Unsolved
This post is more than 5 years old
13 Posts
0
2404
December 24th, 2006 14:00
Win32/Hostblock
i have etrust anitvirus which informed me i am infected with Win32/Hostblock but it can't cure it. my computer is running slow and my task manager is disabled. below is my log and an error i receieved from Hijack This:
An unexpected error has occurred at procedure: modMain_CheckOther1Item()
Error #75 - Path/File access error
Please email me at merijn@spywareinfo.com, reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible
Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1
This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
Logfile of HijackThis v1.99.1
Scan saved at 11:02:56 AM, on 12/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Adelphia HSAgent\bin\tgcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\smss.exe
C:\WINDOWS\dsrss.exe
C:\WINDOWS\ieredir.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: ib2.CBrowserHelper - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\system32\ib14.dll
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [tgcmd] "c:\Program Files\Adelphia HSAgent\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\WINDOWS\ieredir.exe
O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://smiley-associates.no-ip.info/Remote/msrdp.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
An unexpected error has occurred at procedure: modMain_CheckOther1Item()
Error #75 - Path/File access error
Please email me at merijn@spywareinfo.com, reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible
Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1
This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
Logfile of HijackThis v1.99.1
Scan saved at 11:02:56 AM, on 12/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Adelphia HSAgent\bin\tgcmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\smss.exe
C:\WINDOWS\dsrss.exe
C:\WINDOWS\ieredir.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: ib2.CBrowserHelper - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\system32\ib14.dll
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [tgcmd] "c:\Program Files\Adelphia HSAgent\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\WINDOWS\ieredir.exe
O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://smiley-associates.no-ip.info/Remote/msrdp.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
No Events found!


1972vet
3.3K Posts
0
December 25th, 2006 15:00
The file smss.exe is a process that is part of the Microsoft Windows Operating System called "Session Manager Subsystem"...hence the name smss...that file is a vital core file that is an integral and necessary part of the os when it is located here:
C:\Windows\System32\smss.exe
...and I'm certain you have that same file located right where it is supposed to be.
However, the file:
C:\WINDOWS\smss.exe
...is the trojan TROJ_NETZZAK.B
which I'm sure is responsible for the various other trojans your system is infected with.
Download Sysclean Package & save it to your desktop.
- Create a new folder on drive "C:\" and rename it Sysclean - (C:\Sysclean).
- Place the sysclean.com inside that folder.
- Then download the latest Virus Pattern Files - (Pattern files are usually named lptxxx.zip, where xxx is the pattern file number)
- Extract the lptxxx.zip pattern file into the same folder you created for and placed sysclean.com. (Click here for information on how to extract a file if your not sure how to do this. DO NOT scan yet.
Reboot your computer in SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".Note: Some anti-virus programs such as Avast will alert you to a virus attack when running sysclean so it's best to disable them before going to the next step.
Scan with Sysclean as follows:
- Open the Sysclean folder and double-click on sysclean.com to start the scanning process.
- Put a check mark on the "Automatically clean or delete infected files" option by clicking in the checkbox.
- Click the Advanced >> button.
- The scan options appear. Select the "Scan all local fixed drives".
- Click the "Scan button" on the Trend Micro System Cleaner console.
- It will take some time to complete. Be patient and let it clean whatever it finds.
- Another MS-DOS window appears containing the log file generated in the System Cleaner folder.
- To view the log, click the "View button" on the Trend Micro System Cleaner console. The Trend Micro Sysclean Package - Log window appears.
- The Files Detected section shows the viruses that were detected by System Cleaner.
- The Files Clean section shows the viruses that were cleaned.
- The Clean Fail section shows the viruses that were not cleaned.
- Exit when done, reboot normally and re-enable your anti-virus program.
This tool generates a log file (sysclean.log) in the same folder where the scan is completed. When using Sysclean its best to use the Administrator's account or an account with Administrative rights otherwise you will not have the rights to scan some locations. The scanning process may result in "Access Denied" messages for some files. This is normal because these files are protected by the system.Next, Please download the KILLBOX, extract it to your desktop.
Open killbox.exe. First click on Tools-->Delete Temp Files. A box will open with a list of all user profiles.
Check the following boxes at a minimum for each profile by clicking on the drop down and checking the boxes that are enabled. Some will not apply and those boxes will not be available to check. Make sure you do this for all the profiles listed.
Temporary Internet Files
Temp Files
XP Prefetch
If you want to clean your cookies, history, and list of recent files run you may check those boxes as well. Next, click on the Button titled "Delete Selected Temp Files".
Exit by clicking the Button titled "Exit(Save Settings)".
Once back into the main killbox program, check the box Delete on Reboot.
Highlight the entries below in Bold text and then copy them.
C:\WINDOWS\smss.exe
C:\WINDOWS\dsrss.exe
C:\WINDOWS\ieredir.exe
C:\WINDOWS\system32\ib14.dll
C:\WINDOWS\winlogon.exe
C:\Windows\System32\hkcALL.dll
Then in killbox click File-->Paste from Clipboard. Click the "All Files" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes.
A second message will ask to Reboot now? you will need to click No for now.
Note: Killbox will let you know if a file does not exist.
If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until you've completed the instructions below.
Please run HijackThis again and check the following entries that may still exist:
The entry below represents a KeyLogger trojan. You should change ALL OF YOUR PASSWORDS after removal and contact your bank and credit card companies if you indeed do your banking online.
O2 - BHO: ib2.CBrowserHelper - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\system32\ib14.dll
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O4 - HKLM\..\Run: C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: dsrss.exe
O4 - HKLM\..\Run: C:\WINDOWS\ieredir.exe
O4 - HKLM\..\Run: C:\WINDOWS\winlogon.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
Reboot the computer and post back a fresh HijackThis log along with the log from your TrendMicro scan. Thanks!
linzfluttery
13 Posts
0
December 25th, 2006 17:00
Logfile of HijackThis v1.99.1
Scan saved at 2:51:33 PM, on 12/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adelphia HSAgent\bin\tgcmd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Nikon\NkView5\NkvMon.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\LINDSE~1\LOCALS~1\Temp\Temporary Directory 1 for KillBox.zip\KillBox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\CA\SHARED~1\SCANEN~1\InoDist.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: ib2.CBrowserHelper - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\system32\ib14.dll (file missing)
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [tgcmd] "c:\Program Files\Adelphia HSAgent\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\WINDOWS\ieredir.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://smiley-associates.no-ip.info/Remote/msrdp.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
here is the sysclean log:
/--------------------------------------------------------------\
| Trend Micro System Cleaner |
| Copyright 2006, Trend Micro, Inc. |
| http://www.antivirus.com |
\--------------------------------------------------------------/
2006-12-25, 12:53:10, Auto-clean mode specified.
2006-12-25, 12:53:10, Running scanner "C:\Sysclean\TSC.BIN"...
2006-12-25, 12:53:49, Scanner "C:\Sysclean\TSC.BIN" has finished running.
2006-12-25, 12:53:49, TSC Log:
Damage Cleanup Engine (DCE) 3.98(Build 1012)
Windows XP(Build 2600: Service Pack 2)
Start time : Mon Dec 25 2006 12:53:10
Load Damage Cleanup Template (DCT) "C:\Sysclean\tsc.ptn" (version 818) [success]
WORM_SDBOT.TL[virus found]
-->delete registry data("HKEY_USERS",".DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run","winusb32.exe") success
-->delete registry data("HKEY_USERS",".DEFAULT\Software\Microsoft\Windows\CurrentVersion\Runonce","winusb32.exe") success
WORM_CARPET.A[virus found]
-->delete registry data("HKEY_LOCAL_MACHINE","Software\Microsoft\Windows\CurrentVersion\Run","C:\WINDOWS\winlogon.exe") success
Complete time : Mon Dec 25 2006 12:53:49
Execute pattern count(3024), Virus found count(2), Virus clean count(2), Clean failed count(0)
2006-12-25, 14:00:04, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 12:56:49
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean
C:\Documents and Settings\Administrator\Desktop\bkup\backup-20040920-131329-306.dll [TROJ_BRISS.A]
C:\Old HD\WINDOWS\SYSTEM\ezStub3.dll [TROJ_Generic]
C:\Old HD\WINDOWS\SYSTEM\setup_incred_7.exe [TROJ_KEENVAL.E]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP783\A0274644.exe [TROJ_VB.BFG]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP785\A0276841.exe [TROJ_VB.BFG]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277767.dll [TROJ_BRISS.A]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277768.dll [TROJ_Generic]
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277769.exe [TROJ_KEENVAL.E]
C:\WINDOWS\commando.exe [TROJ_HIDERUN.A]
C:\WINDOWS\dsrss.exe [TROJ_VB.BFH]
C:\WINDOWS\ieredir.exe [TROJ_BRIZ.H]
C:\WINDOWS\preredir.exe [TROJ_VB.BFG]
C:\WINDOWS\smss.exe [TSPY_STERS.BD]
C:\WINDOWS\SYSTEM32\awtsqnl.dll [TROJ_Generic]
C:\WINDOWS\SYSTEM32\awvtrom.dll [TROJ_Generic]
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\ldr32a[1].exe [TROJ_Generic]
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\silent[1].exe [TROJ_Generic]
C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts [TROJ_QHOST.BN]
C:\WINDOWS\SYSTEM32\exdl.exe [PE_Generic]
C:\WINDOWS\SYSTEM32\ib14.dll [TROJ_Generic]
C:\WINDOWS\SYSTEM32\ldr32a.exe [TROJ_Generic]
C:\WINDOWS\SYSTEM32\pmkjjij.dll [TROJ_Generic]
94097 files have been read.
94097 files have been checked.
84213 files have been scanned.
126978 files have been scanned. (including files in archived)
22 files containing viruses.
Found 22 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:00:04
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:00:04, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 12:56:49
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean
Success Clean [ TROJ_BRISS.A]( 1) from C:\Documents and Settings\Administrator\Desktop\bkup\backup-20040920-131329-306.dll
Success Clean [ TROJ_Generic]( 1) from C:\Old HD\WINDOWS\SYSTEM\ezStub3.dll
Success Clean [ TROJ_KEENVAL.E]( 1) from C:\Old HD\WINDOWS\SYSTEM\setup_incred_7.exe
Success Clean [ TROJ_VB.BFG]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP783\A0274644.exe
Success Clean [ TROJ_VB.BFG]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP785\A0276841.exe
Success Clean [ TROJ_BRISS.A]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277767.dll
Success Clean [ TROJ_Generic]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277768.dll
Success Clean [ TROJ_KEENVAL.E]( 1) from C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP786\A0277769.exe
Success Clean [ TROJ_HIDERUN.A]( 1) from C:\WINDOWS\commando.exe
Success Clean [ TROJ_VB.BFH]( 1) from C:\WINDOWS\dsrss.exe
Success Clean [ TROJ_BRIZ.H]( 1) from C:\WINDOWS\ieredir.exe
Success Clean [ TROJ_VB.BFG]( 1) from C:\WINDOWS\preredir.exe
Success Clean [ TSPY_STERS.BD]( 1) from C:\WINDOWS\smss.exe
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\awtsqnl.dll
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\awvtrom.dll
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\6JYLAZOX\ldr32a[1].exe
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\O9YJK1IJ\silent[1].exe
Success Clean [ TROJ_QHOST.BN]( 1) from C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\ib14.dll
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\ldr32a.exe
Success Clean [ TROJ_Generic]( 1) from C:\WINDOWS\SYSTEM32\pmkjjij.dll
94097 files have been read.
94097 files have been checked.
84213 files have been scanned.
126978 files have been scanned. (including files in archived)
22 files containing viruses.
Found 22 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:00:04 1 hour 3 minutes 5 seconds (3785.06 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:00:04, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 12:56:49
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=C:\Sysclean
94097 files have been read.
94097 files have been checked.
84213 files have been scanned.
126978 files have been scanned. (including files in archived)
22 files containing viruses.
Found 22 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:00:04 1 hour 3 minutes 5 seconds (3785.06 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:00:04, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
2006-12-25, 14:01:59, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 14:00:05
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean
1051 files have been read.
1051 files have been checked.
951 files have been scanned.
963 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:01:59
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:01:59, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 14:00:05
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean
1051 files have been read.
1051 files have been checked.
951 files have been scanned.
963 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:01:59 1 minute 45 seconds (104.92 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:01:59, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 12/25/2006 14:00:05
VSAPI Engine Version : 8.000-1001
VSCANTM Version : 1.1-1001
Virus Pattern Version : 141 (146983 Patterns) (2006/12/25) (414100)
Command Line: C:\Sysclean\VSCANTM.BIN /NBPM /S /CLEANALL /DCEGENCLEAN /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 E:\*.* /P=C:\Sysclean
1051 files have been read.
1051 files have been checked.
951 files have been scanned.
963 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 12/25/2006 14:01:59 1 minute 45 seconds (104.92 seconds) has elapsed.
---------*---------*---------*---------*---------*---------*---------*---------*
2006-12-25, 14:01:59, Scanner "C:\Sysclean\VSCANTM.BIN" has finished running.
1972vet
3.3K Posts
0
December 25th, 2006 22:00
Open a blank Notepad. Save the command below in Bold text in the blank Notepad as a text file so that you can copy/paste it because we will be booting into safe mode later on during this fix and you will not be able to read these instructions from your browser.
"%userprofile%\desktop\combofix.exe" /wow
After you've created and saved your notepad from the instruction above, please download AVG Anti-Spyware v7.5
( This is Ewido 4.0 renamed. If you already have Ewido installed, please update to this version which has a special "clean driver" for removing persistent malware)
- After download, double click on the file to launch the install process.
- Choose a language, click "OK" and then click "Next".
- Read the "License Agreement" and click "I Agree".
- Accept default installation path: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5, click "Next", then click "Install".
- After setup completes, click "Finish" to start the program automatically or launch AVG Anti-Spyware by double-clicking its icon on your desktop or in the system tray.
- The main "Status" menu will appear. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
- Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
Go to Start > Run and type: services.mscOnce the updates are installed do the following:
Click on the " Scanner" button and choose the " Settings" tab.
Close the application and reboot the computer into Safe mode. Once in safe mode continue with the instructions below:
Open the notepad you saved earlier in the instruction.
Go to start-->run and copy/paste the data you saved in notepad, into the run box and click "OK".
When finished, it will produce a log for you. Save it and post that log in your next reply.
Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.
Open the AVG Anti-Spyware application and click the " Scan" tab.
Click " Complete System Scan" to start.
Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection.
Note: If AVG Anti-Spyware "crashes" or "hangs" during the scan, try scanning again by doing this:
- Scan one sector of the system at a time by using the "Custom Scan" feature. To do this select Scanner > Custom Scan and click on Add drive/directory/file. Browse to C:\Windows > System, add this folder to the list and click on "Start Scan". When the scan is complete, repeat the Custom Scan but this time, browse to and add the System32 folder. Then keep repeating this procedure until all your folders have been scanned. Make sure you include the Documents & Settings folder.
- If this still does not help, then turn the ADS scanner off while making a Custom Scan. To do this select Scanner > Scan Settings and untick "Scan in NTFS Alternate Data Streams". Then repeat the steps above for performing a Custom Scan.
When the scan has finished you will be presented with a list of infected objects found. Click " Apply all actions" to place the files in Quarantine.IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate " No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?
Click on " Save Report" to view all completed scans. Click on the most recent scan you just performed and select " Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\
Exit AVG Anti-Spyware when done.
Please run HijackThis again and check the following:
O2 - BHO: ib2.CBrowserHelper - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - C:\WINDOWS\system32\ib14.dll (file missing)
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O4 - HKLM\..\Run:
C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: dsrss.exe
O4 - HKLM\..\Run: C:\WINDOWS\ieredir.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
Close all windows except for the HijackThis application window
then click Fix Checked.
Locate and delete the following files indicated in Bold text if present:
C:\WINDOWS\system32\ ib14.dll
C:\WINDOWS\ smss.exe
C:\WINDOWS\ dsrss.exe
C:\WINDOWS\ ieredir.exe
C:\Windows\System32\ hkcALL.dll
Reboot back to your normal user mode and post back the following:
ComboFix log
AVG Ant-Spyware log
Fresh HijackThis log
Also, please advise how the computer is running now and if you are having any other issues. Thanks!
linzfluttery
13 Posts
0
December 27th, 2006 12:00
Lindsey Eve - 06-12-26 22:16:41.29 Service Pack 2
ComboFix 06.12.01W - Running from: "C:\Documents and Settings\Lindsey Eve\desktop"
Command switches used :: /wow
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\drivers\fad.sys
((((((((((((((((((((((((((((((( Files Created from 2006-11-26 to 2006-12-26 ))))))))))))))))))))))))))))))))))
2006-12-26 22:27d-------- C:\WINDOWS\erdnt
2006-12-26 21:09 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2006-12-26 21:09d-------- C:\Program Files\Grisoft
2006-12-25 14:34d-------- C:\!KillBox
2006-12-25 12:44d--h----- C:\WINDOWS\PIF
2006-12-25 12:44d-------- C:\Sysclean
2006-12-24 11:16d-------- C:\Program Files\SmartFTP Client 2.0 Setup Files
2006-12-24 11:16d-------- C:\Program Files\SmartFTP Client 2.0
2006-12-24 11:01d-------- C:\hijackthis
2006-12-24 10:54 239,442 --a------ C:\HjThis.exe
2006-12-17 22:51d-------- C:\WINDOWS\Prefetch
2006-12-17 21:14dr-h----- C:\Documents and Settings\Lindsey Eve\Recent
2006-12-17 21:03d-------- C:\Program Files\CCleaner
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-26 22:01 -------- d-------- C:\Program Files\WindowsSA
2006-12-25 12:50 -------- d-------- C:\Program Files\Trillian
2006-12-24 11:17 -------- d-------- C:\Documents and Settings\Lindsey Eve\Application Data\SmartFTP
2006-12-22 20:51 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-12-17 03:02 -------- d-------- C:\Program Files\Internet Explorer
2006-12-17 03:01 -------- d-------- C:\Program Files\Outlook Express
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-11-17 03:02 -------- d-------- C:\Program Files\MSXML 4.0
2006-11-08 00:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-10-19 08:56 713216 --a------ C:\WINDOWS\SYSTEM32\sxs.dll
2006-10-13 07:35 142336 --a------ C:\WINDOWS\SYSTEM32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"Dell AIO Printer A920"="\"C:\\Program Files\\Dell AIO Printer A920\\dlbkbmgr.exe\""
"Realtime Monitor"="C:\\PROGRA~1\\CA\\ETRUST~1\\realmon.exe -s"
"BJCFD"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\\Program Files\\Google\\Gmail Notifier\\G001-1.0.25.0\\gnotify.exe"
"tgcmd"="\"c:\\Program Files\\Adelphia HSAgent\\bin\\tgcmd.exe\" /server /startmonitor /deaf "
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Picasa Media Detector"="C:\\Program Files\\Picasa2\\PicasaMediaDetector.exe"
"Microsoft Windows Session Manager Subsystem"="C:\\WINDOWS\\smss.exe"
"WinSysModule"="dsrss.exe"
"IE Redir"="C:\\WINDOWS\\ieredir.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,80,00,00,00,00,00,00,00,00,02,00,00,c2,01,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Win32 USB2 Driver"="svchosting.exe"
"Micro Update"="dailin.exe"
"System Startup"="voltio.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"Win32 USB2 Driver"="svchosting.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Win32 USB2 Driver"="svchosting.exe"
"Micro Update"="dailin.exe"
"System Startup"="voltio.exe"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"Win32 USB2 Driver"="svchosting.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{502BE9D3-2022-4D6A-3982-BBE8F19B00CC}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"mtklefa"="{2FB0149F-E1D3-4739-809D-4E58659CF2DE}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\America Online 9.0 Tray Icon.lnk"
"backup"="C:\\WINDOWS\\pss\\America Online 9.0 Tray Icon.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\AMERIC~1.0\\aoltray.exe -check"
"item"="America Online 9.0 Tray Icon"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sonic RecordNow!]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AOL ACS"=dword:00000002
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Windows Update.job
Completion time: 06-12-26 22:28:48.60
C:\ComboFix.txt ... 06-12-26 22:28
linzfluttery
13 Posts
0
December 27th, 2006 12:00
Logfile of HijackThis v1.99.1
Scan saved at 9:03:12 AM, on 12/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [tgcmd] "c:\Program Files\Adelphia HSAgent\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\WINDOWS\ieredir.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://smiley-associates.no-ip.info/Remote/msrdp.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
1972vet
3.3K Posts
0
December 27th, 2006 15:00
- Click Start.
- Open My Computer.
- Select the Tools menu and click Folder Options.
- Select the View Tab.
- Under the Hidden files and folders heading select
- Show hidden files and folders.
- Uncheck the Hide protected operating system files
- (recommended) option.
- Click Yes to confirm.
- Click OK.
Next, please click start-->SearchWhen the search window opens, click the "All files and folders" link from the left pane.
Then, enter userinit.exe in the "all or part of the file name" box at the top. Scroll down to the "Look in" box and click the drop down arrow. Select your Local Hard Drive. Scroll down a bit more and click the "More advanced options". Make sure these three are checked:
Search system folders
Search hidden files and folders
Search subfolders
Then click the Search button at the bottom.
Does the search results yield the file at the following file path?:
C:\windows\system32\userinit.exe
If it does then skip the instruction to copy that file from the "C:\windows\ServicePackFiles\i386\userinit.exe" location:
Copy the file userinit.exe from the following cache
If your search does not show the file userinit.exe in the C:\Windows\System32 folder then please do the following...
Right-click on the file userinit.exe and select "Copy".
and right click anywhere in the blank area of the folder (look for a blank space at the bottom of that folder) and select "Paste".
Reboot the computer into Safe mode.
Look to see if your eTrust antivirus application is running in safe mode. If it is, please disable it for this fix. Once you reboot back to your normal user mode, it should be re-enabled.
Please run HijackThis again and check the following:
O2 - BHO: (no name) - {53502e0f-386e-4f30-b92b-7bf306ea7f12} - (no file)
O4 - HKLM\..\Run: C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: dsrss.exe
O4 - HKLM\..\Run: C:\WINDOWS\ieredir.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} - http://www.mt-download.com/MediaTicketsInstaller.cab
O20 - Winlogon Notify: hkcALL - hkcALL.dll (file missing)
O21 - SSODL: mtklefa - {2FB0149F-E1D3-4739-809D-4E58659CF2DE} - (no file)
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
Locate and delete the following fiels/folders indicated in Bold text:
C:\Program Files\ WindowsSA
C:\WINDOWS\ smss.exe
C:\WINDOWS\ dsrss.exe
C:\WINDOWS\ ieredir.exe
C:\WINDOWS\ winlogon.exe
Next, please click start-->Search
When the search window opens, click the "All files and folders" link from the left pane.
Then, enter hkcALL.dll in the "all or part of the file name" box at the top. Scroll down to the "Look in" box and click the drop down arrow. Select your Local Hard Drive. Scroll down a bit more and click the "More advanced options". Make sure these three are checked:
Search system folders
Search hidden files and folders
Search subfolders
Then click the Search button at the bottom.
Delete all instances found.
Boot back to your normal user mode and:
Please perform a scan with F-Secure Online Scanner
Follow the directions in the F-Secure page for proper Installation.
1. Click on the link " F-Secure Online Scanner".
2. You may receive an alert on the address bar at this point to install the ActiveX control.
3. Click on that alert and then click " Insall ActiveX component".
4. Read the license agreement and click " Accept".
5. Click " Custom Scan" and be sure the following are checked:
- Scan whole System
- Scan all files
- Scan whole system for rootkits
- Scan whole system for spyware
- Scan inside archives
- Use advanced heuristics
6. When the scan completes, click the " I want to decide item by item" button.7. For each item found, Select " Disinfect" and click " Next".8. When done, click the " Show Report" button, then copy and paste the entire report into your next reply along with a fresh HijackThis log. Thanks!
linzfluttery
13 Posts
0
January 5th, 2007 19:00
1972vet
3.3K Posts
0
January 5th, 2007 20:00
linzfluttery
13 Posts
0
January 5th, 2007 23:00
Logfile of HijackThis v1.99.1
Scan saved at 7:30:53 PM, on 1/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\notepad.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [tgcmd] "c:\Program Files\Adelphia HSAgent\bin\tgcmd.exe" /server /startmonitor /deaf
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView5\NkvMon.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - https://smiley-associates.no-ip.info/Remote/msrdp.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
1972vet
3.3K Posts
0
January 6th, 2007 02:00
Scroll down to Windows Logon Process Service and right click on it.
Click Properties and under Service Status click Stop, then under Startup Type change it to Disabled.
Delete the Service
Open HijackThis and click Open the Misc Tools section then click--> Delete an NT service.
In the Delete window, type MSWinLogonProcService and press OK.
OK any prompts, close HijackThis, and restart your computer.
Open HijackThis and choose "Do a system scan only" then check the box in front of this entry:
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
Close all windows now except for HijackThis. Click Fix Checked.
Locate and delete the following file indicated in Bold text ( be very careful not to delete the item in the C:\WINDOWS\System32\ folder...that one is fine. The bad item will be only in the C:Windows\ ):
C:\WINDOWS\ winlogon.exe
Reboot and post a fresh HijackThis log. How's the computer running now?
linzfluttery
13 Posts
0
January 6th, 2007 16:00
Open HijackThis and choose "Do a system scan only" then check the box in front of this entry:
O23 - Service: Windows Logon Process Service (MSWinLogonProcService) - Unknown owner - C:\WINDOWS\winlogon.exe" -service (file missing)
that entry is not there.
the computer appears to be running ok at the moment except for i have been unable to download the etrust updates and my windows security thing repeatedly tells me that it is out of date.
1972vet
3.3K Posts
0
January 6th, 2007 17:00
Open HijackThis. Click--> Open the Misc Tools section--> Open Uninstall Manager...--> Save list... and save the list to your Desktop.
Post that list back here along with the AVG scan log.
Is eTrust a Security Suite that is provided by your ISP? If so, what I would like you to consider is uninstalling the security suite you have and installing one of the applications available on the public domain. If you would be intersted, please indicate so in your next reply and I will supply links to the free software. Thanks!
linzfluttery
13 Posts
0
January 8th, 2007 00:00
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:08:04 PM 1/7/2007
+ Scan result:
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278220.dll -> Adware.Aws : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278213.dll -> Adware.BiSpy : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278214.DLL -> Adware.BiSpy : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278207.exe -> Adware.BlazeFind : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278208.dll -> Adware.BlazeFind : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278209.exe -> Adware.BlazeFind : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278210.dll -> Adware.BlazeFind : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278211.exe -> Adware.BlazeFind : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278205.dll -> Adware.CashBack : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278215.dll -> Adware.EliteBar : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278218.exe -> Adware.F1Organizer : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278216.dll -> Adware.MediaTickets : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278212.dll -> Adware.Midaddle : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278219.exe/Save.exe -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278219.exe/SaveUninst.exe -> Adware.SaveNow : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278206.dll -> Adware.WurldMedia : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278198.exe -> Backdoor.Hupigon.hk : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278202.0xe -> Backdoor.Rbot.15 : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278199.0xe -> Downloader.Agent.f : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278197.0ll -> Downloader.BHO.d : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278201.0xe -> Downloader.PurityScan.n : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278200.sys -> Downloader.Small : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278196.0xe -> Dropper.Agent.bc : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278204.0xe -> Dropper.Delf.z : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278217.EXE -> Heuristic.Win32.AVKiller : No action taken.
:mozilla.50:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Lindsey Eve\Cookies\lindsey eve@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Lindsey Eve\Cookies\lindsey_eve@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.109:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.110:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.111:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.112:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.113:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.114:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.88:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.90:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.91:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.95:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.96:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.36:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.135:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.104:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.105:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.106:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.107:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.108:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.37:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.213:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.214:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.215:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.216:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.115:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.116:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.117:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.118:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.203:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.209:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.63:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.64:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.65:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Lindsey Eve\Cookies\lindsey_eve@sec1.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.34:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.35:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.66:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.67:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.68:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.69:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.70:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.147:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.148:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.149:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.227:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.228:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.229:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.230:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.170:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.171:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.172:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.173:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.193:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.119:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.120:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.121:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.122:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.123:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.124:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.125:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.126:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.129:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.130:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.131:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.132:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.133:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Lindsey Eve\Cookies\lindsey_eve@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.212:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.101:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.102:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.103:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.217:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.218:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.219:C:\Documents and Settings\Lindsey Eve\Application Data\Mozilla\Firefox\Profiles\default.ry1\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP787\A0278203.exe -> Trojan.Small : No action taken.
::Report end
linzfluttery
13 Posts
0
January 8th, 2007 00:00
Adelphia High-Speed Internet Self Care
Adobe Flash Player 9 ActiveX
Adobe Reader 6.0.1
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20030807.3)
AOL Instant Messenger
ArcSoft Software Suite
AVG Anti-Spyware 7.5
BitTornado 0.3.7
Broadcom Management Programs
BroadJump Client Foundation
CA eTrust Antivirus
CCHelp
CCleaner (remove only)
CCScore
CDex extraction audio
Cool Edit Pro 2.0
Dell AIO Printer A920
Dell Digital Jukebox Driver
Dell Media Experience
Dell Solution Center
Dell Support
DVDSentry
ESSAdpt
ESSANUP
ESSCAM
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSvpaht
ESSvpot
FaxTools
FinePixViewer Ver.4.0
FUJIFILM USB Driver
Google Gmail Notifier
Google Toolbar for Internet Explorer
GTK+ Runtime 2.4.13 rev a (remove only)
HijackThis 1.99.1
HLPIndex
HLPRFO
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Image Resizer Powertoy for Windows XP
ImageMixer VCD for FinePix
ImageMixer VCD2
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics Driver
Internet Explorer Default Page
iPod for Windows 2005-03-23
iPod for Windows User Guide
iPod System Software Updater 2.1
iTunes
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Kodak EasyShare software
KSU
Macromedia Flash Player
Microsoft .NET Framework 1.1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft PowerPoint 2002
Modem Event Monitor
Modem Helper
Modem On Hold
Mozilla Firefox (1.0.7)
MSXML 4.0 SP2 (KB927978)
Nikon View 5
Notifier
OTtBP
OTtBPSDK
PCDADDIN
PCDHELP
PCDLNCH
Picasa 2
Picture Package
PowerDVD
QuickTime
RAW FILE CONVERTER LE
RealOne Player
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB926255)
SFR
SFR2
Shutterfly Plugin
SmartFTP Client
SmartFTP Client 2.0
SmartFTP Client 2.0 Setup Files (remove only)
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Sony USB Driver
Spybot - Search & Destroy 1.3
TeraNet
Terayon DOCSIS Modem
Trillian
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Viewpoint Media Player
VPRINTOL
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows SR 2.0
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Yahoo! extras
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Messenger Explorer Bar
etrust is something i purchased (from my the IT company that my office uses) and installed and i have never had a problem updating it in the past. i am open to use different spftware.
1972vet
3.3K Posts
0
January 8th, 2007 01:00
Your AVG Anti-Spyware is offering to remove quite a gaggle of malware but you don't have it configured correctly. Please go over the instructions again to configure AVG and run it in safe mode again. This time allow it to remove what malware it finds. Every bit of the malware discovered from the scan log you posted shows that AVG took no action. This is because you either saved the file before you removed it or you failed to tell AVG to quarantine what malware it found.
Post that log and a fresh HijackThis log back here when finished. Perhaps then you might be able to update your eTrust antivirus software.