Unsolved
This post is more than 5 years old
20 Posts
0
2343
October 13th, 2007 19:00
Major problems.........Hope that I did this correctly!
Hi all,
I am having some major spyware issues on my system.
I need some assistance in removing these.
I am hopeing that someone out there can help me with this issue.
I went to frys and they told me to install trend micro internet security pro, so I did that.
They also told me to install spy sweeper, but it either will not let me install it (comes up with errors, or when I try to scan the system, it gives me a windows needs to close error).
There are enormous ammounts of pop ups coming up, only now they are blocked, but I also have this little exclamation point triangle thing in my task bar that keeps flashing, then a little bubble window pops up telling me differnt things everytime. for example, the one that is up now tells me that there is a trojan, click on the exclamation point to download software to cure it.
Also, in my uninstall log, there are programs in there that I have never seen before and they do not give me the option to uninstall them.
There is a Security Toolbar 7.1 at the top of my internet/windows window that i did not install either.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:28:52 PM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Scan saved at 1:28:52 PM, on 10/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
E:\RCDMENU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ISM2\ISMPack6.exe
C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFCommander.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
E:\RCDMENU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qzphupwz.dll
O4 - HKLM\..\Run: [AS00_Netgear] "C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe" -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\ddsvnuxt.dll",sitypnow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe"
O4 - HKCU\..\Run: [TrendSecure Remote File Lock] "C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe"
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Transaction Protector - {E7620C98-FCCC-40E5-92EC-C7685D2E1E40} - C:\Program Files\Trend Micro\TrendSecure\TransactionProtector\TSToolbar.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\qzphupwz.dll
O4 - HKLM\..\Run: [AS00_Netgear] "C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe" -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\ddsvnuxt.dll",sitypnow
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe"
O4 - HKCU\..\Run: [TrendSecure Remote File Lock] "C:\Program Files\Trend Micro\TrendSecure\RemoteFileLock\FLMain.exe"
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
--
End of file - 7467 bytes
End of file - 7467 bytes
No Events found!


Bugbatter
4 Apprentice
•
20.5K Posts
0
October 13th, 2007 20:00
I am reviewing your log.
In the meantime, you can help me by doing the following:
* Please let me know if you have posted this log on another forum.
* I will not handle your log if you are using any cracked software, so if you are, either remove it, or repost your log in a New Message so that someone else will have the option of continuing with it.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple, file sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
Since I find the nature of P2P programs counter productive to restoring your PC to a healthy state, please remove all P2P file sharing programs prior to my providing you with malware removal assistance.
* Please let me know if you are an employee and this system is owned by your employer. If so, do you have permission to make changes to it?
* Please print or copy all instructions to Notepad in order to assist you when carrying out instructions.
In some cases you may be working in Safemode and you will not have the internet available to read information. Please follow all instructions in sequence.
* If your reply does not fit in one post, please reply to yourself until all text is submitted. It may take several posts.
What type of anti-virus and anti-spyware were you using prior to buying TrendMicro IS?
Morse01
20 Posts
0
October 14th, 2007 00:00
No viruses were detected in memory.
Your computer is free of known threats. Virus Detection does not check compressed files.
Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.
No viruses were detected in memory.
Your computer is free of known threats. Virus Detection does not check compressed files.
Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.
Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.
Warning! The scan detected a virus that is active in your computer's memory.The scan ended to prevent further infection.
You should shut down your computer immediately and restart it with an antivirus rescue disk or similar tool.
No viruses were detected in memory.
Morse01
20 Posts
0
October 14th, 2007 00:00
Bugbatter
4 Apprentice
•
20.5K Posts
0
October 14th, 2007 00:00
"Will I need my copy of Windows XP to do this?"
So far, I'd say, no, you won't need it, but I cannot guarantee that. It depends on how things go.
Let's get started. First we will look for the infection. After your next post we will clean the malware.
Please download SmitfraudFix (by S!Ri) to your Desktop.
Double-click Smitfraudfix.exe
Select option #1 - Search by typing 1 and press " Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
IMPORTANT: Do NOT run any other options until you are asked to do so!
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool";
it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm
Morse01
20 Posts
0
October 14th, 2007 00:00
Message Edited by Morse01 on 10-13-2007 06:56 PM
Bugbatter
4 Apprentice
•
20.5K Posts
0
October 14th, 2007 02:00
Please delete Smitfraud Fix. Please download a new copy and try again. Thanks.
Bugbatter
4 Apprentice
•
20.5K Posts
0
October 14th, 2007 03:00
Morse01
20 Posts
0
October 14th, 2007 03:00
I tried to uninstall the smitfraudfix, but I can not locate it??
Morse01
20 Posts
0
October 14th, 2007 03:00
Morse01
20 Posts
0
October 14th, 2007 03:00
Bugbatter
4 Apprentice
•
20.5K Posts
0
October 14th, 2007 03:00
"Please download SmitfraudFix (by S!Ri) to your Desktop."
Morse01
20 Posts
0
October 14th, 2007 03:00
Bugbatter
4 Apprentice
•
20.5K Posts
0
October 14th, 2007 18:00
Let's give Super AntiSpyware a run in the meantime.
Download and scan with SUPERAntiSpyware Free for Home Users
Let me know how things are running at that point.
Morse01
20 Posts
0
October 15th, 2007 03:00
Morse01
20 Posts
0
October 15th, 2007 04:00
http://www.superantispyware.com
Trace Rules Database Version: 1325
Total Scan Time : 02:11:42
Memory threats detected : 4
Registry items scanned : 5914
Registry threats detected : 40
File items scanned : 82633
File threats detected : 72
C:\WINDOWS\SYSTEM32\VTSQR.DLL
C:\WINDOWS\SYSTEM32\VTSQR.DLL
HKLM\Software\Classes\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}\InprocServer32
HKCR\CLSID\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C2BD68AC-1FDE-495A-B11D-6A21B96F547C}
C:\WINDOWS\SYSTEM32\NNNOOOL.DLL
C:\WINDOWS\SYSTEM32\NNNOOOL.DLL
HKLM\Software\Classes\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}\InprocServer32
HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{89AD4D75-2429-462e-BD4E-443F233F6033}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{89AD4D75-2429-462e-BD4E-443F233F6033}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\nnnoool
HKCR\CLSID\{178D4E6A-BA5A-4ECB-8521-F7B8393FDB97}
HKCR\CLSID\{89AD4D75-2429-462E-BD4E-443F233F6033}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
C:\WINDOWS\SYSTEM32\DDCYVTT.DLL
C:\WINDOWS\SYSTEM32\GEBBYYW.DLL
C:\WINDOWS\SYSTEM32\LJJHGED.DLL
C:\WINDOWS\SYSTEM32\EULNXWOT.DLL
C:\WINDOWS\SYSTEM32\EULNXWOT.DLL
C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
[ISMPack6] C:\PROGRAM FILES\ISM2\ISMPACK6.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8FB5B012-E8CB-46cd-B6D2-ED428FAE9043}
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{11B97CF9-C40E-4127-801D-0FE00EB35705}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013708.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013709.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP95\A0013714.DLL
C:\WINDOWS\Prefetch\ISMPACK6.EXE-0C8D659D.pf
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\QZPHUPWZ.DLL
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKU\S-1-5-21-1993962763-813497703-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKU\S-1-5-21-1993962763-813497703-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{11A69AE4-FBED-4832-A2BF-45AF82825583}
C:\Documents and Settings\Morse Family\Cookies\morse family@ad.yieldmanager[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@mediaplex[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@mdlfr[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@media.adrevolver[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@casalemedia[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@fastclick[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@doubleclick[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@login.tracking101[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@da-tracking[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@adopt.euroclick[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@mediatraffic[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@trafficmp[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@tribalfusion[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@franceguide[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@atdmt[2].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@www.mediatraffic[1].txt
C:\Documents and Settings\Morse Family\Cookies\morse family@campagnes[1].txt
C:\Documents and Settings\Justin\Cookies\justin@3.adbrite[1].txt
C:\Documents and Settings\Justin\Cookies\justin@4.adbrite[2].txt
C:\Documents and Settings\Justin\Cookies\justin@ad.adnetinteractive[2].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.adbrite[2].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.awesomehouseparty[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.cartoonnetwork[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.gamesbannernet[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.glispa[2].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.newgrounds[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.pokemoncrater[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.surfnetkids[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ads.toonamijetstream[1].txt
C:\Documents and Settings\Justin\Cookies\justin@banners.battleon[2].txt
C:\Documents and Settings\Justin\Cookies\justin@drivecleaner[1].txt
C:\Documents and Settings\Justin\Cookies\justin@e-2dj6wjl4sndpmdo.stats.esomniture[2].txt
C:\Documents and Settings\Justin\Cookies\justin@e-2dj6wjmisgdzckp.stats.esomniture[2].txt
C:\Documents and Settings\Justin\Cookies\justin@eas.apm.emediate[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ehg-informative.hitbox[2].txt
C:\Documents and Settings\Justin\Cookies\justin@ehg-legonewyorkinc.hitbox[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ehg-veohnetworksinc.hitbox[1].txt
C:\Documents and Settings\Justin\Cookies\justin@ehg-yahoo.hitbox[1].txt
C:\Documents and Settings\Justin\Cookies\justin@eyewonder[1].txt
C:\Documents and Settings\Justin\Cookies\justin@r-kimedia.co[1].txt
C:\Documents and Settings\Justin\Cookies\justin@stats.gamestop[1].txt
C:\Documents and Settings\Justin\Cookies\justin@www.drivecleaner[2].txt
C:\Documents and Settings\Justin\Cookies\justin@www6.addfreestats[1].txt
HKCR\BndDrive2.Band
HKCR\BndDrive2.Band\CLSID
HKCR\BndDrive2.Band\CurVer
HKCR\BndDrive2.Band.1
HKCR\BndDrive2.Band.1\CLSID
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\APPLICATION DATA\SETUP_EN[1].EXE
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2B.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2C.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2D.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2E.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO2F.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO30.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO31.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO32.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO33.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO34.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO35.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO36.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO37.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO38.TMP
C:\DOCUMENTS AND SETTINGS\MORSE FAMILY\LOCAL SETTINGS\TEMP\ICO39.TMP
C:\SYSTEM VOLUME INFORMATION\_RESTORE{DAC31502-EA13-48E0-949D-CD252EAC7D6C}\RP102\A0015153.EXE