Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Closed Thread
 
Thread Tools
Old 07-14-2008, 02:49 PM   #1 (permalink)
Registered User
 
Join Date: Mar 2008
Posts: 36
OS: Windows XP


Spyware/Virus

I have a blue screen on the backround and in the middle it says "Warning! Spyware detected on your computer!" and right on the bottom of that it also says "Install an antivirus or spyware remover to clean your computer." And i did that but it still won't go away.



Deckard's System Scanner v20071014.68
Run by Compaq_Owner on 2008-07-14 14:36:16
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
5: 2008-07-14 21:36:21 UTC - RP5 - Deckard's System Scanner Restore Point
4: 2008-07-14 21:31:37 UTC - RP4 - Software Distribution Service 3.0
3: 2008-07-14 18:20:02 UTC - RP3 - Software Distribution Service 3.0
2: 2008-07-14 06:28:37 UTC - RP2 - Software Distribution Service 3.0
1: 2008-07-14 04:51:38 UTC - RP1 - Software Distribution Service 3.0


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 447 MiB (512 MiB recommended).


-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-14 14:38:32
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\WINDOWS\system32\lphcgdaj0e5d1.exe
C:\Program Files\rhcldaj0e5d1\rhcldaj0e5d1.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\hp\KBD\kbd.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\pphcgdaj0e5d1.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jucheck.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Compaq_Owner\Desktop\ZonedOut\ZonedOut\ZonedOut.exe
C:\Documents and Settings\Compaq_Owner\Desktop\dss.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar3.dll
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [lphcgdaj0e5d1] C:\WINDOWS\system32\lphcgdaj0e5d1.exe
O4 - HKLM\..\Run: [SMrhcldaj0e5d1] C:\Program Files\rhcldaj0e5d1\rhcldaj0e5d1.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Runonce] C:\WINDOWS\smss.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


--
End of file - 8138 bytes

-- File Associations -----------------------------------------------------------

.reg - exefile - DefaultIcon - %1
.reg - exefile - shell\open\command - "%1" %*
.reg - exefile - shell\edit\command - unable to read value
.vbs - exefile - DefaultIcon - %1
.vbs - exefile - shell\open\command - "%1" %*
.vbs - exefile - shell\edit\command - unable to read value


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

S3 sysrest.sys - c:\windows\system32\sysrest.sys
S4 intelppm (Intel Processor Driver) - c:\windows\system32\drivers\intelppm.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

All services whitelisted.


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
Description: 2500 Series
Device ID: USB\VID_043D&PID_010B&MI_00\6&220DCD94&0&0000
Manufacturer:
Name: 2500 Series
PNP Device ID: USB\VID_043D&PID_010B&MI_00\6&220DCD94&0&0000
Service:

Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}
Description: Lexmark 2500 Series
Device ID: USBPRINT\LEXMARK_2500_SERIES\7&AF2718F&0&USB001
Manufacturer:
Name: Lexmark 2500 Series
PNP Device ID: USBPRINT\LEXMARK_2500_SERIES\7&AF2718F&0&USB001
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-07-14 12:23:24 378 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job
2008-07-13 15:11:57 320 --a------ C:\WINDOWS\Tasks\HPCeeSchedule.job
2008-07-13 15:11:39 472 --a------ C:\WINDOWS\Tasks\Easy Internet Sign-up.job
2008-07-11 22:46:07 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2008-07-07 06:30:00 314 --a------ C:\WINDOWS\Tasks\Ad-Aware SE Professional.job


-- Files created between 2008-06-14 and 2008-07-14 -----------------------------

2008-07-14 14:16:16 0 d-------- C:\ie-spyad_zo
2008-07-14 14:14:43 0 d-------- C:\Program Files\SpywareBlaster
2008-07-14 12:01:22 0 d-------- C:\WINDOWS\LastGood
2008-07-14 12:00:52 0 d-------- C:\Program Files\Panda Security
2008-07-14 11:51:33 94208 --a------ C:\WINDOWS\system32\pphcgdaj0e5d1.exe
2008-07-14 11:49:35 23040 --a------ C:\WINDOWS\system32\sysrest32.exe
2008-07-14 11:49:35 15328 --a------ C:\WINDOWS\system32\sysrest.sys
2008-07-13 21:52:10 0 d-------- C:\WINDOWS\system32\PreInstall
2008-07-13 21:34:41 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Adobe
2008-07-13 21:26:43 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Ventrilo
2008-07-13 20:38:37 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Lavasoft
2008-07-13 19:39:54 0 d-------- C:\Program Files\Alwil Software
2008-07-13 19:25:24 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Google
2008-07-13 19:21:59 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\rhcldaj0e5d1
2008-07-13 19:21:25 0 d-------- C:\Program Files\rhcldaj0e5d1
2008-07-13 19:20:48 60928 --a------ C:\WINDOWS\system32\blphcgdaj0e5d1.scr <Not Verified; Sysinternals; Sysinternals Blue Screen>
2008-07-13 19:20:39 110080 --a------ C:\WINDOWS\system32\lphcgdaj0e5d1.exe
2008-07-13 15:57:02 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Aim
2008-07-13 15:51:58 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia
2008-07-13 15:49:29 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Mozilla
2008-07-13 15:16:57 0 dr-hs---- C:\cmdcons
2008-07-13 15:16:31 0 d-------- C:\WINDOWS\setupupd
2008-07-13 15:08:53 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Intuit
2008-07-13 15:08:53 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Identities
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\WINDOWS
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Templates
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Start Menu
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\SendTo
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\PrintHood
2008-07-13 15:08:52 6029312 --a------ C:\Documents and Settings\Compaq_Owner\NTUSER.DAT
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\NetHood
2008-07-13 15:08:52 0 dr------- C:\Documents and Settings\Compaq_Owner\My Documents
2008-07-13 15:08:52 0 d--h----- C:\Documents and Settings\Compaq_Owner\Local Settings
2008-07-13 15:08:52 0 dr------- C:\Documents and Settings\Compaq_Owner\Favorites
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Desktop
2008-07-13 15:08:52 0 d---s---- C:\Documents and Settings\Compaq_Owner\Cookies
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec
2008-07-13 15:08:52 0 d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Real
2008-07-13 1505 262144 --a------ C:\Documents and Settings\Application Data\NTUSER.DAT
2008-07-13 15:03:47 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-07-12 22:41:42 229621 --a------ C:\WINDOWS\Funny UST Scandal.exe
2008-07-07 14:56:01 0 d-------- C:\Program Files\iPod
2008-07-07 14:55:22 0 d-------- C:\Program Files\iTunes
2008-07-07 14:54:40 0 d-------- C:\Program Files\Bonjour
2008-07-07 14:52:55 0 d-------- C:\Program Files\QuickTime
2008-07-07 14:51:33 0 d-------- C:\Program Files\Common Files\Apple
2008-06-22 1503 66560 --a------ C:\WINDOWS\MOTA113.exe
2008-06-22 1502 217073 --a------ C:\WINDOWS\meta4.exe
2008-06-22 1501 0 d-------- C:\Program Files\AviSynth 2.5
2008-06-22 15:04:53 0 d-------- C:\Program Files\eRightSoft
2008-06-22 14:53:43 0 d-------- C:\Mp3 Output
2008-06-16 02:52:10 0 d-------- C:\Program Files\Nero
2008-06-16 02:52:10 0 d-------- C:\Program Files\Common Files\Ahead
2008-06-16 02:52:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Nero


-- Find3M Report ---------------------------------------------------------------

2008-07-14 11:52:03 3649 --a------ C:\WINDOWS\viassary-hp.reg
2008-07-13 23:17:48 0 d-------- C:\Program Files\PC-Doctor 5 for Windows
2008-07-13 20:19:56 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-13 20:10:08 0 d-------- C:\Program Files\Save
2008-07-13 19:37:48 0 d-------- C:\Program Files\Symantec
2008-07-13 19:37:17 0 d-------- C:\Program Files\Common Files
2008-07-13 18:58:17 0 d-------- C:\Program Files\mIRC
2008-07-13 15:46:48 0 d-------- C:\Program Files\Google
2008-07-13 14:49:18 0 d-------- C:\Program Files\Windows NT
2008-07-13 14:49:13 0 d-------- C:\Program Files\Movie Maker
2008-07-13 14:49:12 0 d-------- C:\Program Files\Messenger
2008-07-13 13:29:51 0 d-------- C:\Program Files\Steam
2008-07-03 12:40:19 0 d-------- C:\Program Files\support.com
2008-06-30 20:04:04 0 d-------- C:\Program Files\Lx_cats
2008-06-25 1307 0 d-------- C:\Program Files\Azureus
2008-06-13 13:14:39 0 d-------- C:\Program Files\LimeWire Turbo
2008-06-13 12:58:49 0 d-------- C:\Program Files\LimeWire
2008-05-15 03:00:59 0 d-------- C:\Program Files\StepMania CVS
2008-05-14 19:49:22 0 d-------- C:\Program Files\Yahoo!
2008-05-14 19:47:53 0 d-------- C:\Program Files\Veoh Networks


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"="" []
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [09/21/2005 05:41 PM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [02/17/2005 07:11 AM]
"lphcgdaj0e5d1"="C:\WINDOWS\system32\lphcgdaj0e5d1.exe" [07/13/2008 07:20 PM]
"SMrhcldaj0e5d1"="C:\Program Files\rhcldaj0e5d1\rhcldaj0e5d1.exe" [07/13/2008 03:13 AM]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [05/15/2008 04:19 PM]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" []

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Runonce"="C:\WINDOWS\smss.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 10:00 PM]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [07/13/2008 03:46 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"=1 (0x1)
"NoDispScrSavPage"=1 (0x1)


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a65e6984-4f7d-11da-a231-806d6172696f}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480




-- End of Deckard's System Scanner: finished at 2008-07-14 14:39:19 ------------


Moderators Message

Please be considerate of the fact that the people helping you are all volunteers, and in many cases usually have a job, and a limited amount of time to help, and therefore can only do so much. If no one has replied to your thread within 72hrs after you posted, please reply in your thread with the words BUMP, please to move it forward.

DO NOT Bump the thread unless 72 hours has passed. We work from oldest to newest posts so your wait will be longer if you bump it forward before the 72 hours is up. We look for 0 reply, or 1 reply threads to respond to.

You should also see our sticky at the top of this forum, entitled IMPORTANT - Read This Before Posting For Malware Removal Help

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.


Early bump posts will be deleted.
Attached Files
File Type: txt extra.txt (15.3 KB, 1 views)

Last edited by TheBruce1 : 07-15-2008 at 03:01 PM.
s2jon is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 08:23 PM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81