![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 13
OS: xp
|
Downloader
---------------------------------------------------------
ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 2:25:56 PM, 1/1/2006 + Report-Checksum: C79C1512 + Scan result: [516] VM_00D60000 -> Downloader.Agent.uj : Error during cleaning [540] VM_00BF0000 -> Downloader.Agent.uj : Error during cleaning [1340] VM_007B0000 -> Downloader.Agent.uj : Error during cleaning [352] VM_00930000 -> Downloader.Agent.uj : Error during cleaning [112] VM_008F0000 -> Downloader.Agent.uj : Error during cleaning [400] VM_00890000 -> Downloader.Agent.uj : Error during cleaning [480] VM_01000000 -> Downloader.Agent.uj : Error during cleaning [492] VM_009E0000 -> Downloader.Agent.uj : Error during cleaning [560] VM_00A40000 -> Downloader.Agent.uj : Error during cleaning [680] VM_00870000 -> Downloader.Agent.uj : Error during cleaning [2336] VM_003A0000 -> Downloader.Agent.uj : Error during cleaning [2620] VM_007D0000 -> Downloader.Agent.uj : Error during cleaning ::Report End Then... Logfile of HijackThis v1.99.1 Scan saved at 2:26:58 PM, on 1/1/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\wdfmgr.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\Fast.exe C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe C:\Program Files\Slim Multimedia Keyboard\OSD.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\HijackThis\HijackThis.exe R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe" "ZyXEL\ZyXEL USB ADSL" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O4 - HKCU\..\Run: [Advanced Spyware Remover] C:\Program Files\Evonsoft\ASR\Asr.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {87632451-1331-3451-2621-452727222157} - ms-its:mhtml:file://C:\nosuch.mht!http://loli.enacre.net/chm.chm::/exe.exe O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8885291C-1BE4-450E-B494-91FF12DED8C8}: NameServer = 85.255.116.23 85.255.112.166 O17 - HKLM\System\CCS\Services\Tcpip\..\{99DBC017-2C09-4A01-80C7-653FD17A181C}: NameServer = 85.255.116.23,85.255.112.166 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Please Help Sir! |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
|
You may want to print out these instructions for reference, since you will have to restart your computer during the fix.
Please download FixWareout from one of these sites: http://downloads.subratam.org/Fixwareout.exe http://swandog46.geekstogo.com/Fixwareout.exe Save it to your desktop and run it. Click Next, then Install. Make sure 'Run fixit' is checked and click Finish. The fix will begin. Follow the prompts. You will be asked to reboot your computer. Your system may take longer than usual to load - this is normal. When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items: O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto O16 - DPF: {87632451-1331-3451-2621-452727222157} - ms-its:mhtml:file://C:\nosuch.mht!http://loli.enacre.net/chm.chm::/exe.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{8885291C-1BE4-450E-B494-91FF12DED8C8}: NameServer = 85.255.116.23 85.255.112.166 O17 - HKLM\System\CCS\Services\Tcpip\..\{99DBC017-2C09-4A01-80C7-653FD17A181C}: NameServer = 85.255.116.23,85.255.112.166 Click Fix Checked. Close HijackThis and click OK to proceed. Delete this folder: C:\Program Files\winupdates\ At the end of the fix, you may need to restart your computer again. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below. Please download Ewido Security Suite at http://www.ewido.net/en/download/. 1. Install Ewido Security Suite. 2. When installing, under 'Additional Options' uncheck: * Install background guard * Install scan via context menu 3. Launch Ewido, there should be an icon on your desktop, double click it. 4. The program will now open to the main screen. 5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment. 6. You will need to update Ewido to the latest definition files. * On the left hand side of the main screen click update. * Then click on Start Update. 7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'. 8. Exit Ewido. DO NOT scan yet. If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually. Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Don't run it yet. Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingcomputer.com/foru...howtutorial=61 ). CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff. Now open Ewido and do a scan on your system. * Click on scanner. * Click on 'Complete System Scan' and the scan will begin. * While the scan is in progress you will be prompted to clean the first infected file it finds. Choose 'Remove', then put a check next to 'Perform action on all infections' in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK. Exit Ewido when it's done. * Once the scan has completed, there will be a button located on the bottom of the screen named 'Save report'. * Click 'Save report'. * Save the report to your desktop. Restart your computer to get back to Normal Mode. Post the Ewido report and a new HijackThis log here. Also post the contents of the logfile C:\fixwareout\report.txt here.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 13
OS: xp
|
Reports
Fixwareout ver 1.003
Last edited 12/5/2005 Post this report in the forums please Reg Entries that were deleted HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\xedocne HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\gib_ogol HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\repiwoh HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\23plhps HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\mgcppp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\tesvaf HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\32refaselif HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. »»»»» Search by size and names... C:\WINDOWS\SYSTEM32\CSLZI.EXE »»»»» Misc files »»»»» Checking for older varients covered by the Rem3 tool --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 2:36:59 AM, 1/2/2006 + Report-Checksum: F8789B72 + Scan result: C:\Documents and Settings\Tommy Cheung\Complete\Able2Extract Pro 3.0.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Acronis Privacy Expert Suite 8.0.789.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\All Adobe DVD-X.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Asylum.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Aurora MPEG To DVD Burner 4.76.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\AutoScreenRecorder 2.1.281 Pro.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\AutoScreenRecorder Pro 2.1.281.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\BloodRayne 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Copy DVD Gold 2.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\DialogBlocks 2.06.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\DVDFab Platinum 2.9.65.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Enemy Of The State.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Flash Player Pro 2.6.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Game Collector 2.02.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\HyperCam 2.13.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Led Zeppelin - Box Set (4 cds).zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\MeggieSoft Canasta 16.4 16404.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\MeggieSoft Euchre and Ecarte 16.4 164.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Microsoft Office 2006.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Musicmatch Jukebox Plus 10.00.4015c.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Need For Speed Most Wanted Black.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Partiton Magic 8.05.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Partners.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\PayPal Flash Button Creator 1.5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\PhotoLine 32 - 12.01.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Prime (2005).zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Pro Evolution Soccer 5.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Rounders.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Silence Becomes You.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Spyware Doctor.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\SuperVideoCap 4.38.510.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\SWAT 4.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Symantec Norton Ghost 10.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\The 40 Year Old Virgin.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\The Man.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\The Polar Express.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Vanilla Sky.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Vietcong 2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\Warcraft III The Frozen Throne.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Complete\XmlBlueprint XML Editor 3.9.1220.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Desktop\Diagnostics\ZoneAlarm 6.0.667.000 Pro\Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\Tommy Cheung\Desktop\ZoneAlarm 6.0.667.000 Pro\Setup.exe -> Worm.VB.an : Cleaned with backup C:\RECYCLER\S-1-5-21-1177238915-115176313-725345543-1003\Dc1.tmp -> Worm.VB.an : Cleaned with backup C:\RECYCLER\S-1-5-21-1177238915-115176313-725345543-1003\Dc2.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\WINDOWS\system32\cslzi.exe -> Downloader.Agent.uj : Cleaned with backup Logfile of HijackThis v1.99.1 Scan saved at 2:39:01 AM, on 1/2/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\Fast.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe C:\Program Files\ICQLite\ICQLite.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Slim Multimedia Keyboard\OSD.EXE C:\WINDOWS\system32\notepad.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\ewido\security suite\SecuritySuite.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\HijackThis\HijackThis.exe R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll F1 - win.ini: run= C:\WESTWOOD\REDALERT\INSTICON.EXE O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZyXEL\ZyXEL USB ADSL\CnxDslTb.exe" "ZyXEL\ZyXEL USB ADSL" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKCU\..\Run: [Advanced Spyware Remover] C:\Program Files\Evonsoft\ASR\Asr.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Slim Multimedia Keyboard.lnk = C:\Program Files\Slim Multimedia Keyboard\MagicKey.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe ::Report End |
|
|
|
|
#4 (permalink) |
|
Manager Emeritus - Security Center, Expert Analyst, Moderator - Security Team; Rangemaster, TSF Academy & Supporter
|
Perform an online scan with Internet Explorer with Panda ActiveScan
** click on "Free use ActiveScan" located on the top right hand corner
__________________
We Are The BORG Spyware KILLER and Adware Destroyer!
![]() ![]() ![]() Spyware/Adware Removal Tools Hijackthis Ad-aware SE Spybot Search&Destroy SpywareBlaster CWShredder |
|
|
| Thread Tools | |
|
|