACT list and started sending EMAILS it got maybe THREE emails through until we pulled the plug anyone ENCOUNTER this? I'm having trouble finding an infection by this name, but it sounds like a worm of some sort.
What protection do you have?

You should update all protection and scan with it in Safe Mode. Afterwards, post a HijackThis log for us to look at.know dude we cant do a thing like we get to black thing thingy but u cant do anything Without alot more info on your system. OS and what happened prior to this and alot less textspeak it's hard to move on from here.Quote from: wefr0 on AUGUST 03, 2007, 07:58:29 PM

know dude we cant do a thing like we get to black thing thingy but u cant do anything

To be perfectly honest, I have no idea what you're saying. Like patio said...we need more info, as well as coherent sentences.forget it hes out a good 1000 bucks cus of this viruses Incoherent gibberish. Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3568.

Solve : Winantispy2007 downloaded to my computer without my permission?

Answer»

You still have a couple of bad entries showing up...
O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\nyxmqbgx.dll",forkonce

O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe (file missing)


Also...make sure you delete ALL of the files I listed in my last post. Simply removing the entries isn't enough. If you're having trouble doing this, I can create a batch script that should do it for you.

I still need this...
Quote from: CBMatt on July 21, 2007, 04:54:52 PM

You appear to have a PurityScan infection. Copy everything inside the quote box below (starting with dir) and paste it into Notepad. Go up to File > Save As... and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.

Quote
dir C:\Program Files\?racle /a h > files.txt
notepad files.txt

Locate findfile.bat on your Desktop and double-click on it. It will open Notepad with some text in it. Please post the contents of that Notepad file here.
I'm sorry there wasnt anything in the notepad file I did it but it came up empty.

After fixing the others here is the hijack log.


Logfile of HijackThis v1.99.1
Scan saved at 9:48:31 PM, on 7/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\vsnpstd2.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\Program Files\Pando Networks\Pando\pando.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Raynelle\My Documents\my programs\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup
O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll
O9 - Extra button: (no name) - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra 'Tools' menuitem: CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - OPTIONS group: [INTERNATIONAL] International*
O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL CONNECTIVITY Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
I seem to be getting IE pop ups like a myspace celebrity profile and I won this crap, but I dont even have IE open.. I use Mozilla firefox. AND I have the popupblocker on IE set at block ALL popups.. In the add/remove programs list I have windows internet exlporer 7 and IEpro7 entries... is this the same thing? I also have programs that have no size on it? Im sorry I keep posting UGHH now I am getting pop ups in firefox.... something like system doctor.com your computer is under attack! get help now! You could be getting the popups through the messenger service which would indicate that your windows is not uptodate.
If this is the case then update your windows or disable the messenger service.
Start>Settings>Control Panel>Admin Tools>Services>Messenger...Disable.
Did you run the scans I suggested, all 4 of them?I am now.. sorry.. the ROGUE remover wiped out a bunch of things that said winanitspy2007. but i'm still getting the pop up. ewido is running, and so is panda active scan.

I'm getting a question from zone alarm to allow a generic hos process for win32 services to accept internet connections.. its svchost.exe???/Okay...look in C:\Program Files for a ?racle folder. The question mark is a wildcard, which means it could start with any letter. So, the folder could be called Tracle, Iracle, or (most likely) Oracle. This folder needs to be deleted. If you find more than one folder with such a name, let me know before you do anything.


Did you try this suggestion from Fed...
Quote from: Fed on July 21, 2007, 09:14:35 PM
You could be getting the popups through the messenger service which would indicate that your windows is not uptodate.
If this is the case then update your windows or disable the messenger service.
Start>Settings>Control Panel>Admin Tools>Services>Messenger...Disable.
Did you run the scans I suggested, all 4 of them?
You can also try Shoot The Messenger.

As for ZoneAlarm...it may be a legit request, but you might want to read through this thread...
http://www.computing.net/security/wwwboard/forum/272.html




Quote from: nellenaz on July 21, 2007, 09:00:46 PM
In the add/remove programs list I have windows internet exlporer 7 and IEpro7 entries... is this the same thing? I also have programs that have no size on it?
This is IE7Pro...
http://www.ie7pro.com

It's an add-on for IE7. You don't need it, but it's not malicious. Also...not all programs list their filesizes. Are any of these programs suspicious?By the way, here is some info for those programs you listed earlier...

Digital Content Portal (Comes with some Dell computers. Some consider it to be spyware, but it doesn't appear to be malicious. Can be removed if you don't want it.)
EarthLink Setup Files (Can be removed if you have no interest in EarthLink.)
f Get HI speed Internet! (Not sure what this is. Probably related to FlashGet. Should be able to remove safely.)
Macromedia Flash Player (You should keep this.)
Microsoft .NET Framework 1.1 (You might want to upgrade to 2.0.)
Microsoft .NET Framework 1.1 Hotfix (KB8928366) (Are you sure that's the right number? I can't find info on this exact hotfix.)
Microsoft COMPRESSION Client Pack 1.0 For windows (This is safe.)
Microsoft Plus! Digital Media Edition Installer (This is safe, but you don't need it.)
Microsoft Plus! Photo story 2 I.E Microsoft User-mode driver Framework feature Pack 1.0 (This is safe. Keep it if you want it.)
NetZero Installer (You can remove this if you have no interest in NetZero.)
PhotoClick (Not sure about this one. Could be related to this.)
RealPlayer Basic (Media player that probably came with your computer. It's safe.) (Safe.)
Sonic DLA (Safe, but not free.)
Sonic RecordNow! Audio (Safe, but not free.)
Sonic RecordNow! Copy (Safe, but not free.)
Sonic RecordNow! Data (Safe, but not free.)
Sonic Update Manager (Safe.)
WebCyberCoach 3.2 Dell (Came with Dell. Should be safe.)
Windows Installer 3.1 (KB89353) (This is safe.)
Windows Media Format 11 runtime (Part of Windows Media Player. You should keep this.)
Windows Media Player 11 (You should keep this.)
Apple Software Update (Safe. Probably came with your Apple Mobile Device.)
IE7Pro (IE7 add-on. Safe.)
Learn2 Player (Uninstall Only) (Bloatware installed by AOL; often comes with Dell computers. It's not malicious, but you don't need it.)
Conexant D480 MDC v.9x Modem (Modem driver. Might want to keep this.)
Digital Line Detect (Comes with Dell; used to be considered spyware. Should be safe, but you don't need it.)
AOL Coach Version 1 (build:20040229. 1 en) (AOL bloatware. Not malicious, but you don't need it.)
AOL Connectivity Services (Automatically reconnects you if you lose your AOL connection.)
Apple Mobile Device Support (Comes with the latest versions of iTunes. If you don't have an iPhone, then you don't need this.)
Viewpoint Media Player (More AOL bloatware. Technically not malicious, but I usually advise removing it.)
Windows Desktop Search 3.01 (Search tool. You don't need it, but it's safe, and might be useful.) Well I ran ALL the programs Fed suggested, coupled with what Chris told me and I seem to be in the clear. I didnt have a ?acle folder, but i did see something like that deleted with one of the programs. I'm going to run all of the programs again

Roguerunner,
AVG Free
Ccleaner
panda active scan
superantispyware
ewido online
and spybot

and see what they come up with again

how often should I run these programs?

And thank you Chris for all the information on those programs.. I'm going to be deleting a LOT today..

Quote from: CBMatt on July 22, 2007, 04:04:32 AM
By the way, here is some info for those programs you listed earlier...

Digital Content Portal
Microsoft .NET Framework 1.1 Hotfix (KB8928366) (Are you sure that's the right number? I can't find info on this exact hotfix.)

it wasn't!! it is KB928366 somehow and 8 got added.. I was c/p from microsoft onenote. so probably happened then.

AVG Free came up clean!!

Will keep you updated.

Oh and the messenger service was already disabled.

oh and no none of the programs were suspicious, I just didnt know what they were.

Thanks guys!!! You're lifesavers!!! Don't forget to keep your Windows uptodate and create a new restore point.So, no more popups, then? Excellent.

Like Fed says, you should clear your restore points and create a new one...

1. Go to Start > Programs > Accessories > System Tools > System Restore
2. Click on System Restore Settings.
3. Check Turn off System Restore and click OK.
4. Restart your computer.
5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK.
6. Create a new restore point and close the program.

System Restore will now be active again. If you would like to learn more about System Restore, go here.

Also, I see that your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. Once you have installed the latest version, you should remove any older versions of Java.

For more info on infections and how to stay clean, please read through this guide.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3569.

Solve : My connection is unstable.?

Answer»

Hi everyone,

When playing a little online game, or while using msn, i get disconnected for like 10 seconds or so and then it comes back. On my modem, the ''atm'' light turns off and the ''dsl'' one flashes red. I would need UR help to know if that problem is due to some virus, or just from my internet provider...

Thx a lot for ur help in advance.Check to make sure you have DSL filters on ALL the phone connections in the house...Hi patio, thx for replying.

Yea i actually looked on all the phones and each has its own filter. I use windows xp sp2, high speed bell sympatico internet, amd athlon 1700+, 756 RAM, etc.

The problem must be due to something else. What should I do next? I ran a AVG scan in safe mode and it didn't find anything..Spybot S&D found like 3 spywares, deleted em..and adware SE personnal found 27 tracking cookies, which i deleted too.
Call your ISP and request a line test...they can do this while you are on the phone with them.
Is this a new condition or has it always been this way ? ?
Any new construction going on in your area ?Quote from: bennyman on July 22, 2007, 09:14:21 AM

Hi patio, thx for replying.

Yea i actually looked on all the phones and each has its own filter.
...

And each DSL filter is installed in the right direction?

Please don't ask me how I know this makes a difference.


Hi,

Well in the past, like 1 year ago, i've had the same KIND of problems with my connection...I thought it was some trojan downloader that was using my connection to the max...so I just formated. But now this unstability came back. This week I should be able to call my ISP and try to do that line test. But just to make sure, I would need ur help to find out is there is any junk running on my comp with a HJT scan or ne other program. I'm not sure my computer is healthy right now...

This help would be greatly appreciated from your part.
Thx for ur time again.Run all your protection apps in safemode and then post back with the results and a HijackThis log...
The Resident Experts will be along shortly.

Make sure to list what you ran and the results,,,FORMATTING wipes the drive clean, allowing you to do a fresh install of Windows. If you formatted, then you shouldn't have to worry about malicious infections. But if you would still like us to take a look at an HJT log, you're free to post it.

EDIT: Nevermind, I just re-read your post. When you said "I just formatted" I thought you meant today. Go ahead and follow patio's advice.Due to lack of feedback, I am closing this topic. If you are the ORIGINAL poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3570.

Solve : Agh help please!?

Answer»

Hey all, this is my first post here, im HOPING to et some answers

I'm using Windows XP homeedition. WELL i turned on my computer YESTERDAY to find that none of my programs would open, except windows messenger and Internet Explorer (hence how i'm typing this). When i try to open a program, like iTunes for instance, it comes up with the message "a later version is already installed. installation cannot continue", even though iTunes is allready installed and was working fine yesterday morning.

Another problem i cant access "all programs" from the start menu, clicking on the all prgrams ICON does nothing at all. I cannot system restore as it says its unable to restore at this time. Restarting does not have any affect, starting in safe mode doesnt work and i cant completely wipe my system as im not given this option on startup, even whilst pressing "ctrl + F8"

I can however access photos and word documents ect. allthough i cannot open them due to microsoft word not working.

If anyone can shed some light on the problem, it would be much appreciated. Thanks in advance.Hornzog .......... Strange that all these issues just appeared at the same time and right out of the blue.

You are using XP home .......
Do you have sp2 installed and all the other critical updates ?

Do you have your original windows xp home edition cd if required?

Does your machine have a working updated anti-virus?

If you go to My Computer/Program files ........ open the programs folder and find the program you wish to use, are you able to open the program from there?

Did you do a windows update yesterday before this all started or any other software update?

Are you able to get into the bios if necessary?


dl65 Firstly, thanks for your interest in the problem.

I do have SP2 installed and i did have a working anti-virus system (which now doesnt start up)

I have the windows home edition CD

I did not install any updates before the problem occured, but Windows Automatic Updates keeps trying to update the same security update over and over again.

I was able to install Microsoft Office again by using the CD, and itunes now opens through clicking on a music file in my documents.

Not being totally familiar with computers I don't know what bios is/how to access it.

Through program files i can access a few programs like Windows Media Player, Guitar Pro, but not everything. It seems most of the programs downloaded via the internet work without too many problems. But theres no sign of my anti-virus. And where i used to have around 10 programs starting up, which appeared in the task bar, nothing no longer starts up and the internet only connects when i open internet explorer.

Thanks for your reply.Do you have any antivirus installed?
did it detect and erase any suspected threats?

3571.

Solve : storm worm??

Answer»

And if you THINK you might be infected, you may want to POST a HijackThis log.Due to lack of feedback, I am closing this topic. If you are the original POSTER and you would like this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3572.

Solve : reset all cookies reset every ie startup?

Answer»

all protection programs have different database and different names for the same infection. those might have found it but couldn't remove it or just quantined it. superantispyware as a nice vundo database along with other infections. and some infections just need specialty tools to remove them completelyWell, your main infection was Vundo. I'm not sure why VundoFix didn't pick it up...it should have recognized the infection because it's not a new version. PERHAPS it was old enough to not be supported. I will see if I can get an ANSWER from the creator. Anyway...although you had Vundo, I don't think it was the one changing your settings. You also had an IE hijacker, which I believe was causing the problems you described. In addition to these, you had a couple of infections that I can't identify.

As for why McAfee and Spyware Doctor didn't catch the infection, just look at unlovedwarrior's post. Personally, I would consider switching from McAfee to AVG Free. It's free and tends to clean infections better than McAfee. I think their firewall is great, but their anti-virus leaves something to be desired.

And yes, there are changes you can make to increase your security. First of all, you should clear out your restore points and create a new one...

1. Go to Start > Programs > Accessories > System Tools > System Restore
2. Click on System Restore Settings.
3. Check Turn off System Restore and click OK.
4. Restart your computer.
5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK.
6. Create a new restore point and close the program.

System Restore will now be active again. If you would like to LEARN more about System Restore, go here.

I see that your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next.

For future prevention, I would suggest AdAware SE Personal, AVG Anti-Spyware, and Spybot - Search & Destroy for spyware/adware. You should have at least two of these installed on your program (one may pick up what another can't) and update them regularly. For viruses, AVG Anti-Virus is a very good choice. In my experience, it has been one of the best. And again, make sure you update it regularly. It would also be a good idea to have CCleaner handy for cleaning up unnecessary temporary files and registry entries. Do this at least once a week. I would also advise downloading SiteAdvisor and SpywareBlaster, which will both make your internet browsing a lot safer.

Also...you're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.

For further information on keeping yourself protected, check out this malware guide.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3573.

Solve : Spybot?

Answer»

I recently tired to download Spybot on to my laptop and it went through then told me that I need to have to adminstrator password which is myself, and when entered it STILL didn't go through, so I couldn't FINALIZE the download, what should I do?which browser are you using?
when it refers to "administrator password" it COULD be refering to a master password which is set in the browser. You can access it through options or internet settings..depending on which browser you're using.

3574.

Solve : Safemode lockout?

Answer»

I downloaded Embarq online security software,I did not disable My Windows XP Firewall prior installing the other firewall,now I do not have any icons or start menu and my safe MODE is a dark screen.how do i disable one of those firewalls,without being able to acces safe mode and get to add and remove programs.login to your pc, and when you arrive at your iconless and taskbarless desktop, PRESS ctrl+alt+del and add NEW task 'explorer.exe' and see if you can access add/remove programs from there.I tried explore.exe to no avil,Ispent 45 min.with an embarq IT and ET in TASKMANAGER,without any results.hmm....INSTEAD of task manager...try pressing start button + r to bringup the run menu. then type explorer.exe

3575.

Solve : Trojan Downloader on XP...Mega Problems?

Answer» Combofix Part II

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 21:3863128---------C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 01:07]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46]
"HostManager"="C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe" [2006-09-25 20:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]

[HKEY_LOCAL_MACHINE\SYSTEM\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Trent Berger^Start Menu^Programs^Startup^Anapod Manager.lnk]
path=C:\Documents and Settings\Trent Berger\Start Menu\Programs\Startup\Anapod Manager.lnk
backup=C:\WINDOWS\pss\Anapod Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
C:\Program Files\Blubster\Blubster.exe SILENT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
"C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
C:\PROGRA~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\autorun.exe


Contents of the 'Scheduled Tasks' folder
2007-06-15 06:39:50 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-04 05:51:53 C:\WINDOWS\tasks\MP Scheduled Scan.job

**************************************************************************

catchme 0.3.914 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-04 02:30:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-04 2:32:14
C:\ComboFix-quarantined-files.txt ... 2007-07-04 02:32

--- E O F ---Hijack This
Logfile of HijackThis v1.99.1
Scan saved at 2:35:58 AM, on 7/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Trent Berger\Desktop\HijackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dell.com/
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL CONNECTIVITY Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Your HijackThis log looks clean to me. ComboFix picked up quite a few infected files, WinAntiVirus in particular. Even after running the scans, are you still experiencing PROBLEMS?

I noticed that you have Blubster installed on your computer. According to reviews, it hosts a lot of risky downloads (like all file-sharing programs) and it seems to cause a fair amount of system instability. On top of that it is bundled with third party adware. You don't have to get rid of it, but if I were you, I would. You can read a little about it here.

Also, I found this in your ComboFix log...
C:\Program Files\Kap.GRETests

Are you at all familiar with this? It appears to be related to Jersey Cow Software, but I can't find any actual information on it.



As for the programs you have downloaded...although you don't have to, I would advise keeping the anti-spyware programs. Unfortunately, there's not one program that can detect everything, so it's good to have a few. And the ones you have are some of the best. However, you don't need all of them...but you should have two at the very least.

I would also suggest keeping CCleaner. It's very handy and you should run it a couple of times each WEEK to help tidy things up a bit.

Once we are done here, you're free to get rid of HijackThis and ComboFix if you wish. You can delete the logs at any time. Once you post them here, there's no need for them on your computer.Thanks again, a few questions.

1) What can I do to clean up my infected files and programs?
-You stated combo fix found a lot of files, and that I have the GRE program and blubuster.
-How can I get rid of these and get my computer fixed?

2) Why is it I keep every few days getting the same viruses found again on symnatec?
-Is there anything I can do to fix this thing once and for all?

3) The computer is better, but not 100%.
-I am most concerned about deleting all iffy programs AND
-The combofix infected files
-Reappearing virusesComboFix removes all infected files. If they keep coming back, then there's definitely something else going on. Go ahead and run the program again and post another log.

And I hate to make you get another program, but I think you should download and save Blacklight to your desktop:

Double-click fsbl.exe then accept the agreement and click on Scan. Once it's complete, click on Next.

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"







As for Blubster...you should be able to uninstall it through Add/Remove Programs. You should be able to do the same with Kap.GREsts, but I'm not sure what it might be called. Perhaps we can take a look at the programs installed on your computer. Go ahead and open up HijackThis. Click on "Open the Misc Tools SECTION" and then "Open Uninstall Manager". From there, click on "Save list" and save the Notepad file to your desktop. Open that file and paste the contents here.1) Combofix Log Part I

"My Name" - 2007-07-06 11:29:57 - ComboFix 07-07-03.9 - Service Pack 2


((((((((((((((((((((((((( Files Created from 2007-06-06 to 2007-07-06 )))))))))))))))))))))))))))))))


2007-07-04 02:2351,200--a------C:\WINDOWS\nircmd.exe
2007-07-02 02:54d--------C:\Program Files\CCleaner
2007-06-30 15:0110,872--a------C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-28 04:221,060,864--a------C:\WINDOWS\system32\mfc71.dll
2007-06-15 02:44d--------C:\Program Files\iTunes
2007-06-15 02:44d--------C:\Program Files\iPod
2007-06-08 16:04d--------C:\Program Files\Lavasoft
2007-06-08 16:04d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-08 16:03d--------C:\Program Files\Common Files\Wise Installation Wizard


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-06 14:47:38--------d-----wC:\Program Files\Symantec AntiVirus
2007-07-04 16:25:5217,634----a-wC:\WINDOWS\system32\nvModes.dat
2007-07-02 03:31:594,755----a-wC:\WINDOWS\mozver.dat
2007-06-30 05:42:23--------d-----wC:\DOCUME~1\TRENTB~1\APPLIC~1\Wal-Mart Digital Photo Manager
2007-06-30 04:50:34--------d-----wC:\Program Files\Google
2007-06-21 23:35:29--------d-----wC:\Program Files\America Online 9.0
2007-06-15 06:42:27--------d-----wC:\Program Files\QuickTime
2007-06-15 06:39:49--------d-----wC:\Program Files\Apple Software Update
2007-06-11 20:21:02--------d-----wC:\Program Files\Common Files\AOL
2007-06-04 19:18:489,344----a-wC:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 19:17:028,320----a-wC:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 19:14:566,272----a-wC:\WINDOWS\system32\drivers\AWRTPD.sys
2007-05-25 19:47:21--------d-----wC:\Program Files\Kap.GRETests
2007-05-16 15:12:02683,520------wC:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15144,896------wC:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:232,854,400----a-wC:\WINDOWS\system32\msi.dll
2007-04-17 02:47:3633,624----a-wC:\WINDOWS\system32\wups.dll
2007-04-17 02:45:541,710,936----a-wC:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48549,720----a-wC:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42325,976----a-wC:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36203,096----a-wC:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:2892,504----a-wC:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:2053,080----a-wC:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:2043,352----a-wC:\WINDOWS\system32\wups2.dll
2007-04-13 19:19:527,680----a-wC:\WINDOWS\system32\lsdelete.exe
2007-04-13 17:31:03103,984----a-wC:\WINDOWS\system32\AOLDial.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-01-12 21:3863128---------C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 01:07]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46]
"HostManager"="C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe" [2006-09-25 20:52]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C
"tscuninstall"=%systemroot%\system32\tscupgrd.exe

2) ComboFix Log Part II

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Trent Berger^Start Menu^Programs^Startup^Anapod Manager.lnk]
path=C:\Documents and Settings\Trent Berger\Start Menu\Programs\Startup\Anapod Manager.lnk
backup=C:\WINDOWS\pss\Anapod Manager.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster]
C:\Program Files\Blubster\Blubster.exe SILENT

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
"C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
"C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Wireless Manager UI]
C:\WINDOWS\system32\WLTRAY

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend]
C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
C:\PROGRA~1\SYMANT~1\VPTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
"C:\Program Files\Windows Defender\MSASCui.exe" -hide


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
AutoRun\command- E:\autorun.exe


Contents of the 'Scheduled Tasks' folder
2007-06-15 06:39:50 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-06 14:50:01 C:\WINDOWS\tasks\MP Scheduled Scan.job

**************************************************************************

catchme 0.3.914 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-06 11:32:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-06 11:32:42
C:\ComboFix-quarantined-files.txt ... 2007-07-06 11:32
C:\ComboFix2.txt ... 2007-07-04 02:32

--- E O F ---
3) Whenever I do ComboFix
-Internet Explorer icon automatically is downloaded onto my desktop.
-Why? Is this a problem?


4) FSBL downloaded
-Scanned, no problems
-Log

07/06/07 11:41:59 [Info]: BlackLight Engine 1.0.64 initialized
07/06/07 11:41:59 [Info]: OS: 5.1 build 2600 (Service Pack 2)
07/06/07 11:41:59 [Note]: 7019 4
07/06/07 11:41:59 [Note]: 7005 0
07/06/07 11:42:05 [Note]: 7006 0
07/06/07 11:42:05 [Note]: 7011 1580
07/06/07 11:42:05 [Note]: 7026 0
07/06/07 11:42:06 [Note]: 7026 0
07/06/07 11:42:08 [Note]: FSRAW library version 1.7.1022
07/06/07 11:46:11 [Note]: 2000 1012
07/06/07 11:46:11 [Note]: 2000 1012
07/06/07 11:46:11 [Note]: 2000 1012
07/06/07 11:46:11 [Note]: 2000 1012
07/06/07 11:47:28 [Note]: 7007 0


5) Hijack This Logfile

Logfile of HijackThis v1.99.1
Scan saved at 11:48:10 AM, on 7/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\BitLord\BitLord.exe
C:\Documents and Settings\Trent Berger\Desktop\HijackThis(2).exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dell.com/
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe


6) I months ago thought I deleted all of kaplantests and bluebuster.
I can not find it on add/remove.
-Why is it not deleted when I already thought it was done
-Is there anything I can do to finish?


7) Do I need to save and keep the logs of ComboFix, FSBL, and HiJack This or may I delete?


When I download music, not often I
-Go to isohunt, download torrent with bitloard
-Would you call this safe and is there anything I can do to safeguard?
-Should I run a cleaner after?

Thanks.Everything looks clean to me. You may want to give the Outerinfo remover a try. I have my suspicions, but we're running out of options, and it might work...
http://www.outerinfo.com/howto.html

ComboFix might be making a change to the registry that causes the IE icon to appear on your desktop. I don't have a definite answer for this, but I've seen it before and I wouldn't be concerned.

If you already removed those programs, then they may have just left some files behind. Most programs will still leave something behind, even after you've uninstalled it.

You can go ahead and delete the logs.

And yes, you should scan those downloads. In fact, you should can ALL downloads once they're on your computer.Alright

1) I downloaded the program, it says everything is deleted.

2) According to you do you think my computer is safe for the time being?
Knock on wood it is running fine.

3) What do you think the problem was or how did it become?

4) Do you have a recommendation on what I can do to keep it safe from now on, should I keep
-Symnatec anti-virus active
-AVG spyware active
-Have Ad aware, spybot search and destroy, ewido spyware as backups
-HiJack this, ComboFix, and CCleaner all stay on the computer and run everything once a week?

Is this a good a plan or do I need to add anything or delete?
Hijack this and Combofix, should those be run only when necessary not regularly?

5) Should I encounter a problem in the future, what can I do to make sure if I must reformat I have everything and don't lose material?

Thanks.If your problem is gone and stays that way, then I have no reason to think you need to worry about anything.

There are many ways to get infected. My guess would be that you downloaded something that installed third party software without your knowledge. It's always a good idea to read the EULA before installing anything. EULAlyzer is a helpful program...
http://www.javacoolsoftware.com/eulalyzer.html

To learn more about how you may have been infected and for even more prevention tips, read Tony Klein's protection article.

Personally, I'm not a fan of Symantec/Norton and would suggest replacing it with AVG Free. However, if you are happy with it and wish to keep it, then that's fine. Your anti-spyware programs are all good and should be kept. AVG Anti-Spyware is a very good program, but unfortunately, once the trial runs out, the resident shield is disabled. Because of this, I think Spybot would be better as your active anti-spyware. But as long as you perform regular scans, it won't make much of a difference. With all of these backups, you've got a good arsenal.

You should keep CCleaner and run it at least once a week. I run it everyday, but that's just my preference. HijackThis and Combofix should only be run when needed again. I would suggest keeping them someone on your computer, though.

If you encounter further problems, the best thing to do is update your protection programs and then scan with each one in Safe Mode. If your problem still persists, then you can post another HijackThis log and ask for assistance. If it ever gets to the point where you need to reformat, you should back up all of your important data (pictures, documents, media) onto CD's. There are loads of free burning programs out there. It's usually advised to simply re-download software rather than backing it up. This is entirely up to you, of course.

If you have any other questions, I'll be happy to answer them to the best of my ability.1) Thank you very much for your time and helpfulness. I really appreciate your continued interest and responses to my serious questions.

2) I'll review the links on the EULA analzyer plus the protection.

3) As far as further things to do, my AVG anti spyware trial ran out.
-What does this mean, it still automatically boots up on my computer and says I am "now" protected against 864,XXX threats, yet the icon is now black and white as opposed to colored.
Is it actually working and protecting me or not and is there any use in keeping it active?

4) When I run the CCleaner, it deletes about 19.5 mb of files each time, is this normal?
-Additionally when I run "scan for problems" the same problems appear, again should this be of worry?

5) How do you download material onto CDs that allow them to be "backed up" if reformatted
-Internet browser settings
Desktop icons
-Programs
-Documents
-Pictures
-Music?

Thanks.1. You're very welcome. It's my pleasure to help out when I can, and I'm glad to be of service.

3. This is what I was referring to in my last post when I said that the Resident Shield will be disabled. AVG Anti-Spyware is still fully functional after the trial runs out. However, the live scanning no longer works. This means that it doesn't scan incoming files and you have to perform scans manually. The same goes for updates; it will no longer update automatically, so you have to go to the Update tab and do it yourself. The program is still very useful, but I would suggest keeping Spybot active instead, and have AVG as your backup when you perform routine scans.

4. Depending on the connection you have, this is probably normal for CCleaner. Especially if it's set to also scan Temporary Internet Files. I'm on a slow dial-up connection and I tend to get about 6 to 12 MB in a day. Of course, this depends on your activities. I just performed a scan and included my Temporary Internet Files (which I only do about once a week), and it added on an additional 95 MB. Make sure you click on Run Cleaner each time.

As for the registry scan...what issues keep coming up? Are you clicking on Fix selected issues?

5. For backing up info onto CD's, you first need to make sure you have a CD-R/RW drive. Typically, the front of the CD drive will say something about Compact Disc ReWritable. Another thing you will need is burning software. CDBurnerXP Pro is a decent program. Lastly, you need blank CD-R/RW discs. These days, you can get 50 for about $15.

Burning programs are usually fairly self-explanatory (select the files you want and the program to copy them), but if you need help, let us know.Thanks again.
I have in the past downloaded music and burnt it on to CD, it is right to assume then I have the necessary components on my computer to back up information, is it really any different?
What do you, simply click save to CD, and the once reformatted download it from the CD?

Thanks.Yes, it's a lot like burning music. But instead of burning a music CD, you're burning a data CD. The process is essentially the same, though. And so is the equipment. And yes, after reformatting, you simply insert the CD's and take the data off. Personally, I think an external hard drive would be easier and more reliable, but they're also a bit more expensive.
3576.

Solve : 3 Antiviruses - Will they work together??

Answer»

Sorry if this is in the wrong place, i just thought since this was about viruses and malware...
Does anyone know if i can use Kaspersky 6, Avast, and Zonealarm 7.0 together without problems?
Haven't researched the newest update for Avast so insert whatever number is the latest.NO, do not use more than ONE active antivirus scanner at the same time as they will conflict.

Personally I recommend AVG Free or what I use NOD32.i encountered a similar problem before. my windows xp home had been underperforming for a while. so i used norton antivirus and ran a full SYSTEM scan. the results showed that i had over 300 trojans. However, norton erased them all in one clean SWEEP. I did the scan in normal mode.
What i suggest, is you uninstall 2 of the antivirus softwares, and RUN a scan again using the remaining antivirus software, and see if the threats are erased for good.ZoneAlarm is a FIREWALL, so you should keep it. As for an anti-virus, however, only one is recommended. Using more than one may make it difficult to detect and clean infections, and it may also cause problems with your computer's performance. I would go with AVG, but Kaspersky and Avast are also good choices.So, i should keep zonealarm as a firewall and install avg? Zonealarm also has an antivirus, does that mean i should disable it?Ah, didn't think about that. Yes, I think it would be better to disable it and use the AVG anti-virus instead. But it's entirely up to you, of course.

And personally, when it comes to a firewall, I prefer Comodo, but again...that's up to you.Zonealarm 7 uses the Kaspersky AV engine which in my opinion is just as good (if not better) than AVG. So I would suggest you only use Zonealarm then.
But like CBMatt said... it is entirely up to you.Basically...it's DIFFERENT strokes for different folks. But it doesn't necessarily mean that one is better than the other (we could debate this forever). Whatever you decide upon, just make sure you only have one.Could i use comodo in conjunction with zonealarm?No, you should never have two firewalls. This will create a lot of complications and it may compromise your security, as well as cause lag on your computer.

3577.

Solve : new start up entry?

Answer»

My pc has been running slow for a while after start up. I checked the start floder and found a new entry ZSSnp211.exe. Can any body help with info on this please .Thanks.Quote from: Richenstony on AUGUST 09, 2007, 02:35:01 AM

http://www.majorgeeks.com/downloadget.php?id=5554&file=10&evp=4122712c2af084c815e5fd4f2b249d83


The download above is for a program called hijackthis , it can detect anything hiding that could be malicious all though it also picks up general window processes , so it cant tell whats bad ........ scan and save log and post your log in the virus section..... do not attempt to FIX anything!
Post the log for us to have a look at tedder,
ZSSnp211.exe is a file often ASSOCIATED with Bigdog/Vimicro, who make various products, the most common being webcams. Although they mainly cater to the Chinese market, they're not exclusive to the area. I'm not 100% sure exactly what this particular file does, but I believe it is your webcam DRIVER. It shouldn't be anything malicious. You can try disabling it, but it may cause your webcam to not function properly. That's about the best ANSWER I can give you.

However, I'm fairly confident that you don't have anything to worry about. But if you wish, you may still post a HijackThis log.
3578.

Solve : Trojan Horse Removal?...?

Answer»

Well I got careless of what I was downloading so now I am stuck with Advertisment Pop-ups, my computer starts extreamly slow, and I think it is hidden. When I do a virus scan with AVG Free I delete the INFECTED files but when I am connected to the internet the Trojan DOWNLOADER downloads all the same viruses/trojans that I deleted, same thing with the adware (Which I use Spybot Seek & DESTROY) is there a way where I can delete all these viruses/trojans without reinstall Windows? Any help would be apperiated.DLoad install update and run AVG Anti-Spyware which is also free...it's more designed for removing trojans which it seems you have...

After that DLoad and run HijackThis...DO NOT LET it fix anything ...instead save the log as a file and post it here after your finished.

It may take 2 or 3 POSTS to fit it all.If i were you, i'd purchase some antivirus software. I'd recommend Norton Internet Security, and Win Antivirus Pro. But if you want to cut back on the cost, you can always just get Norton Antivirus. When i first ran a full system scan using Norton Antivirus, I discovered over 300 trojans. All of them were removed cleanly, and quickly.He has an anti-virus program...

AVG is better than adequate protectionQuote from: JXY on August 08, 2007, 05:34:26 AM

If i were you, i'd purchase some antivirus software. I'd recommend Norton Internet Security, and Win Antivirus Pro.
AVG Free is easily superior to these programs. In fact, we often advise removing Norton. And we always remove WinAntiVirus Pro because it's basically considered an infection.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
3579.

Solve : avg process?

Answer»

every time I try to connect to net the avg update process takes place is this normal , taI'm not sure if that is the AVG default or not but I have my auto update turned off because I'm on dialup & prefer to update when it suits me.How LONG has this been happening? How often do you connect to the internet? I'm guessing it's probably just a coincidence. AVG updates PRETTY often, which could be the cause. You could try TURNING off the automatic updates, although I wouldn't really suggest doing so.It's a normal running process...if you click on Schedule in the main PANE and select properties below you can set the time at which AVG updates daily.

3580.

Solve : strange files?

Answer»

Hi. Please excuse me because I've never posted to any forum before.
I had a tech over to check my computer and he found a whole series of files that started out as t1oo (26 of these) and t350 (14 of these) with all different extensions like am, ar, at, b0, etc. They were all 0 KB and had the same modification date. The times for one group was the same, then the next group would be a few minutes later, etc., but all times were between 1:47 and 1:59 PM. When I checked Properties, it said no viruses were found, but it's still a bit disconcerting to have all these useless (?) files there.
He said he was totally unfamiliar with this, did some searching on the web and came up with nothing. Does anyone know what these are, and can I delete them?

I sure hope I can find my way back here to see if anyone has an answer.

BTW, Dell DIMENSION E510, XP Media Center Editon, SP2. Is that enough info?

ArtieWhat dfirectory were they in ? ?
Installed any new hardware/software recently ? ?
Are you USING a webcam or digital camera on that machine ? ?I clicked on My Computer and then Local Disk (C:) and there they were.

No webcam or digital camera.

I had to reinstall my HP printer about a week or two ago because I had done a "restore" trying to get my computer to work better (it sort of had the hiccups and was really slow) and I lost my printer. But nothing was installed on the date that says these files were "modified".

So they are in the root folder of C: ? ?

List all the protection programs you have installed currently and we'll go from there...If opening My Computer and double clicking on Local Disk (C:) which opens a window with a heading of C:\ means it's in the "root folder" of C, then yes.

And by protection programs, I assume that you mean virus, spy and trojan protection?

CounterSpy, Trend Micro PC-cillin, Trojan Hunter, to the BEST of my knowledge (which is obviously quite limited)

I'm not real good at technical stuff.Remove all those programs, I think one of em is actually spyware itself...

GO to www.avast.com, get the free anti virus and enjoy yourself.

And delete those files. They are nothing.Keep your protection programs they are fine.Quote from: lil_falco on August 10, 2007, 07:15:44 PM

Remove all those programs, I think one of em is actually spyware itself...

GO to www.avast.com, get the free anti virus and enjoy yourself.

And delete those files. They are nothing.

Ignore this advice.

Update and run the protection programs you have in safemode.
To enter safemode tap F8 repeatedly after turning the machine on and before you see the Windows splash screen.
Let them fix what they find.
Then DLoad and install HijackThis. Install it in it's own directory not the Desktop.
Run a scan with it. DO NOT let it fix anything yet.
Save the log as a text file and post it here. It may take 2 or 3 posts to include the entire log.
3581.

Solve : CPU usesage reads 100%?

Answer»

Lately I have had to do a restore on my computer every other day. Seems that my computer cpu usage jumps up to 100%. After the restore it goes down to 28% and my computer functions OK. Could this be due to a virus? I run AVG anti virus on my system.

Thanks

EdYou are restoring every other day ? ?
What method ? ?
System restore ?what other protections do you haveUse the Task Manager (Ctrl + Alt + Del ... click on the Processes TAB...a screenshot would help) or Process Explorer to see what's USING up so many resources.Due to LACK of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3582.

Solve : V:15A 2121 Aueno5 12 Do you know what this is??

Answer»

I have a blue field in my left hand CORNER of my screen. It has V:15A 2121 Aueno5 12 in that field. Since I have had the message I find that when my screen goes to the screen saver I get flashing bright lights instead of the screen saver. When you look at the desk top items and go to click on ONE it is like the message is above it on the computer screen. I need help this is driving me crazy! I am SORRY if this has been posted some where else. I am new to this web site.Could you give us a screenshot? Hit the Print Screen key and go to Start > Programs > Accessories > Paint. Upload the picture to a site such as PhotoBucket and post the link here. Also, what OS do you have?Due to lack of feedback, I am CLOSING this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with INFORMATION about your computer and your problem.

3583.

Solve : Registry Entry?

Answer»

The following is appearing in my registry, I have know idea where it came from and I cant delete it.

HKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò


Please find my logfile if is of any assistance.

Logfile of HijackThis v1.99.1
Scan saved at 2:54:57 PM, on 24/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASWLSVC.exe
C:\PROGRA~1\OPTUSI~1\backweb\5543390\Program\SERVIC~1.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Optus Internet Security Suite\backweb\5543390\program\fsbwsys.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe
C:\Program Files\Optus Internet Security Suite\Common\FSMB32.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Optus Internet Security Suite\backweb\5543390\Program\fspex.exe
C:\Program Files\Optus Internet Security Suite\Common\FCH32.EXE
C:\Program Files\Optus Internet Security Suite\Common\FAMEH32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsqh.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsrw.exe
C:\Program Files\Optus Internet Security Suite\FSPC\fspc.exe
C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsav32.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI TECHNOLOGIES\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\ASUS\WLAN CARD Utilities\Center.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\PROGRA~1\OPTUSI~1\ANTI-S~1\fsaw.exe
C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Optus Internet Security Suite\FSGUI\fsguidll.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Gary & Sue\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://desktop.optusnet.com.au/dsl/favorites/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://desktop.optusnet.com.au/dsl/favorites/homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.optusnet.com.au/dsl/favorites/homepage
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [Control Center] C:\Program Files\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Optus Internet Security Suite\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Optus Internet Security Suite\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
O4 - Global Startup: Optus Internet Security Suite.lnk = C:\Program Files\Optus Internet Security Suite\backweb\5543390\Program\fspex.exe
O8 - Extra context menu item: &Block this popup - C:\Program Files\Optus Internet Security Suite\Anti-Spyware\blockpopups.htm
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Optus Internet Security Suite\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Optus Internet Security Suite\Anti-Spyware\ieshield.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://desktop.optusnet.com.au/dsl/favorites/homepage
O23 - Service: ASWLSVC - Unknown OWNER - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Optus Internet Security Suite (BackWeb Plug-in - 5543390) - Singtel Optus - C:\PROGRA~1\OPTUSI~1\backweb\5543390\Program\SERVIC~1.EXE
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
O23 - Service: FSBWSYS - F-Secure Corp. - C:\Program Files\Optus Internet Security Suite\backweb\5543390\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FSPC\fshttps\fshttps.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

A .DLL file appears to be disrupting the LSP chain on your computer. We need to get rid of it.

  • Please download LSPFix from here.
  • Run the LSPFix.exe that you have just finished downloading.
  • Check the I know what I'm doing box.
  • In the Keep box you should see one or more instances of winsflt.dll.
  • Select every instance of winsflt.dll and move each one to the Remove box by clicking the >> button.
  • When you are done click Finish>>.

Other than that, your log looks pretty clean. However, you do have this...

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

It's related to RealTek. Technically, it's considered spyware, but it isn't malicious. You don't have to remove it, but if you wish, I can tell you how.

Once you have run LSPFix, update your anti-virus program. Then download SUPERAntiSpyware and update that. Reboot in Safe Mode and scan with each program, one at a time.

Then restart and update us on how things are running.

Also...are there any keys inside of that registry entry?Thanks so far for your help.

I have done all that you have outlined above and yes there are other keys in this problem I would like to get rid of.

HKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer
HKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer\Recent File ListHKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer\Settings

Can you explain to me how to delete the above without having to re format again.

CheersOkay...I'm thinking two things. Either you have Hadith Viewer installed on your computer, or you have an infection (at this point, I suspect VX2). The strange characters make think the former might be a possibility, as Arabic wouldn't show up properly in the registry. Do you have Hadith Viewer installed on your computer? Check your Add/Remove Programs list (look for anything that might relate to the name HViewer). If it's there...did you install it? And if so, where did you download it from? I don't believe the program is malicious, but many sites hosting it are known for having risky downloads.

If you do NOT have Hadith Viewer installed, then follow these instructions...

Download CCleaner (install without Yahoo! toolbar) and configure it according to this guide. Run the Cleaner and Issues.


Download and install the latest version of Ad-Aware. If you have an older version, choose to uninstall it when prompted. After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run. Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".

Close Ad-Aware, if it is CURRENTLY open.
Download the VX2 Cleaner 2.0 Plug-in from Here
  • After installing, restart Ad-Aware before running the VX2 Cleaner.
  • Using VX2 Cleaner 2.0
NOTE: If you have earlier attempted to run Ad-Aware to remove VX2, you may need to run the VX2 Cleaner several times to remove possible VX2 remains.
  • If you have already attempted to remove VX2 with Ad-Aware, do the following:
    • Before running the VX2 Cleaner, make sure other anti-virus or anti-spyware applications are closed.
    • Run the VX2 Cleaner. If you computer is infected with VX2, a dialog box with text such as “New VX2 variant found” or “VX2 variant 1 found” will appear.
    • Press "Clean" and a dialog box with text “The first phase completed. Please reboot and perform a Smart Scan" will appear. After saving your work, reboot your system manually.
    • Repeat this until the VX2 Cleaner reports "System clean". Press "Close” to exit.
    • Run Ad-Aware one more time and scan your computer to make sure VX2 has been found and removed.
    Manually download Latest definition file: Here
    • Please Note Version SE Build 1.06 is now available! This download is for use with Ad-Aware SE versions only.
    • Manual Installation: Unzip the archive, replace the existing file and restart Ad-Aware\Ad-Watch.
    • You can also use the webupdate component implemented in Ad-Aware to install this update.


    Go ahead and post back with an update on how things are running.Cheers Mate.

    I will be offline for a few days and I will let you know how I get on.Alrighty, we'll leave the light on for you.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    3584.

    Solve : virus software cant remove on windows update?

    Answer»

    i have this contra virus software tring to get us to buy it weird thing is it is comming throgh our windows update icon and we CANT seem to get it to stop and it is bothering the way we use the computer when the message comes up on our computer that our system has been infected we already have virus software what can i do please anyone that can help it is real bothersomeyou might be infected with smitfruad.. what OS and other protections do you have?

    look here for removal instructions of this infection.


    oh and can i get a mod to move this to the virus section please and THANK youA question for the mod as he has to go to here anyway:
    Why has doitinachevy 0 posts?!
    He just posted wright?

    Jonas

    Edit:Oh its off topic!
    Sorry my bad. I though we were in other.lol its ok. i Pm a mod to move this postthanks ChrisQuote from: doitinachevy on July 25, 2007, 07:16:03 AM

    i have this contra virus software tring to get us to buy it weird thing is it is comming throgh our windows update icon and we cant seem to get it to stop and it is bothering the way we use the computer when the message comes up on our computer that our system has been infected we already have virus software what can i do please anyone that can help it is real bothersome


    Hi all,



    After a long time not visiting the forum, where I apologise for, I'm back.


    @doitinachevy : What antivirussoftware are you using ?

    Hopefully not Norton or Mcafee.


    Do you have any antispyware tools installed ? If yes : which ones ?

    Quote from: unlovedwarrior on July 25, 2007, 08:16:16 AM
    thanks Chris
    No problemo.

    I agree that this sounds like SmitFraud. doitanechevy, please FOLLOW the link in unlovedwarrior's post and then post back with a HijackThis log and an update on how things are going.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a NEW Topic with information about your computer and your problem.
    3585.

    Solve : Win32 DNS Changer,Zlob DNS Changer?

    Answer»

    Hi All,I'm back again.After following advice on here,I use (amongst other things) Spybot search & destroy.It has pinpointed the spyware as in the topic title.When I click the fix problems button it says they're fixed but another scan shows they are still there.I did a general GOOGLE search for both,The win32 one showed up on a french site but GOOGLES translation didn't help much! The zlob one showed a couple of sites to fix the PROBLEM but the spyware changed the site & diverted me away from it!
    I started to follow these suggestions "NOTE: New users might find going through the following steps to be useful:

    1. Turn off System Restore if applicable. (Windows ME & XP users)"
    When I do this,I get a window that says"You have chosen to turn off System Restore.If you continue,all existing restore points will be deleted and you will not be able to track or undo changes to your computer.Do you want to turn off System Restore?"
    I'm not sure I want to delete the existing restore points.I have downloaded hijack this so can do a logfile if it helps.

    You should delete all your backups because they may contain backed up malware. Therefore if you were to restore it you would be RESTORING the malware.

    Yes, please post a HJT log and experts will take a look at it for you.don't delete them yet wait until we have cleared your infection.. dl superantispyware... and what other protections do you have?? and what windows do you have? and please post a log after youve done a complete superantispyware scanAre you PERFORMING your scans in Safe Mode or in Normal Mode? If you do the scans in Safe Mode, there's a much higher chance of removing the infection. Give it a try, and if you're still having problems, feel free to post a HijackThis log.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

    3586.

    Solve : MP3 software virus?

    Answer» HI I've tried to delete this mp3 software that my uncle installed from my computer using Add or remove but it wouldn't let me. My anti-virus picked a few GENETIC trojan from that software. I deleted it's folder in program files. But in Add or remove it's still there. Please help... Thankyou

    Here's my HJT log:

    Logfile of HijackThis v1.99.1
    Scan saved at 4:22:21 PM, on 7/25/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Common Files\AOL\1125001301\ee\aolsoftware.exe
    C:\Program Files\AIM6\aim6.exe
    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
    C:\Program Files\AIM6\aolsoftware.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\cidaemon.exe
    c:\program files\common files\aol\1125001301\ee\aexplore.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Program Files\HJT\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimtoday.aim.com/today/aimtoday.adp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/
    R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {B339E38A-22DD-4425-92C2-3C15F9643F4B} - C:\WINDOWS\system32\vtutu.dll (file missing)
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll (file missing)
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125001301\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00001024-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter24 Class) - http://download.netmarble.com/web/nmstarter/NMStarter24.cab
    O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab
    O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
    O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
    O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
    O16 - DPF: {89981B1D-07DA-43C3-9770-06C51E7E5DCE} (NostaleWebStarter Control) - http://game.nostale.com/sso/NostaleWebLauncher.cab
    O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
    O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdfense8237.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
    O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
    O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
    O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {F7899FAE-51C9-4EF5-B98C-A64997635235} (GSPRunGame Class) - http://www.playinfinity.net/cab/WindyGSPAx.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exewhats the software name? have you tried in safe mode?? get Ccleaner and run the cleaner then go to tools on the left hand side. and see if you can uninstall it from there. If not then report back with any error messages. if you can then run the issues scan also on the left side above tools, save when prompted to and make SURE you save somewhere where you will remember. the issues scan a couple of times to make sure your registery is cleaned up good.

    also what protection programs are you usingScan with HijackThis and check the following entries...

    O2 - BHO: (no name) - {B339E38A-22DD-4425-92C2-3C15F9643F4B} - C:\WINDOWS\system32\vtutu.dll (file missing)

    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab


    Close all other windows and click on Fix Checked.

    You've had a past Vundo infection, so you may want to follow the below instructions, just to be on the safe side...

    1. Download VundoFix and save it to your desktop.
    2. Run VundoFix and click on Scan For Vundo.
    3. Once it's done SCANNING, click on Remove Vundo.
    4. When it prompts you to remove the files, click on Yes.
    5. Your desktop will go blank as it's removing files. Don't worry, this is normal.
    6. It will prompt you to restart your computer, so click OK.
    7. When your computer is turned back on, your problem should be gone.
    8. The program normally produces a Vundofix.txt file. Please locate this file and paste the contents in your next post.

    And then, just to be thorough...
    1. Download VirtumundoBeGone and save it to your desktop.
    2. Reboot into Safe Mode.
    3. Once you are in Safe Mode, run VirtumundoBeGone and follow the instructions.
    4. Exit when it has finished and reboot back into normal mode.
    5. The program normally produces a VBG.txt file. Please locate this file and paste the contents in your next post.



    Also...I see that your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next.


    You should update your AVG and scan with it in Safe Mode. Do that and follow unlovedwarrior's instructions and let us know how everything's running.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    3587.

    Solve : found some virus on my computer, help?

    Answer»

    Hi, I just ran a hijack VIRUS scan on my computer and found some virus. I am clueless as to how to remove them. Can someone PLEASEEEEEEEE help me. I definitely need a knight in shining armor for this one . Thanks a mil.

    Here is what i found:

    Logfile of HijackThis v1.99.1
    Scan saved at 7:49:11 PM, on 7/27/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\WINDOWS\System32\confgldr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\winasp.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\vwgwrbds.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ojndgbtm.exe
    C:\WINDOWS\System32\wumgr.exe
    C:\Program Files\Common Files\AOL\1102561437\ee\AOLSoftware.exe
    C:\WINDOWS\DELLMMKB.EXE
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft Office\Register\Remind32.exe
    C:\Program Files\Microsoft Office\programs\ccwin9.exe
    C:\Program Files\Microsoft Office\programs\alarm.exe
    C:\Program Files\Microsoft Office\programs\dad9.exe
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Netropa\OSD.exe
    c:\program files\common files\aol\1102561437\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
    c:\program files\common files\aol\1102561437\ee\aolsoftware.exe
    C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\America Online 9.0b\waol.exe
    C:\Program Files\America Online 9.0b\shellmon.exe
    C:\DOCUMENTS and Settings\Jason Grefski\My Documents\HijackThis.exe
    C:\WINDOWS\system32\NOTEPAD.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://smbusiness.dellnet.com/
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=Explorer.exe C:\logon.exe
    O2 - BHO: (no name) - {26FD0383-8810-6B17-5EFB-22DA61DAB6BD} - C:\WINDOWS\System32\pgpwsdhk.dll
    O2 - BHO: (no name) - {9B1620DE-F835-7274-BCB0-17E839C0AECB} - C:\WINDOWS\System32\eygdlfmr.dll
    O2 - BHO: (no name) - {DEA8140A-770B-1DB4-B7E7-9E992EFFCD06} - C:\WINDOWS\System32\wgpfumyy.dll (file missing)
    O4 - HKLM\..\Run: [Shell Logon] C:\logon.exe
    O4 - HKLM\..\Run: [vwgwrbds] C:\WINDOWS\System32\vwgwrbds.exe
    O4 - HKLM\..\Run: [Video Process] winasp.exe
    O4 - HKLM\..\Run: [qyslqvcl] C:\WINDOWS\System32\qyslqvcl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ojndgbtm] C:\WINDOWS\System32\ojndgbtm.exe
    O4 - HKLM\..\Run: [Microsoft Update Manager] wumgr.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102561437\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
    O4 - HKLM\..\Run: [Com+ Sys] csrs.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\RunServices: [Configuration Loader] confgldr.exe
    O4 - HKLM\..\RunServices: [Video Process] winasp.exe
    O4 - HKLM\..\RunServices: [Com+ Sys] csrs.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Manager] wumgr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Microsoft Update Manager] wumgr.exe
    O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Microsoft Office\Register\Remind32.exe
    O4 - Global Startup: CorelCENTRAL 9.LNK = C:\Program Files\Microsoft Office\programs\ccwin9.exe
    O4 - Global Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Microsoft Office\programs\alarm.exe
    O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
    O4 - Global Startup: Desktop Application Director 9.LNK = C:\Program Files\Microsoft Office\programs\dad9.exe
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jason Grefski\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jason Grefski\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ACTIVEX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
    O16 - DPF: {53A1630A-DB38-4316-B18F-911719E1F66E} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v11/ticker.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/23c1c0030ac94826fe15/netzip/RdxIE2.cab
    O16 - DPF: {7160FB1B-3DE0-4C42-81F0-41B4269990B0} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v12/ticker.cab
    O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/lsacd_xmlwebservices/Http/OIFActiveX/ofmctl.cab
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: Configuration Loader - Unknown owner - C:\WINDOWS\System32\confgldr.exe" -service (file missing)
    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: ritmtqunjmkh (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)
    O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
    O23 - Service: Video Process - Unknown owner - C:\WINDOWS\System32\winasp.exe" -service (file missing)
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    Ok do you have any sort of poker games on your computer .......


    Tony Download, install & update...
    CLEANUP
    Ccleaner
    (During install, uncheck the Yahoo Toolbar option)
    (After install, set Options>Advanced> 'Uncheck the 48 hour box')
    ANTI SPYWARE
    Adaware
    Spybot S&D
    ANTI VIRUS
    AVG Free
    (After install, set Options to 'scan all files')
    ANTI TROJAN
    Ewido for W2K & XP
    or
    A-squared a² for 98 & ME
    (Winall)

    Turn off System Restore if applicable. (ME & XP users)

    Run Ccleaner
    Run Ad-Aware
    Run Spybot
    Run AVG Free
    Run Ewido or a-squared (a²)
    Re-start in Safe Mode
    Re-run AVG Free

    Re-start in Normal Mode
    Turn on System Restore if applicable. (ME & XP users)

    Then come back with a fresh HJT log.Before doing anything, I'm going to have to ask you to apply Service Pack 1a for Windows XP. Without this update, you're wide open to re-infection, and we're both just wasting our time.
    Click here: http://www.microsoft.com/windowsxp/downloads/updates/sp1/default.mspx
    Apply the update and reboot. Do NOT install SP2 at this time!

    Once you have done that...

    1. Download VundoFix and save it to your desktop.
    2. Run VundoFix and click on Scan For Vundo.
    3. Once it's done scanning, click on Remove Vundo.
    4. When it prompts you to remove the files, click on Yes.
    5. Your desktop will go blank as it's removing files. Don't worry, this is normal.
    6. It will prompt you to restart your computer, so click OK.
    7. When your computer is turned back on, your problem should be gone.
    8. The program normally produces a Vundofix.txt file. Please locate this file and paste the contents in your next post.

    And then, just to be thorough...
    1. Download VirtumundoBeGone and save it to your desktop.
    2. Reboot into Safe Mode.
    3. Once you are in Safe Mode, run VirtumundoBeGone and follow the instructions.
    4. Exit when it has finished and reboot back into normal mode.
    5. The program normally produces a VBG.txt file. Please locate this file and paste the contents in your next post.



    Post back with those logs, as well as a fresh HijackThis log.


    Also...I would advise against turning off System Restore at this point. If anything goes wrong, you won't be able to go back to a previous restore point. It may be infected, but an infected restore point is better than no restore point at all. We will worry about taking care of this after getting you cleaned up. Just MAKE sure you don't use System Restore for the time being.You should dump your other two threads and post all your actions & results in here.Hi,

    I apologize for not posting my response in the correct areas, I am not familiar with posting questions/answers on forums.

    I am in the process of removing some virus from my computer and was advised to install Service Parck 1a for windows XP, which I did. I was then advised to download Vundo Fix; however, the program found no infected files. I later downloaed VirtumundoBeGone and ran another HijfackThis scan. I was told to re-post my finding so below are these findings. I am new to forums and I receive notification indicating that my message was too long so i split it in two. Thanks a mil!

    Here is what I found with VirtumundoBeGone Scan:



    [07/28/2007, 17:47:52] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Jason Grefski\My Documents\VirtumundoBeGone.exe" )
    [07/28/2007, 17:48:10] - Detected System Information:
    [07/28/2007, 17:48:10] - Windows Version: 5.1.2600,
    [07/28/2007, 17:48:10] - Current Username: Jason Grefski (Admin)
    [07/28/2007, 17:48:10] - Windows is in SAFE mode with Networking.
    [07/28/2007, 17:48:10] - Searching for Browser Helper Objects:
    [07/28/2007, 17:48:10] - BHO 1: {26FD0383-8810-6B17-5EFB-22DA61DAB6BD} ()
    [07/28/2007, 17:48:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [07/28/2007, 17:48:10] - Checking for HKLM\...\Winlogon\Notify\pgpwsdhk
    [07/28/2007, 17:48:10] - Key not found: HKLM\...\Winlogon\Notify\pgpwsdhk, continuing.
    [07/28/2007, 17:48:10] - BHO 2: {9B1620DE-F835-7274-BCB0-17E839C0AECB} ()
    [07/28/2007, 17:48:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [07/28/2007, 17:48:10] - Checking for HKLM\...\Winlogon\Notify\eygdlfmr
    [07/28/2007, 17:48:10] - Key not found: HKLM\...\Winlogon\Notify\eygdlfmr, continuing.
    [07/28/2007, 17:48:10] - BHO 3: {DEA8140A-770B-1DB4-B7E7-9E992EFFCD06} ()
    [07/28/2007, 17:48:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [07/28/2007, 17:48:10] - Checking for HKLM\...\Winlogon\Notify\wgpfumyy
    [07/28/2007, 17:48:10] - Key not found: HKLM\...\Winlogon\Notify\wgpfumyy, continuing.
    [07/28/2007, 17:48:10] - Finished Searching Browser Helper Objects
    [07/28/2007, 17:48:10] - Finishing up...
    [07/28/2007, 17:48:10] - Nothing found! Exiting...Hi,

    this is a continuation of the above response; its my result from Hijackthis

    Logfile of HijackThis v1.99.1
    Scan saved at 5:57:43 PM, on 7/28/2007
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Nhksrv.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\WINDOWS\System32\confgldr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\winasp.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\vwgwrbds.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ojndgbtm.exe
    C:\WINDOWS\System32\wumgr.exe
    C:\Program Files\Common Files\AOL\1102561437\ee\AOLSoftware.exe
    C:\WINDOWS\DELLMMKB.EXE
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\America Online 9.0b\waol.exe
    C:\Program Files\Microsoft Office\Register\Remind32.exe
    C:\Program Files\Microsoft Office\programs\alarm.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Microsoft Office\programs\dad9.exe
    C:\Palm\HOTSYNC.EXE
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Netropa\OSD.exe
    C:\WINDOWS\System32\wuauclt.exe
    c:\program files\common files\aol\1102561437\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exe
    c:\program files\common files\aol\1102561437\ee\aolsoftware.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\America Online 9.0b\shellmon.exe
    C:\Documents and Settings\Jason Grefski\My Documents\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://smbusiness.dellnet.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://smbusiness.dellnet.com/
    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: Shell=Explorer.exe C:\logon.exe
    O2 - BHO: (no name) - {26FD0383-8810-6B17-5EFB-22DA61DAB6BD} - C:\WINDOWS\System32\pgpwsdhk.dll
    O2 - BHO: (no name) - {9B1620DE-F835-7274-BCB0-17E839C0AECB} - C:\WINDOWS\System32\eygdlfmr.dll
    O2 - BHO: (no name) - {DEA8140A-770B-1DB4-B7E7-9E992EFFCD06} - C:\WINDOWS\System32\wgpfumyy.dll (file missing)
    O4 - HKLM\..\Run: [Shell Logon] C:\logon.exe
    O4 - HKLM\..\Run: [vwgwrbds] C:\WINDOWS\System32\vwgwrbds.exe
    O4 - HKLM\..\Run: [Video Process] winasp.exe
    O4 - HKLM\..\Run: [qyslqvcl] C:\WINDOWS\System32\qyslqvcl.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ojndgbtm] C:\WINDOWS\System32\ojndgbtm.exe
    O4 - HKLM\..\Run: [Microsoft Update Manager] wumgr.exe
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102561437\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
    O4 - HKLM\..\Run: [Com+ Sys] csrs.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
    O4 - HKLM\..\Run: [Configuration Loader] confgldr.exe
    O4 - HKLM\..\RunServices: [Configuration Loader] confgldr.exe
    O4 - HKLM\..\RunServices: [Video Process] winasp.exe
    O4 - HKLM\..\RunServices: [Com+ Sys] csrs.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Manager] wumgr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Microsoft Update Manager] wumgr.exe
    O4 - Global Startup: Camio Viewer 2000.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
    O4 - Global Startup: Corel Registration.lnk = C:\Program Files\Microsoft Office\Register\Remind32.exe
    O4 - Global Startup: CorelCENTRAL 9.LNK = C:\Program Files\Microsoft Office\programs\ccwin9.exe
    O4 - Global Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Microsoft Office\programs\alarm.exe
    O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
    O4 - Global Startup: Desktop Application Director 9.LNK = C:\Program Files\Microsoft Office\programs\dad9.exe
    O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jason Grefski\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Jason Grefski\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020713/qtinstall.info.apple.com/samantha/us/win/QuickTimeInstaller.exe
    O16 - DPF: {53A1630A-DB38-4316-B18F-911719E1F66E} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v11/ticker.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/23c1c0030ac94826fe15/netzip/RdxIE2.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1185654450389
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1185654429499
    O16 - DPF: {7160FB1B-3DE0-4C42-81F0-41B4269990B0} (MSN Money Ticker) - http://fdl.msn.com/public/investor/v12/ticker.cab
    O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/lsacd_xmlwebservices/Http/OIFActiveX/ofmctl.cab
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: Configuration Loader - Unknown owner - C:\WINDOWS\System32\confgldr.exe" -service (file missing)
    O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
    O23 - Service: ritmtqunjmkh (MsUpdate6) - Unknown owner - C:\WINDOWS\System32\msupd6.exe (file missing)
    O23 - Service: Netropa NHK Server (Nhksrv) - Unknown owner - C:\WINDOWS\Nhksrv.exe
    O23 - Service: Video Process - Unknown owner - C:\WINDOWS\System32\winasp.exe" -service (file missing)
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    Quote from: Fed on July 27, 2007, 06:58:43 PM

    Download, install & update...
    CLEANUP
    Ccleaner
    (During install, uncheck the Yahoo Toolbar option)
    (After install, set Options>Advanced> 'Uncheck the 48 hour box')
    ANTI SPYWARE
    Adaware
    Spybot S&D
    ANTI VIRUS
    AVG Free
    (After install, set Options to 'scan all files')
    ANTI TROJAN
    Ewido for W2K & XP
    or
    A-squared a² for 98 & ME
    (Winall)

    Turn off System Restore if applicable. (ME & XP users)

    Run Ccleaner
    Run Ad-Aware
    Run Spybot
    Run AVG Free
    Run Ewido or a-squared (a²)
    Re-start in Safe Mode
    Re-run AVG Free

    Re-start in Normal Mode
    Turn on System Restore if applicable. (ME & XP users)

    Then come back with a fresh HJT log.
    Did you install SP1? You HijackThis log still shows you as not having any Service Packs installed. It also still shows a Vundo infection. If VundoFix isn't catching it, then you should try ComboFix...

    Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.

    Also, it is very very important that you have SP1 installed! Without it, you'll be terribly vulnerable to more infections.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    3588.

    Solve : Something weird really ,?

    Answer»

    Uhm well I got this message, and i dont KNOW what the *censored* to do.. please help me :&GT;

    I would shoot the messenger. ----> Google it.And update your XP via Windows Update. The messenger feature should be disabled if you are fully updated.Good catch Deerpark. Well I reckon one of my freinds had this problem and it was some kind of spyware If your XP is up to date then this might be a spyware issue. But since you haven't told us whether your XP is fully updated we can't SAY if it's spyware related.Have you tried the suggestions yet?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you REQUIRE help, please start a New Topic with information about your computer and your problem.

    3589.

    Solve : internet exeplorer keeps poping up?

    Answer»

    ok this happens when im ONLINE and sometime offline my pc which is a sony OS windows Xp home edition serviuce pack 2........
    so a window keeps popping up and it says dilet.org php and it keeps poping up
    ive done several virus scans but nothing pops up if i should block this SITE tell me and give me directions on howFirst of all, you should update your anti-virus and scan with it in SAFE MODE.

    If you're still having problems after that, post a HijackThis log.Due to lack of FEEDBACK, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or ANOTHER moderator and it can be arranged.

    If you are not the original poster and you REQUIRE help, please start a New Topic with information about your computer and your problem.

    3590.

    Solve : Outlook Express - can't open any links?

    Answer»

    When I receive an email I can't open links. Ex: Kohl's sends an ad and says "start shopping" and I click and go no where.

    I have XP . someone please help. This doesn't sound like a virus issue to me. Might have to do with your settings. Have you always had this problem? When did it start? Just for the heck of it...what protection do you have?DUE to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

    3591.

    Solve : Help I downloaded and now have problems?

    Answer»

    Please help I downloaded defender pro on my computer and nothing but problems so I uninstalled and reinstalled norton. I currently have norton antivirus only!!! And I searched through the forums and found some free SPYWARE and such but when I scan my computer it says that it fixed 5 of my 441 errors please help !!!!!And I forgot to say that my computer is running really slow and it keeps freezing up on me . I was wondering if there is SOMTHING else I am to do after I deleated it?Time for a MAJOR cleanup. See here...

    Suggestion - dump Norton and install AVG Free anti-virus and Zone ALARM Free firewall..

    Good luckThank-you for your help I downloaded AVG but I went to spybot and downloaded it and it said I have 1024 bugs and pay his amount I went to it straight from your link??? I thought it was free Please help am I doing somthing wrong?Quote from: cindyann on August 04, 2007, 05:58:32 AM

    Thank-you for your help I downloaded AVG but I went to spybot and downloaded it ..."

    Did you download AVG anti-virus, or spybot, or both.... or what? Your statement is unclear.


    Dusty said, " .... install AVG Free anti-virus ..."


    Quote
    and it said I have 1024 bugs and pay his amount I went to it straight from your link??? I thought it was free Please help am I doing somthing wrong?


    Did you go to this page? : http://free.grisoft.com/doc/1
    Look for where it says, "Anti Virus" and "Free of charge"


    I hope that helps.


    I can assure you that Spybot is free, here are the links to the usual cleaning tools.

    CLEANUP
    Ccleaner
    (During install, uncheck the Yahoo Toolbar option)
    (After install, SET Options>Advanced> 'Uncheck the 48 hour box')
    ANTI SPYWARE
    Adaware
    Spybot S&D
    ANTI VIRUS
    AVG Free
    (After install, set Options to 'scan all files')
    ANTI TROJAN
    Ewido for W2K & XPDue to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    3592.

    Solve : Will this help someone help me??

    Answer»

    I hope someone can read this and help me out because i dont know what i'm doing.

    [Saving disk SPACE - old attachment deleted by admin]Download, install & update...
    CLEANUP
    Ccleaner
    (During install, uncheck the Yahoo Toolbar option)
    (After install, set Options&GT;Advanced> 'Uncheck the 48 hour box')
    ANTI SPYWARE
    Adaware
    Spybot S&D
    ANTI VIRUS
    AVG Free
    (After install, set Options to 'scan all files')
    ANTI TROJAN
    Ewido for W2K & XP
    or
    A-squared a² for 98 & ME
    (Winall)

    Turn off System Restore if applicable. (ME & XP USERS)

    Run Ccleaner
    Run Ad-Aware
    Run Spybot
    Run AVG Free
    Run Ewido or a-squared (a²)
    Re-start in Safe Mode
    Re-run AVG Free

    Re-start in Normal Mode
    Turn on System Restore if applicable. (ME & XP users)
    Then come back with a fresh HJT log.well i think it worked everything is working great. thank you very much.

    [Saving disk space - old attachment deleted by admin]You log seems to suggest that svchost.exe is missing from your computer. This may be a mistake, but it's a VITAL system file, so we should make sure. Navigate to the C:\WINDOWS\system32 folder and tell me, is there a svchost.exe file? Also, do you have an official Windows CD?

    There are also a few things in your log that should be taken care of. Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet...

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    O1 - Hosts: ::1 localhost

    O2 - BHO: (no name) - {D61D7E1A-6613-49CA-B6F9-51DB248E209D} - C:\Program Files\Video ActiveX Access\iesplg.dll (file missing)

    O4 - HKLM\..\Run: [ZangoOE] C:\Program Files\Zango\bin\10.0.328.0\OEAddOn.exe
    O4 - HKLM\..\Run: [ZangoSA] "C:\Program Files\Zango\bin\10.0.328.0\ZangoSA.exe"

    O13 - Gopher Prefix:


    Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

    Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

    Hotbar
    Video ActiveX Access
    Zango


    Please note any other programs that you dont recognize in that list in your next response.

    Navigate to and delete the following folder(s) if present...

    C:\Program Files\Video ActiveX Access
    C:\Program Files\Zango


    Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.

    Because it's not necessary, I will lock your other thread to avoid confusion.Due to lack of feedback, I am closing this topic. If you are the ORIGINAL poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

    3593.

    Solve : MatCash F?

    Answer»

    I have a Virus on a different computer that's named Matcash F., should i use HIJACKTHIS to get rid of it? I'm using Microsoft win xp sp2.DLoad and run Stinger in safemode with System Restore turned off...
    Then run any other protection apps you have as well the same way.
    Then post a list of what you have run and also a HJT log for our RESIDENT Guru's to check out...We often use HijackThis to aid us in the removal of infections, but you should never make any changes with it unless you know what you're doing or are advised by someone who KNOWS what they're doing. Go ahead and follow patio's instructions and we'll take it from there.

    However, I would suggest not turning off System Restore just yet.Due to lack of feedback, I am closing this topic. If you are the original POSTER and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a NEW Topic with information about your computer and your problem.

    3594.

    Solve : Virtual Memory Minimum is low?

    Answer»

    By the way, you should get yourself a firewall. You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.Hi CBMatt

    Thanks for answering my latest questions (again!)your knowledge is invaluable you know.

    In regards to a firewall, I am pretty sure that my Nortons has a firewall on it at the moment HOWEVER, I understand also from a reliable source here on the board that Comodo is the one to go with. As soon as I get a free minute I am going to download it, just havent had time yet. I went to buy some RAM TODAY with my results from "Crucial" and they told me that it could be tricky installing it as I would have to "earth" myself. YIKES!! what is that all about? Sounds electrically scary! Thus, I have been persuaded to have a Harvey Norman technician install it for me when it comes in, apparently the RAM in my computer at the moment is "old" RAM so they have to order it in. What next! Anyway, at least theres light at the end of the tunnel.

    Thanks again CBMatt

    Installing RAM is generally not at all difficult. You just need to ensure that the stick is the correct way round and it has been inserted until both latches 'latch' onto the notches. Make sure that the power plug is completely out.

    By 'grounding' yourself the Harvey Norman people SIMPLY mean: not working on static prone surfaces, such as carpet, touching / holding the case or power supply of the computer, or using an electrostatic wrist band.

    Glad to see this forum has helped you.When it comes to a firewall, I would definitely say Comodo is about the best. I recently switched over to it and I'm very pleased with how well it works. I would suggest ditching Norton and just sticking with free alternatives.

    As for RAM...like DeltaSlaya said, it's pretty easy to install. Not scary at all. You just have to ground yourself by holding onto the metal of the computer case. It's to avoid any static shock that may damage components. It's really pretty simple, though. But if you're not comfortable with it, then it might be best to have someone else do it.

    3595.

    Solve : Symantec Antivirus 10?

    Answer»

    Hi there, I'd install the Symantec Antivirus 10 Corporate Edition on a computer that runs Windows XP, but I have some clue about it, because it has been INSTALLED the SQL Server database manager, and I don't know why, because the old VERSION doesn't install it. Please help me with this because it makes that the cumputer turns slowly.

    Best RegardsYou should forget about NORTON and get AVG Free. It's free, it works really well, and it's easy on your resources.

    3596.

    Solve : i dont know what it is...?

    Answer»

    almost three months past, my old HD say goodbye to me (got damaged and did not leave anything to me)
    so i bought a new one and install a fresh xp sp2 pro.
    i have still no internet in my house so i cant follow most of the rules in here.
    The virus/worm or LET say malware name i noticed is "Cn.wAQdn Isass.exe" in folder C-windows.1
    (but when i take a look that folder, i cant FIND this *censored* thing) the SS&D ALWAYS found everytime i scanned it.
    i found in google 2 cases but no definite remedy.
    i got infected coz of the flash drive of my friend (he ask some of video converter) since i have no internet i did not bother to install AV, AS, FW.
    so here my problem: its always puting a folder name "New folder" in every drive connected with my pc with info (when mouse pointing the folder there is= Company: IT University File Version: 1.0.0 )
    Run,TaskManager, System Restore and folder option are all missing. i noticed that everytime i scanned and fixed with SS&D, Run and TaskManager are coming back but system restore still missing. But when i reboot again, back to square one again(infected again).

    So how i gonna deal with this? im getting afraid to lost again my data.
    i only inquired this here in the pc here my work (even my flash drive is getting infected everytime i connect to my pc in the house)
    so i mustt scanned it here via AVg before i open and always found boot.exe worm

    just let me know what to do.
    Please help me and thanks in advance

    [Saving disk space - old attachment deleted by admin]Your infection looks pretty bad. I'm not sure how much we can do for you as far as cleaning it goes. You should update your protection and scan with it in Safe Mode (not Normal Mode).

    Then download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.



    One thing that throws me off is your Windows folder. It's named WINDOWS.1, which isn't typical. Has it always been this way? Do you also have a WINDOWs (without the number) folder? Do you perhaps have two installations of your OS?

    Please post back with your results, answers, and a new HijackThis log (from Normal Mode).Quote from: CBMatt on July 28, 2007, 09:59:18 PM

    Your infection looks pretty bad. I'm not sure how much we can do for you as far as cleaning it goes. You should update your protection and scan with it in Safe Mode (not Normal Mode).

    Then download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls.



    One thing that throws me off is your Windows folder. It's named WINDOWS.1, which isn't typical. Has it always been this way? Do you also have a WINDOWs (without the number) folder? Do you perhaps have two installations of your OS?

    Please post back with your results, answers, and a new HijackThis log (from Normal Mode).

    THANK you very much for your reply here.
    First thing first i can put here almost what you ask by tomorow (coz im at work and no internet in my home)
    some i can answer:
    windows.1 im not sure when this folder birth in my c drive
    Windows- i have this folder in my c drive
    OS- only one, its Xp SP2

    i will follow all your instruction then i will post tomorow

    thanks again...I had this same problem a long time ago. the way i fixed it i had to reformat my computer. You can always do that but as you said you dont wana loose everything :SI don't want to have to resort to a reformat just yet, but it may come down to it. When you try the above and post back with your results, I'll take a look, but be prepared to backup your data.also can you do the hijackthis in normal mode after scans?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
    3597.

    Solve : clicked random .cn php link?

    Answer»

    Sorry for not showing this forum thread an eye for the last couple of days I had a holiday, well the AVG scan in safe mode found no threats so I guess I am clear

    ALSO SP2 CREATES lag for RTCW: Enemy Territory.

    Thanks for all the help.
    Again, I'm wondering what your specs are. Also, what kind of connection you have.
    Enemy Territory runs pretty smoothly on my computer with SP2. The only thing that has ever caused me lag is my connection.Both games you mentioned have Forums and not many references to trouble with SP2...
    I AGREE with CBMatt.Due to LACK of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

    3598.

    Solve : Explorer being assaulted by trojan?

    Answer»

    His virus's consumed him ...... and soon the WORLD.....

    TONY

    Ive seen him on TODAY....Due to lack of feedback, I am closing this topic. If you are the ORIGINAL poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

    If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

    3599.

    Solve : malware scans did not find much about "Assert Failed"?

    Answer»

    I got the "ASSERT FAILED" and ddcmigrate.exe Application Error - these two alerts come up as SOON as the boot completes. I click OK a couple times and they GO away...
    \Projects\wtkernel\src\Win32\cm\Core\cmCodeModule.cpp:90 m_CodeHandle!=NULL
    I ran CCLEANER, anti-malware and HijackThis. I am running XP with SP3
    Here are my 3 logs. Please let me know if you see anything I can do. Thanks!

    see attached

    [attachment deleted by admin]

    3600.

    Solve : removing virus as power user?

    Answer»

    Dell Dimension 2400 desktop
    Intel Pentium 2.19 GHz
    512 RAM Windows XP Home SP2
    80G DRIVE Malewarebytes
    AVG 8.5387 Anti Virus
    avg anti spyware

    I have used my computer for many years and run my anti virus many times but this time after running I am told that I have 62 virus that cannot be removed as standard USER rights. It then asks if I want to remove threat as power user and presents a run as WINDOW to enter a user other than current user with a box for user name and pass word. ---There is no other user but me. I tried putting in my user(fredand bev)and my email password but nothing I enter lets me continue. Any HELP would be greatly appreciated.

    BEV