![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
|
|
LinkBack | Thread Tools |
|
|
#21 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista
|
Ack--so sorry, I forgot you still have Ewido. Ewido has been purchased by Grisoft, makers of AVG Antivirus, and the program is now known as AVG Anti-Spyware. Ewido currently can still be updated to the newest definitions, but this support will likely not last forever. I recommend you uninstall Ewido, restart your system, then download and install AVG Anti-Spyware. Update it's definitions as directed below, and run a scan where I have it placed in this fix.
Download AVG Anti Spyware Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
You would run the scan the same as you did with Ewido. Let's see if the updated version finds anything else. **Before you download the newest version and run another scan, please do the following for me:
I can be going over that report while you download AVG A-S and run that scan--post the AVG A-S results when ready.
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#22 (permalink) |
|
Registered User
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP
|
The CMD scan has been on the same screen for a while now, is this normal? Its saying a "report will be produced, please wait until this window closes". Should I just be patient or has it stalled?
|
|
|
|
|
#24 (permalink) |
|
Registered User
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP
|
Its a relevant question, I did get confused. I'm not so good with this extracting and zip file malarky
If I delete the programs I downloaded, could you talk me through how to do it please? I use WinRar. |
|
|
|
|
#25 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista
|
No apologies necessary...I did the same thing myself when testing it.
![]() First, find where the Autoruns folder is unzipped to. Write down, or note the full path of where the folder is located. When unzipping the Autocmd--Winrar will automatically fill in the 'unzip to' field for you--you don't want that path. Select 'Browse' and browse to the location that the Autoruns folder is in. Double click it and that path should now show in the 'unzip to' field.
|
|
|
|
|
#26 (permalink) |
|
Registered User
Join Date: Nov 2006
Location: London, England
Posts: 68
OS: Windows XP
|
Right, firstly here's the AVG report.
AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 21:59:03 28/11/2006 + Scan result: :mozilla.27:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.28:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.29:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.79:C:\Documents and Settings\Lee\Application Data\Mozilla\Firefox\Profiles\9dx75rxh.default\cookies.txt -> TrackingCookie.Sitestat : No action taken. C:\System Volume Information\_restore{B191484F-6940-4C0A-B094-69318FF0F599}\RP468\A0117420.exe -> Trojan.DNSChanger.gp : No action taken. :Report end I didn't know if you wanted me to apply all actions so I thought it best I did. The tracking cookies I deleted and the Trjoan.DNS I quarantined. Hope I did the right thing. Now, despite my best efforts the Auto stuff refused to work and got me rather angry ![]() I do however have the whole report, I hope its not too tough to assess. If it is I apologise and with some more advice I'll try to get the report. Here it is: Lee - 28/11/2006@20:12:19.68 running from C:\Documents and Settings\Lee\Desktop\Autoruns\ Other users of this machine: * Everyone else ---------------------------------------------------------------------------------- HKLM\System\CurrentControlSet\Services ANISERVICE Airgo Networks NIC Service (Not verified) Airgo Networks, Inc. c:\windows\system32\aniserv.exe Automatic LiveUpdate Scheduler Manages the scheduling of Automatic LiveUpdate sessions (Verified) Symantec Corporation c:\program files\symantec\liveupdate\aluschedulersvc.exe ccEvtMgr Event propagation and logging service (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccevtmgr.exe ccProxy Symantec Proxy Service (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccproxy.exe ccSetMgr Settings storage and management service (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccsetmgr.exe CFSvcs Service of ConfigFree. (Not verified) TOSHIBA CORPORATION c:\program files\toshiba\configfree\cfsvcs.exe ewido anti-spyware 4.0 guard ewido anti-spyware guard (Not verified) Anti-Malware Development a.s. c:\program files\ewido anti-spyware 4.0\guard.exe navapsvc Handles Norton AntiVirus Auto-Protect events. (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\navapsvc.exe Pml Driver HPZ12 PML Driver (Not verified) HP c:\windows\system32\hpzipm12.exe SiteAdvisor Service Provides low-level support for McAfee SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\4608\saservice.exe SNDSrvc Symantec Network Drivers Service (Verified) Symantec Corporation c:\program files\common files\symantec shared\sndsrvc.exe SPBBCSvc Symantec SPBBC (Verified) Symantec Corporation c:\program files\common files\symantec shared\spbbc\spbbcsvc.exe Symantec Core LC Symantec Core LC (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe UserAccess7 c:\windows\system32\uaservice7.exe HKLM\System\CurrentControlSet\Services eeCtrl Symantec Eraser Control Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\eengine\eectrl.sys EraserUtilRebootDrv Symantec Eraser Utility Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys ewido anti-spyware 4.0 driver c:\program files\ewido anti-spyware 4.0\guard.sys GEARAspiWDM CDRom Class Filter Driver (Verified) GEAR Software Inc. c:\windows\system32\drivers\gearaspiwdm.sys NAVENG AV Engine (Verified) Symantec Corporation c:\program files\common files\symantec shared\virusdefs\20061128.018\naveng.sys NAVEX15 AV Engine (Verified) Symantec Corporation c:\program files\common files\symantec shared\virusdefs\20061128.018\navex15.sys Netdevio TOSHIBA Network Device Usermode I/O Protocol (Not verified) TOSHIBA Corporation. c:\windows\system32\drivers\netdevio.sys SAVRT AutoProtect (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\savrt.sys SAVRTPEL SAVRTPEL (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\savrtpel.sys Secdrv SafeDisc driver (Not verified) Macrovision Europe Ltd c:\windows\system32\drivers\secdrv.sys SPBBCDrv SPBBC Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\spbbc\spbbcdrv.sys SYMDNS DNS Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symdns.sys SymEvent Symantec Event Library (Verified) Symantec Corporation c:\program files\symantec\symevent.sys SYMFW Firewall Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symfw.sys SYMIDS IDS Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symids.sys SYMIDSCO IDS Core Driver (Verified) Symantec Corporation c:\program files\common files\symantec shared\symcdata\idsdefs\20061113.031\symidsco.sys symlcbrd Symantec Core Component (Verified) Symantec Corporation c:\windows\system32\drivers\symlcbrd.sys SYMNDIS NDIS Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symndis.sys SYMREDRV Redirector Filter Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symredrv.sys SYMTDI Network Dispatch Driver (Verified) Symantec Corporation c:\windows\system32\drivers\symtdi.sys TVALD Toshiba Notebook PC SMI Driver (Not verified) Toshiba Corporation c:\windows\system32\drivers\nbsmi.sys WNIPROT5 Airgo Networks Ndis 5.0 Protocol driver (Not verified) Airgo Networks, Inc. c:\windows\system32\wniprot5.sys HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors HP Standard TCP/IP Port Standard TCP/IP Port Monitor DLL (Not verified) Hewlett Packard c:\windows\system32\hptcpmon.dll HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls interceptor.dll API Interceptor (Not verified) Tenebril Inc. c:\windows\system32\interceptor.dll HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run TPSMain (Not verified) TOSHIBA Corporation c:\windows\system32\tpsmain.exe THotkey (Not verified) TOSHIBA c:\program files\toshiba\toshiba applet\thotkey.exe TFncKy TFncKy (Not verified) TOSHIBA Corporation C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe AGRSMMSG SoftModem Messaging Applet (Not verified) Agere Systems c:\windows\agrsmmsg.exe HydraVisionDesktopManager HydraDM (Not verified) ATI Technologies Inc. c:\program files\ati technologies\ati hydravision\hydradm.exe Startup Manager Scanner c:\program files\startup mechanic\startupmonitor.exe ccApp Symantec User Session (Verified) Symantec Corporation c:\program files\common files\symantec shared\ccapp.exe SiteAdvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\4608\siteadv.exe HKLM\SOFTWARE\Classes\Protocols\Filter application/octet-stream Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll application/x-complus Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll application/x-msdownload Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll HKLM\SOFTWARE\Classes\Protocols\Handler msnim MSN Messenger Protocol Handler (Not verified) Microsoft Corporation c:\program files\msn messenger\msgrapp.dll siteadvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\4608\siteadv.dll HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components 0 File not found: About:Home HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components n/a Microsoft .NET IE SECURITY REGISTRATION (Not verified) Microsoft Corporation c:\windows\system32\mscories.dll C:\Documents and Settings\Lee\Start Menu\Programs\Startup Scheduler.lnk Scheduler daemon (Not verified) Tenebril Incorporated c:\program files\spycatcher 2006\scheduler daemon.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run TOSCDSPD CD/DVD Drive Acoustic Silencer (Not verified) TOSHIBA c:\program files\toshiba\toscdspd\toscdspd.exe msnmsgr MSN Messenger (Not verified) Microsoft Corporation c:\program files\msn messenger\msnmsgr.exe iIWiper iISystem Wiper (Not verified) iISoftware c:\program files\iisystem wiper\systemwiper.exe Task Scheduler AppleSoftwareUpdate.job Software Application (Verified) Apple Computer, Inc. c:\program files\apple software update\softwareupdate.exe Norton AntiVirus - Run Full System Scan - Lee.job Norton AntiVirus Scanner Module (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\navw32.exe Symantec NetDetect.job File not found: C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects AcroIEHlprObj Class Adobe Acrobat IE Helper Version 6.0 for ActivieX (Verified) Adobe Systems, Incorporated c:\program files\adobe\acrobat 6.0\reader\activex\acroiehelper.dll {089FD14D-132B-48FC-8861-0048AE113215} SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\4608\siteadv.dll SpywareBlock Class Spyware blocking module (Not verified) Tenebril Inc. c:\program files\spycatcher 2006\scactiveblock.dll PCTools Site Guard Site Guard (Not verified) PC Tools c:\program files\spyware doctor\tools\iesdsg.dll SSVHelper Class Java(TM) 2 Platform Standard Edition binary (Not verified) Sun Microsystems, Inc. c:\program files\java\jre1.5.0_09\bin\ssv.dll CNisExtBho Class NIS Shell Extension (Verified) Symantec Corporation c:\program files\common files\symantec shared\adblocking\nisshext.dll CNavExtBho Class Norton AntiVirus Shell Extension Module (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\navshext.dll PCTools Browser Monitor iesdpb.dll (Not verified) GuideWorks Pty. Ltd. c:\program files\spyware doctor\tools\iesdpb.dll HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ewido anti-spyware 4.0 ewido anti-spyware guard (Not verified) Anti-Malware Development a.s. c:\program files\ewido anti-spyware 4.0\shellexecutehook.dll HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved Display Panning CPL Extension File not found: deskpan.dll Fusion Cache Microsoft .NET Runtime Execution Engine (Not verified) Microsoft Corporation c:\windows\system32\mscoree.dll Shell Extensions for RealOne Player RealPlayer Shell Extensions (Not verified) RealNetworks, Inc. c:\program files\real\realplayer\rpshell.dll iTunes iTunes Mini Player DLL (Not verified) Apple Computer, Inc. c:\program files\itunes\itunesminiplayer.dll WinRAR shell extension c:\program files\winrar\rarext.dll OpenOffice.org Column Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.0\program\shlxthdl.dll OpenOffice.org Infotip Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.0\program\shlxthdl.dll OpenOffice.org Property Sheet Handler (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.0\program\shlxthdl.dll OpenOffice.org Thumbnail Viewer (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.0\program\shlxthdl.dll Crypteze Shell extension Crypteze Shell Extensions 1.0 (Not verified) kcSystems Inc. c:\program files\kcsystems\crypteze\cryptezeshl.dll HKLM\Software\Classes\Folder\Shellex\ColumnHandlers {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} (Not verified) Sun Microsystems, Inc. c:\program files\openoffice.org 2.0\program\shlxthdl.dll HKLM\Software\Microsoft\Internet Explorer\Toolbar Norton Internet Security 2006 NIS Shell Extension (Verified) Symantec Corporation c:\program files\common files\symantec shared\adblocking\nisshext.dll Norton AntiVirus Norton AntiVirus Shell Extension Module (Verified) Symantec Corporation c:\program files\norton internet security\norton antivirus\navshext.dll McAfee SiteAdvisor SiteAdvisor (Verified) McAfee, Inc. c:\program files\siteadvisor\4608\siteadv.dll HKLM\Software\Microsoft\Internet Explorer\Extensions PartyPoker.com RunApp MFC Application c:\program files\partygaming\partypoker\runapp.exe If it's easier for you I've attached a document in notepad with the above report in it. |
|
|
|
|
#27 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista
|
Hi,
Everything appears in order there as well. Let's have a look at Windows Event Viewer. It might give us a clue as to what is causing these issues Go to Start > Run - type in eventvwr <Press Enter> You will see Application, Security & System listed in the left pane.
|
|
|
|
|
#29 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,029
OS: WinXP and Vista
|
Hi Lee,
Those are definitely OS related issues and you would be better served discusssing this with the Windows XP experts. Give them a description of your remaining issues as well as the Event Viewer info and let them know you've been cleared by the HijackThis section. |
|
|
| Thread Tools | |
|
|