Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Help Please, Adware Virus, I Can't Uninstall It,

Options
2»

Comments

  • Niels
    Options

    Hello inSAnitY13x


    If superantispyware can't remove it you have to run smitfraudfix also. For the exact instructions see my instructions to balasblue. Run also rogueremover.


    Best regards


    Niels

  • GUYS I DID IT!!!!!!!!!!


    thank you for your help! it was easier than most people might think!


    All you have to do is reboot on safe mode, sign into your account and when a window pops up asking if you wish to do a system restore, click YES! I went back 1 week in time to restore everything from there :D I'm so excited!

  • Niels
    Options

    Hello inSAnitY13x


    That isn't really removing the infection. But it can help.


    Best regards


    Niels

  • All I care about is that it's gone :)

  • Well, System Restore deletes all exe, dll, sys, ini, and probably several other types of files created after the restore point and restores all deleted files of the same types. Also restores the registry in its previous state, so the infection is removed, if you can go back in time to a point before the infection occurred. You're fortunate to have successfully restored to such a point. To help you avoid future spyware infections, you may want to install Spyware Blaster, you can read more about it and download it here: http://filehippo.com/download_spywareblaster/


    :)

  • Niels
    Options

    Hello bluesprite


    I did once a system restore to an earlier date and I was still able to execute a program that normally wasn't installed yet. That is why I don't recommend it by just going back to a previous point.


    Best regards


    Niels

  • That is certainly strange, Niels. It's not how it's supposed to work, if it works properly, that is. I've had that only if the program has been installed on a drive different than C:, on which I've disabled System Restore. In that case the program will remain intact. But even just restoring the registry is enough to deactivate the infection from loading automatically, which then can be removed with the help of a scanner. It's one of the easiest things to try first and it's safe to try, before turning to alternatives. :)

  • Hi Niels & bluesprite


    Sorry for the delay in getting back, it's a bit hectic here.


    I ran SmitFraudFix and have posted the report below.


    I'm still getting lots & lots of advertising pop ups. Also I'm still getting these bogus antispyware security windows coming up. One of these popped up while I was here in the forum. I did as you said Niels and did a print screen and pasted it into 'paint' but I can't seem to then copy it here in this post. I was going to paste it here for you to see in the hope it would help you so you could see what it was. Perhaps you would be kind enough to post here the instructions on how to copy it here as InSAnitY13x did with her screen shot. I tried copy & paste, that didn't work I couldn't 'paste'. I tried draggin the picture into this post but then I lost the forum and just had the picture, so I'd appreciate if you could explain how to do it.


    I'll check back in a while to see what you say.


    Bye the way if we can't sort my computer out by the 15th Oct I'll have to leave it until after we've moved as that is the day we move.


    Here's the report below.


    Thanks again


    Carol


    SmitFraudFix v2.232


    Scan done at 12:04:52.12, 03/10/2007


    Run from C:\Smitfraud\SmitfraudFix


    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT


    The filesystem type is NTFS


    Fix run in safe mode


    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix


    !!!Attention, following keys are not inevitably infected!!!


    SrchSTS.exe by S!Ri


    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts


    127.0.0.1 localhost


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix


    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» DNS


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System


    !!!Attention, following keys are not inevitably infected!!!


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning


    Registry Cleaning done.


    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix


    !!!Attention, following keys are not inevitably infected!!!


    SrchSTS.exe by S!Ri


    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

  • Niels
    Options

    Hello balasblue


    The problem here in this section is that I can't see what you have uploaded.


    I saw another suspecious entry in your hijackthis logfile :


    O17 - HKLM\System\CCS\Services\Tcpip\..\{68CDEDDE-1059-4A7E-A9BC-444989ABD99F}: NameServer = 212.139.132.57 212.139.132.56


    Did superantispyware found something?


    Click on start,run,type msconfig click on ok or press on the enter button of your keyboard. Now click on the startup tab. You have to enter the name of each item that you will find after the checked box. On this website. When you are on that website you have to type the name in the blank field before the search button.You will get information but you have to look at the key ( N or X or ?). If you see the key by one of your startup items you have to uncheck the box on the startup tab of msconfig.


    Best regards


    Niels

  • The addresses in that entry are the DNS servers of Tiscali UK Ltd., which is her ISP, so nothing suspicious there.


    Balasblue, could you please create a new logfile with Hijack This and post it so we can see the current state of your registry? When you fixed the entries the last time, did the popups stop for some time before they started appearing again, or they never went away?

  • Hi Niels & bluesprite


    I have run Hijack This again and below is the results. Thought I'd do this bit first in case it helped you more.


    Can you tell me how to get the screen shots from 'paint' to copy or paste in a post here. As I say I was going to show you the rogue antispyware window, but couldn't get it to 'paste' in the forum post page ??. I'd very much appreciate it if you could tell me how to do it.


    Thanks


    Carol


    Scan results.


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 19:47:33, on 03/10/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16512)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


    C:\WINDOWS\Explorer.EXE


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\system32\drivers\KodakCCS.exe


    C:\Program Files\KService\KService.exe


    C:\WINDOWS\system32\ScsiAccess.EXE


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\system32\VTTimer.exe


    C:\WINDOWS\system32\S3trayp.exe


    C:\WINDOWS\RTHDCPL.EXE


    C:\Program Files\Softwin\BitDefender10\bdmcon.exe


    C:\Program Files\Softwin\BitDefender10\bdagent.exe


    C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe


    C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe


    C:\Program Files\QuickTime\qttask.exe


    C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe


    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\WINDOWS\kdx\KHost.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe


    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\IncrediMail\bin\IncMail.exe


    C:\PROGRA~1\INCRED~1\bin\IMApp.exe


    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    C:\Program Files\Softwin\BitDefender10\vsserv.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll


    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll


    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe


    O4 - HKLM\..\Run: [s3Trayp] S3trayp.exe


    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE


    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe


    O4 - HKLM\..\Run: [bDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"


    O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"


    O4 - HKLM\..\Run: [adiras] adiras.exe


    O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe


    O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [smileycons] C:\Program Files\Smileycons\smileycons.exe


    O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all


    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe


    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe


    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe


    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\bin\resources\WebMenuImg.htm


    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000


    O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html


    O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html


    O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html


    O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab


    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab


    O17 - HKLM\System\CCS\Services\Tcpip\..\{68CDEDDE-1059-4A7E-A9BC-444989ABD99F}: NameServer = 212.139.132.57 212.139.132.56


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe


    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe


    O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe


    O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE


    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 7719 bytes

  • I can't see anything wrong in this log. I checked all the startup items and all of them seem legitimate. Please open Hijack This and click on Open the Misc Tools section. Under System Tools, click Open hosts file manager. Click the Open in Notepad button, then copy the contents and paste them here. Now click the Back button and then click the Open ADS spy button. Click Scan, and if anything comes up, click Save log, then save the file and paste the contents here.

  • Niels
    Options

    Hello balasblue


    I suggest that you make your screenshot and upload it to this website. To do that press on browse now navigate to the folder or location where you stored your screenshot and press on open. You have to wait till the process finishes post the downloadlink.


    Best regards


    Niels

  • Hello bluesprite & Niels


    Here's the Hijack This report. Nothing came up when I did the ADS Scan.


    I hope I did the screen shot ok, I did as you said, clicked on 'browse' went to the screen shot I saved and clicked on open and then on the green upload button. But I'm a bit confused, sorry. It says attachment space used 820.23K, and the route to the file is in the window next to the browse button, but it also says 'you did not select a file to upload' so I'm not sure what I did wrong. When you say post the downloadlink, I'm not sure what you mean by that? sorry.


    Perhaps you could try explaining it again, really sorry, doing my best.


    Thanks


    Carol


    # Copyright © 1993-1999 Microsoft Corp.


    #


    # This is a sample HOSTS file used by Microsoft TCP/IP for Windows.


    #


    # This file contains the mappings of IP addresses to host names. Each


    # entry should be kept on an individual line. The IP address should


    # be placed in the first column followed by the corresponding host name.


    # The IP address and the host name should be separated by at least one


    # space.


    #


    # Additionally, comments (such as these) may be inserted on individual


    # lines or following the machine name denoted by a '#' symbol.


    #


    # For example:


    #


    # 102.54.94.97 rhino.acme.com # source server


    # 38.25.63.10 x.acme.com # x client host


    127.0.0.1 localhost

  • bluesprite
    edited October 2007
    Options

    Post the URL (the route) of the file, if you've been given one. Upload it again and give the new one if you don't have the old one anymore. As for the logfile, it's clean, and I really don't know what else to do about your problem. You have some toolbars on your browser, like the eBay and easy web print, I'm wondering if any of them might be the culprit.

  • Kkay
    Options

    Hi peeps! I have been using most of the suggestions you have been giving re: removing an adware/spyware virus. Very educational so far, thank you. Well here I am posting with a computer that as slow as AOL dial up in 1992 ,cause of the virus that was let in while someone uploaded a game online. Anywho... So far I have downloaded & scanned with:


    Superantispyware


    Hijack This


    Rogue Remover


    Ad Ware 2007


    Spywareblaster would download but not install, just some noise then nothing.


    Also Ad Ware 2007 scanned first time, then I quarentined,then next time tried to scan had this Error message: Exception EInvalid OP in module Ad-Awre2007.exe at 015c293a. Invalid floating point operation. So I uninstalled it & tried to reinstall it. Now it sometimes scans sometimes same error message comes up.


    Rogue Remover did remove some stuff in the beg. cause that's the first thing I used.


    Superantispyware removed alot of stuff,however,not all spyware/adware cause it still continued. Also I did notice that some of the things it removed would come back after opening browser for any website or search( I do think that my browser has been hijacked & is the source of my problem,but I am not great on the tech stuff, just noticed alot of the same names coming back on the scans)


    One important thing I did notice is that after downloading Superantispyware, I also had flash animation pop-ups of anti-spy removal services(1 in particular) that same ad appears everywhere. This animation is the same one that when you go to initially download & one of you(I think Niels)said dont click on the advertisement wait for the real download, well it's that one. I didnt ever click on it,but it follows me everywhere!!


    So again, here I am for your help if you would be soooooo kind to let me know what's my next step as I am ready to hurl the computer out the window,it's gotten so carrier pigeon would be quicker.LOL


    Here's my Hijack this log


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 2:03:41 AM, on 10/10/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16512)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Windows Defender\MsMpEng.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\Explorer.EXE


    C:\Documents and Settings\Owner\My Documents\aawservice.exe


    C:\WINDOWS\system32\brsvc01a.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\system32\brss01a.exe


    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe


    C:\WINDOWS\system32\Brmfrmps.exe


    C:\WINDOWS\eHome\ehRecvr.exe


    C:\WINDOWS\eHome\ehSched.exe


    C:\WINDOWS\system32\nvsvc32.exe


    C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe


    C:\WINDOWS\system32\dllhost.exe


    C:\WINDOWS\ehome\ehtray.exe


    C:\Program Files\Digital Media Reader\readericon45G.exe


    C:\WINDOWS\eHome\ehmsas.exe


    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe


    C:\WINDOWS\RTHDCPL.EXE


    C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe


    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe


    C:\Program Files\Brother\ControlCenter2\brctrcen.exe


    C:\WINDOWS\system32\RUNDLL32.EXE


    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe


    C:\Program Files\QuickTime\qttask.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\Verizon\McciTrayApp.exe


    C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe


    C:\Program Files\Softwin\BitDefender10\bdagent.exe


    C:\Program Files\Windows Defender\MSASCui.exe


    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe


    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe


    C:\WINDOWS\system32\hphmon04.exe


    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\iPod\bin\iPodService.exe


    C:\Program Files\11g USB adapter\Wifiusb.exe


    C:\Program Files\BigFix\BigFix.exe


    C:\Documents and Settings\Owner\My Documents\HostFileEditor.exe


    C:\WINDOWS\system32\drwtsn32.exe


    C:\Documents and Settings\Owner\My Documents\Ad-Aware2007.exe


    C:\WINDOWS\system32\drwtsn32.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Documents and Settings\Owner\My Documents\Ad-Aware2007.exe


    C:\WINDOWS\system32\drwtsn32.exe


    C:\WINDOWS\system32\wuauclt.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    C:\Program Files\Softwin\BitDefender10\vsserv.exe


    C:\WINDOWS\system32\wuauclt.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/clientapps/AutoSear...rch/search.html


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/


    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/clientapps/AutoSear...//www.yahoo.com


    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://activate.verizon.net/launch/res1/ht...oo_pc_help.html


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll


    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe


    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe


    O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe


    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE


    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE


    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


    O4 - HKLM\..\Run: [VerizonServicepoint.exe] C:\Program Files\Verizon\Servicepoint\VerizonServicepoint.exe


    O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot


    O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe


    O4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe


    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun


    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe


    O4 - HKLM\..\Run: [bDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"


    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide


    O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard utility\1.3\MMKEYBD.EXE


    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe


    O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"


    O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe


    O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe


    O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win27.tmp.exe


    O4 - HKLM\..\Run: [smgr] mgrs.exe


    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


    O4 - HKLM\..\Run: [searchIndexer] rundll32.exe "C:\WINDOWS\system32\dyfxgbeo.dll",sitypnow


    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [zeSetup.exe] C:\DOWNLO~1\ZESETU~1.EXE /r


    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet


    O4 - Global Startup: 802.11g USB adapter.lnk = C:\Program Files\11g USB adapter\Wifiusb.exe


    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe


    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe


    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe


    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    O9 - Extra button: ReconnectToolbar - {3625C83A-0065-48B3-A81C-0D21DD0BDFA6} - C:\Program Files\Auction Trust Network\Reconnect\ReconnectToolbar.dll


    O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe


    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204


    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll


    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab


    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1186040307750


    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup162.cab


    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Documents and Settings\Owner\My Documents\aawservice.exe


    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe


    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe


    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe


    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe


    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS


    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)


    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 11015 bytes


    YEA, thats alot of log,HUH?


    Also did try to disable a couple of the things in manage add ons in internet explorer but they always re-enable themselves.As of now I set everything in Internet options Security & such to default,so that you can help me set that correct as well,if you would.


    Last but not least is one name that keeps coming back on the scans VUNDO/VARIANT(as of right now I'm not sure if that ones quarentined or gone or what)... just in case that's helpful.


    If you can help me on this I would so make you my best friend in the whole world!!! :wub:

  • Kkay
    Options

    Last thing(Man,do I talk alot?) I have Windows XP service pack2/use yahoo mail/Internet Explorer w/ a Yahoo homepage & toolbar & default google search/Verizon FIOS internet/Bitdefender v10(obvious)


    If theres any other unnecessary stuff I could get rid of please let me know. I have deleted some complete programs & files/things but some did not delete everything cause that little scary box sometimes pops up & tells you that if you delete that particular file/folder or program that it might render other programs inoperable or not be able to open other stuff. A good example of this is AOL, I did delete most of it,but some things with AOL on them had that scary box pop up. I dont use AOL or ever intend to have any of there services if I can help it. Thank you again soooo very much. ;)

  • bluesprite
    edited October 2007
    Options

    Remove these:


    O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win27.tmp.exe


    O4 - HKLM\..\Run: [smgr] mgrs.exe


    O4 - HKCU\..\Run: [zeSetup.exe] C:\DOWNLO~1\ZESETU~1.EXE /r


    The first two belong to a malware and the last isn't something you should have starting automatically every time. After you fix the entries in Hijack This, run a search or locate those files and delete them from your hard disk. Purge your System Restore and run all the scans that you did before. You have a lot of startup items, perhaps you have a very fast computer to handle them lol. Also, there's some Symantec leftover, if you don't use a Symantec product anymore (which you shouldn't), run some Symantec Removal Tool. The other thing I saw is, you have installed Ad Aware 2007 in your My Documents folder. It's not a problem, but definitely unpractical and unusual.


    Hope you get rid of the problem, and btw, don't you plan to install BitDefender 11?


    :)

  • Kkay
    Options

    Hi, me again. I did read your reply Bluesprite. I didn't get a chance to remove those. Well, what happened is after I posted, I really was taking a look at the Flash animation & some particular adware & spyware install or whatever files that would be quarantined or removed with some of the programs you told me about & then they would come back again as soon as I open my browser. Well, I figured out that the Superantispyware or Rogueremover had spyware/adware in it & maybe even the spywareblaster that would download but never open up.So it would remove the initial infection I had but then install it's own.I think it was the Superantispyware. Well, I removed those programs & downloaded AVG anti spy & anti virus free version & ran them both. Well, those files I mentioned were detected again & I quarantined/removed them & my computer hasn't had a pop up or flash animation anything since.


    I did want to tell you & Niels thank you so much for your posts, without them I would have been lost. Not to mention the computer education that I recieved along with it. Thank you again,Kkay

  • Niels
    Options

    Hello Kkay


    Go to start,run,type regedit press enter expand hkey_local_machine open the following folder : software and these subfolders: microsoft,windows,currentversion,run you will find it at the right side of the screen select it and press on the delete button. You will find 3 entries: mgrs.exe,win27.tmp.exe, C:\DOWNLO~1\ZESETU~1.EXE /r


    Superantispyware and rogueremover are trustfull products who doesn't have adware included. Or I must misunderstood what you said. Good to hear that what I said helped in some way.


    Best regards


    Niels

  • Hi Everyone... Sorry if I'm butting in but I REALLY need some help form people who know what they are doing... because I sure as anything don't...


    I'm getting the same window pop up on 2 PCs and would love to get rid of it once and for all... We have broadband in 2 different places (I've recently moved out of the family home)... So my pc and the family pc have never been linked and seem to be messing up in he same way


    What can I do to stop this?


    If I need to use Hijack this then you'll need to tell me a reliable download site and how to use it without messing up my pc.. and obviously what else i need to use..


    I’ve tried using one suggestion of opening IE>tools>popup blocker.. but i don't seem to have that.. i have tools but no popup blockers.. and the windows updates are done automatically


    Can you help me PLEASE! :(:(:(:( Preferably before I go completely do lally tap


    Thank you


    VEN

  • Niels
    Options

    Hello Ven_tura


    I recommend that you first do this:


    Download rogue remover


    here


    .Start the program press on check for updates,press again of check for updates,when there are update available you can click on download do that. After you have done that when there aren't updates any more you will get informed press on close. After that press on the scan button.


    Superantispyware:


    Install it after that double click on the shortcut of the program you will see an icon near your system clock that looks like a bug (insect) right click on it and click on check for updates. When you have done that reboot your pc but press several times on the F8 button before the windows loading screen. Select safe mode and press enter. Now click on your user account and log-in. After that start superantispyware by doing the same thing as when your performed an update but click now on scan for ... (spywaren,adware,malware) select complete scan and press on next. Let the program remove everything. Reboot your pc as you always do.


    Download hijackthis.


    Just double click on hijack this and press on do a system scan and save a log file. Copy the entire log file to your next post.


    Best regards


    Niels

  • Hi Niels


    thank you for your advise i will definately try what you have suggested however the link you supplied for the 1st program does not appear to work


    Ven

  • Niels
    Options

    Hello Ven_tura


    Try this link. Choose one of the download locations.


    Best regards


    Niels

  • Hi thanks for the new link


    here is the Hijackthis log file


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 03:44:18, on 21/10/2007


    Platform: Windows 2000 SP4 (WinNT 5.00.2195)


    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Boot mode: Normal


    Running processes:


    C:\WINNT\NEW\System32\smss.exe


    C:\WINNT\NEW\system32\winlogon.exe


    C:\WINNT\NEW\system32\services.exe


    C:\WINNT\NEW\system32\lsass.exe


    C:\WINNT\NEW\system32\svchost.exe


    C:\WINNT\NEW\system32\spoolsv.exe


    C:\WINNT\NEW\System32\svchost.exe


    C:\WINNT\NEW\system32\hidserv.exe


    C:\WINNT\NEW\system32\regsvc.exe


    C:\WINNT\NEW\system32\MSTask.exe


    C:\WINNT\NEW\system32\stisvc.exe


    C:\WINNT\NEW\System32\WBEM\WinMgmt.exe


    C:\WINNT\NEW\System32\mspmspsv.exe


    C:\WINNT\NEW\system32\svchost.exe


    C:\WINNT\NEW\Explorer.EXE


    C:\WINNT\NEW\system32\internat.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =


    http://www.google.co.uk/


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}


    - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll


    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -


    C:\Program Files\Spybot - Search & Destroy\SDHelper.dll


    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -


    C:\WINNT\NEW\system32\msdxm.ocx


    O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon


    O4 - HKLM\..\Run: [LoadQM] loadqm.exe


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program


    Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [sony Ericsson PC Suite] "C:\Program Files\Sony


    Ericsson\Mobile2\Application Launcher\Application Launcher.exe"


    /startoptions


    O4 - HKCU\..\Run: [internat.exe] internat.exe


    O4 - HKCU\..\Run: [spyware Cleaner] "C:\Program Files\Spyware


    Cleaner\SpywareCleaner.Exe" /boot


    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN


    Messenger\msnmsgr.exe" /background


    O4 - HKCU\..\Run: [MtdAcqu] "C:\Program


    Files\Creative\MediaSource5\MtdAcqu.exe" /s


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program


    Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default


    user')


    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program


    Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User


    'Default user')


    O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program


    Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe


    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft


    Office\Office\OSA9.EXE


    O8 - Extra context menu item: &Clean Traces - C:\Program


    Files\DAP\Privacy Package\dapcleanerie.htm


    O8 - Extra context menu item: &Download with &DAP - C:\Program


    Files\DAP\dapextie.htm


    O8 - Extra context menu item: Download &all with DAP - C:\Program


    Files\DAP\dapextie2.htm


    O16 - DPF: Yahoo! Backgammon -


    http://download2.games.yahoo.com/games/clients/y/at1_x.cab


    O16 - DPF: Yahoo! Dominoes -


    http://download2.games.yahoo.com/games/clients/y/dot9_x.cab


    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)


    -


    http://www.update.microsoft.com/windowsupd...rols/en/x86/cli


    ent/wuweb_site.cab?1188643760134


    O20 - Winlogon Notify: !SASWinLogon - C:\Program


    Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) -


    VERITAS Software Corp. - C:\WINNT\NEW\System32\dmadmin.exe


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision


    Corporation - C:\Program Files\Common


    Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe


    --


    End of file - 3525 bytes

  • Niels
    Options

    Hello Ven_tura


    I see that spywarecleaner is installed this is a rogue product.


    Fix this entry to do that check the box before :


    O4 - HKCU\..\Run: [spyware Cleaner] "C:\Program Files\SpywareCleaner\SpywareCleaner.Exe" /boot and press on fix checked. Now go to start,run,type regedit press enter now expand hkey_current_user,open the follow folder : software and subfolders,microsoft,windows,currentversion,run,you must take a look at the right side and delete the entry called SpywareCleaner.exe by leftclicking on it and press on the delete button.


    Now go to start,my computer,double click on the icon of your hard disc open the folder program files when you have done that Delete the spywarecleaner folder. Go back to the registry (typing regedit by run) now expand hkey_local_machine,software,microsoft,windows,currentversion,app paths,SpywareCleaner.exe If present select it and delete it. Now navigate further to uninstall, Spyware Cleaner If present delete only the Spyware Cleaner entry. After that go back to the key hkey_local_machine but open software and remove also the Spyware Cleaner reference. Now navigate also to these locations and do the same:


    system\controlset001\services\eventlog\application\SpywareCleanerService


    system\currentcontrolset\services\eventlog\application\SpywareCleanerService


    system\controlset001\services\SpywareCleanerService


    system\currentcontrolset\services\SpywareCleanerService


    You will find them also under hkey_local machine.


    It could be that these references are already deleted.


    Best regards


    Niels

  • Hi I have the same screen coming up saying I should download SWS spyware which I'm not going to do.


    Could someone have a look at my hijack this log please?


    Logfile of Trend Micro HijackThis v2.0.0 (BETA)


    Scan saved at 13:31:07, on 21/10/2007


    Platform: Windows Vista (WinNT 6.00.1904)


    Boot mode: Normal


    Running processes:


    C:\Windows\system32\Dwm.exe


    C:\Windows\system32\taskeng.exe


    C:\Windows\Explorer.EXE


    C:\Program Files\Windows Defender\MSASCui.exe


    C:\hp\support\hpsysdrv.exe


    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe


    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe


    C:\Windows\System32\rundll32.exe


    C:\Windows\System32\rundll32.exe


    C:\Windows\RtHDVCpl.exe


    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe


    C:\Program Files\Common Files\Symantec Shared\ccApp.exe


    C:\Program Files\Windows Sidebar\sidebar.exe


    C:\Program Files\MSN Messenger\msnmsgr.exe


    C:\Program Files\Windows Media Player\wmpnscfg.exe


    C:\Program Files\Mozilla Firefox\firefox.exe


    C:\Users\Rich T\Desktop\HiJackThis_v2.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    O1 - Hosts: ::1 localhost


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll


    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll


    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll


    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide


    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe


    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"


    O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"


    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe


    O4 - HKLM\..\Run: [CCUTRAYICON] FactoryMode


    O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe


    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"


    O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe


    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun


    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter


    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background


    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe


    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000


    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll


    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL


    O13 - Gopher Prefix:


    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab


    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab


    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab


    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab


    O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll


    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll


    O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe


    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe


    O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe


    O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe


    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe


    O23 - Service: Intel® Software Services Manager (ISSM) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe


    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe


    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE


    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe


    O23 - Service: Intel® Viiv Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe


    O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe


    O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel® Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe


    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe


    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe


    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


    --


    End of file - 9654 bytes

  • Niels
    Options

    Hello Manimal


    I recommend that you first download the stable version of hijack this. You will find the download link on the reply I gave to ven_tura.


    These entries you may already check the box and press on fix checked:


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    O1 - Hosts: ::1 localhost


    Start Internet Explorer.


    Go to tools,Pop-up Blocker,Pop-up Blocker Settings,select remove everything.


    Best regards


    Niels

  • thank you Niels


    i think that has worked but only time will tell... i may post back in the next few days with another Hijack this log from a different pc would i would apprieciate the help with that one :)

  • Niels
    Options

    Hello Ven_tura


    You can install some additional software so you wouldn't get infected soon. What you always must do is using windows update.


    Spywareblaster


    This tool blocks unwanted active x files. Most of the infections are due malicious websites that install these active x files.


    If you don't want to get on malicious sites you can download this also.


    Best regards


    Niels

  • Thanks again Niels.. it looks like that pc will be ok for a while but i'm not sure about this one .. i've followed the same steps here's the Hijackthis log anything i need to worry about on here


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 9:55:32 PM, on 10/26/2007


    Platform: Windows 2000 SP4 (WinNT 5.00.2195)


    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Boot mode: Normal


    Running processes:


    C:\WINNT\System32\smss.exe


    C:\WINNT\system32\winlogon.exe


    C:\WINNT\system32\services.exe


    C:\WINNT\system32\lsass.exe


    C:\WINNT\system32\svchost.exe


    C:\WINNT\system32\spoolsv.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\WINNT\System32\svchost.exe


    c:\PROGRA~1\mcafee.com\vso\mcshield.exe


    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe


    C:\WINNT\System32\nvsvc32.exe


    C:\WINNT\system32\regsvc.exe


    C:\WINNT\system32\MSTask.exe


    C:\WINNT\system32\stisvc.exe


    C:\WINNT\Explorer.EXE


    C:\WINNT\System32\WBEM\WinMgmt.exe


    C:\WINNT\system32\mspmspsv.exe


    C:\WINNT\system32\svchost.exe


    C:\WINNT\System32\svchost.exe


    C:\WINNT\SOUNDMAN.EXE


    C:\WINNT\System32\TrayIcon.exe


    C:\Program Files\McAfee.com\VSO\mcvsshld.exe


    c:\program files\mcafee.com\agent\mcagent.exe


    C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe


    C:\Program Files\McAfee.com\VSO\oasclnt.exe


    C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe


    C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    C:\Program Files\QuickTime\qttask.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe


    C:\Program Files\iPod\bin\iPodService.exe


    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    C:\WINNT\system32\internat.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll


    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll


    O2 - BHO: MSVPS System - {C4F4DBBD-4A4C-4B40-97DA-2FE06DBB2901} - C:\WINNT\bndsrwgo.dll


    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx


    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O3 - Toolbar: The netadv - {F17B1418-2C0C-4295-BD55-BCDD3C730FBE} - C:\DOCUME~1\home\LOCALS~1\Temp\ac8zt2\netadv.dll (file missing)


    O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon


    O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE


    O4 - HKLM\..\Run: [DisplayTrayIcon] C:\WINNT\System32\TrayIcon.exe


    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize


    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask


    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe


    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe


    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe


    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe


    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb07.exe


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"


    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [internat.exe] internat.exe


    O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe


    O4 - HKCU\..\Run: [spywareBot] "C:\Program Files\SpywareBot\SpywareBot.exe" -boot


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')


    O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\espmain.exe


    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm


    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm


    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813


    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab


    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal...nosticsxp2k.cab


    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/28b489cfad3c51...ip/RdxIE601.cab


    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab


    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1190815337031


    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cab


    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab


    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/realarcade-webgam...outLauncher.cab


    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.gamehouse.com/realarcade-webgam...opcaploader.cab


    O20 - AppInit_DLLs: C:\WINNT\system32\hadjajr.ini


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O21 - SSODL: msvb - {9D1D6453-77C1-4C09-AED8-241DB488E3A2} - C:\WINNT\msvb.dll (file missing)


    O21 - SSODL: sysdx - {EF437D33-FF2E-4FBD-9E93-FD89F8C5250A} - C:\WINNT\sysdx.dll (file missing)


    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe


    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe


    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe


    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe


    --


    End of file - 9262 bytes

  • Niels
    Options

    Hello Ven_tura


    Sorry for the delay.


    Fix these entries:


    O2 - BHO: MSVPS System - {C4F4DBBD-4A4C-4B40-97DA-2FE06DBB2901} - C:\WINNT\bndsrwgo.dll


    O3 - Toolbar: The netadv - {F17B1418-2C0C-4295-BD55-BCDD3C730FBE} - C:\DOCUME~1\home\LOCALS~1\Temp\ac8zt2\netadv.dll (file missing)


    O4 - HKCU\..\Run: [spywareBot] "C:\Program Files\SpywareBot\SpywareBot.exe" -boot


    O20 - AppInit_DLLs: C:\WINNT\system32\hadjajr.ini


    O21 - SSODL: msvb - {9D1D6453-77C1-4C09-AED8-241DB488E3A2} - C:\WINNT\msvb.dll (file missing)


    O21 - SSODL: sysdx - {EF437D33-FF2E-4FBD-9E93-FD89F8C5250A} - C:\WINNT\sysdx.dll (file missing)


    Best regards


    Niels

  • I have read through the posts you guys have supplied as I am having the same problems. As soon as I log on to the internet i begin getting pop ups. I have downloaded the Hijack This software and am downloading the rogueremover software as we speak...if you guys would look over the Hijack report i would appreciate it...i havent got a clue about this stuff. Really appreciate you help...thanks so much


    JD


    mtfireguyjd@aol.com


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 12:46:19 PM, on 11/30/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16544)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Windows Defender\MsMpEng.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\System32\WLTRYSVC.EXE


    C:\WINDOWS\System32\bcmwltry.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE


    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe


    C:\WINDOWS\system32\HPZipm12.exe


    C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\system32\SearchIndexer.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\Explorer.EXE


    C:\Program Files\Canon\CAL\CALMAIN.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


    C:\WINDOWS\system32\WLTRAY.exe


    C:\WINDOWS\stsystra.exe


    C:\WINDOWS\system32\dla\tfswctrl.exe


    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


    C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe


    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe


    C:\Program Files\Windows Defender\MSASCui.exe


    C:\Program Files\NetWaiting\NetWaiting.exe


    C:\Program Files\Messenger\msmsgs.exe


    C:\Program Files\Digital Line Detect\DLG.exe


    C:\Program Files\Google\Google Updater\GoogleUpdater.exe


    C:\Program Files\Windows Desktop Search\WindowsSearch.exe


    C:\Program Files\Netscape ISP Dialer\LiteDialer.exe


    C:\WINDOWS\system32\wuauclt.exe


    C:\Program Files\Netscape ISP Dialer\aoltpsdL.exe


    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE


    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE


    C:\Documents and Settings\Hoosurcowboy\Local Settings\Temporary Internet Files\Content.IE5\CFRCX55G\Windows-KB890830-V1.35[1].exe


    c:\2d774feb4682b8515600c1d901ea\mrtstub.exe


    C:\WINDOWS\system32\MRT.exe


    C:\Program Files\Internet Explorer\IEXPLORE.EXE


    c:\program files\winamp toolbar\WinampTbServer.exe


    C:\WINDOWS\system32\mmc.exe


    C:\WINDOWS\system32\SearchProtocolHost.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    C:\WINDOWS\system32\SearchProtocolHost.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gacc.nifc.gov/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:11535


    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;127.0.0.1:11535;update.microsoft.com;*windowsupdate.microsoft.com;*win


    owsupdate.com;download.microsoft.com;codecs.microsoft.com;activex.microsoft.com;


    iveupdate.symantecliveupdate.com;liveupdate.symantec.com;service1.symantec.com;*


    nai.com;*.networkassociates.com;*mcafee.com;*.mapquest.com;*.phobos.apple.com;up


    ate.adobe.com;admin.isp.netscape.com


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


    O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll


    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


    O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe


    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe


    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide


    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\NetWaiting.exe


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O4 - Global Startup: Digital Line Detect.lnk = ?


    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe


    O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204


    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab


    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll


    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab


    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal...nosticsxp2k.cab


    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab


    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab


    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab


    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab


    O16 - DPF: {DF1C8E21-4045-4D67-B528-335F1A4F0DE9} - http://us2-scripts.dlv4.com/binaries/egacc..._1073_em_XP.cab


    O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - http://www.plaxo.com/activex/plx_upldr-2k-xp.cab


    O17 - HKLM\System\CCS\Services\Tcpip\..\{4661F9C9-B569-4EC3-A81C-C7E8E9EAFE1A}: NameServer = 205.188.146.145


    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


    O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


    --


    End of file - 11408 bytes

  • alexcrist
    alexcrist
    edited December 2007
    Options

    Hello mtfireguy,


    The only thing suspicious that I could find in your log is this:


    O16 - DPF: {DF1C8E21-4045-4D67-B528-335F1A4F0DE9} - http://us2-scripts.dlv4.com/binaries/egacc..._1073_em_XP.cab


    But there aer two processes running that are extremely suspicious (and I think, 98%, they're infections):


    C:\Documents and Settings\Hoosurcowboy\Local Settings\Temporary Internet Files\Content.IE5\CFRCX55G\Windows-KB890830-V1.35[1].exe

    c:\2d774feb4682b8515600c1d901ea\mrtstub.exe


    Please find these files, put them in a ZIP archive protected by the password infected and upload them into your next post.


    After you upload them, remove the folder c:\2d774feb4682b8515600c1d901ea\ (with everything it contains) and the file C:\Documents and Settings\Hoosurcowboy\Local Settings\Temporary Internet Files\Content.IE5\CFRCX55G\Windows-KB890830-V1.35[1].exe


    These files might be hidden. So do this:


    - Open Explorer


    - Click Tools -> Folder Options... -> View


    - Search for the option Show hidden files and folders and check it and for the option Hide system protected files and disable it.


    - Click Apply


    After that, restart your PC and post a new HijackThis! log.


    Cris.

  • Guy,


    having a bit of a nightmare here...... And Need your HELP!!!!!


    I have some sort of adware virus, causing lots of unwanted pop ups, I have seen you have helped other in the same position, so I'm asking for help.....


    now i'm a bit of a novice, but I can follow instructions, so here's my problem....


    I get unwanted pop ups all the time, advertising products, from phone to flowers to dating site & including some ****!!!!!


    I tried to follow some of your instructions in earlier posts, but i'm struggling.....


    I downloaded hijackthis & have don e log file...


    Here it is.....


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 14:22:27, on 06/12/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe


    C:\WINDOWS\system32\spoolsv.exe


    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe


    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe


    c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe


    C:\WINDOWS\system32\nvsvc32.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe


    c:\APPS\Powercinema\Kernel\TV\CLSched.exe


    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    C:\WINDOWS\Explorer.EXE


    C:\WINDOWS\sm56hlpr.exe


    C:\WINDOWS\RTHDCPL.EXE


    C:\WINDOWS\system32\RUNDLL32.EXE


    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe


    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe


    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe


    C:\APPS\Powercinema\PCMService.exe


    C:\apps\ABoard\ABoard.exe


    C:\apps\ABoard\AOSD.exe


    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE


    C:\Program Files\QuickTime\qttask.exe


    C:\Program Files\Common Files\Symantec Shared\ccApp.exe


    C:\WINDOWS\system32\rundll32.exe


    C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe


    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe


    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


    C:\APPS\SMP\SmpSys.exe


    C:\Program Files\MSN Messenger\MsnMsgr.Exe


    C:\Program Files\BitTorrent\bittorrent.exe


    C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe


    C:\Program Files\Logitech\QuickCam10\COCIManager.exe


    C:\Program Files\MSN Messenger\usnsvc.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redi...&key=SEARCH


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll


    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - c:\apps\skype\phone\IEPlugin\SKYPEI~1.DLL


    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll


    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll


    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll


    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll


    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC


    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName


    O4 - HKLM\..\Run: [sMSERIAL] sm56hlpr.exe


    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE


    O4 - HKLM\..\Run: [skyTel] SkyTel.EXE


    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"


    O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"


    O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe


    O4 - HKLM\..\Run: [PCMService] "c:\APPS\Powercinema\PCMService.exe"


    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe


    O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"


    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"


    O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent


    O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"


    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"


    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKCU\..\Run: [smpcSys] C:\APPS\SMP\SmpSys.exe


    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background


    O4 - HKCU\..\Run: [bitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


    O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm


    O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm


    O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\apps\skype\phone\IEPlugin\SKYPEI~1.DLL


    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm


    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204


    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab


    O16 - DPF: {3B5E9B23-7537-4601-A9E8-FA0D956DEA16} (csauie1 Control) - http://www.couponreport.net/ftp/v3123/csauie1.cab


    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab


    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab


    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1190734378828


    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe


    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe


    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe


    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe


    O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe


    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe


    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE


    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe


    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe


    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe


    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


    O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe


    --


    End of file - 12780 bytes


    I have also added SUPERantispyware & spyware blaster......


    Please help me......

  • Hello, I took a look at your log but couldn't find anything bad. Maybe because it's 1:20 AM, but anyway, while waiting for someone else to check your log as well, I can suggest a program I've been using lately which proves to be very good at blocking and disabling malware, even when you install it on an infected system. Download it here: http://www.threatfire.com/files/tfinstall.exe . Install it and it will detect any process with malicious or suspicious behaviour. When asked, choose to delete or quarantine the detected files. Post again to tell us how did it go.

  • Hey CRIS,


    THANKS SO MUCH MAN for lookin at my stuff...i tried to find the files but they dont seem to be on my computer...i opened up hidden files where they should be and the folders werent there. I ran another report after i ran my virus scan and my spyblaster and here it is...maybe it will make more sense or you can show me what i did wrong


    JD


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 9:28:34 AM, on 12/7/2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16544)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\system32\svchost.exe


    C:\Program Files\Windows Defender\MsMpEng.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\System32\WLTRYSVC.EXE


    C:\WINDOWS\System32\bcmwltry.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\Explorer.EXE


    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


    C:\WINDOWS\system32\WLTRAY.exe


    C:\WINDOWS\stsystra.exe


    C:\WINDOWS\system32\dla\tfswctrl.exe


    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


    C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe


    C:\Program Files\Windows Defender\MSASCui.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    C:\Program Files\IOGEAR\Bluetooth Software\BTTray.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\Program Files\Digital Line Detect\DLG.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe


    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE


    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe


    C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe


    C:\WINDOWS\system32\HPZipm12.exe


    C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


    C:\WINDOWS\system32\svchost.exe


    C:\PROGRA~1\Grisoft\AVG7\avgw.exe


    C:\Program Files\Canon\CAL\CALMAIN.exe


    C:\Program Files\Internet Explorer\IEXPLORE.EXE


    C:\WINDOWS\system32\wuauclt.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gacc.nifc.gov/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070924


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


    O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll


    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll


    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe


    O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe


    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe


    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\ADDED PROGRAMS\Winamp\winampa.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide


    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto


    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [instant Access] C:\WINDOWS\system32\nsinet.exe /res


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O4 - Global Startup: Bluetooth.lnk = ?


    O4 - Global Startup: Digital Line Detect.lnk = ?


    O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000


    O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\IOGEAR\Bluetooth Software\btsendto_ie_ctx.htm


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll


    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll


    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204


    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab


    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll


    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab


    O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal...nosticsxp2k.cab


    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase4009.cab


    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab


    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab


    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab


    O16 - DPF: {FF1CD9A3-00CD-45C1-8182-4EEC229A182D} (Plaxo Auto-Import Utility) - http://www.plaxo.com/activex/plx_upldr-2k-xp.cab


    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe


    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\IOGEAR\Bluetooth Software\bin\btwdins.exe


    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


    O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - C:\Program Files\ADDED PROGRAMS\PrfldSvc.exe


    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


    --


    End of file - 10531 bytes

  • Hi! My first post here, so I hope I do this right! I have the same problem as all the other users in this thread. I will post my hijack-log and I would appreciate if you could take a look and see if you can help.


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 18:42:10, on 09.12.2007


    Platform: Windows XP SP2 (WinNT 5.01.2600)


    MSIE: Internet Explorer v7.00 (7.00.6000.16544)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\WINDOWS\Explorer.EXE


    C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe


    C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe


    C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe


    C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe


    C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe


    C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe


    C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe


    C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe


    C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe


    C:\Programfiler\iTunes\iTunesHelper.exe


    C:\WINDOWS\system32\ctfmon.exe


    C:\Programfiler\MSN Messenger\msnmsgr.exe


    C:\Programfiler\WIDCOMM\Bluetooth-programvare\BTTray.exe


    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE


    C:\Programfiler\HPQ\SHARED\HPQWMI.exe


    C:\Programfiler\MSN Messenger\usnsvc.exe


    C:\Programfiler\iPod\bin\iPodService.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\Programfiler\Grisoft\AVG7\avgcc.exe


    C:\Programfiler\eMule\emule.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\Ati2evxx.exe


    C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe


    C:\Programfiler\Mozilla Firefox\firefox.exe


    C:\Programfiler\VideoLAN\VLC\vlc.exe


    C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.finderg.com


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger


    O2 - BHO: Koblingshjelpeprogram for Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll


    O3 - Toolbar: HP-visning - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\Programfiler\HP\Digital Imaging\bin\HPDTLK02.dll


    O4 - HKLM\..\Run: [ATIPTA] C:\Programfiler\ATI Technologies\ATI Control Panel\atiptaxx.exe


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_03\bin\jusched.exe"


    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Programfiler\hpq\HP Wireless Assistant\HP Wireless Assistant.exe


    O4 - HKLM\..\Run: [synTPLpr] C:\Programfiler\Synaptics\SynTP\SynTPLpr.exe


    O4 - HKLM\..\Run: [synTPEnh] C:\Programfiler\Synaptics\SynTP\SynTPEnh.exe


    O4 - HKLM\..\Run: [HP Software Update] C:\Programfiler\Hp\HP Software Update\HPWuSchd2.exe


    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programfiler\HPQ\Quick Launch Buttons\EabServr.exe /Start


    O4 - HKLM\..\Run: [Cpqset] C:\Programfiler\HPQ\Default Settings\cpqset.exe


    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe


    O4 - HKLM\..\Run: [TkBellExe] "C:\Programfiler\Fellesfiler\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 8.0\Reader\Reader_sl.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\QTTask.exe" -atboottime


    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


    O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u


    O4 - HKLM\..\Run: [WinampAgent] C:\Programfiler\Winamp\wianmpa.exe


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Programfiler\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [fhoyomt] c:\windows\system32\fhoyomt.exe fhoyomt


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe


    O4 - HKCU\..\Run: [msnmsgr] "C:\Programfiler\MSN Messenger\msnmsgr.exe" /background


    O4 - HKCU\..\Run: [updateMgr] C:\Programfiler\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9


    O4 - HKCU\..\Run: [HijackThis startup scan] C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe /startupscan


    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJENESTE')


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOKAL TJENESTE')


    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETTVERKSTJENESTE')


    O4 - HKUS\S-1-5-21-2933604105-1953609872-583326203-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Miriam')


    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')


    O4 - Startup: PartMetBackup.lnk = C:\Programfiler\Java\jre1.6.0_03\bin\javaw.exe


    O4 - Global Startup: BTTray.lnk = ?


    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programfiler\Hp\Digital Imaging\bin\hpqtra08.exe


    O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office\OSA9.EXE


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe


    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe


    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=NB_NO&c=Q305&bd=pavilion&pf=laptop


    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programfiler\Fellesfiler\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe


    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Programfiler\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programfiler\WIDCOMM\Bluetooth-programvare\bin\btwdins.exe


    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Programfiler\HPQ\SHARED\HPQWMI.exe


    O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Programfiler\iPod\bin\iPodService.exe


    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Programfiler\Fellesfiler\LightScribe\LSSrvc.exe


    --


    End of file - 7663 bytes


    Thanks! Liam

  • alexcrist
    Options

    @jonnym9:


    Do you know the file C:\APPS\IE\offline\uk.htm? If you don't, fix the following lines:


    R1 - HKLM\Software\Microsoft\Internet Explorer\Ma in,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\ IE\offline\uk.htm


    @mtfireguy and Liam: as soon as I can, I'll take a look at your logs.


    Cris.

  • alexcrist
    Options

    @mtfireguy:


    Your log looks clean. The only thing that might be a malware is:


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18- 009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    But this also might be the legit Google Toolbar. So if you use this toolbar, don't fix this line.


    Cris.

  • alexcrist
    Options

    @Liam:


    The following application seems very suspiciuos:


    O4 - HKLM\..\Run: [fhoyomt] c:\windows\system32\f hoyomt.exe fhoyomt

    Searching on Google for it revealed only 3 results (one on this thread, the other 2 on some French forum, also related to a similar problem).


    If you don't know this application, fix the above line. The rest of the log looks clean.


    Cris.

  • rosap
    Options

    Hi Niels


    Someone else with the same problems ! Hope you can help me ! Until now have been very naive re computer threats and just recently (very foolishly it now appears with hindsight !) downloaded something called web media player, which I think has now given me the same SWS anti-spyware and ‘pop up’ problems that everyone else here has been getting.


    Initally after looking at various web-sites and forums, in an attempt to get rid of it I ran various anti-spy ware programs namely, Ad-Aware 2007, AVG Anti-spyware 7.5, Spybot Search & Destroy, CCleaner and also bought Spyware Doctor 5.5 & Anti-virus as well as their Registry Minder software....all of them found various ‘threats’ and ‘infections’ which they cleared but none solved this problem.


    After seeing your forum thread, I have also run Superanti Spyware 4.0 (it found no problems) and Smitfraudfix (found problems and for some reason deleted my windows provided screensaver). I struggled to download Rogue remover so haven’t tried that yet.


    After all these – I still have the problem and in addition my boot up and general pc speed is now horribly slow, including internet access, but also access to all my Microsoft office packages, even when IE is not open and they also keep hanging in the middle of me using them. ( I think this maybe an issue of Spyware Doctor??)


    I have a Tosh Satellite A100 with windows Vista with Internet Explorer (not sure what version) and have already set all cookies to be blocked but I’m still spontaneously getting new tabs popping up whenever the internet is open and I’m just generally browsing (seem to originate from http: fp.pc-on-internet/? many times I get a message saying that they want to install Adobe Flash. I also use WiFi with Alice (Italy Telecom) (does this mean I’m more vulnerable to issues?)


    Finally just for info, based on some of the advice you have given others, I cant find the ‘run’ command in Start, so if I need to do that, can you give me some pointers ?!


    Here is my HJT output


    Thanks a million !


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 11:20:13, on 14/03/2008


    Platform: Windows Vista (WinNT 6.00.1904)


    MSIE: Internet Explorer v7.00 (7.00.6000.16609)


    Boot mode: Normal


    Running processes:


    C:\Windows\System32\smss.exe


    C:\Windows\system32\csrss.exe


    C:\Windows\system32\wininit.exe


    C:\Windows\system32\csrss.exe


    C:\Windows\system32\services.exe


    C:\Windows\system32\lsass.exe


    C:\Windows\system32\lsm.exe


    C:\Windows\system32\winlogon.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\System32\svchost.exe


    C:\Windows\System32\svchost.exe


    C:\Windows\System32\svchost.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\system32\SLsvc.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\system32\svchost.exe


    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


    C:\Windows\System32\spoolsv.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\system32\agrsmsvc.exe


    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe


    C:\Windows\system32\svchost.exe


    C:\Program Files\Spyware Doctor\pctsAuxs.exe


    C:\Program Files\Spyware Doctor\pctsSvc.exe


    C:\Windows\system32\svchost.exe


    C:\Windows\system32\TODDSrv.exe


    C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe


    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


    C:\Windows\System32\svchost.exe


    C:\Windows\system32\SearchIndexer.exe


    C:\Windows\system32\taskeng.exe


    C:\Windows\system32\taskeng.exe


    C:\Windows\system32\Dwm.exe


    C:\Windows\Explorer.EXE


    C:\Program Files\Windows Defender\MSASCui.exe


    C:\Program Files\Java\jre1.6.0\bin\jusched.exe


    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe


    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe


    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe


    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


    C:\Windows\RtHDVCpl.exe


    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe


    C:\Program Files\Common Files\Symantec Shared\ccApp.exe


    C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe


    C:\Windows\System32\igfxtray.exe


    C:\Windows\System32\hkcmd.exe


    C:\Windows\System32\igfxpers.exe


    C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe


    C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\Spyware Doctor\pctsTray.exe


    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe


    C:\Program Files\Windows Sidebar\sidebar.exe


    C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe


    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


    C:\Program Files\Windows Media Player\wmpnscfg.exe


    C:\Users\Tricia\AppData\Local\cdkapwm.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe


    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE


    C:\Program Files\Windows Media Player\wmpnetwk.exe


    C:\Windows\System32\rundll32.exe


    C:\Program Files\Synaptics\SynTP\SynToshiba.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe


    C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe


    C:\Program Files\iPod\bin\iPodService.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe


    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe


    C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtProc.exe


    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    C:\Windows\system32\taskeng.exe


    C:\Windows\system32\SearchProtocolHost.exe


    C:\Program Files\Internet Explorer\ieuser.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    C:\Windows\system32\wbem\wmiprvse.exe


    C:\Windows\system32\SearchFilterHost.exe


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer fornito da Alice


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    O1 - Hosts: ::1 localhost


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll


    O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll


    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll


    O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll


    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"


    O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE


    O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe


    O4 - HKLM\..\Run: [smoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe


    O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe


    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart


    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup


    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit


    O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe


    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe


    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe


    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"


    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"


    O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup


    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe


    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe


    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe


    O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [AliceRV_McciTrayApp] C:\Program Files\Alice ti aiuta\McciTrayApp.exe


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    O4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"


    O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"


    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized


    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun


    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe


    O4 - HKCU\..\Run: [cdkapwm] c:\users\tricia\appdata\local\cdkapwm.exe cdkapwm


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')


    O4 - Startup: Ritaglio schermata e avvio di OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE


    O4 - Global Startup: Bluetooth Manager.lnk = ?


    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll


    O9 - Extra button: Invia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


    O9 - Extra 'Tools' menuitem: I&nvia a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL


    O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?EN (file missing)


    O9 - Extra button: Alice - {9FE4C600-94CD-49E1-B98D-B20AB9547DB0} - http://gw.aliceadsl.it/alice (file missing) (HKCU)


    O13 - Gopher Prefix:


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe


    O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe


    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe


    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe


    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe


    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE


    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe


    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe


    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe


    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe


    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe


    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe


    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe


    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe


    --


    End of file - 13294 bytes