![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2009
Posts: 1
OS: windows vista
|
I have a problem with google. I was unable to log in to my gmail account and the screen would say "Failed to connect". Also whenever I search on google, the links redirect me to other search engine sites such as "relevant search"? I don't know it's weird. I need help!
Malwarebytes' Anti-Malware 1.36 Database version: 2047 Windows 6.0.6001 Service Pack 1 4/27/2009 6:32:52 AM mbam-log-2009-04-27 (06-32-52).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 230628 Time elapsed: 1 hour(s), 59 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\ExtraAV.DocHostUIHandler (Rogue.ExtraAntivirus) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Users\Joannn mf!\AppData\Roaming\Extra Antivirus (Rogue.Extraantivir) -> Quarantined and deleted successfully. C:\ProgramData\RootSys (Rogue.ExtraAntivirus) -> Quarantined and deleted successfully. Files Infected: C:\Users\Joannn mf!\AppData\Roaming\Extra Antivirus\cookies.sqlite (Rogue.Extraantivir) -> Quarantined and deleted successfully. C:\Users\Joannn mf!\AppData\Roaming\Extra Antivirus\Instructions.ini (Rogue.Extraantivir) -> Quarantined and deleted successfully. C:\ProgramData\RootSys\extrav.cfg (Rogue.ExtraAntivirus) -> Quarantined and deleted successfully. SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 04/27/2009 at 11:26 PM Application Version : 4.26.1000 Core Rules Database Version : 3868 Trace Rules Database Version: 1816 Scan type : Complete Scan Total Scan Time : 00:43:25 Memory items scanned : 920 Memory threats detected : 0 Registry items scanned : 7142 Registry threats detected : 0 File items scanned : 26447 File threats detected : 20 Adware.Tracking Cookie C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@ads.pointroll[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@ar.atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@cdn.at.atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@atwola[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@questionmarket[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@ads.bridgetrack[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@at.atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@mediaplex[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@videoegg.adbureau[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@ar.atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@apmebf[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@insightexpressai[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@imrworldwide[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@advertising[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@doubleclick[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@at.atwola[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@cdn.at.atwola[1].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@tacoda[2].txt C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\Low\joannn_mf!@revsci[1].txt ;*********************************************************************************************************************************************************************************** ANALYSIS: 2009-04-28 21:03:04 PROTECTIONS: 3 MALWARE: 2 SUSPECTS: 0 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== Spybot - Search and Destroy 1.0.0.6 No No Windows Defender 1.1.1505.0 No Yes SUPERAntiSpyware 4, 26, 0, 1000 No Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@questionmarket[2].txt 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Users\Joannn mf!\AppData\Roaming\Microsoft\Windows\Cookies\joannn_mf!@atwola[1].txt ;=================================================================================================================================================================================== SUSPECTS Sent Location ?????y39? ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description ?????y39? ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:10:08 PM, on 5/13/2009 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18226) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Dell\DellDock\DellDock.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\OEM02Mon.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Windows\System32\WLTRAY.EXE C:\Windows\system32\igfxsrvc.exe C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\Digital Line Detect\DLG.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Windows\system32\WerCon.exe C:\Users\Joannn mf!\Downloads\HijackThis.exe C:\Windows\system32\DllHost.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: 206.53.61.77 google.ae O1 - Hosts: 206.53.61.77 google.as O1 - Hosts: 206.53.61.77 google.at O1 - Hosts: 206.53.61.77 google.az O1 - Hosts: 206.53.61.77 google.ba O1 - Hosts: 206.53.61.77 google.be O1 - Hosts: 206.53.61.77 google.bg O1 - Hosts: 206.53.61.77 google.bs O1 - Hosts: 206.53.61.77 google.ca O1 - Hosts: 206.53.61.77 google.cd O1 - Hosts: 206.53.61.77 google.com.gh O1 - Hosts: 206.53.61.77 google.com.gi O1 - Hosts: 206.53.61.77 google.com.hk O1 - Hosts: 206.53.61.77 google.com.jm O1 - Hosts: 206.53.61.77 google.com.ly O1 - Hosts: 206.53.61.77 google.com.mx O1 - Hosts: 206.53.61.77 google.com.my O1 - Hosts: 206.53.61.77 google.com.na O1 - Hosts: 206.53.61.77 google.com.nf O1 - Hosts: 206.53.61.77 google.com.ng O1 - Hosts: 206.53.61.77 google.ch O1 - Hosts: 206.53.61.77 google.com.np O1 - Hosts: 206.53.61.77 google.com.om O1 - Hosts: 206.53.61.77 google.com.pa O1 - Hosts: 206.53.61.77 google.com.pr O1 - Hosts: 206.53.61.77 google.com.qa O1 - Hosts: 206.53.61.77 google.com.sg O1 - Hosts: 206.53.61.77 google.com.tj O1 - Hosts: 206.53.61.77 google.com.tr O1 - Hosts: 206.53.61.77 google.com.tw O1 - Hosts: 206.53.61.77 google.com.ua O1 - Hosts: 206.53.61.77 google.dj O1 - Hosts: 206.53.61.77 google.com.vc O1 - Hosts: 206.53.61.77 google.it.ao O1 - Hosts: 206.53.61.77 google.de O1 - Hosts: 206.53.61.77 google.dk O1 - Hosts: 206.53.61.77 google.dm O1 - Hosts: 206.53.61.77 google.dz O1 - Hosts: 206.53.61.77 google.ee O1 - Hosts: 206.53.61.77 google.fi O1 - Hosts: 206.53.61.77 google.fm O1 - Hosts: 206.53.61.77 google.fr O1 - Hosts: 206.53.61.77 google.ge O1 - Hosts: 206.53.61.77 google.gg O1 - Hosts: 206.53.61.77 google.gm O1 - Hosts: 206.53.61.77 google.gr O1 - Hosts: 206.53.61.77 google.gy O1 - Hosts: 206.53.61.77 google.ht O1 - Hosts: 206.53.61.77 google.ie O1 - Hosts: 206.53.61.77 google.im O1 - Hosts: 206.53.61.77 google.in O1 - Hosts: 206.53.61.77 google.it O1 - Hosts: 206.53.61.77 google.ki O1 - Hosts: 206.53.61.77 google.kz O1 - Hosts: 206.53.61.77 google.la O1 - Hosts: 206.53.61.77 google.li O1 - Hosts: 206.53.61.77 google.lk O1 - Hosts: 206.53.61.77 google.lv O1 - Hosts: 206.53.61.77 google.ma O1 - Hosts: 206.53.61.77 google.md O1 - Hosts: 206.53.61.77 google.ms O1 - Hosts: 206.53.61.77 google.mu O1 - Hosts: 206.53.61.77 google.mv O1 - Hosts: 206.53.61.77 google.mw O1 - Hosts: 206.53.61.77 google.nl O1 - Hosts: 206.53.61.77 google.no O1 - Hosts: 206.53.61.77 google.nr O1 - Hosts: 206.53.61.77 google.nu O1 - Hosts: 206.53.61.77 google.pl O1 - Hosts: 206.53.61.77 google.pn O1 - Hosts: 206.53.61.77 google.pt O1 - Hosts: 206.53.61.77 google.ro O1 - Hosts: 206.53.61.77 google.ru O1 - Hosts: 206.53.61.77 google.rw O1 - Hosts: 206.53.61.77 google.sc O1 - Hosts: 206.53.61.77 google.se O1 - Hosts: 206.53.61.77 google.sh O1 - Hosts: 206.53.61.77 google.si O1 - Hosts: 206.53.61.77 google.sm O1 - Hosts: 206.53.61.77 google.sn O1 - Hosts: 206.53.61.77 google.st O1 - Hosts: 206.53.61.77 google.tl O1 - Hosts: 206.53.61.77 google.tm O1 - Hosts: 206.53.61.77 google.tt O1 - Hosts: 206.53.61.77 google.us O1 - Hosts: 206.53.61.77 google.vg O1 - Hosts: 206.53.61.77 google.vu O1 - Hosts: 206.53.61.77 google.ws O1 - Hosts: 206.53.61.77 google.co.bw O1 - Hosts: 206.53.61.77 google.co.ck O1 - Hosts: 206.53.61.77 google.co.id O1 - Hosts: 206.53.61.77 google.co.il O1 - Hosts: 206.53.61.77 google.co.in O1 - Hosts: 206.53.61.77 google.co.jp O1 - Hosts: 206.53.61.77 google.co.ke O1 - Hosts: 206.53.61.77 google.co.kr O1 - Hosts: 206.53.61.77 google.co.ls O1 - Hosts: 206.53.61.77 google.co.ma O1 - Hosts: 206.53.61.77 google.co.mz O1 - Hosts: 206.53.61.77 google.co.nz O1 - Hosts: 206.53.61.77 google.co.th O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll O2 - BHO: ooVoo Toolbar - {A057A204-BACC-4D26-8087-36EE87E26986} - C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O3 - Toolbar: ooVoo Toolbar - {A057A204-BACC-4D26-8087-36EE87E26986} - C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [oovoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe O4 - Global Startup: Dell Remote Access.lnk = ? O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O13 - Gopher Prefix: O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: dlbt_device - - C:\Windows\system32\dlbtcoms.exe O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 15541 bytes |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) | |
|
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
Join Date: Oct 2007
Location: Georgia
Posts: 10,622
OS: XP SP3
|
Re: Virus
Hello and Welcome to TSF.
We no longer use HijackThis as our initial analysis tool. We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a Quote:
------------------------------------------------------ Please follow our pre-posting process outlined here: NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help After running through all the steps, you shall have a proper set of logs. Please post them in a new thread, as this one shall be closed. If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply. Please note that the Virus/Trojan/Spyware Help forum is extremely busy, and it may take a while to receive a reply. ------------------------------------------------------ |
|
|
|
![]() |
| Thread Tools | |
|
|