Unsolved

This post is more than 5 years old

24 Posts

1727

March 7th, 2007 02:00

Application freezing and slow in opening log included

I hope you can help i have downloaded and used hijack this here is my log file. I cannot run either msn messenger or yahoo messenger both freeze. There are a few other programs that just sort of hang there and takes a long time to open.
Logfile of HijackThis v1.99.1
Scan saved at 11:54:37 PM, on 3/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Aliant\Aliant Security Services\fws.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Windows\Java.exe
C:\Program Files\Aliant\Servicepoint\ASA.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Java Plugins] C:\Windows\Java.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.phreik.com/controls/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6179812F-D2EF-4762-B667-0BAD7A7BB5DA}: NameServer = 142.177.1.2 142.177.129.11
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

I have run anti virus and spyware both have found nothing. Thanks in advance Oceanview

Message Edited by Oceanview on 03-06-2007 10:18 PM

Message Edited by Oceanview on 03-06-2007 10:27 PM

10.4K Posts

March 7th, 2007 12:00

Oceanview

You have an unusual file I'd like to have checked please. It's a legit file name, but it's in the wrong location which is suspicious.
When you Submit it that it is the file in the location listed

Please upload this file to Jotti's Online Virus Scan
  • C:\Windows\Java.exe

  • Click " Browse" at the top of the page
    - Navigate to (Locate using windows explorer)

    • C:\Windows\Java.exe

    - Click " Open" Then the "Submit" and let the scan finish
    - Scroll down to the bottom of the page to find the results
    - Copy/paste the results in your next reply.

Using Windows Explorer (direections if needed)
  • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
  • And one question; have you downloaded any Java plug-ins for Firefox?
    bamajim   Graduate of MRU

     

    24 Posts

    March 7th, 2007 14:00

    I got this report at the bottom of the page. I hope this is the correct scan for my computer. From what i am reading none of it looks good! As for a java update in firefox I am not totally sure if i did or not. I did update java just dont know which one it was for internet explorer or firefox. Scan taken on 07 Mar 2007 17:53:14 (GMT) AntiVir Found nothing ArcaVir Found Trojan.Spy.Keylogger.Az Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Spy.Win32.KeyLogger.az Fortinet Found nothing Kaspersky Anti-Virus Found Trojan-Spy.Win32.KeyLogger.az NOD32 Found nothing Norman Virus Control Found W32/Keylog.BKG Panda Antivirus Found nothing VirusBuster Found TrojanSpy.KeyLogger.KL VBA32 Found nothing Message Edited by Oceanview on 03-07-2007 11:52 AM

    Message Edited by Oceanview on 03-07-2007 11:57 AM

    10.4K Posts

    March 7th, 2007 15:00

    Oceanview

    Need you to help us out with a little research please

    Download Suspicious File Packer from here.

    Unzip it to your desktop. Open it and copy and paste in this list of files below
    When it has created the archive on your desktop please upload that to the forum here.

    C:\Windows\Java.exe

    Here are the directions for uploading the file:

    Just click "New Topic", fill in the needed details and post a link to your thread here. Click the "Browse" button. Navigate to the file on your computer. When the file is listed in the window click "Post" to upload the file.

    Be sure you post the link to this thread in that topic.

    When done, then reply and we will start the cleanup :smileyhappy:
     
    Thanks
     
    bamajim   Graduate of MRU

     

    24 Posts

    March 7th, 2007 16:00

    I have done as requested and posted in above link hope you can help me thanks in advance Oceanview

    10.4K Posts

    March 7th, 2007 17:00

    Oceanview

    Thanks for your help :smileyhappy:

    1. Please download the Killbox.
    • 1)Save it to the desktop and run it.
      2) Select " Delete on Reboot", and then select "All files".
      3) Copy the file names below to the clipboard by highlighting them and pressing Control-C:

      • C:\Windows\Java.exe

      4) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
      5) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.  Click " No" at the Pending Operations prompt.
    2. Rerun Hijackthis (scan only) and place checks beside the following entries
    • O4 - HKLM\..\Run: [Java Plugins] C:\Windows\Java.exe
      O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - (no file)
    Close all other open windows except Hijackthis and Select " Fix checked"

    Close Hijackthis->>Reboot your PC->>Rerun Hijackthis and post a fresh Hijackthis log
     
    bamajim   Graduate of MRU
     

    24 Posts

    March 7th, 2007 18:00

    ok i have done all that was requested here is my log file
     
    Logfile of HijackThis v1.99.1
    Scan saved at 4:05:45 PM, on 3/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Aliant\Aliant Security Services\fws.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Command Software\dvpapi.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\UPHClean\uphclean.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\WINDOWS\stsystra.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Aliant\Servicepoint\ASA.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll
    O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.phreik.com/controls/msnchat45.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
     
    unfortunately these steps did not fix the problems i am having with msn messenger and yahoo messenger.  I was hoping it would of but alas it did not.  I dont know if you can help with that but what is happening is I can sign on both but when i go to anything (minimize, click contact name, ect) else it freezes.  Thanks for all the help
    Oceanview

    10.4K Posts

    March 7th, 2007 18:00

    Oceanview

    I'm not sure if removing the infection will resolve your concern with messenger, but we need to get the PC clean from infection

    1. Go here and Download AVG Anti-Spyware
    ( 30 day free trial version) Save it to Your Desktop
     
    Double Click AVG Anti-Spyware-setup
    (It will create its own folder)
    Once the program starts You will be at the Status menu
    • Under "Your computers Security"
      Click Update now (next to last update)
      After the update loads
      Under Automatic updates Uncheck download and install updates automatically(recommended)
      (you can always select maual updates the next day)
    At the top toolbar Click Scanner Then the settings tab
    • Under How to act? Set default action for detected malwareTo Quarantine
      Under how to scan All boxes should be checked
      Under Possibly unwanted software All boxes should be checked
      Under reports Select Automatically generate report after every scan
      Uncheck Only if threats were found
      Under what to scan Scan every file should be highlited
    Exit AVG (But do not run it yet)

    Reboot into Safe Mode
    This can be done by
    • Restart your PC, and after it starts, but before you see the Windows Splash screen
      Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
      Use your arrow keys and select Safe Mode and then Enter
    Run AVG Anti-Spyware
    • Click scanner
      Select Complete system scan
    Once the scan finishes
    • Select Apply all actions (The items found will be quarantined)
      Click save report as (Another window will open)
      Save it to your desktop
      (By default It will be saved in the AVG folder as)
      C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
    Exit AVG
     
    Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
    • Double click the report-scan txt. you saved to your desktop
      It will open in Notepad
      Copy and paste that report as a reply to this thread
    Your reply should include
    • a fresh Hijackthis log
      your report_scan.txt log from AVG
        bamajim   Graduate of MRU

         

        24 Posts

        March 7th, 2007 19:00

        i sure do hope i have done this right here is the report for avg. AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 5:47:48 PM 3/7/2007 + Scan result: C:\Program Files\Video ActiveX Object -> Adware.Generic : No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.Generic : No action taken. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : No action taken. :mozilla.148:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.247realmedia : No action taken. :mozilla.149:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.247realmedia : No action taken. :mozilla.293:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.300:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.335:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.400:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.406:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.408:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.456:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.484:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.506:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.607:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.692:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.73:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.74:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.75:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.76:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.789:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.78:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.79:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.80:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.81:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.82:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.83:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.84:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.85:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\The Burtons\Cookies\the burtons@2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\The Burtons\Cookies\the burtons@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. :mozilla.366:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.367:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.373:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.384:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.385:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.324:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adtech : No action taken. :mozilla.326:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Adtech : No action taken. :mozilla.322:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.323:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.325:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.327:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.328:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.62:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\The Burtons\Cookies\the burtons@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. :mozilla.630:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Bfast : No action taken. :mozilla.563:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken. :mozilla.639:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken. :mozilla.232:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.233:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.234:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.37:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.38:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.39:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.40:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.41:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.42:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.43:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.44:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.45:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.634:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Clickbank : No action taken. :mozilla.381:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Clickhype : No action taken. :mozilla.30:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.395:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken. :mozilla.396:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken. :mozilla.397:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken. :mozilla.398:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Cpvfeed : No action taken. :mozilla.46:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken. :mozilla.49:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt ->

        24 Posts

        March 7th, 2007 19:00

        and now the hijackthing report Logfile of HijackThis v1.99.1 Scan saved at 5:54:16 PM, on 3/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Aliant\Aliant Security Services\fws.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Command Software\dvpapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\UPHClean\uphclean.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Aliant\Servicepoint\ASA.exe C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Dell Support\DSAgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.phreik.com/controls/msnchat45.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{6179812F-D2EF-4762-B667-0BAD7A7BB5DA}: NameServer = 142.177.1.2 142.177.129.11 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe Thanks once again for all the help Oceanview

        Message Edited by Oceanview on 03-09-2007 10:25 AM

        24 Posts

        March 7th, 2007 19:00

        Part 2 TrackingCookie.Euroclick : No action taken. :mozilla.50:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.51:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.52:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.211:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.217:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.218:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.116:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.117:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.118:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.119:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.120:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.635:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken. :mozilla.356:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.357:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.358:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.483:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.690:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.525:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Hotlog : No action taken. :mozilla.467:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Information : No action taken. :mozilla.115:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.496:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken. :mozilla.516:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Onestat : No action taken. :mozilla.517:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Onestat : No action taken. :mozilla.518:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Onestat : No action taken. :mozilla.268:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.270:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.271:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.272:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.555:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.556:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.557:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.558:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.47:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.48:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.668:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. :mozilla.466:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revenue : No action taken. :mozilla.135:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.136:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.137:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.138:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.139:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.140:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.382:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.613:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.614:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.615:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.616:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.617:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.768:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.526:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Spylog : No action taken. :mozilla.100:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.101:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.102:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.103:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.104:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.105:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.106:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.107:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.108:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.97:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.98:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.99:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.463:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.464:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.465:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.769:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.770:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.771:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.772:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.773:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.774:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.253:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.61:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.721:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.722:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.723:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.724:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.725:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.726:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.444:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Weborama : No action taken. :mozilla.413:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken. :mozilla.524:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yadro : No action taken. :mozilla.368:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.369:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.370:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.371:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.372:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.376:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.130:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.131:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.132:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.133:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.134:C:\Documents and Settings\The Burtons\Application Data\Mozilla\Firefox\Profiles\xgwvqj4c.default\cookies.txt -> TrackingCookie.Zedo : No action taken. ::Report end

        10.4K Posts

        March 7th, 2007 20:00


        Oceanview

        Close, but not quite. Your AVG log shows this
        • C:\Program Files\Video ActiveX Object -> Adware.Generic : No action taken.

        When it should say Quarantined

        Recheck the settings and Rerun AVG. The critical ones are below in red

        Open AVG Anti Spyware
        At the top toolbar Click Scanner Then the settings tab

        Under How to act? Set default action for detected malwareTo Quarantine

        Run AVG Anti-Spyware

        Click scanner
        Select Complete system scan
        Once the scan finishes

        Select Apply all actions (The items found will be quarantined)
        Click save report as (Another window will open)
        Save it to your desktop

        It is not necessary for you to repost the results again, just post one or 2 lines so I can see that the settings are correct.

        And you will need to repost your Hijackthis log it's jumbled up again :smileywink:
         
        bamajim   Graduate of MRU
         

        10.4K Posts

        March 7th, 2007 20:00

         



        Message Edited by bamajim on 03-07-2007 04:16 PM

        24 Posts

        March 7th, 2007 22:00

        here is the hijackthis file

        Logfile of HijackThis v1.99.1
        Scan saved at 8:33:37 PM, on 3/7/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Aliant\Aliant Security Services\fws.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\Common Files\Command Software\dvpapi.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\UPHClean\uphclean.exe
        C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        C:\WINDOWS\stsystra.exe
        C:\WINDOWS\System32\DLA\DLACTRLW.EXE
        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
        C:\Program Files\Aliant\Servicepoint\ASA.exe
        C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\Dell Support\DSAgnt.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.ca.dell.com/content/default.aspx?c=ca&l=en&s=gen
        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row-rel&channel=ca&ibd=5061213
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Aliant\Aliant Security Services\pkR.dll
        O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Aliant\Aliant Security Services\FBHR.dll
        O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
        O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [ASA.exe] "C:\Program Files\Aliant\Servicepoint\ASA.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: Digital Line Detect.lnk = ?
        O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab55579.cab
        O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.phreik.com/controls/msnchat45.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{6179812F-D2EF-4762-B667-0BAD7A7BB5DA}: NameServer = 142.177.1.2 142.177.129.11
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Aliant Security Services Personal Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\Aliant\Aliant Security Services\fws.exe
        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

        In this preview of the message the log looks right lets hope its still is right when i submit the post!

        Message Edited by Oceanview on 03-07-2007 06:34 PM

        24 Posts

        March 7th, 2007 22:00

        AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 8:39:04 PM 3/7/2007 + Scan result: Ok I think i got that part corrected. C:\Program Files\Video ActiveX Object -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2583130195-954403614-1304302529-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-2583130195-954403614-1304302529-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.IntCodec : Cleaned with backup (quarantined). C:\Documents and Settings\The Burtons\Cookies\the burtons@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\The Burtons\Cookies\the burtons@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\The Burtons\Cookies\the burtons@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned

        Message Edited by Oceanview on 03-08-2007 01:41 PM

        24 Posts

        March 8th, 2007 22:00

        Sorry to bother you guys but how long does it take to get a reply? It is now 24 hours since last post. Thanks Oceanview
        No Events found!

        Top