![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 36
OS: WinXP
|
InternetExplorer freezes and pop-up problem
HI,
I have recently been having problems with my internet explorer.It freezes alot and i also get alot of pop-ups.I have used AVG virus scanner but it has not detected any viruses...I was wondering if someone could help out...below is a copy of hijackThis log...thankx in advance! Logfile of HijackThis v1.99.1 Scan saved at 19:13:14, on 11/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\D-Tools\daemon.exe C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe C:\Program Files\Lexmark 6200 Series\lxbumon.exe C:\Program Files\Lexmark 6200 Series\ezprint.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Shareaza\Shareaza.exe c:\progra~1\intern~1\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\system32\lxbucoms.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.red.clientapps.yahoo.com/c...ww.yahoo.co.uk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: (no name) - {D3112506-0954-32A6-A821-AB7C777D7864} - C:\DOCUME~1\user\APPLIC~1\INFOTH~1\STUPID ITCH.exe O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [lxbumon.exe] "C:\Program Files\Lexmark 6200 Series\lxbumon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 6200 Series\ezprint.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LFM] C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe -t O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE O4 - HKCU\..\Run: [NetGuard Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe" -STARTUP O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [idol frag] C:\DOCUME~1\user\APPLIC~1\BLAHME~1\For Grey Wait.exe O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra button: DownloadMP3 - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\System32\DownloadMP3 (file missing) O9 - Extra button: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe O9 - Extra 'Tools' menuitem: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0CFA086E-6336-4D95-B6AA-90F564E99631} (TNSClicker.Clicker) - http://www.shopandscan.com/TNSClicker.CAB O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/u...0/sdcregie.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094227271843 O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B3F8F451-788A-11D0-89D9-00A0C90C9B67} (MCSiTreeCtl Class) - http://activex.microsoft.com/controls/mcsi/mcsitree.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/...pcuploader.cab O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/game...ploader_v6.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: gdiwxp - gdiwxp.dll (file missing) O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Analyst, Security Team
|
You also have Norton installed...decide whether to keep AVG or Norton and uninstall one of them now.
We don't recommend using file sharing programs like Shareaza and Limewire as they may help contribute to these problems. Please print the below instructions or copy them to Notepad. Make sure to work through the fixes in the order mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. Also if you have any programs that may prevent system changes (like Spybot's TeaTimer program, Ad-aware's Ad-Watch, and others), make sure you disable them before doing any of the fixes (or accept the changes for the fix we give you when asked by the programs). Go to My Computer->Tools (or View)->Folder Options->View tab: * Under the Hidden files and folders heading, select Show hidden files and folders (it's Show all files for Windows 98). * Uncheck the Hide protected operating system files (recommended) option. * Click Yes to confirm and then click OK. ** You may change the above options back after your log is clean. If we ask you to fix something that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep). Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingcomputer.com/foru...howtutorial=61 ). Make sure to close any internet browsers that may still be open. Uninstall the following via the Add/Remove Panel (Start->Settings->Control Panel->Add/Remove Programs) if found: Messenger Plus - this program contains a 'sponsor' program. If you installed this 'sponsor' program, uninstall Messenger Plus and reinstall it back but without the sponsor. In this case you did install it... Casino - unless you intentionally installed this...then you may ignore any of the fixes below pertaining to this program Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you checked the last one: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.red.clientapps.yahoo.com/c...ww.yahoo.co.uk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html O2 - BHO: (no name) - {D3112506-0954-32A6-A821-AB7C777D7864} - C:\DOCUME~1\user\APPLIC~1\INFOTH~1\STUPID ITCH.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKCU\..\Run: [idol frag] C:\DOCUME~1\user\APPLIC~1\BLAHME~1\For Grey Wait.exe O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: DownloadMP3 - {76DD9E77-F06C-4471-AB6C-CF03C5C6B5B0} - C:\WINDOWS\System32\DownloadMP3 (file missing) O9 - Extra button: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe O9 - Extra 'Tools' menuitem: Club Dice Casino - {907A768D-DD74-476d-8487-FD27DF7AD7FF} - C:\Casino\Club Dice Casino\casino.exe O16 - DPF: {0CFA086E-6336-4D95-B6AA-90F564E99631} (TNSClicker.Clicker) - http://www.shopandscan.com/TNSClicker.CAB O20 - Winlogon Notify: gdiwxp - gdiwxp.dll (file missing) Locate the following Files/Folders and delete them if they exist (if no location given, just do a search for them): C:\DOCUME~1\user\APPLIC~1\INFOTH~1\ C:\Program Files\MessengerPlus! 3\ C:\DOCUME~1\user\APPLIC~1\BLAHME~1\ C:\WINDOWS\System32\DownloadMP3 C:\Casino\ Restart. Perform an online scan with Internet Explorer at Panda ActiveScan http://www.pandasoftware.com/products/activescan.htm * Click on 'Scan your PC' button. There should be a popup - if you have a pop-up blocker, make sure it's not blocking it. * Click 'Check Now' & a pop-up window will appear. * Enter your Country, State and E-mail Address & click 'Scan Now' - begin downloading Panda's ActiveX controls (8 MB size). * Begin the scan by selecting My Computer. * If it finds any malware, it will offer you a report. Ignore any entry it finds (since it wants you to buy the program for removal) as we will address this later. * Click on see report. Then click Save report. * Post that log in your next reply along with a new HijackThis log. Also give us this log: Download FindLOP http://metallica.geekstogo.com/findlop.zip and unzip to a folder. Inside the folder find findlop.bat Double click on it and it will create the file C:\findlop.txt Find that file and copy the content into your next reply.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it. |
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 36
OS: WinXP
|
Active Scan:
Incident Status Location Adware:adware/gator Not disinfected C:\WINDOWS\GatorPdpLoudInstaller.log Spyware:spyware/betterinet Not disinfected Windows Registry Dialer:dialer.db Not disinfected HKEY_CURRENT_USER\SOFTWARE\MATRIX_HTML Adware:adware/surfaccuracy Not disinfected Windows Registry Potentially unwanted tool:application/altnet Not disinfected HKEY_CLASSES_ROOT\Interface\{582AB125-1403-42FB-9EFB-198690BA1496} Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\user\Cookies\user@112.2o7[2].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\user\Cookies\user@2o7[2].txt Spyware:Cookie/66.246.209 Not disinfected C:\Documents and Settings\user\Cookies\user@66.246.209[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Cookies\user@888[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Cookies\user@888[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Cookies\user@ad.yieldmanager[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\user\Cookies\user@adopt.hbmediapro[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Cookies\user@adrevolver[1].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Cookies\user@adrevolver[3].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Cookies\user@ads.pointroll[1].txt Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\user\Cookies\user@adtech[2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Cookies\user@adultfriendfinder[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\user\Cookies\user@advertising[2].txt Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\user\Cookies\user@adviva[2].txt Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\user\Cookies\user@anm.co[2].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\user\Cookies\user@apmebf[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as-eu.falkag[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as-us.falkag[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as1.falkag[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\user\Cookies\user@atdmt[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@ath.belnk[1].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\user\Cookies\user@atwola[1].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\user\Cookies\user@azjmp[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@belnk[1].txt Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\user\Cookies\user@bfast[1].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\user\Cookies\user@bluestreak[2].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\user\Cookies\user@bravenet[2].txt Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\user\Cookies\user@bs.serving-sys[1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\user\Cookies\user@burstnet[1].txt Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\user\Cookies\user@c.enhance[1].txt Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\user\Cookies\user@c.goclick[1].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Cookies\user@c3.gostats[2].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\user\Cookies\user@casalemedia[2].txt Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\user\Cookies\user@cassava[1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\user\Cookies\user@cgi-bin[3].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\user\Cookies\user@cgi-bin[9].txt Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\user\Cookies\user@clickbank[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@com[2].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\user\Cookies\user@ct.360i[2].txt Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\user\Cookies\user@data.coremetrics[1].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\user\Cookies\user@did-it[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@dist.belnk[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\user\Cookies\user@errorsafe[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\user\Cookies\user@fastclick[2].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Cookies\user@gostats[1].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\user\Cookies\user@go[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\user\Cookies\user@hitbox[2].txt Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\user\Cookies\user@hotlog[2].txt Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\user\Cookies\user@i.screensavers[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@image.checkmystats.com[2].txt Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\user\Cookies\user@landing.domainsponsor[1].txt Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\user\Cookies\user@linksynergy[1].txt Spyware:Cookie/Lop Not disinfected C:\Documents and Settings\user\Cookies\user@lop[1].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\user\Cookies\user@maxserving[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\user\Cookies\user@media.fastclick[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\user\Cookies\user@mediaplex[2].txt Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\user\Cookies\user@offeroptimizer[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\user\Cookies\user@overture[1].txt Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\user\Cookies\user@paypopup[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\user\Cookies\user@perf.overture[1].txt Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\user\Cookies\user@qksrv[2].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\user\Cookies\user@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\user\Cookies\user@realmedia[1].txt Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\user\Cookies\user@revenue[1].txt Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\user\Cookies\user@rn11[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\user\Cookies\user@searchportal.information[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@sel.as-eu.falkag[2].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\user\Cookies\user@serving-sys[2].txt Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\user\Cookies\user@spylog[2].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\user\Cookies\user@statcounter[2].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\user\Cookies\user@stats1.reliablestats[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\user\Cookies\user@statse.webtrendslive[2].txt Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\user\Cookies\user@targetnet[1].txt Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\user\Cookies\user@toplist[1].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\user\Cookies\user@tradedoubler[1].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\user\Cookies\user@trafficmp[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@uol.com[2].txt Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\user\Cookies\user@valueclick[1].txt Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\user\Cookies\user@weborama[1].txt Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\user\Cookies\user@webpower[2].txt Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\user\Cookies\user@winfixer[2].txt Spyware:Cookie/ademails Not disinfected C:\Documents and Settings\user\Cookies\user@www.ademails[2].txt Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\user\Cookies\user@www.advnt01[1].txt Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\user\Cookies\user@www.affiliatefuel[2].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\user\Cookies\user@www.burstbeacon[1].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\user\Cookies\user@www.errorsafe[1].txt Spyware:Cookie/Exitexchange Not disinfected C:\Documents and Settings\user\Cookies\user@www.exitexchange[1].txt Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\user\Cookies\user@www.intelli-tracker[1].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\user\Cookies\user@www.myaffiliateprogram[2].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\user\Cookies\user@xiti[1].txt Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\user\Cookies\user@xmts[2].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\user\Cookies\user@yadro[1].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\user\Cookies\user@z1.adserver[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Cookies\user@zedo[2].txt Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\sendtrustbarbonce\Anti Hole.exe Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\sendtrustbarbonce\Debug Team.exe Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\sendtrustbarbonce\Waybold.exe Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@247realmedia[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@888[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@ad.yieldmanager[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@adopt.hbmediapro[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@adrevolver[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@adrevolver[3].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@ads.pointroll[1].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@adultfriendfinder[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@advertising[1].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@apmebf[1].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@as-us.falkag[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@atdmt[2].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@atwola[1].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@azjmp[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@belnk[1].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@bluestreak[1].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@bravenet[2].txt Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@c.enhance[1].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@casalemedia[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@dist.belnk[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@doubleclick[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@fastclick[2].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@go[2].txt Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@i.screensavers[1].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@maxserving[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@mediaplex[1].txt Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@offeroptimizer[1].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@questionmarket[1].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@realmedia[2].txt Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@rn11[2].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@stats1.reliablestats[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@tribalfusion[1].txt Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@winfixer[2].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@xiti[1].txt Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Elhom\Cookies\elhom@xmts[2].txt Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-68d0d310-36675b2e.zip[GetAccess.class] Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-68d0d310-36675b2e.zip[Installer.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-68d0d310-36675b2e.zip[NewSecurityClassLoader.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-68d0d310-36675b2e.zip[NewURLClassLoader.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv566.jar-311ab963-69c65fda.zip[Matrix.class] Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv566.jar-311ab963-69c65fda.zip[Dummy.class] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\user\Cookies\user@112.2o7[2].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\user\Cookies\user@2o7[2].txt Spyware:Cookie/66.246.209 Not disinfected C:\Documents and Settings\user\Cookies\user@66.246.209[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Cookies\user@888[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Cookies\user@888[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Cookies\user@ad.yieldmanager[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\user\Cookies\user@adopt.hbmediapro[2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Cookies\user@adrevolver[1].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\user\Cookies\user@adrevolver[3].txt Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Cookies\user@ads.pointroll[1].txt Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\user\Cookies\user@adtech[2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Cookies\user@adultfriendfinder[1].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\user\Cookies\user@advertising[2].txt Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\user\Cookies\user@adviva[2].txt Spyware:Cookie/NewMedia Not disinfected C:\Documents and Settings\user\Cookies\user@anm.co[2].txt Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\user\Cookies\user@apmebf[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as-eu.falkag[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as-us.falkag[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@as1.falkag[2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\user\Cookies\user@atdmt[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@ath.belnk[1].txt Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\user\Cookies\user@atwola[1].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\user\Cookies\user@azjmp[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@belnk[1].txt Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\user\Cookies\user@bfast[1].txt Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\user\Cookies\user@bluestreak[2].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\user\Cookies\user@bravenet[2].txt Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\user\Cookies\user@bs.serving-sys[1].txt Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\user\Cookies\user@burstnet[1].txt Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\user\Cookies\user@c.enhance[1].txt Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\user\Cookies\user@c.goclick[1].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Cookies\user@c3.gostats[2].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\user\Cookies\user@casalemedia[2].txt Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\user\Cookies\user@cassava[1].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\user\Cookies\user@cgi-bin[3].txt Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\user\Cookies\user@cgi-bin[9].txt Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\user\Cookies\user@clickbank[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@com[2].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\user\Cookies\user@ct.360i[2].txt Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\user\Cookies\user@data.coremetrics[1].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\user\Cookies\user@did-it[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Cookies\user@dist.belnk[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\user\Cookies\user@errorsafe[1].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\user\Cookies\user@fastclick[2].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Cookies\user@gostats[1].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\user\Cookies\user@go[1].txt Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\user\Cookies\user@hitbox[2].txt Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\user\Cookies\user@hotlog[2].txt Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\user\Cookies\user@i.screensavers[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@image.checkmystats.com[2].txt Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\user\Cookies\user@landing.domainsponsor[1].txt Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\user\Cookies\user@linksynergy[1].txt Spyware:Cookie/Lop Not disinfected C:\Documents and Settings\user\Cookies\user@lop[1].txt Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\user\Cookies\user@maxserving[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\user\Cookies\user@media.fastclick[1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\user\Cookies\user@mediaplex[2].txt Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\user\Cookies\user@offeroptimizer[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\user\Cookies\user@overture[1].txt Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\user\Cookies\user@paypopup[2].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\user\Cookies\user@perf.overture[1].txt Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\user\Cookies\user@qksrv[2].txt Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\user\Cookies\user@questionmarket[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\user\Cookies\user@realmedia[1].txt Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\user\Cookies\user@revenue[1].txt Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\user\Cookies\user@rn11[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\user\Cookies\user@searchportal.information[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\user\Cookies\user@sel.as-eu.falkag[2].txt Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\user\Cookies\user@serving-sys[2].txt Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\user\Cookies\user@spylog[2].txt Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\user\Cookies\user@statcounter[2].txt Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\user\Cookies\user@stats1.reliablestats[2].txt Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\user\Cookies\user@statse.webtrendslive[2].txt Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\user\Cookies\user@targetnet[1].txt Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\user\Cookies\user@toplist[1].txt Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\user\Cookies\user@tradedoubler[1].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\user\Cookies\user@trafficmp[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\user\Cookies\user@tribalfusion[1].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Cookies\user@uol.com[2].txt Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\user\Cookies\user@valueclick[1].txt Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\user\Cookies\user@weborama[1].txt Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\user\Cookies\user@webpower[2].txt Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\user\Cookies\user@winfixer[2].txt Spyware:Cookie/ademails Not disinfected C:\Documents and Settings\user\Cookies\user@www.ademails[2].txt Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\user\Cookies\user@www.advnt01[1].txt Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\user\Cookies\user@www.affiliatefuel[2].txt Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\user\Cookies\user@www.burstbeacon[1].txt Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\user\Cookies\user@www.errorsafe[1].txt Spyware:Cookie/Exitexchange Not disinfected C:\Documents and Settings\user\Cookies\user@www.exitexchange[1].txt Spyware:Cookie/Intelli-tracker Not disinfected C:\Documents and Settings\user\Cookies\user@www.intelli-tracker[1].txt Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\user\Cookies\user@www.myaffiliateprogram[2].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\user\Cookies\user@xiti[1].txt Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\user\Cookies\user@xmts[2].txt Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\user\Cookies\user@yadro[1].txt Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\user\Cookies\user@z1.adserver[1].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\user\Cookies\user@zedo[2].txt Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7773431a.exe Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\bis21.exe Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\sta8.exe Adware:Adware/Lop Not disinfected C:\Program Files\Adverts\uninst.exe Adware:Adware/Comet Not disinfected C:\Program Files\Screensavers.com\Installer\bin\ScreensaversInst.dll Adware:Adware/Comet Not disinfected C:\Program Files\Screensavers.com\Installer\bin\siuninst.exe Spyware:Cookie/Hbmediapro Not disinfected C:\Program Files\SpyHunter\Backup\user@adopt.hbmediapro[1].txt.bak Spyware:Cookie/RealMedia Not disinfected C:\Program Files\SpyHunter\Backup\user@realmedia[1].txt.bak Spyware:Cookie/RealMedia Not disinfected C:\Program Files\SpyHunter\Backup\user@realmedia[2].txt.bak Spyware:Cookie/Rightmedia Not disinfected C:\Program Files\SpyHunter\Backup\user@rightmedia[2].txt.bak Virus:Trj/PasswordStealer.A Disinfected C:\WINDOWS\system32\gdiw2k.sys Virus:Trj/Downloader.IEZ Disinfected C:\WINDOWS\system32\msqdev.exe |
|
|
|
|
#4 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 36
OS: WinXP
|
HijackThis:
Logfile of HijackThis v1.99.1 Scan saved at 13:36:37, on 14/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\D-Tools\daemon.exe C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe C:\Program Files\Lexmark 6200 Series\lxbumon.exe C:\Program Files\Lexmark 6200 Series\ezprint.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\WINDOWS\system32\lxbucoms.exe C:\Program Files\Shareaza\Shareaza.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe C:\Program Files\FBM Software\ZeroSpyware Lite\ZeroSpyware Lite.exe C:\Documents and Settings\user\Desktop\HijackThis.exe C:\Program Files\Symantec\LiveUpdate\AUpdate.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [lxbumon.exe] "C:\Program Files\Lexmark 6200 Series\lxbumon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 6200 Series\ezprint.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LFM] C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe -t O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE O4 - HKCU\..\Run: [NetGuard Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe" -STARTUP O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/u...0/sdcregie.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094227271843 O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B3F8F451-788A-11D0-89D9-00A0C90C9B67} (MCSiTreeCtl Class) - http://activex.microsoft.com/controls/mcsi/mcsitree.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/...pcuploader.cab O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/game...ploader_v6.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe FindLop: [TRACE] Enumerating jobs and queues [TRACE] Activating job 'Norton AntiVirus - Scan my computer - user.job' [TRACE] Printing all job properties ApplicationName: 'C:\PROGRA~1\NORTON~1\Navw32.exe' Parameters: '/task:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"' WorkingDirectory: '' Comment: 'This is a schedule scan task from Norton AntiVirus.' Creator: 'user' Priority: NORMAL MaxRunTime: 259200000 (3d 0:00:00) IdleWait: 10 IdleDeadline: 60 MostRecentRun: 04/11/2006 20:00:00 NextRun: 04/14/2006 20:00:00 StartError: S_OK ExitCode: 0 Status: SCHED_S_TASK_READY ScheduledWorkItem Flags: DeleteWhenDone = 0 Suspend = 0 StartOnlyIfIdle = 0 KillOnIdleEnd = 0 RestartOnIdleResume = 0 DontStartIfOnBatteries = 0 KillIfGoingOnBatteries = 0 RunOnlyIfLoggedOn = 1 SystemRequired = 0 Hidden = 0 TaskFlags: 0 1 Trigger Trigger 0: Type: Weekly WeeksInterval: 1 DaysOfTheWeek: U.T..F. StartDate: 09/06/2004 EndDate: 00/00/0000 StartTime: 20:00 MinutesDuration: 0 MinutesInterval: 0 Flags: HasEndDate = 0 KillAtDuration = 0 Disabled = 0 [TRACE] Activating job 'Symantec NetDetect.job' [TRACE] Printing all job properties ApplicationName: 'C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE' Parameters: '' WorkingDirectory: 'C:\Program Files\Symantec\LiveUpdate' Comment: 'Symantec NetDetect' Creator: 'user' Priority: NORMAL MaxRunTime: 259200000 (3d 0:00:00) IdleWait: 10 IdleDeadline: 60 MostRecentRun: 04/14/2006 13:36:00 NextRun: 04/14/2006 17:37:00 StartError: S_OK ExitCode: 0 Status: SCHED_S_TASK_READY ScheduledWorkItem Flags: DeleteWhenDone = 0 Suspend = 0 StartOnlyIfIdle = 0 KillOnIdleEnd = 0 RestartOnIdleResume = 0 DontStartIfOnBatteries = 0 KillIfGoingOnBatteries = 0 RunOnlyIfLoggedOn = 1 SystemRequired = 0 Hidden = 0 TaskFlags: 0 1 Trigger Trigger 0: Type: Daily DaysInterval: 1 StartDate: 04/14/2006 EndDate: 00/00/0000 StartTime: 17:37 MinutesDuration: 1440 MinutesInterval: 240 Flags: HasEndDate = 0 KillAtDuration = 0 Disabled = 0 |
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2005
Posts: 3,065
OS: Windows XP
|
Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.
Please follow the instructions here to clear Sun Java's cache. Downloads(make sure to save these in a permanent location) Cleanup! (Alternate Link)- Install it. You will use this later. *NOTE* Cleanup deletes EVERYTHING out of temporary folders and does not make backups. I have attached a file to this post called eli.zip Download it to your desktop and unzip it. Double click on eli.reg and click yes when prompted to merge it into your registry. Next, please reboot your computer in SafeMode by doing the following:
Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs: Adverts Screensavers.com File and Folder Deletions Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist. C:\WINDOWS\GatorPdpLoudInstaller.log C:\Program Files\Adverts C:\Program Files\Screensavers.com Tools Open Cleanup! by double-clicking the icon on your desktop (or from Start > All Programs). Set the program up as follows: Click Options Move the slider button down to Custom CleanUp! Check the following:
Click OK, Press the CleanUp! button to start the program.If prompted to reboot, click Yes. Reboot your system in Normal Mode. Post a new Hijackthis log and let us know if there are any remaining issues. |
|
|
|
|
#6 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2005
Posts: 3,065
OS: Windows XP
|
Sorry for the inconvenience, it would appear that I forgot to attach the eli.zip file. It is attached to this post, download and unzip it then double click on Eli.reg and click Yes at the prompt
|
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: Dec 2005
Posts: 36
OS: WinXP
|
hi,I completed all the scans required.The problem i had with my InternetExplorer freezing has been fixed and i no longer get pop-ups(apart from the 1 or 2)...but i have noticed since the scans that my internetexplorer sometimes requires be to refresh the page 2-3 times for a website to come up...i wasnt sure if it was because of my internet connection because other progrmas such as yahoo messenger and msn messenger that require internet connection work well....below is a new HijackThis log:
Logfile of HijackThis v1.99.1 Scan saved at 19:47:16, on 19/04/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\ewido\security suite\ewidoctrl.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\D-Tools\daemon.exe C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe C:\Program Files\Lexmark 6200 Series\lxbumon.exe C:\Program Files\Lexmark 6200 Series\ezprint.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe C:\Program Files\Winamp\winampa.exe C:\WINDOWS\system32\lxbucoms.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Shareaza\Shareaza.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\LimeWire\LimeWire.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\user\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/...arch.yahoo.com O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [lxbumon.exe] "C:\Program Files\Lexmark 6200 Series\lxbumon.exe" O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 6200 Series\ezprint.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LFM] C:\PROGRA~1\LEAPFR~1\LeapFrogMessenger.exe O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Program Files\VideoraiPodConverter\VideoraiPodConverter.exe -t O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE O4 - HKCU\..\Run: [NetGuard Lite] "C:\Program Files\FBM Software\ZeroSpyware Lite\NetGuard Lite.exe" -STARTUP O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {0CFA086E-6336-4D95-B6AA-90F564E99631} (TNSClicker.Clicker) - http://www.shopandscan.com/TNSClicker.CAB O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamps.com/download/u...0/sdcregie.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094227271843 O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B3F8F451-788A-11D0-89D9-00A0C90C9B67} (MCSiTreeCtl Class) - http://activex.microsoft.com/controls/mcsi/mcsitree.cab O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yaho...tocomplete.cab O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/...pcuploader.cab O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD 2002\InstFred.ocx O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://static.photobox.co.uk/sg/common/uploader.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/game...ploader_v6.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxbu_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbucoms.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2005
Posts: 3,065
OS: Windows XP
|
The problem you are describing does not sound like a malware issue. One source of that problem may be Cleanup! Your browser commonly stores a local copy of a webpage in a cache so that it loads faster the next time you visit the same site. Cleanup! cleared out this cache so some pages may load slower than you are used to whiule the cache is rebuilt.
Your log appears to be clean. If you still have any problems let me know and we will work on diagnosing those through other means. If not, there are just a few more things to go through to finish this off and help prevent future infections. Please post one more time even if you have no problems so we can mark this thread as resolved. Disabling the Viewing of Hidden and System Files
Setting a new Restore Point Go to Start >> Run - type control sysdm.cpl,,4 & press Enter.
Windows Update Make sure to get the latest updates for Windows and Internet Explorer at Microsoft Update Site. Prevention A good virus scanner is a necessity in today's computer environment. Many virus scanners include active components that protect you from infection without even running a scan. Some good free antivirus programs include: AVG Free Avast! Home Edition (Antivirus & Firewall) AntiVir A firewall is the first line of defense standing between the internet and your computer. Some good free firewalls are: Zone Alarm Outpost Tiny Personal Firewall Sunbelt Kerio Personal Firewall Adaware SE and Spybot SD are a pair of anti-spyware scanners that should be run every week or two. Although there is some overlap there are many pieces of malware that is caught by one of these and not the other, therefore it is recommended you use both to compliment each other. Spybot also contains two other useful pieces. The first is "Immunize", this helps protect your computer against known exploits. The second is "TeaTimer", with this feature enabled you will receive notifications of all changes to the registry such as programs adding themselves to start-up and you default search page being changed. Spyware Blaster is a powerful tool that prevents "drive-by" downloads and other unwanted installations. It also uses no system resources, run it once and you're all set. Spyware Guard Is a realtime protection engine to guard your computer from spyware. This program does for spyware what an antivirus program does for viruses. IE-Spyad is a program that only needs to be run once to protect you from many malicious sites. It adds domains of known adware companies into the Restricted List of Internet Explorer, preventing them from performing malicious actions on your PC. The MVPS HOSTS file is a file you can download and use to replace your regular hosts file. It prevents many sites from performing malicious actions by blocking the sites from ever being accessed. Together these programs form a powerful barrier between the Internet and your computer. However, all the programs stand alone and feel free to eliminate any you are not comfortable with. Any protection you add to your PC is better than no protection at all. Alternative Programs Here are some alternatives that are either less suceptible than others to malware or don't contain malware where similar programs do. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN) Desktop Weather - Free taskbar weather program that is free, malware free, and resource light. Firefox - This is an increasingly popular alternate browser. Whilst Internet Explorer is not a bad browser, almost every exploit crafted is targeted to take advantage of an IE weakness. Sun's Java - It's much more secure than Microsoft's Java Virtual Machine. |
|
|
| Thread Tools | |
|
|