

InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
4351. |
Solve : Norton SystemWorks 2004 HELP? |
Answer» hey |
|
4352. |
Solve : DjRunner & SVC Host? |
Answer» After just getting rid of the GAOBOT virus last week & every other poosible virus i've just found out that these two "djrunner.exe and svchost.exe" didnt disappear.. I was able (it appears) to disinfect a home system (sitting behind a firewall) from djrunner2 by deleting the /bin directory that it was in and deleting a rtdx11??.dat FILE, an exe beginning with cdg... and all relevant registry entries.You can dig through this thread from another forum.. http://computercops.biz/posts30937-30.htmlThanks for the links but i honestly am still lost. Im not sure what to delete, im afraid in case i delete something important..Quote im afraid in case i delete something important Q: What's the worst that could happen? A: Your system blows up and you're horribly burned and scarred, relying on others to care for your basic necessities. Since this is unlikely (you might have to format your computer and start again) I'd say follow the advice in the other thread. You might be able to figure it out and post the fix here for others.Quote Q: What's the worst that could happen? Oh just forget it, if anybody else (dl65, raptor or any of the other members that i have respect for) have an answer of think they can help me, i'd really appreciate it. If not, then so be it. Thanks Quote Svchost.exe is a system function, I donot think you can remove or want to remove that. Raptor, svchost.exe is a type of virus too.. Ive found that out from my searches on google. I came across the post you mentioned when searching for djrunner.exe on google too but im completely lost on what to do! If you are affraid of deleting something that may be important to keep your computer functioning, you can always make a system RESTORE before proceeding.I'd just like to correct myself there, the virus is scvhost.exe.. it's disguised as this so when you look at your processes you will think its svchost.exe The c & v are reversed. Think i've found an answer for this on another forum. If the solution works, ill post it here.I find it strange that Norton does not detect these viruses. Did you update Norton by enabling Live Update and trying to update manually? http://housecall.trendmicro.com/ Perhaps Trend Micro is able to assist you. http://www.grisoft.com/us/us_index.php You may also try AVG Anti-Virus. I have never tried this program, but I have seen forum members recommend it. If you have allready tried these solutions, I SUGGEST you either wait for the (much) more experienced members to come online or contact one of the Anti-virus companies technical support.Quote If you are affraid of deleting something that may be important to keep your computer functioning, you can always make a system restore before proceeding Exactly my point. So you might lose some data.. big deal. In the big scheme of things you'll probably come out ahead with new knowledge. I fondly remember my first format.. I was so scared to type in those words.. Format C:Thanks Raptor, I find it completely strange too why Norton isnt picking this up. The Live Updates are working fine since getting rid of Gaobot and ive done Housecall & AVG on it but not picking up anything either.. Might try Norton's support. Do you know if they give support VIA email? Thanks for your helphttp://www.symantec.com/techsupp/support_options.html Judging from their prices, it would be less costly to format. However, if you really wish to resolve this situation you can try to contact Trend Micro or AVG Technical support. |
|
4353. |
Solve : HijackThis! Log? |
Answer» Hello. There are no problems with my computer but i jus want to stay on the safe side so can somebody please examine my HijackThis log and tell wut to delete? i will really appreciate it. thank u. |
|
4354. |
Solve : toolbar.dll? |
Answer» I need some help a toolbar INSTALLED itself on my pc and I found the thing in regedit and deleted all the files I saw that pretained to it. I thought I had it fixed.... a MINUTE later it REINSTALLED itself........... how do I get rid of it.Please Read This First - VIRUSES & Spyware |
|
4355. |
Solve : I know virtually nothing..about viruses that is? |
Answer» My brother sent me an email saying he has received 2 emails from me with ATTACHMENTS on them, but I didn't send either one of them. We both assume it's a virus, but we don't know what it is. |
|
4356. |
Solve : psw.bispy.d? |
Answer» hi, |
|
4357. |
Solve : Any Help Appreciated...? |
Answer» Ok my comp has completely gone kaput.. it loads as normal my desktop image comes up and then nothing! No icons, no toolbar, when i click cntrl alt DLT the only program that shows up is something called Mdm, I have no idea what that is! .... try these methods .....hopefully one will work for you . Ok the first one worked for me in the sense that I managed toload it in safe mode but all it has done is that now my desktop is there with safe mode written in all corners but still no icons or toolbar! When i try ti right click the mouse notihng happens theres nothing for me to click on anywhere lol grrrr machines hate me!! Oh tho when i clicked cntrl alt delt no programs showed up not even the Mdm one. It was all empty!! One thing i did think of is the desktop wallpaper is new.. I only set it there the night b4 this all happened, it is of red fireworks bursting over the statue of liberty... I have no idea if that could have anything to do with it but I had a virus sent to me once a while ago in a picture of fireworks!! This computer was given to me a short while ago and so I don't have all the usual discs and stuff u get with a new comp, (could I use a boot disc from another comp if it too is windows 98??) The comp worked fine until the other night so i don't think it is something that has been there a while... :-/ HC. Yes, you can use a boot disk from another W98 machine. Don't forget to make it write protected to be on the safe side. |
|
4358. |
Solve : cws_ns3? |
Answer» what a piece of scumware this is its belongs to ENIGMASOFTWAREGROUP.COM 207.44.220.11 and a pain in the neck to get rid of...have spyweeper from webroot check your system for it?merlin_2......Yes Cool Web Search + whatever is a pain . |
|
4359. |
Solve : My 32.mydoom? |
Answer» the MYDOOM VIRUS is BACK so be careful ok...>http://securityresponse.symantec.com/avcenter/venc/data/[emailprotected] |
|
4360. |
Solve : Virus syptoms? |
Answer» Hello, i just REINSTALLED my whole hard drive because i had a virus on my computer. I finally GOT everything set up, including my anti virus software, as well as downloading adaware and i think was hit with another virus. A message from Norton came up and identified it as a trojan. My homepage resets every time I try to get on the interent and there are pornography links added to my "favorites" However, when I search my computer for viruses with Norton, it says my system is clear. Adaware has also deleted about 140 objects from my computer. I need help on what to do, if I have a virus or not, and if so how to go about getting rid of it... because Norton says my system is clean. Thanks very much.Try Spybot S&D http://www.safer-networking.org/index.php?page=mirrors |
|
4361. |
Solve : Panda!! Don't trust..? |
Answer» The free online panda virus check is a hoax. When they emailed me they gave me a file defanged. I checked it with norton and what do ya know panda sent a virus before you run online program they'll ask for your email and tell you to dl the defanged and open it. Then once that it is done they'll tell you to run the online virus checker. Once youve installed the defanged it installs the virus. All Panda wants is to feel allmighty and powerful, meanwhile they plauged you and the online checker will say *hey you have a virus blah blah blah*. Panda is not to be trusted.Dorian Galli .......If you want a reliable online virus checker ......try ....... http://www.symantec.com/index.htm scroll down to the Symantec security check and then choose the virus scan........This will take a while depending on the number of files on your pc........It works. I don't even use a virus scanner anymore. Just switch off the preview pane in you're email client and don't open any attachments you didn't request. If you know anything about computers, viruses are so easy to spot. Anything? Do you have any idea how easy it is to be infected by even updating Windows? Not only that, Virus scanners (The better ones) also scan for trojans and spyware and they warn you of POSSIBLE infected files. Never go without a virus scan, especially not if you only know anything about computers.I am aware of how easy it can be. But the fact is that 99 out of every 100 viruses come via email (so to speak), and the bulk of them follow the same format, ie... "Wanna see sexy Russian teen lesbian dwarves on their WEBCAMS? Run this strange looking *.exe file!" ... Anyone with any sense will delete these files without thinking twice. I have a few webmail accounts kicking around which I use as spam-catchers which take away the bulk of the junk, so viruses don't come that often anyway. I do, however, run a firewall, which warns me of any incoming and outgoing connections which I can analyse to find trojans and spyware. I use Spybot to get rid of any undesirables. Please do explain the FOLLOWING though - I'm intrigued: Quote Do you have any idea how easy it is to be infected by even updating Windows?Are you mocking me? Even downloading Windows UPDATES can cause a new security hole to exist. That is what Microsoft is known for.its so obvious that most anti-virus/m$oft would be out of bussiness if their products were any good ....the conspiracy theory comes into play...you will have to just as in life gamble what software is used for firewalls virus detection and operating systems isps etc...most may contain scumware spyware adware etc...by having a dig at posters is out of order and it solves nothing ...nothing at all...imho.. |
|
4362. |
Solve : My Hijackthis Log and also an Error? |
Answer» I just downloaded this and whenever I click on it, I get an error but it stills work, I get the same error when I click scan. |
|
4363. |
Solve : Norton AV: "System Status: Urgent attention&q? |
Answer» For a couple of DAYS now, I've had a trojan of some sort always changing my homepage. I installed a number of programs to do sth about this, but with no success (Adaware, Spysweeper, HIJACK Blaster). |
|
4364. |
Solve : Norton Virus Software? |
Answer» HELLO, Can someone please help. Question is I have two home computers. I NEED to put 2004 Norton on both computers. Can I BUY one Norton Internet security 2004 and put it on both computers. And If subcription is going to expire next month does Symantec stop your virus updates a month before ? cannot use update at all on one computer. Please help. beebee......First .....I believe Norton only allows you to install NAV 2004 on one machine....however check the license to be sure.....Now that they are using the activation system ( this is to discourage buying one program and then loading it on several machines ) Did you activate the program when you loaded it on the second machine......Because if its not activated I dont believe you can get the updates......and in answer to your second query.......you should be able to receive updates right up until your subscription expires ...GIVEN you have activated it . You will receive messages remindinding you that your subscription will expire in so many days. Hope this answers your questions......You can call Norton toll free and get further info. Cheers dl65 Dont use the disk hogger nav try another many out there who do a better job...norton is BRILLIANT for speed disk win doctor and ghost but thats it m$oft has clung to norton for years ? |
|
4365. |
Solve : My Comp Is Mest? |
Answer» Well first let me explain a few things my computer has been doing: (1) Whenever I click on IE, my homepage is always changed to something like "Virgin Lovers" or some other porn service page, despite me changing it constantly to my normal homepage. (2) Whenever I click on ANY folder on my computer, my computer either freezes where I have no choice but to restart the computer, or "Explorer" is not responding when I hit control ALT delete. (3) My Internet keeps acting up and I have pages that do not load because I'm apparently not connected to the internet, eventhough I have ADSL. (4) I can't Defrag my computer because the Defragging is quite sensitive I guess, and even moving the mouse CANCELS the defragging. |
|
4366. |
Solve : Hi i have pc probs & need some answers please? |
Answer» hi |
|
4367. |
Solve : virus i need help plz? |
Answer» well i have a virus that alters win.ini and other files so it loads itself when i boot, even in safe mode, there are two of them that came together at the same time they are: |
|
4368. |
Solve : short, cryptic email messages? |
Answer» Once every day or two I get short, ANONYMOUS, cryptic email messages, like... |
|
4369. |
Solve : Someone Following Me Online?? |
Answer» Hello All, |
|
4370. |
Solve : Hijackthis!? |
Answer» Logfile of HijackThis v1.98.0 |
|
4371. |
Solve : kthx.owns-u.com. virus/ worm whatever? |
Answer» Hi, |
|
4372. |
Solve : homepage.com? |
Answer» Sorry if this has been posted before but I searched and couldn't find it. |
|
4373. |
Solve : connection refused and error? |
Answer» First time using this site & I'm, also not comp. savvy. Pls. be patient. I recently had a problem going on the Best Buy site. I used to be able to access but now I get a mess. that reads Wcs2000 has caused an error Wcs2000 will now close. Then it bumps me offline. Every single time and only that site. Also I occ. get a message that reads The connection was refused when attempting to contact compuserve.com or any other site I'm logging into. It doesn't happen too often but it's something that cocerns me since it never happened before. What does it mean Is Wcs2000 software you are using to connect to the Internet? If it is, I suggest you uninstall it and then install an updated version. that reads Wcs2000 has caused an error<unknown> Wcs2000 will now close. I donot know what Wsc2000 is. It is a term you introduced in your first post. A very good and reliable adware scanner is Adaware 6.0. It is avaible from Lavasoft USA I also suggest you look into a virus scanner such as Kaspersky (Personal Edition) or Norton Anti-Virus. |
|
4374. |
Solve : Backdoor.sheldor - Trojan horse? |
Answer» I have the virus referenced above. Everytime I start my computer I receive the error message "E47150: INCORRECT MPEG data format." I have Windows ME. When I try to boot into safe mode or normal mode nothing comes on the desk TOP, and there are no items in the task manager. I have no functionality. Is there any way to BYPASS the boot routine so that I can get to the command prompt?You can PUT in a boot disk and get to the command prompt that way but the safe mode options screen should provide an option to boot to prompt.Quote Backdoor.sheldor - Trojan horse on: Today at 9:18am **Moved from a PM** I think Mac has a link to a site with bootdisk downloads. Look for any post of his and the link will be at the bottom. |
|
4375. |
Solve : Can't find MacScan or equivalent? |
Answer» I RUN a Mac Power PC, OS 9.2.2, and I'm looking for a download of MacScan or the equivalent. EVERYWHERE I go, it says it's not currently AVAILABLE, or the like. Can anybody direct me? |
|
4376. |
Solve : URGENT! Please help :[? |
Answer» My brand new computer is messed up, PLEASE help. The other problem isn't virus related though. Sorry. |
|
4377. |
Solve : Can someone identify these?? |
Answer» We have Windows 98 on our computer at work. We also have Norton ANTI Virus, with all UPDATES, etc. We recently ran a virus scan and found the following files(?) in Quarantine. |
|
4378. |
Solve : Installing Norton AV? |
Answer» I can't install ng Norton AV it keeps saying that it's having trouble installing Test_SymRedir. I really need help please! Anyone knows what to do?Which operating system are you using?Kitkat....what version is it your trying to install? |
|
4379. |
Solve : An icon suddenly appeared on the system tray? |
Answer» Next to the time there is a yellow bell that blinks on and off. When I put the cursor over it it SAYS: "Take Advantage of the Hot Summer Sale" I TRIED right clicking on it to see if I could delete it but it only has: Open message and leave it. |
|
4380. |
Solve : AOL KICK OFF? |
Answer» well apparently someway somehow some1 got on my screen name for aol on my other pc and sent pictures idk of wat and we got kicked off and then it happend again ne suggestionsFrom what I have heard, AOL is a horrible provider. You may wish to stay tuned for the opinions of the members who have experience with this provider..Many suns ago, when AOL first started, it was small and good. These were the days when DOS was KING and MICROSOFT was a small company. AOL was essentially a BBS, with a hugh download area filled with free software, and technical help abounded. Then Microsoft released things on the masses that were called IE and Windows. AOL was virtually consumed by them. As time progressed, AOL became powerful. It thought it knew what was best for its users. The download area disappeared, and the technical help became nonexistant. With all its power, AOL began to abuse its users, and the charter members left in droves. It charged exorbitant rates, censored its members, and its software PRACTICALLY took over the users machines and refused to play nice with other software. And this, my son, is how AOL came to suck. |
|
4381. |
Solve : i have a dumb question about a computer camera? |
Answer» yes i have a really stupid question a friend of mine is 32 and gay and is very dumb when it comes to computers and she was on her camera on her computer and was taking some PICTURES and LETTING it snap pics of him while he was in front of it and stuff and he is worried the pictures went other places without his knowledge |
|
4382. |
Solve : Firefox Browser Hijacker - Not Detected by Malwarebytes! - Removal Process? |
Answer» Sharing this here in case anyone else gets hit with this one. I was surfing the web today and this one struck. Normally these hijackers get detected and cleaned out by malwarebytes but this one is able to hide somehow. Critical Alert ... Your Computer has alerted us that it is infected with a virus and spyware. Malwarebytes with the latest definitions does not catch this which is amazing. All others I have come across get flagged and caught in memory as the hijacker is running from a temp location. This one though Malwarebytes says your computer is clean 0 problems detected. So I had to go through this process below to clean my system of it. Simply bringing up task manager and ending firefox process and then relaunching firefox does not fix this as Firefox wants to run to the last page that was open as part of its crash recovery process which was triggered by ending the process tree for firefox in task manager. Quote So here is the fix:Quote NOTE: Do not assemble that URL path and go there because it will likely take your browser hostage!I did anyway- I get the dialog you mentioned but I don't get any looped audio or anything. It only affected that browser tab. I pressed escape on the dialog and escape to "stop" the page and nothing else happened. I have very pessimistic default options, however, and NoScript probably blocked some of it as well. Also it looks like it's gone now- It only gives a cpanel error. Good information. Thanks for the warning. |
|
4383. |
Solve : My computer still has hope?? |
Answer» My mother-in-law gave us this computer I believe it was purchased back in 2002, it's compaq, the operating system is xp-sp3.. if this make sense. My mother-in-law gave us this computer I believe it was purchased back in 2002, it's compaq, the operating system is xp-sp3.. if this make sense. That's too old to be honest, restoring it may work but eventually will work slow due to it's oldness plus if you buy a new OS lets say windows 7, I don't know if that laptop is capable running it I'm guessing you may have some trouble looking for the compatible drivers for it and it will work slowly, here's my proof for it, I own a desktop i5 4th gen (8gb ram) the mobo only support 8.1 I tried upgrading it to windows 10 it works I found a couple of drivers too but it was slow about 40% I can see the dip in the changes. So I think that will gonna happened too. So if you buy a new XP it will work but not sure how long, as stated above you should buy a new laptop so you can be sure to hold all the tasks you needed and saves you time.Tonyshaw, You did not say how important this PC is to you. How much might you to have it replaced? It can be replace by a refurbished newer model for under $200. It will have windows 10 and a 90-day warranty, Example: https://www.amazon.com/HP-Quad-Core-Windows-10-Refurbished/dp/B01CV9G1BO/ref=sr_1_3?ie=UTF8&qid=1542580383&sr=8-3&keywords=hp+refurbished+desktop+computer+8300 Quote This Certified Refurbished product is tested and certified to look and work like new. The REFURBISHING process includes FUNCTIONALITY testing, basic cleaning, inspection, and repackaging. The product ships with all relevant accessories, a minimum 90-day warranty, and may arrive in a generic box. Only select sellers who maintain a high performance bar may offer Certified Refurbished products on Amazon.comYou can get a one-year warranty about $20 more. Like almost everyone has stated, this computer is getting to be quite old, and the computer that Geek put a link to in his answer would probably be perfect for what you need it for. However, one good program that seems to work good if I need an all around computer optimizer, is 360 Total Security. It scans for viruses, cleans out junk files, the works. You can download it here:https://www.360totalsecurity.com/?utm_source=google&utm_medium=cpc&gclid=CjwKCAiAuMTfBRAcEiwAV4SDkeJnLOvijPgqu7t7O_PD1x6AWFP5Ka9JFNrH3L19bQDRRR-jIX8amBoCeJsQAvD_BwE BUT!If you know how to correctly factory restore a computer and keep your important files, then I recommend doing that before doing anything else. You can then download a program like VLC Media Player to open those file types which have a hard time. You can then install all of your other programs that you has on your computer before the reset. Putting something like windows 7 on this machine probably wouldn't work all that well. So I do recommend buying the computer that Geek posted as your new daily driver. Hope everything goes smoothly! AnthonyAt 16 years, I don't think you have much hope left of salvaging anything from it. Plus, you say it's on XP. As much as I love XP, it doesn't have support and I wouldn't want to do any serious business work on a machine that can fail on me any time. You can perhaps look into a Chromebook if all you want is to access the net. I got a Chromebook for the heck of it since my work is primarily online, and I have to say that I'm impressed with the overall performance. It's not a laptop replacement but it works fine for majority of use cases. As for your computer, can you share the specs? You might be able to add a faster processor and upgrade the RAM for a quick performance boost |
|
4384. |
Solve : "need" FREE Firewall >>> please? |
Answer» Can someone recommend a decent "free" firewall download for my I heard Zone Alarm is a good free firewall. THANKS ANDREW! LOL "dumbass me" << I waited 15 minutes to download the free 13 MB file, then at the end it told me it was not compatable with my ol widows 98 , ;-0 should have done my homework before installing, thanks for your info though*http://www.comcen.com.au/~fed/sygate.zipPlease can you recommend a free firewall for Windows ME now that Zone Alarm has stopped updating? Microsoft RECOMMENDS these: http://www.microsoft.com/athome/security/protect/windowsme/firewall.mspx BUT, I want one that isn't a short-term free trial. :-/ Thank you. Quote http://www.comcen.com.au/~fed/sygate.zip that should work for winmeYou can check out a large list of free firewalls here: http://www.cleancomputerhelp.com/firewalls You will need to LOOK into the ones you may want to see if they are capatible w/ Win '98.Quote QuoteI heard Zone Alarm is a good free firewall. See how not posting info ahead of time can slow down the whole HELP process ? ?I'd also recommend Sygate. ZoneAlarm is good, but it is just too bloated IMO. Sygate does what it's supposed to and nothing else. My thoughts exactly SA, Zone Alarm has just gone over the top with frills. |
|
4385. |
Solve : "Nutsy" computer, logs attached? |
Answer» I followed all the instructions as directed by EvilFantasy's posts suggested by BatchRocks. |
|
4386. |
Solve : ZeuS? |
Answer» That looks good. Please tell me how your computer is working before we cleanup.As FAR as I can tell, everything works as before. I didn't notice any irregularity.Ok. We can do some cleanup. Secunia Software Inspector keeps telling me that my Java and Adobe Flash Player are not up-to-date, although I downloaded the newest versions and restarted the computer. Furthermore, the update programs Secunia offers (right below "Update instructions") seem not to work. When I open them nothing happens. I got the newest versions now from the official Java- and Flash Player-websites. Still Secunia says, they are not up-todate.There could be parts of a previous version left which would prompt those messages. It is most important to keep your Windows OS and Java up-to-date. I did notice that you have this on your computer: C:\Users\user\AppData\Roaming\Pocomail\Attach\keygen.zip ==> Cracks & Keygens <== Crackware is illegal and certainly very dangerous for the safety of your computer. Quote can I be sure that what we removed from my computer was really ZeuS? Can I use my computer for banking and the like without concern?There were some infections that affected your MBR (Master Boot Record). If you want to use this computer for banking I would strongly suggest a third-party firewall. I can be cumbersome at first to use but it will give added protection. Firewalls protect against hackers and malicious intruders. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
4387. |
Solve : Zcodec < delivers the nasties!? |
Answer» Users looking for the latest and greatest video software may not just be in danger from media lawyers. Security firm Panda Software last week warned that zCodec, which claims to offer "up to 40 percent better (video) quality," is in fact an adware program that can install Trojans, rootkits and other malicious software. |
|
4388. |
Solve : Adobe Flash player installed McAfee Security Scan Plus? |
Answer» Hello everyone,, |
|
4389. |
Solve : Virus Help? |
Answer» I use Zonealarm Ver 7.0 along with adaware and spybot w/tea timer. My ZA is a combo firewall a virus scan and just today started picking up this "Worm.Win32.Huhk.c", I am not able to access some sites that require Java or do any downloads includes MS updates for XP. It quarantines it but it keeps coming back, any ideas whats up. I select the more info link in ZA but it can't tell me anything about this. See screen capture fm by pc. " HouseCall requires that you activate at least Java Script. If you would like to continue, please activate Java Script in the browser settings and reload the page!"Then do so.All items listed with Java in the advanced tab of my browser are selected, I will restart and try again, thanks. If you're USING Internet Explorer, try FIREFOX, if you're gonna be able to download it.No go, I'll try firefox. OKIt ended up being a false/positive all is well know, thanks for the effort and help. You're welcome |
|
4390. |
Solve : Is This a Flaw in Kerio?? |
Answer» I ask, because I don't know - but it seemed odd. |
|
4391. |
Solve : Viruses and Hardware? |
Answer» my computer was shuting down too ofthen so i formatted it, but when installing a window pops up that says my HARD disk is messed up. so now i went and BOUGHT a new hard drive. i have 2 hard DRIVES one with alot of important info on it. at the same TIME a virus could be on that hard drive. should i STILL have the d drive connected to my new c drive? |
|
4392. |
Solve : help please...msn virus , photo.zip still , log file attached? |
Answer» Logfile of Trend Micro HijackThis v2.0.2
//log from MsnVirRem MsnVirRem Log by Skate_Punk_21 Fix running from: C:\Documents and Settings\jsu\Desktop 8/21/2008 11:22:09 PM ---Infection Files Found--- NO INFECTION FILES FOUND - Cleaning Aborted. //new log file Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:25:10 PM, on 8/21/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\Program Files\ActivCard\ActivClient\acautsrv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\ActivCard\ActivClient\acachsrv.exe C:\Program Files\ActivCard\ActivClient\acevents.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\Documents and Settings\jsu\Desktop\AVG Anti-Spyware\guard.exe C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lenovo\System Update\SUService.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\system32\conime.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UdaterUI.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Network Associates\Common Framework\McTray.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\TpScrLk.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\LVCOMSX.EXE D:\Folder Lockbox\flockbox.exe C:\Program Files\360safe\safemon\360tray.exe C:\Program Files\Southwest Airlines\Ding\Ding.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\jsu\rah.exe \o O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [flockbox] D:\Folder Lockbox\flockbox.exe /a O4 - HKLM\..\Run: [hipg] C:\WINDOWS\system32\hipg.exe \j O4 - HKLM\..\Run: [360Safetray] C:\Program Files\360safe\safemon\360tray.exe /start O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Add to QQ Customized Emoticons - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: Add to QQ Emotions - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Send Picture with QQ MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Upload to QQ Network Hard Disk - C:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 上傳到QQ網路硬碟 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 新增到QQ自定義面板 - D:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 新增到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: 氝樓善QQ桶 - C:\Program Files\QQ\Africa2003\AddEmotion.htm O8 - Extra context menu item: 添加到QQ自定義面板 - d:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\TM2008\Bin\AddEmotion.htm O8 - Extra context menu item: 用QQ MMS傳送該圖片 - D:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: 用QQ彩信發送該圖片 - d:\Program Files\Tencent\QQ\SendMMS.htm O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra 'Tools' menuitem: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra 'Tools' menuitem: AE°TQQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing) O9 - Extra 'Tools' menuitem: QQiA2E1??sIoEeOA - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing) O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O14 - IERESET.INF: START_PAGE_URL=http://cc.cadence.com O15 - Trusted Zone: crm.cadence.com O15 - Trusted Zone: crm-chs.cadence.com O15 - Trusted Zone: crm-cht.cadence.com O15 - Trusted Zone: crm-eng.cadence.com O15 - Trusted Zone: crm-jpn.cadence.com O15 - Trusted Zone: crm-kor.cadence.com O15 - Trusted Zone: srvcrmws.cadence.com O15 - Trusted Zone: srvcrmws01p.cadence.com O15 - Trusted Zone: srvcrmws02p.cadence.com O15 - ESC Trusted Zone: http://*.update.microsoft.com O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {3D3BF1F8-9696-4A5E-B4F1-49101C997B70} (VaxSIPUserAgentCAB Control) - http://labs.jaduka.com/VaxSIPUserAgentCAB.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214863331625 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\Software\..\Telephony: DomainName = global.cadence.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = global.cadence.com O20 - Winlogon Notify: acautsrv - C:\Program Files\ActivCard\ActivClient\ackpbsc.dll O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) O20 - Winlogon Notify: acunlock - C:\Program Files\ActivCard\ActivClient\acunlock.dll O20 - Winlogon Notify: opnnkiHY - opnnkiHY.dll (file missing) O20 - Winlogon Notify: SLLgnEvt - SLLgnEvt.dll (file missing) O23 - Service: ActivCard Authentication Service (ACachSrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acachsrv.exe O23 - Service: ActivCard Authentication Client Service (acautsrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acautsrv.exe O23 - Service: ActivCard Middleware Service (Accoca) - ActivCard Corp. - C:\Program Files\Common Files\ActivCard\accoca.exe O23 - Service: ActivCard Event Service (acevents) - ActivIdentity - C:\Program Files\ActivCard\ActivClient\acevents.exe O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing) O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing) O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Documents and Settings\jsu\Desktop\AVG Anti-Spyware\guard.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Cadence VPN\Extranet_serv.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe -- End of file - 17722 bytes Turn OFF AVG Antispyware so it does not interfere with the fixes we make with HijackThis. * Launch AVG Anti-Spyware. * From the "Status" menu, select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. * Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows". Restart the computer and leave AVG Antispyware OFF until we are completely done with cleaning. ---------- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) - O4 - HKLM\..\Run: [hipg] C:\WINDOWS\system32\hipg.exe \j - O4 - HKLM\..\Run: [360Safetray] C:\Program Files\360safe\safemon\360tray.exe /start - O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) - O9 - Extra button: (no name) - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing) - O9 - Extra 'Tools' menuitem: QQiA2E1??sIoEeOA - {DEDEB80D-FA35-45d9-9460-4983E5A8AFE6} - d:\Program Files\Tencent\QQ\QQIEHelper.dll (file missing) - O20 - Winlogon Notify: opnnkiHY - opnnkiHY.dll (file missing) - O20 - Winlogon Notify: SLLgnEvt - SLLgnEvt.dll (file missing) - O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (file missing) - O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (file missing) Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Go to Start > Run and type Notepad.exe then click OK. Copy and paste the following text within the code box into the new Notepad file. Code: [Select]@ECHO OFF sc stop AntiVirScheduler sc delete AntiVirScheduler sc stop AntiVirService sc delete AntiVirService exit In Notepad select File and Save as Choose the Save to location to be the Desktop and for the File name: type in fixme.bat making sure that the Save as type field says All files. Next double click fixservice.bat to run it. A black box should open and close after a short time, this is normal. Do not continue until the black box has closed Delete fixservice.bat from the Desktop. ---------- Go to Start > Run and type notepad.exe then click OK Copy the text in the Code box below and paste it into Notepad. Code: [Select]REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "hipg"=- "360Safetray"=- In Notepad go to File > Save as... Next to File name: type fixme.reg Use the dropdown box next to Save as type: and select All files. Save it to the Desktop. There should now be a file on the Desktop that looks like this Double-click fixme.reg it and allow it to merge with the Registry. You may not see anything happen but give it a few seconds or so to finish. Now delete the fixme.reg file from the Desktop. ---------- Now run a new HijackThis scan and post the log.file attached : thanks! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:20:39 AM, on 8/22/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\Program Files\ActivCard\ActivClient\acautsrv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\ActivCard\ActivClient\acachsrv.exe C:\Program Files\ActivCard\ActivClient\acevents.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lenovo\System Update\SUService.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\system32\conime.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UdaterUI.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Network Associates\Common Framework\McTray.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\TpScrLk.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Analog Devices\SoundMAX\Smax4.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\LVCOMSX.EXE D:\Folder Lockbox\flockbox.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\jsu\rah.exe \o O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [flockbox] D:\Folder Lockbox\flockbox.exe /a O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Add to QQ Customized Emoticons - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: Add to QQ Emotions - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Send Picture with QQ MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Upload to QQ Network Hard Disk - C:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 上傳到QQ網路硬碟 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 新增到QQ自定義面板 - D:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 新增到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: 氝樓善QQ桶 - C:\Program Files\QQ\Africa2003\AddEmotion.htm O8 - Extra context menu item: 添加到QQ自定義面板 - d:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\TM2008\Bin\AddEmotion.htm O8 - Extra context menu item: 用QQ MMS傳送該圖片 - D:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: 用QQ彩信發送該圖片 - d:\Program Files\Tencent\QQ\SendMMS.htm O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra 'Tools' menuitem: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra 'Tools' menuitem: AE°TQQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O14 - IERESET.INF: START_PAGE_URL=http://cc.cadence.com O15 - Trusted Zone: crm.cadence.com O15 - Trusted Zone: crm-chs.cadence.com O15 - Trusted Zone: crm-cht.cadence.com O15 - Trusted Zone: crm-eng.cadence.com O15 - Trusted Zone: crm-jpn.cadence.com O15 - Trusted Zone: crm-kor.cadence.com O15 - Trusted Zone: srvcrmws.cadence.com O15 - Trusted Zone: srvcrmws01p.cadence.com O15 - Trusted Zone: srvcrmws02p.cadence.com O15 - ESC Trusted Zone: http://*.update.microsoft.com O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {3D3BF1F8-9696-4A5E-B4F1-49101C997B70} (VaxSIPUserAgentCAB Control) - http://labs.jaduka.com/VaxSIPUserAgentCAB.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214863331625 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\Software\..\Telephony: DomainName = global.cadence.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = global.cadence.com O20 - Winlogon Notify: acautsrv - C:\Program Files\ActivCard\ActivClient\ackpbsc.dll O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) O20 - Winlogon Notify: acunlock - C:\Program Files\ActivCard\ActivClient\acunlock.dll O23 - Service: ActivCard Authentication Service (ACachSrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acachsrv.exe O23 - Service: ActivCard Authentication Client Service (acautsrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acautsrv.exe O23 - Service: ActivCard Middleware Service (Accoca) - ActivCard Corp. - C:\Program Files\Common Files\ActivCard\accoca.exe O23 - Service: ActivCard Event Service (acevents) - ActivIdentity - C:\Program Files\ActivCard\ActivClient\acevents.exe O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Cadence VPN\Extranet_serv.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe -- End of file - 16226 bytes I still see C:\Temp\photo.zip got created repeatedly , delete won't stop it.Download Malwarebytes' Anti-Malware (MBAM)
Post the MBAM log and let me know how things are now.//log attached , thanks!! Malwarebytes' Anti-Malware 1.25 Database version: 1076 Windows 5.1.2600 Service Pack 2 12:51:13 AM 8/22/2008 mbam-log-08-22-2008 (00-51-13).txt Scan type: Quick Scan Objects scanned: 56575 Time elapsed: 7 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 16 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\qqiehelper.qqbrowserhelperobject (Spyware.OnlineGames) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qqiehelper.qqbrowserhelperobject.1 (Spyware.OnlineGames) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\aldd (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\BaiDu\bar (Adware.Cinmus) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM939e4926.xml (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\BM939e4926.txt (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully. after delete photo.zip under c:\temp , I re-start msn, then msn started to send our virus to all my contact . and photo.zip reappear under \temp Were getting there, it will take multiple steps but we will get it. This is a stubborn one to deal with. Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. thanks Evil: I am almost 80% done , not sure if I am ok now. It took me a long time to get the combofix to run due to my antivirus program. I can't turn it off unless in safe mode. (company computer) combofix ran in safe mode, but got killed after reboot (during generating report) . I assume it is done. msn seems normal so far. attached log from hijack Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 02:19, on 2008-08-22 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0013) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\Program Files\ActivCard\ActivClient\acautsrv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\ActivCard\ActivClient\acachsrv.exe C:\Program Files\ActivCard\ActivClient\acevents.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lenovo\System Update\SUService.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\conime.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\Program Files\Network Associates\Common Framework\UdaterUI.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Network Associates\Common Framework\McTray.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe C:\WINDOWS\system32\TpScrLk.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\LVCOMSX.EXE D:\Folder Lockbox\flockbox.exe C:\Program Files\Southwest Airlines\Ding\Ding.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\WINDOWS\explorer.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\ThinkVantage Fingerprint Software\launcher.exe" /startup O4 - HKLM\..\Run: [TPKBDLED] C:\WINDOWS\system32\TpScrLk.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [flockbox] D:\Folder Lockbox\flockbox.exe /a O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe O8 - Extra context menu item: &使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_link.htm O8 - Extra context menu item: &全部使用 FlashGet 下載 - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Add to QQ Customized Emoticons - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Add to QQ Customized Panel - C:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: Add to QQ Emotions - C:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Foxy ?? - res://C:\Program Files\Foxy\Foxy.exe/download.htm O8 - Extra context menu item: Send picture by MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Send Picture with QQ MMS - C:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: Upload to QQ Network Hard Disk - C:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 上傳到QQ網路硬碟 - D:\Program Files\Tencent\QQ\AddToNetDisk.htm O8 - Extra context menu item: 新增到QQ自定義面板 - D:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 新增到QQ表情 - D:\Program Files\Tencent\QQ\AddEmotion.htm O8 - Extra context menu item: 氝樓善QQ桶 - C:\Program Files\QQ\Africa2003\AddEmotion.htm O8 - Extra context menu item: 添加到QQ自定義面板 - d:\Program Files\Tencent\QQ\AddPanel.htm O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\TM2008\Bin\AddEmotion.htm O8 - Extra context menu item: 用QQ MMS傳送該圖片 - D:\Program Files\Tencent\QQ\SendMMS.htm O8 - Extra context menu item: 用QQ彩信發送該圖片 - d:\Program Files\Tencent\QQ\SendMMS.htm O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll O9 - Extra button: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra 'Tools' menuitem: SSO Wizard - {48428AD9-F53A-4c40-AC16-41DB6A2B67C6} - C:\Program Files\ActivIdentity\SecureLogin\localhero.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra 'Tools' menuitem: PPLive - {95B3F550-91C4-4627-BCC4-521288C52977} - D:\PPLive\PPLive.exe O9 - Extra button: QQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra 'Tools' menuitem: AE°TQQ - {c95fe080-8f5d-11d2-a20b-00aa003c157b} - d:\Program Files\Tencent\QQ\QQ.EXE O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O14 - IERESET.INF: START_PAGE_URL=http://cc.cadence.com O15 - Trusted Zone: crm.cadence.com O15 - Trusted Zone: crm-chs.cadence.com O15 - Trusted Zone: crm-cht.cadence.com O15 - Trusted Zone: crm-eng.cadence.com O15 - Trusted Zone: crm-jpn.cadence.com O15 - Trusted Zone: crm-kor.cadence.com O15 - Trusted Zone: srvcrmws.cadence.com O15 - Trusted Zone: srvcrmws01p.cadence.com O15 - Trusted Zone: srvcrmws02p.cadence.com O15 - ESC Trusted Zone: http://*.update.microsoft.com O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com.cn/webscanner/kavwebscan_unicode.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {3D3BF1F8-9696-4A5E-B4F1-49101C997B70} (VaxSIPUserAgentCAB Control) - http://labs.jaduka.com/VaxSIPUserAgentCAB.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1214863331625 O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\Software\..\Telephony: DomainName = global.cadence.com O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = global.cadence.com O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = global.cadence.com O20 - Winlogon Notify: acautsrv - C:\Program Files\ActivCard\ActivClient\ackpbsc.dll O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing) O20 - Winlogon Notify: acunlock - C:\Program Files\ActivCard\ActivClient\acunlock.dll O23 - Service: ActivCard Authentication Service (ACachSrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acachsrv.exe O23 - Service: ActivCard Authentication Client Service (acautsrv) - ActivCard Corp. - C:\Program Files\ActivCard\ActivClient\acautsrv.exe O23 - Service: ActivCard Middleware Service (Accoca) - ActivCard Corp. - C:\Program Files\Common Files\ActivCard\accoca.exe O23 - Service: ActivCard Event Service (acevents) - ActivIdentity - C:\Program Files\ActivCard\ActivClient\acevents.exe O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: McAfee Host Intrusion Prevention Service (enterceptAgent) - McAfee, Inc. - C:\Program Files\McAfee\Host Intrusion Prevention\FireSvc.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Cadence VPN\Extranet_serv.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe -- End of file - 16321 bytes I need the ComboFix log. Go to C:\combofix.txt and see it the log is there. |
|
4393. |
Solve : XP Antivirus? |
Answer» The program files can be backed up onto a CD or flash drive.
IE is still the same wont let me access those links you posted and it gives me strange google searchesTry booting into Safe Mode and running a Full system scan with MalwareBytes.Alrite that'll take me about more then an hour. So ill see you thenif you're using xp or VISTA and have system restore points, I'd have just restored to an earlier date. However .... first complete the fixes that are already in place Quote from: mcxeb52! on August 22, 2008, 03:05:17 PM if you're using xp or vista and have system restore points, I'd have just restored to an earlier date. However .... first complete the fixes that are already in place It's best to follow the instuctions evilfantasy gave. Malwarebytes' Anti-Malware 1.17 Database version: 856 6:32:19 PM 8/22/2008 mbam-log-8-22-2008 (18-32-19).txt Scan type: Full Scan (C:\|J:\|) Objects scanned: 118149 Time elapsed: 1 hour(s), 17 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Richard\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Richard\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Richard\Local Settings\Temp\.tt3.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Documents and Settings\Richard\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully. Done. Have you got a Hijack This log at all? Or is it that you had to type it out? I think it will be needed.Agreed, if we could get a HJT log at some point it would be a huge help. This scan can only be run in Safe Mode. Download SDFix by AndyManchesta and save it to your desktop. When using this tool, you must use the Administrator's account or an account with Administrative rights
Open the SDFix folder and double click RunThis.bat to start the script.
http://www.windowsvistaplace.com/xp-antivirus-2008-removal-instructions-xp-antivirus-2008/spyware-removal EDIT: I cant download SDdFix. Link is being stupidQuote from: kpac on August 22, 2008, 04:31:26 PM Quote from: mcxeb52! on August 22, 2008, 03:05:17 PMif you're using xp or vista and have system restore points, I'd have just restored to an earlier date. However .... first complete the fixes that are already in place Yeah. isn't that what I said? I'd fix it a certain WAY that has helped me many times but evilfantasy is already taken him so far so why stop at this point?Quote from: hunt3rshadow on August 22, 2008, 05:10:42 PM Yes very well, I will do as you stated BTW I cant download HJT it wont let me with the links being stupid. What can you do with this PC? Can you go to another computer and download all these tools? If you can, do that, and copy them to a flash drive or CD or something, and run them on the infected PC.Thanks to everyone's help. I just got rid of this cursed thing by running MBAM multiple times then cleaning my registry. My computer's running fine so far and the background has changed back to normal.It may seem fine, but the virus might be still on your computer. I recommend you continue with posting the logs/following our instructions etc.Quote from: kpac on August 23, 2008, 08:54:40 AM It may seem fine, but the virus might be still on your computer. At least for now, I'd post a new HiJackThis Log and have evilfantasy review it one more time to be sure it's clean. You don't want to have traces of diseases still lingering in your body that might potentially open up another problem EVEN though you are now feeling fine and life appears to be going on normally. |
|
4394. |
Solve : Can't log into safemode or normal mode; computer states I have spyware? |
Answer» Hello, |
|
4395. |
Solve : Registry....? |
Answer» okay I think I did everything right thank you again Evilfantasy I really appreciate it.Uninstall Java(TM) 6 Update 5 |
|
4396. |
Solve : Firefox crashes and IE is invaded? |
Answer» Do this to remove all unstable older versions of Flash. |
|
4397. |
Solve : help again? |
Answer» Logfile of Trend Micro HijackThis v2.0.2 |
|
4398. |
Solve : Would you like to learn to fight malware?? |
Answer» It can often TAKE up to a week to get accepted, sometimes longer during the summer. Just be PATIENT and I'm sure you'll hear SOMETHING from them soon enough. If not, you can ALWAYS try applying somewhere else.Quote from: CBMatt on August 22, 2008, 04:36:56 PM It can often take up to a week to get accepted, sometimes longer during the summer. Just be patient and I'm sure you'll hear something from them soon enough. If not, you can always try applying somewhere else. Yep... Took about 2 weeks for me and I applied in the start of "summer". |
|
4399. |
Solve : ...be Genuine' get Microsoft Security Essentials for Free'? |
Answer» if you are looking for a lifetime anti-virus, malware and spyware protection' and USING a genuine copy of Windows OS' you can get their free security software for this... |
|
4400. |
Solve : CA Internet Security Provided by Road Runner? |
Answer» Has anybody had problems with CA, which I think stands for Computer Associates, the internet security service provided free by Road Runner? |
|