Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 05-12-2007, 11:06 AM   #21 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi. Ok. Heres the log:


StartDreck (build 2.1.7 public stable) - 2007-05-12 @ 18:02:41 (GMT +01:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 2)
Internet Explorer: 6.0.2900.2180
Logged in as Jorge Martins at LINUX

舞egistry
舞un Keys
翟urrent User
舞un
*CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
*MSMSGS="C:\Programas\Messenger\msmsgs.exe" /background
舞unOnce
聞efault User
舞un
*CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
舞unOnce
腿ocal Machine
舞un
*ESB=C:\WINDOWS\System32\ESB.exe
*4mtcsb=C:\WINDOWS\System32\4mtcsb.EXE
*PRONoMgr.exe=C:\Programas\Intel\NCS\PROSet\PRONoMgr.exe
*IgfxTray=C:\WINDOWS\System32\igfxtray.exe
*HotKeysCmds=C:\WINDOWS\System32\hkcmd.exe
*AudioHQ=C:\Programas\Creative\SBLive\AudioHQ\AHQTB.EXE
*Creative Launcher=C:\Programas\Creative\Launcher\CTLauncher.exe
*NeroCheck=C:\WINDOWS\System32\\NeroCheck.exe
*InCD=C:\Programas\Ahead\InCD\InCD.exe
*SunJavaUpdateSched=C:\Programas\Java\jre1.5.0\bin\jusched.exe
*AVG7_CC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
*QuickTime Task="C:\Programas\QuickTime\qttask.exe" -atboottime
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
舞unOnce
舞unServices
舞unServicesOnce
舞unOnceEx
舞unServicesOnceEx
肇iles
艋ystem/Drivers
舞unning Processes
+0=<idle>
+4=<system>
+740=\SystemRoot\System32\smss.exe
+816=\??\C:\WINDOWS\system32\csrss.exe
+840=\??\C:\WINDOWS\system32\winlogon.exe
+884=C:\WINDOWS\system32\services.exe
+896=C:\WINDOWS\system32\lsass.exe
+1064=C:\WINDOWS\system32\svchost.exe
+1128=C:\WINDOWS\system32\svchost.exe
+1268=C:\WINDOWS\System32\svchost.exe
+1320=C:\WINDOWS\System32\S24EvMon.exe
+1368=C:\WINDOWS\System32\svchost.exe
+1516=C:\WINDOWS\System32\svchost.exe
+1884=C:\WINDOWS\system32\spoolsv.exe
+200=C:\WINDOWS\system32\ZCfgSvc.exe
+356=C:\WINDOWS\Explorer.EXE
+696=C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\Anti-coisas\AVG Anti-Spyware 7.5\guard.exe
+708=C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
+720=C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
+800=C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
+1032=C:\Programas\ewido\security suite\ewidoctrl.exe
+1092=C:\Programas\Ahead\InCD\InCDsrv.exe
+1196=C:\WINDOWS\System32\RegSrvc.exe
+1304=C:\WINDOWS\System32\RoamMgr.exe
+1552=C:\WINDOWS\system32\slserv.exe
+1596=C:\WINDOWS\System32\svchost.exe
+144=C:\WINDOWS\system32\wdfmgr.exe
+1084=C:\WINDOWS\System32\4mtcsb.EXE
+1296=C:\WINDOWS\System32\igfxtray.exe
+1448=C:\WINDOWS\System32\hkcmd.exe
+1540=C:\Programas\Creative\SBLive\AudioHQ\AHQTB.EXE
+1804=C:\Programas\Ahead\InCD\InCD.exe
+1956=C:\Programas\Java\jre1.5.0\bin\jusched.exe
+2132=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
+2164=C:\Programas\QuickTime\qttask.exe
+2296=C:\WINDOWS\system32\ctfmon.exe
+2356=C:\Programas\Messenger\msmsgs.exe
+2364=C:\WINDOWS\System32\1XConfig.exe
+2704=C:\Programas\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
+2956=C:\WINDOWS\System32\alg.exe
+180=C:\WINDOWS\system32\wuauclt.exe
+268=C:\Programas\Mozilla Firefox\firefox.exe
+3596=C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\StartDreck\StartDreck.exe
翠pplication specific
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 05-12-2007, 01:01 PM   #22 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Download Dr.Web CureIt & save it on your desktop.

  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

NOTE: The scan will require at least an hour.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-12-2007, 03:13 PM   #23 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi. Heres the log. incur嫛el = incurable, movido = moved.

base junk.exe C:\Documents and Settings\All Users\Application Data\third mags grid inside Trojan.Swizzor Incur嫛el.Movido.
Face Find.exe C:\Documents and Settings\All Users\Application Data\third mags grid inside Trojan.Swizzor Incur嫛el.Movido.
jugs bone.exe C:\Documents and Settings\All Users\Application Data\third mags grid inside Trojan.Swizzor Incur嫛el.Movido.
Junk ping.exe C:\Documents and Settings\All Users\Application Data\third mags grid inside Trojan.Swizzor Incur嫛el.Movido.
support plan.exe C:\Documents and Settings\All Users\Application Data\third mags grid inside Trojan.Swizzor Incur嫛el.Movido.
fohyoirb.exe C:\Documents and Settings\Jorge Martins\Application Data\about amok Trojan.Swizzor Incur嫛el.Movido.
owlxvvxh.exe C:\Documents and Settings\Jorge Martins\Application Data\about amok Trojan.Swizzor Incur嫛el.Movido.
tmjeierh.exe C:\Documents and Settings\Jorge Martins\Application Data\about amok Trojan.Swizzor Incur嫛el.Movido.
xhdskubs.exe C:\Documents and Settings\Jorge Martins\Application Data\about amok Trojan.Swizzor Incur嫛el.Movido.
zkuhxctx.exe C:\Documents and Settings\Jorge Martins\Application Data\about amok Trojan.Swizzor Incur嫛el.Movido.
mirc.exe C:\mIRC Program.mIRC.616 Incur嫛el.Movido.
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 04:59 AM   #24 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Hi again

LOP is the only thing that seems to be present.

Please run combofix again, just as you did previously.

Post back with c:\combofix.txt
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 08:06 AM   #25 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi. Heres the log:

"Jorge Martins" - 2007-05-13 14:53:51 Service Pack 2
ComboFix 07-05.11.V - Running from: "C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\"


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))


2007-05-12 20:26 <DIR> d-------- C:\DOCUME~1\JORGEM~1\DoctorWeb
2007-05-09 19:59 <DIR> d-------- C:\Programas\SopCast
2007-05-09 19:59 <DIR> d-------- C:\DOCUME~1\JORGEM~1\APPLIC~1\SopCast
2007-05-07 21:04 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-06 20:20 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-06 20:20 <DIR> d-------- C:\Programas\Your Uninstaller 2006
2007-05-06 20:20 <DIR> d-------- C:\DOCUME~1\JORGEM~1\APPLIC~1\URSoft


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-12 19:54:40 -------- d-----w C:\DOCUME~1\JORGEM~1\APPLIC~1\about amok
2007-05-06 19:13:35 -------- d--h--w C:\Programas\InstallShield Installation Information
2007-05-06 19:11:55 -------- d-----w C:\Programas\GameSpy Arcade
2007-05-06 19:11:08 -------- d-----w C:\Programas\Finale 2003
2007-05-06 18:46:04 -------- d-----w C:\Programas\eMule
2007-04-25 18:48:41 -------- d-----w C:\Programas\TVU Player
2007-04-25 18:11:45 -------- d-----w C:\Programas\PartyGaming.Net
2007-03-25 17:22:30 64,140 ----a-w C:\WINDOWS\system32\perfc016.dat
2007-03-25 17:22:30 428,328 ----a-w C:\WINDOWS\system32\perfh016.dat
2007-03-17 13:43:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:37:34 578,560 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:37:34 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:37:34 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:33:32 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:18:52 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Programas\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
{53707962-6F74-2D53-2644-206D7942484F}=C:\DOCUME~1\JORGEM~1\AMBIEN~1\ANTI-C~1\SPYBOT~1\SDHelper.dll
{8ABC10F3-9DFD-6742-EB72-D9D7C8DD4570}=C:\WINDOWS\gacud1.dll [x]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ESB"="C:\\WINDOWS\\System32\\ESB.exe"
"4mtcsb"="C:\\WINDOWS\\System32\\4mtcsb.EXE"
"PRONoMgr.exe"="C:\\Programas\\Intel\\NCS\\PROSet\\PRONoMgr.exe"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"AudioHQ"="C:\\Programas\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"Creative Launcher"="C:\\Programas\\Creative\\Launcher\\CTLauncher.exe"
"NeroCheck"="C:\\WINDOWS\\System32\\\\NeroCheck.exe"
"InCD"="C:\\Programas\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="C:\\Programas\\Java\\jre1.5.0\\bin\\jusched.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"QuickTime Task"="\"C:\\Programas\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ESB"="C:\WINDOWS\System32\ESB.exe" [2002-12-02 02:32]
"4mtcsb"="C:\WINDOWS\System32\4mtcsb.EXE" [2002-11-29 12:45]
"PRONoMgr.exe"="C:\Programas\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 18:21]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 03:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 03:11]
"AudioHQ"="C:\Programas\Creative\SBLive\AudioHQ\AHQTB.EXE" [1999-04-12 02:00]
"Creative Launcher"="C:\Programas\Creative\Launcher\CTLauncher.exe" []
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Programas\Ahead\InCD\InCD.exe" [2003-06-03 10:54]
"SunJavaUpdateSched"="C:\Programas\Java\jre1.5.0\bin\jusched.exe" [2004-09-03 06:50]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-23 15:04]
"QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2005-09-05 04:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
"MSMSGS"="C:\Programas\Messenger\msmsgs.exe" [2004-10-13 17:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Programas\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="C:\Programas\ewido\security suite\shellhook.dll"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\Anti-coisas\AVG Anti-Spyware 7.5\shellexecutehook.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0




[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HTTPFilter HTTPFilter\0\0
DcomLaunch DcomLaunch\0TermService\0\0

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-13 14:56:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-13 14:56:50
C:\ComboFix-quarantined-files.txt ... 2007-05-13 14:56
C:\ComboFix2.txt ... 2007-05-10 20:49
C:\ComboFix3.txt ... 2007-05-08 01:41
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 09:40 AM   #26 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Hi again

Registry Fix
Click on the zip file attached to this post to open and extract the file Quanta2.reg to your desktop. Double click on the file Quanta2.reg to run it. Answer yes to any prompts and allow it to merge into the Registry.



File Deletions
Delete the following Folder indicated in BLUE if it still exists.

C:\DOCUMENTS AND SETTINGS\JORGEM~1\APPLICATION DATA\about amok

Note: If it resists, you may have to boot to Safe Mode to delete it.


Run combofix again and post the log.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner

Last edited by Glaswegian; 03-27-2008 at 04:11 PM.
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 10:01 AM   #27 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi. Heres the log:

"Jorge Martins" - 2007-05-13 16:54:27 Service Pack 2
ComboFix 07-05.11.V - Running from: "C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\"


((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))


2007-05-12 20:26 <DIR> d-------- C:\DOCUME~1\JORGEM~1\DoctorWeb
2007-05-09 19:59 <DIR> d-------- C:\Programas\SopCast
2007-05-09 19:59 <DIR> d-------- C:\DOCUME~1\JORGEM~1\APPLIC~1\SopCast
2007-05-07 21:04 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-05-06 20:20 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2007-05-06 20:20 <DIR> d-------- C:\Programas\Your Uninstaller 2006
2007-05-06 20:20 <DIR> d-------- C:\DOCUME~1\JORGEM~1\APPLIC~1\URSoft


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-05-06 19:13:35 -------- d--h--w C:\Programas\InstallShield Installation Information
2007-05-06 19:11:55 -------- d-----w C:\Programas\GameSpy Arcade
2007-05-06 19:11:08 -------- d-----w C:\Programas\Finale 2003
2007-05-06 18:46:04 -------- d-----w C:\Programas\eMule
2007-04-25 18:48:41 -------- d-----w C:\Programas\TVU Player
2007-04-25 18:11:45 -------- d-----w C:\Programas\PartyGaming.Net
2007-03-25 17:22:30 64,140 ----a-w C:\WINDOWS\system32\perfc016.dat
2007-03-25 17:22:30 428,328 ----a-w C:\WINDOWS\system32\perfh016.dat
2007-03-17 13:43:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:37:34 578,560 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:37:34 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:37:34 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:33:32 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
2007-02-05 20:18:52 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Programas\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
{53707962-6F74-2D53-2644-206D7942484F}=C:\DOCUME~1\JORGEM~1\AMBIEN~1\ANTI-C~1\SPYBOT~1\SDHelper.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ESB"="C:\\WINDOWS\\System32\\ESB.exe"
"4mtcsb"="C:\\WINDOWS\\System32\\4mtcsb.EXE"
"PRONoMgr.exe"="C:\\Programas\\Intel\\NCS\\PROSet\\PRONoMgr.exe"
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"AudioHQ"="C:\\Programas\\Creative\\SBLive\\AudioHQ\\AHQTB.EXE"
"Creative Launcher"="C:\\Programas\\Creative\\Launcher\\CTLauncher.exe"
"NeroCheck"="C:\\WINDOWS\\System32\\\\NeroCheck.exe"
"InCD"="C:\\Programas\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="C:\\Programas\\Java\\jre1.5.0\\bin\\jusched.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"QuickTime Task"="\"C:\\Programas\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ESB"="C:\WINDOWS\System32\ESB.exe" [2002-12-02 02:32]
"4mtcsb"="C:\WINDOWS\System32\4mtcsb.EXE" [2002-11-29 12:45]
"PRONoMgr.exe"="C:\Programas\Intel\NCS\PROSet\PRONoMgr.exe" [2003-05-28 18:21]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 03:24]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 03:11]
"AudioHQ"="C:\Programas\Creative\SBLive\AudioHQ\AHQTB.EXE" [1999-04-12 02:00]
"Creative Launcher"="C:\Programas\Creative\Launcher\CTLauncher.exe" []
"NeroCheck"="C:\WINDOWS\System32\\NeroCheck.exe" [2001-07-09 11:50]
"InCD"="C:\Programas\Ahead\InCD\InCD.exe" [2003-06-03 10:54]
"SunJavaUpdateSched"="C:\Programas\Java\jre1.5.0\bin\jusched.exe" [2004-09-03 06:50]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-04-23 15:04]
"QuickTime Task"="C:\Programas\QuickTime\qttask.exe" [2005-09-05 04:30]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56]
"MSMSGS"="C:\Programas\Messenger\msmsgs.exe" [2004-10-13 17:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Programas\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{54D9498B-CF93-414F-8984-8CE7FDE0D391}"="C:\Programas\ewido\security suite\shellhook.dll"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Documents and Settings\Jorge Martins\Ambiente de trabalho\Anti-coisas\AVG Anti-Spyware 7.5\shellexecutehook.dll"


HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\0\0
Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages scecli\0\0




[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService DnsCache\0\0
rpcss RpcSs\0\0
imgsvc StiSvc\0\0
termsvcs TermService\0\0
HTTPFilter HTTPFilter\0\0
DcomLaunch DcomLaunch\0TermService\0\0

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-13 16:56:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-13 16:56:26
C:\ComboFix-quarantined-files.txt ... 2007-05-13 16:56
C:\ComboFix2.txt ... 2007-05-13 14:56
C:\ComboFix3.txt ... 2007-05-10 20:49
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 10:57 AM   #28 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

I assume that nothing has changed?
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 12:13 PM   #29 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Yes, nothing changed. I still cant remove StrongestOptimizer and browser still shuts down in some cases, like the HJT Log Help, and the downloads of Gmer, HJT and Avenger.

I ran a search on Google for StrongestOptimizer and i came across a couple of sites.

The first one is this which claims it can remove StrongestOptimizer (in the google search page). Is it trustworthy?

The second is this where there is a talk about the subject, but both my italian and computer skills are not very good so i thought i shouldnt risk trying some programs sugested. I did try Your Uninstaller (even without Gmer) but it didnt work.

As far as i can tell my problem is unique, for i cant download Gmer, HJT or Avenger.
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 04:02 PM   #30 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Hi again

Click on the zip file attached to this post to open and extract the file regfix3.reg to your desktop. Double click on the file regfix3.reg to run it. Answer yes to any prompts and allow it to merge into the Registry.


Now go to Start > Run and type in catchme in the run box and click OK.

Post back with the log produced.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner

Last edited by Glaswegian; 03-27-2008 at 04:11 PM.
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 04:51 PM   #31 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi Glaswegian. Thx for help so far.

Something curious happened. When i typed catchme on the Run, the whole Run window disappeared and all the icons on desktop disappeared, as for the start bar. Then all came back, except the Run window. I tried to find the log in the desktop and in c:\ but no luck. I assume it restarted the Windows Explorer, though not shure. I tried again, but faster, and a window appeared for just a second, and quickly shut down. No log.

Now i cant see Run because catchme is written there and i dont have time to change it before the window disappears.
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 04:55 PM   #32 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,338
OS: N/A


Re: i cant get rid of StrongestOptimizer

Navigate to this directory - C:\Windows

Locate & rename catchme.exe to KMD.exe.

Then doubleclick on it.
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-13-2007, 07:40 PM   #33 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi sUBs. Cant rename the file.

I can right-click on the file but if i try to change name i get the same thing: window closes, desktop icons and start-bar disappear, then all reappears, except c:\windows.
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 12:03 AM   #34 (permalink)
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,338
OS: N/A


Re: i cant get rid of StrongestOptimizer

I have fixed the link for regdump.exe. Please try it now
__________________

Question - what have you done for the community today?
sUBs is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 07:40 AM   #35 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

The regdump log is attached.
Attached Files
File Type: zip sUBs.zip (59.7 KB, 3 views)
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 12:54 PM   #36 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Hi again

Click on the zip file attached to this post to open and extract the file quanta123.bat to your desktop. Double click on the file quanta.bat to run it. A window will open and close quickly - this is normal. Now reboot your PC and let me know if things are any better.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner

Last edited by Glaswegian; 03-27-2008 at 04:11 PM.
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 01:33 PM   #37 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Hi Glaswegian.

Its all the same. Cant remove StrongestOptimizer and also cant google for HJT (if i write all). I did a printscreen (its attached) the moment the program window appeared. It may help.
Attached Images
File Type: jpg quantapic.JPG (50.4 KB, 5 views)
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 01:53 PM   #38 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

Can you see if this file is still on your system

c:\windows\system32\orfihdrh.bak
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 02:02 PM   #39 (permalink)
Registered User
 
Join Date: May 2007
Posts: 31
OS: XP


Re: i cant get rid of StrongestOptimizer

Yes it is.
Quanta123 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 05-14-2007, 02:08 PM   #40 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,153
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: i cant get rid of StrongestOptimizer

OK

Try again with this batch file - same as before - should work this time...

If possible can I ask you to stay online for a few minutes after you've posted...
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner

Last edited by Glaswegian; 03-27-2008 at 04:11 PM.
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 05:27 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85