Unsolved
This post is more than 5 years old
41 Posts
0
1598
November 23rd, 2006 19:00
can anyone help me please remove Win32/Adware.WhenU.SaveNow application
Guys, i just got a new computer and i am usin nod32 full edition antivirus, i have spybot destroy and defend, i have lavasof adaware se, i have zonealarm pro edition, and for some reason when i scanned my computer with nod32 it found this Win32/Adware.WhenU.SaveNow application infectin two of my registry files. It didnt give me any options except to leave it alone, so i dont know what to do..
i am pannickin cause this is a new computer, very expensive...
please please if anyone can help, that would be great thank you!!
i am pannickin cause this is a new computer, very expensive...
please please if anyone can help, that would be great thank you!!
No Events found!


1972vet
3.3K Posts
0
November 23rd, 2006 23:00
eTrust
Trend Micro Anti-Spyware for the Web
Panda SpyXposer
Webroot Spy Audit
Snowboarder1714
41 Posts
0
November 24th, 2006 01:00
Message Edited by Snowboarder1714 on 11-23-200609:23 PM
Snowboarder1714
41 Posts
0
November 24th, 2006 04:00
Snowboarder1714
41 Posts
0
November 24th, 2006 04:00
Incident Status Location
Spyware:Cookie/Go Reported C:\Documents and Settings\Anyone\Cookies\anyone@go[2].txt
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[.atwola.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[.bravenet.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[.toplist.cz/]
Spyware:Cookie/Adserver Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[adserver.filefront.com/]
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[.maxserving.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[searchportal.information.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-10.txt[.fortunecity.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.realmedia.com/]
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.atwola.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.bravenet.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.toplist.cz/]
Spyware:Cookie/Adserver Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[adserver.filefront.com/]
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.maxserving.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[searchportal.information.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-11.txt[.fortunecity.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.realmedia.com/]
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.atwola.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.bravenet.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.toplist.cz/]
Spyware:Cookie/Adserver Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[adserver.filefront.com/]
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.maxserving.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[searchportal.information.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-12.txt[.fortunecity.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.realmedia.com/]
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.atwola.com/]
Spyware:Cookie/did-it Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.did-it.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.toplist.cz/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.bravenet.com/]
Spyware:Cookie/Adserver Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[adserver.filefront.com/]
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.maxserving.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[searchportal.information.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-13.txt[.fortunecity.com/]
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[.atwola.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[.realmedia.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[searchportal.information.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[.toplist.cz/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[.bravenet.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies-6.txt[.fortunecity.com/]
Spyware:Cookie/2o7 Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.atwola.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/PointRoll Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Falkag Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Belnk Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Com.com Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.com.com/]
Spyware:Cookie/did-it Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.did-it.com/]
Spyware:Cookie/FortuneCity Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Maxserving Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/QuestionMarket Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Traffic Marketplace Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Tribalfusion Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Yadro Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Adserver Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Searchportal Reported C:\Documents and Settings\Jonathan Rogel\Application Data\Mozilla\Firefox\Profiles\4vcv8hww.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Toplist Reported C:\Documents and Settings\Jonathan Rogel\Cookies\jonathan rogel@toplist[1].txt
Virus:mIRC/Gen Reported C:\Program Files\hix\aliases.ini
Virus:Application/MotherboardMonitor.A Reported C:\Program Files\hix\mem.dll
Virus:Application/MotherboardMonitor.A Reported C:\Program Files\hix\moo.dll
Virus:Application/MotherboardMonitor.A Reported C:\Program Files\hix\scripts\systeminfo\moo.dll
Virus:Application/MotherboardMonitor.A Reported C:\Program Files\mIRC\mem.dll
Virus:Application/MotherboardMonitor.A Reported C:\Program Files\mIRC\moo.dll
Snowboarder1714
41 Posts
0
November 24th, 2006 04:00
1972vet
3.3K Posts
0
November 24th, 2006 13:00
I was looking for any of them to find the Win32/Adware.WhenU.SaveNow and I see, none of them did. I now strongly suspect the finding from Nod32 was a false positive. You DO have the option of asking that software vendor about the problem as well. When any application designed to flag problem software finds anything deemed a "False Positive" it is usually talked about on their help form or through their own support communications with their customers. You can research that at your own liesure. Meanwhile, lets get rid of the problems you DO have:
Please download Ad-Aware SE Personal Edition 1.06 and install it. If you already have version 1.06, please configure it as indicated below. If you have a previous version of Ad-Aware, please uninstall your current version and install the newest version SE 1.06.
1) Run Ad-Aware, and click Check for updates now.
2) Select Configurations (click the Gear wheel at the top) as follows:
- General Button > Safety & Settings: Check (Green) all three.
- Tweak Button > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
Click Proceed.3) To start the scan, Click > "Scan Now" at left
- Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
- Select "Search for low-risk threats"
- Select "Perform full system scan"
- Click Next
4) When the scan has completed, select Next.Next, please download and scan with AVG Anti-Spyware v7.5
( This is Ewido 4.0 renamed. If you already have Ewido installed, please update to this version which has a special "clean driver" for removing persistent malware)
- After download, double click on the file to launch the install process.
- Choose a language, click "OK" and then click "Next".
- Read the "License Agreement" and click "I Agree".
- Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
- After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
- The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
- Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.mscOnce the updates are installed do the following:
Click on the " Scanner" button and choose the " Settings" tab.
Close the application and reboot the computer into Safe mode. Once in safe mode continue with the instructions below:
Open the AVG Anti-Spyware application and click the " Scan" tab.
Click " Complete System Scan" to start.
Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection.
Note: If AVG Anti-Spyware "crashes" or "hangs" during the scan, try scanning again by doing this:
- Scan one sector of the system at a time by using the "Custom Scan" feature. To do this select Scanner > Custom Scan and click on Add drive/directory/file. Browse to C:\Windows > System, add this folder to the list and click on "Start Scan". When the scan is complete, repeat the Custom Scan but this time, browse to and add the System32 folder. Then keep repeating this procedure until all your folders have been scanned. Make sure you include the Documents & Settings folder.
- If this still does not help, then turn the ADS scanner off while making a Custom Scan. To do this select Scanner > Scan Settings and untick "Scan in NTFS Alternate Data Streams". Then repeat the steps above for performing a Custom Scan.
When the scan has finished you will be presented with a list of infected objects found. Click " Apply all actions" to place the files in Quarantine.IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate " No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?
Click on " Save Report" to view all completed scans. Click on the most recent scan you just performed and select " Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
Exit AVG Anti-Spyware when done. Reboot back to your normal user mode.
Please perform this online scan: F-Secure Online Scanner Next Generation Beta
1. Click on the link " F-Secure Online Scanner Next Generation Beta".
2. You may receive an alert on the address bar at this point to install the ActiveX control.
3. Click on that alert and then Click Insall ActiveX component.
4. Read the license agreement and click " Accept".
5.Click " Custom Scan" and be sure the following are checked:
- Scan whole System
- Scan all files
- Scan whole system for rootkits
- Scan whole system for spyware
- Scan inside archives
- Use advanced heuristics
6. When the scan completes, click the " I want to decide item by item" button.7. For each item found, Select " Disinfect" and click " Next".
8. When done, click the " Show Report" button, then copy and paste the entire report into your next reply along with the AVG Anti-Spyware scan log and a fresh HijackThis log. Thanks!
Snowboarder1714
41 Posts
0
November 24th, 2006 21:00
turn off restore points, boot, turn them back on.
i didnt do that, because i trust you guys more, because i was helped about 4 months ago and it was very nice, and you guys seem much capable of knowing what to do..
do you think i should do that, because these are the infected files
C:\System Volume Information\_restore{0CD024A4-8E43-4FB2-8E36-470466DF6455}\RP24\A0014007.exe »NSIS »BSplayer_WhenUSave_InstallerInst.exe - Win32/Adware.WhenU.SaveNow application
C:\System Volume Information\_restore{0CD024A4-8E43-4FB2-8E36-470466DF6455}\RP24\A0014008.exe »NSIS »SetupInst.exe - Win32/Adware.WhenU.SaveNow application
and this is waht he told me Anything in C:\System Volume Information is in restore points and not active
If the procedure is followed then the old infected restore points are cleared and a new one is set
so what do you think, by the way, i ran everything you siad, and i ran spybot a couple of times, and it cleaned minor tihngs. :]
tell me what u think of the information the other guy gave me.
Snowboarder1714
41 Posts
0
November 24th, 2006 21:00
here is the f-secure scan and the hijackthis log.
Scanning Report
Friday, November 24, 2006 16:48:48 - 18:04:15
Computer name: JON
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
Result: 1 malware found
W32/Multidrp.GB (virus)
* C:\Documents and Settings\All Users\Application Data\AOL Downloads\triton_suite_install_6.0.28.1\ampx.exe (Submitted)
Statistics
Scanned:
* Files: 221641
* System: 4539
* Not scanned: 76
Actions:
* Disinfected: 0
* Renamed: 0
* Deleted: 0
* None: 1
* Submitted: 1
Files not scanned:
Options
Scanning engines:
* F-Secure Libra: 2.4.2, 2006-11-24
* F-Secure AVP: 7.0.171, 2006-11-24
* F-Secure Orion: 1.2.37, 2006-11-24
* F-Secure Blacklight: 1.0.31, 0000-00-00
* F-Secure Draco: 1.0.35, 0260-02-44
* F-Secure Pegasus: 1.19.0, 2006-08-29
Scanning options:
* Scan all files
* Scan inside archives
* Use Advanced heuristics
HIJACKTHIS LOG :
Logfile of HijackThis v1.99.1
Scan saved at 6:05:35 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.warezfaw.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
1972vet
3.3K Posts
0
November 24th, 2006 22:00
In your case, this issue has been relatively minor...just an adware infection that is not so critical that we need to remove the restore points. The reason we frown on removing restore points for a user even though you will see it recommended by most well respected antivirus vendors is because an infected restore point is better than no restore point. If the computer will not perform properly and you want to restore to some point in time, having followed those recommendations you might just be seeing red one day.
On to your present log:
The program ViewPoint View Manager is Foistware.
You probably did not intend to download this program...more than likely it was forced upon you, bundled with some other download. To remove it, click start-->control panel-->add/remove programs.
Scroll down the list to locate the program name, click on it to highlight it, then click Remove. Reboot the computer when the uninstallation completes.
It is also noted that you are running more than one antivirus in real time. Running more than one antivirus application on board in real time will actually reduce your level of protection. You also run the risk of data loss from a system crash that the instability can cause...and I also see by your log that you already have had some crash issues in the past.
In the event that some malware makes it's way to your hard disk, each antivirus application will wrestle over "access" rights to the offender and will want to zip the file and arrest the application.
This struggle will (in theory) continue infinitely which can culminate in a complete system crash.
Please decide which antivirus application to keep and uninstall the other. Most probably you paid for the Nod32. Since the AVG antivirus is free, consider uninstalling that one. Please remember that the AVG antivirus is separate from the AVG Anti-Spyware. Don't uninstall that...you can keep that and use it as an on demand scanner.
Please run HijackThis again and check the following:
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O4 - HKLM\..\Run: C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: %systemroot%\system32\dumprep 0 -u
Close all windows now except HijackThis, then click "Fix Checked".
Locate and delete the following folder/file indicated in Bold text:
C:\Program Files\Viewpoint\ Viewpoint Manager\ViewMgr.exe
Reboot and post a new HijackThis log. Please advise how the computer is running and if you are having any other issues. Thanks!
Snowboarder1714
41 Posts
0
November 24th, 2006 23:00
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
i scanned with hijack this 3 times, 'fixing' that one 3 times, and it still comes back. and thats about it, here is the hijack this log the newest one:
Logfile of HijackThis v1.99.1
Scan saved at 8:33:29 PM, on 11/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\nvraidservice.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDCountdown\LCDCountdown.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDPop3\LCDPOP3.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.warezfaw.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
the one last thign is i want you to tell me, how i can make my internet fast, is there a way from the computer that i have to do something, and i want to get rid of all the things i dont need, files and folders of old stuff that i deleted but are still on, and just things i dont want/need, that will help make my computer faster, and more reliable. Also what antivirus firewall, and other programs like antispyware, and adaware removers, do you recomend for me to have, so i can have my computer safe and working well?
1972vet
3.3K Posts
0
November 25th, 2006 00:00
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.
Run HijackThis again and check this:
O2 - BHO: (no name) - {348FE907-249E-4C65-A838-F34A193FE1D1} - (no file)
Again, close all windows then click "Fix Checked".
Reboot. Run Spybot S&D again and re-enable your TeaTimer.
Quote::
i want to get rid of all the things i dont need, files and folders of old stuff that i deleted but are still on, and just things i dont want/need, that will help make my computer faster, and more reliable.
At the bottom of my signature block, you'll see the two graphics for "Unite" and "ASAP"...just beneath that is the instruction "Click when things go wrong". Click that link and scroll down that list to find your guidance...follow those instructions from there.
Also what antivirus firewall, and other programs like antispyware, and adaware removers, do you recomend for me to have, so i can have my computer safe and working well?
The antivirus software and firewall you have are fine. For your antispyware/adware software use the free downloads I already recommeded.
Now that your system is clean, let's create a new restore point.
Please click "Start > Programs > Accessories > System Tools > System Restore"
In the new window, check the 'Create a restore point' in the right pane and click "Next".
In the "Restore point description" textbox, name your restore point to something you will easily recognize. I recommend something like yyyymmdd_Clean (ex. 20060101_Clean)
Click "Create" and reboot your computer.
In the future, there are some things you can do to prevent spyware infections:
Install the following freeware programs:
SpywareGuard
Spywareblaster
Keep your anti-virus and spyware definitions up to date. Be sure to scan often.
Stay updated with the most recent Windows patches using
Microsoft's Windows Update.
If you still wish to use Internet Explorer in the future for any surfing, please make sure you install SpywareBlaster (from above) to protect you from most ActiveX infections.
Run CCleaner often. Download the Basic or Slim version unless you WANT the Yahoo Toolbar.
Or if you just want to run your on board Disk Cleanup ("Start > Programs > Accessories > System Tools > Disk Cleanup" ), just open the utility and check off the following:
Downloaded Program Files, Temporary Internet Files, Recycle Bin, and Temporary Files
So how did I get infected in the first place?
Regards, and Happy Surfing!
Snowboarder1714
41 Posts
0
November 25th, 2006 01:00
1972vet
3.3K Posts
0
November 25th, 2006 03:00
What is the Resident TeaTimer?
The Resident TeaTimer is a new tool of Spybot-S&D which perpetually monitors the processes called/initiated. It immediately detects known malicious processes wanting to start and terminates them giving you some options how to deal with this process in the future: You can set TeaTimer to:
- be informed, when the process tries to start again
- automatically kill the process
- or generally allow the process to run There is also an option to delete the file associated with this process.
In addition, TeaTimer detects, when something wants to change some critical registry keys This is the reason that the HijackThis entry you tried to delete kept coming back. When you use HijackThis to remove an entry, you are actually editing the Registry in a sense. The TeaTimer application will prevent HijackThis from removing the Registry entry if the user is unfamiliar with it's use. Typically, a HijackThis analyst will have the user disable any protective software such as this before any fix is attempted...and that's fine. I just prefer not to disable any protective software until it proves to be a hindrance. Some users know and understand the reasons for their protective software intervening and they know how to answer. I just prefer to err on the side of caution. It harms nothing to leave the protective software to run while the user attempts to follow the posted "Fix" instructions. However, disabling it prematurely puts the user at a slight risk of further infection. As in this case, the only down side to that practice is that it requires the extra post instruction to disable the protection in order to complete the fix. I don't mind at all having to post one extra step as we did. I'd rather you keep your protection active until you understand the need to disable it. TeaTimer can protect you against such changes again giving you an option: You can either "Allow" or "Deny" the change. As TeaTimer is always running in the background, it takes some resources of about 5 MB.
1972vet
3.3K Posts
0
November 25th, 2006 03:00
Both have moderators who are available around the clock...so you shouldn't have to wait long for your answer.
Snowboarder1714
41 Posts
0
November 25th, 2006 03:00