DreamsAndGasoline

Members
  • Content Count

    13
  • Joined

  • Last visited

Posts posted by DreamsAndGasoline

  1. By the way, I uninstalled AVG

    Thanks so much again for all your time and help :)

    Oh, should I uninstall Windows Defender too?

    Logfile of HijackThis v1.99.1

    Scan saved at 10:25:07 PM, on 11/14/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Windows Defender\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\hkcmd.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\internet explorer\iexplore.exe

    C:\Program Files\internet explorer\iexplore.exe

    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"

    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O11 - Options group: [iNTERNATIONAL] International*

    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1168275719667

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1189816471609

    O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  2. Uh Oh

    -------------------------------------------------------------------------------

    KASPERSKY ONLINE SCANNER REPORT

    Wednesday, November 14, 2007 10:22:03 PM

    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)

    Kaspersky Online Scanner version: 5.0.98.0

    Kaspersky Anti-Virus database last update: 15/11/2007

    Kaspersky Anti-Virus database records: 459675

    -------------------------------------------------------------------------------

    Scan Settings:

    Scan using the following antivirus database: extended

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    A:\

    C:\

    D:\

    Scan Statistics:

    Total number of scanned objects: 31155

    Number of viruses found: 1

    Number of infected objects: 4

    Number of suspicious objects: 0

    Duration of the scan process: 00:40:17

    Infected Object Name / Virus Name / Last Action

    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09142007-205940.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4400000\465857EF.VBN Infected: Exploit.Win32.IMG-ANI.ak skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4400001\4658585C.VBN Infected: Exploit.Win32.IMG-ANI.ak skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4400002\465858C9.VBN Infected: Exploit.Win32.IMG-ANI.ak skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine4400003\46585960.VBN Infected: Exploit.Win32.IMG-ANI.ak skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\User\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{B81507D0-61E8-4806-A483-52EA8508F938} Object is locked skipped

    C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\27SF5XH1\bind[1].htm Object is locked skipped

    C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\User\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\User\ntuser.dat.LOG Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped

    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped

    C:\Program Files\Symantec AntiVirus\SAVRT493NAV~.TMP Object is locked skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\System Volume Information\_restore{B60E9EA2-00E9-49F8-B1CB-B50785BBC336}\RP351\change.log Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\browser.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped

    C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped

    C:\WINDOWS\CSC0000001 Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\EventCache\{F5C70DEE-E0D0-446B-B0C7-F906D58A61AF}.bin Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  3. And the new HijackThis Log:

    Logfile of HijackThis v1.99.1

    Scan saved at 8:52:23 PM, on 11/12/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Windows Defender\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\hkcmd.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe

    C:\Program Files\internet explorer\iexplore.exe

    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O11 - Options group: [iNTERNATIONAL] International*

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1168275719667

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1189816471609

    O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  4. HI! thanks for helping! I greatly appriciate it, and so do my parents.

    Here is the ComboFix report:

    ComboFix 07-11-08.1 - User 2007-11-12 19:47:12.1 - NTFSx86

    Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe

    * Created a new restore point

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\Documents and Settings\User\Desktop\internet.lnk

    .

    ((((((((((((((((((((((((( Files Created from 2007-10-13 to 2007-11-13 )))))))))))))))))))))))))))))))

    .

    2007-11-12 19:45 51,200 --a------ C:\WINDOWS\NirCmd.exe

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2007-11-13 00:39 --------- d-----w C:\Program Files\Symantec AntiVirus

    2007-11-12 13:00 --------- d-----w C:\Documents and Settings\User\Application Data\AVG7

    2007-09-16 07:07 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2

    2007-09-15 01:41 --------- d-----w C:\Program Files\Virtual Earth 3D

    2007-09-15 00:59 --------- d-----w C:\Program Files\Windows Defender

    2007-09-14 23:55 --------- d-----w C:\Documents and Settings\User\Application Data\MSN6

    2007-09-14 23:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\MSN6

    2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-06-21 23:48]

    "HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-06-21 23:44]

    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 15:52]

    "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2005-04-17 12:30]

    "Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-03-28 09:18]

    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-23 08:04]

    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

    R3 EraserUtilDrv10733;EraserUtilDrv10733;\??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10733.sys

    S3 MXBULK;DualCam Still, MXBulk3.Sys;C:\WINDOWS\system32\Drivers\MXBulk3.sys

    *Newly Created Service* - CATCHME

    .

    Contents of the 'Scheduled Tasks' folder

    "2007-11-13 00:30:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

    - C:\Program Files\Windows Defender\MpCmdRun.exe

    .

    **************************************************************************

    catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2007-11-12 19:49:26

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully

    hidden files: 0

    **************************************************************************

    .

    Completion time: 2007-11-12 19:50:49

    .

    --- E O F ---

  5. This is log from my parents computer. It is extremely slow. They don't have hardly anything stored on their computer. Some family snapshots and a few word documents. They get a fairly good amount of objects in Symantec Antivirus Quarantine. Here are a few:

    * http://securityresponse.symantec.com/secur...-101518-4323-99

    * http://securityresponse.symantec.com/avcen...o.cgi?vid=19040

    * http://securityresponse.symantec.com/secur...-062217-0726-99

    * A few are just under the file name "00000004.zip", "00000001.zip", ext. Says "Still contains one infected items"

    HijackThis Log:

    Logfile of HijackThis v1.99.1

    Scan saved at 3:39:49 PM, on 11/12/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Windows Defender\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\hkcmd.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\WINDOWS\System32\svchost.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Grisoft\AVG7\avgcc.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\O5UZ4LIN\hijackthis_sfx[1].exe

    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O11 - Options group: [iNTERNATIONAL] International*

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

    O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1168275719667

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1189816471609

    O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    THANKS!!!

    Meg

  6. Oh Great! Thanks!

    I have another question.

    You said only one anti virus. Do I disable the one that came on my computer? Trend Micro Pro-cillin 12?

    I also have Ad-Aware SE, cwshredder (Trend Micro Inc.), AVG, Windows Defender, and Spybot and Destroy. Wow, didn't know I had that much, lol.

    What do I need to keep.. if anything. I'll download what you recommend.

    Thanks!

    Meg

  7. Scanning Report

    Saturday, October 27, 2007 22:50:12 - 00:05:52

    Computer name: MEG

    Scanning type: Scan system for viruses, rootkits, spyware

    Target: C:\ D:\

    --------------------------------------------------------------------------------

    Result: 19 malware found

    Tracking Cookie (spyware)

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    System

    --------------------------------------------------------------------------------

    Statistics

    Scanned:

    Files: 34313

    System: 7987

    Not scanned: 5

    Actions:

    Disinfected: 0

    Renamed: 0

    Deleted: 0

    None: 19

    Submitted: 0

    Files not scanned:

    C:\PAGEFILE.SYS

    C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT

    C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{A83E6793-3287-434B-90A0-D6C7561031A4}.BIN

    C:\DOCUMENTS AND SETTINGS\MEG YOUNG\LOCAL SETTINGS\TEMP\HSPERFDATA_MEG YOUNG\2308

    C:\DOCUMENTS AND SETTINGS\MEG YOUNG\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{C135997B-277B-44D1-8EEC-D0C2BABB5B2A}

    --------------------------------------------------------------------------------

    Options

    Scanning engines:

    F-Secure Libra: 2.4.2, 2007-10-26

    F-Secure AVP: 7.0.171, 2007-10-27

    F-Secure Orion: 1.2.37, 2007-10-26

    F-Secure Blacklight: 1.0.64

    F-Secure Draco: 1.0.35, 0597-150-72

    F-Secure Pegasus: 1.19.0, 2007-09-18

    Scanning options:

    Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX

    Use Advanced heuristics

  8. Opps! Sorry! And Thanks for helping!

    Logfile of HijackThis v1.99.1

    Scan saved at 7:54:08 PM, on 10/27/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\csrss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Windows Defender\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\WLTRYSVC.EXE

    C:\WINDOWS\System32\bcmwltry.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe

    C:\WINDOWS\eHome\ehRecvr.exe

    C:\WINDOWS\eHome\ehSched.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    C:\WINDOWS\system32\svchost.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    C:\WINDOWS\ehome\mcrdsvc.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    C:\WINDOWS\system32\dllhost.exe

    C:\WINDOWS\System32\alg.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\ehome\ehtray.exe

    C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\system32\msiexec.exe

    C:\WINDOWS\system32\MsiExec.exe

    C:\WINDOWS\system32\MsiExec.exe

    C:\Program Files\Grisoft\AVG7\avgcc.exe

    C:\Program Files\Viewpoint\Common\ViewpointService.exe

    C:\Program Files\AIM6\aim6.exe

    C:\Program Files\AIM6\aolsoftware.exe

    C:\Program Files\Windows Defender\MSASCui.exe

    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe

    O4 - HKLM\..\Run: [broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe

    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"

    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"

    O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP

    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start

    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"

    O4 - HKCU\..\Run: [slide.exe] c:\program files\slide\slide.exe

    O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\RunOnce: [sWHelper] "C:\WINDOWS\system32\Macromed\Shockwave 10\PostUpdate.exe" 1010011

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O11 - Options group: [iNTERNATIONAL] International*

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1192475246640

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe

    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe

    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe

    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe

    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

  9. I thought you're not supposed to shut down that way. Should I try?

    And Terrorist.. I didn't see anything there that would help me.. Did I look over something? I found the shortcut to restart. I'm going to try that now. Thanks Guys!

    I also posted my hijackthis log in the malwear removal forum, Do you think that when someone looks at that, it will show the problem?

  10. I have Windows XP Media Center. A few days ago, I tried to restart by clicking the button on the bottom of the start menu. Instead of the pretty colorful box with the pretty buttons (haha): that gray ugly old school box popped up with the drop down menu. The screen faded out like it always does, but when I chose the restart one the box disappears and the screen brightens right back up. Nothing happened, not one thing. I tried to shut down, and log off. They did the same thing. Anyone have any ideas?! *Please talk Computer English to me :) Oh, another thing.. Is there anyway to shut down without holding the power button down? I really don't want to have to do that.

    Please Helpppppppp,

    Thank you so much,

    Meg

  11. I have Windows XP Media Center. A few days ago, I tried to restart by clicking the button on the bottom of the start menu. Instead of the pretty colorful box with the pretty buttons (haha): that gray ugly old school box popped up with the drop down menu. The screen faded out like it always does, but when I chose the restart one the box disappears and the screen brightens right back up. Nothing happened, not one thing. I tried to shut down, and log off. They did the same thing. *Please talk Computer English to me : )

    Please Helpppppppp,

    Thanks for your time!,

    Meg

    Logfile of HijackThis v1.99.1

    Scan saved at 4:07:47 PM, on 10/26/2007

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (but I usually use firefox)

    (7.00.6000.16544)

    Running processes:

    C:WINDOWSSystem32smss.exe

    C:WINDOWSsystem32csrss.exe

    C:WINDOWSsystem32winlogon.exe

    C:WINDOWSsystem32services.exe

    C:WINDOWSsystem32lsass.exe

    C:WINDOWSsystem32svchost.exe

    C:WINDOWSsystem32svchost.exe

    C:Program FilesWindows

    DefenderMsMpEng.exe

    C:WINDOWSSystem32svchost.exe

    C:WINDOWSsystem32svchost.exe

    C:WINDOWSsystem32svchost.exe

    C:WINDOWSSystem32WLTRYSVC.EXE

    C:WINDOWSSystem32bcmwltry.exe

    C:WINDOWSsystem32spoolsv.exe

    C:Program FilesCommon FilesAppleMobile

    Device

    SupportbinAppleMobileDeviceService.exe

    C:PROGRA~1GrisoftAVG7avgamsvr.exe

    C:PROGRA~1GrisoftAVG7avgupsvc.exe

    C:PROGRA~1GrisoftAVG7avgemc.exe

    C:Program FilesCommon FilesCreative Labs

    SharedServiceCreativeLicensing.exe

    C:WINDOWSeHomeehRecvr.exe

    C:WINDOWSeHomeehSched.exe

    C:PROGRA~1TRENDM~1INTERN~1PcCtlCom.exe

    C:WINDOWSsystem32svchost.exe

    C:PROGRA~1TRENDM~1INTERN~1Tmntsrv.exe

    C:WINDOWSehomemcrdsvc.exe

    C:PROGRA~1TRENDM~1INTERN~1TmPfw.exe

    C:WINDOWSsystem32dllhost.exe

    C:WINDOWSSystem32alg.exe

    C:WINDOWSExplorer.EXE

    C:WINDOWSehomeehtray.exe

    C:Program FilesTrend MicroInternet

    Security 12pccguide.exe

    C:WINDOWSSystem32svchost.exe

    C:WINDOWSsystem32ctfmon.exe

    C:WINDOWSsystem32svchost.exe

    C:Program FilesiPodbiniPodService.exe

    C:WINDOWSsystem32wuauclt.exe

    C:WINDOWSsystem32msiexec.exe

    C:WINDOWSsystem32MsiExec.exe

    C:WINDOWSsystem32MsiExec.exe

    C:Program FilesGrisoftAVG7avgcc.exe

    C:Program FilesMozilla Firefoxfirefox.exe

    C:Program

    FilesViewpointCommonViewpointService.exe

    C:Program FilesAIM6aim6.exe

    C:Program FilesAIM6aolsoftware.exe

    C:Program FilesCommon

    FilesRealUpdate_OBrealsched.exe

    C:PROGRA~1TRENDM~1INTERN~1tmproxy.exe

    C:Documents and SettingsMeg

    YoungDesktophijackthis_sfx.exe

    C:Program FilesHijackThisHijackThis.exe

    R0 - HKCUSoftwareMicrosoftInternet

    ExplorerMain,Start Page = http://yahoo.com/

    R1 - HKLMSoftwareMicrosoftInternet

    ExplorerMain,Default_Page_URL =

    http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLMSoftwareMicrosoftInternet

    ExplorerMain,Default_Search_URL =

    http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLMSoftwareMicrosoftInternet

    ExplorerMain,Search Page =

    http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLMSoftwareMicrosoftInternet

    ExplorerMain,Start Page =

    http://go.microsoft.com/fwlink/?LinkId=69157

    O2 - BHO: Adobe PDF Reader Link Helper -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

    C:Program FilesCommon

    FilesAdobeAcrobatActiveXAcroIEHelper.dll

    O2 - BHO: DriveLetterAccess -

    {5CA3D70E-1895-11CF-8E15-001234567890} -

    C:WINDOWSSystem32DLADLASHX_W.DLL

    O2 - BHO: SSVHelper Class -

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

    C:Program

    FilesJavajre1.6.0_02binssv.dll

    O4 - HKLM..Run: [ehTray]

    C:WINDOWSehomeehtray.exe

    O4 - HKLM..Run: [broadcom Wireless Manager

    UI] C:WINDOWSsystem32WLTRAY.exe

    O4 - HKLM..Run: [igfxtray]

    C:WINDOWSsystem32igfxtray.exe

    O4 - HKLM..Run: [igfxhkcmd]

    C:WINDOWSsystem32hkcmd.exe

    O4 - HKLM..Run: [igfxpers]

    C:WINDOWSsystem32igfxpers.exe

    O4 - HKLM..Run: [PDVDDXSrv] "C:Program

    FilesCyberLinkPowerDVD DXPDVDDXSrv.exe"

    O4 - HKLM..Run: [pccguide.exe] "C:Program

    FilesTrend MicroInternet Security

    12pccguide.exe"

    O4 - HKLM..Run: [DMXLauncher] C:Program

    FilesDellMedia ExperienceDMXLauncher.exe

    O4 - HKLM..Run: [AVG7_CC]

    C:PROGRA~1GrisoftAVG7avgcc.exe /STARTUP

    O4 - HKLM..Run: [DLA]

    C:WINDOWSSystem32DLADLACTRLW.EXE

    O4 - HKLM..Run: [iSUSPM Startup]

    C:PROGRA~1COMMON~1INSTAL~1UPDATE~1ISUSP

    M.exe -startup

    O4 - HKLM..Run: [iSUSScheduler]

    "C:Program FilesCommon

    FilesInstallShieldUpdateServiceissch.exe"

    -start

    O4 - HKLM..Run: [Windows Defender]

    "C:Program FilesWindows

    DefenderMSASCui.exe" -hide

    O4 - HKLM..Run: [Adobe Photo Downloader]

    "C:Program FilesAdobePhotoshop Album

    Starter Edition3.2Appsapdproxy.exe"

    O4 - HKLM..Run: [Adobe Reader Speed

    Launcher] "C:Program FilesAdobeReader

    8.0ReaderReader_sl.exe"

    O4 - HKLM..Run: [sunJavaUpdateSched]

    "C:Program

    FilesJavajre1.6.0_02binjusched.exe"

    O4 - HKLM..Run: [iTunesHelper] "C:Program

    FilesiTunesiTunesHelper.exe"

    O4 - HKLM..Run: [sigmatelSysTrayApp]

    stsystra.exe

    O4 - HKLM..Run: [QuickTime Task]

    "C:Program FilesQuickTimeQTTask.exe"

    -atboottime

    O4 - HKLM..Run: [TkBellExe] "C:Program

    FilesCommon

    FilesRealUpdate_OBrealsched.exe" -osboot

    O4 - HKCU..Run: [OE_OEM] "C:Program

    FilesTrend MicroInternet Security

    12TMAS_OETMAS_OEMon.exe"

    O4 - HKCU..Run: [slide.exe] c:program

    filesslideslide.exe

    O4 - HKCU..Run: [Microsoft Location

    Finder] "C:Program FilesMicrosoft Location

    FinderLocationFinder.exe"

    O4 - HKCU..Run: [ctfmon.exe]

    C:WINDOWSsystem32ctfmon.exe

    O4 - HKCU..RunOnce: [sWHelper]

    "C:WINDOWSsystem32MacromedShockwave

    10PostUpdate.exe" 1010011

    O4 - Global Startup: Microsoft Office.lnk =

    C:Program FilesMicrosoft

    OfficeOffice10OSA.EXE

    O8 - Extra context menu item: E&xport to

    Microsoft Excel -

    res://C:PROGRA~1MICROS~4Office10EXCEL.EX

    E/3000

    O9 - Extra button: (no name) -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:Program

    FilesJavajre1.6.0_02binssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java

    Console -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:Program

    FilesJavajre1.6.0_02binssv.dll

    O9 - Extra button: (no name) -

    {B205A35E-1FC4-4CE3-818B-899DBBB3388C} -

    C:Program FilesCommon FilesMicrosoft

    SharedEncarta Search BarENCSBAR.DLL

    O9 - Extra button: (no name) -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    %windir%Network Diagnosticxpnetdiag.exe

    (file missing)

    O9 - Extra 'Tools' menuitem:

    @xpsp3res.dll,-20001 -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    %windir%Network Diagnosticxpnetdiag.exe

    (file missing)

    O9 - Extra button: Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:Program FilesMessengermsmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows

    Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:Program FilesMessengermsmsgs.exe

    O11 - Options group: [iNTERNATIONAL]

    International*

    O16 - DPF:

    {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}

    (Installation Support) - C:Program

    FilesYahoo!CommonYinsthelper.dll

    O16 - DPF:

    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

    (MUWebControl Class) -

    http://www.update.microsoft.com/microsoftupd

    ate/v6/V5Controls/en/x86/client/muweb_site.c

    ab?1192475246640

    O20 - Winlogon Notify: igfxcui -

    C:WINDOWSSYSTEM32igfxdev.dll

    O20 - Winlogon Notify: WgaLogon -

    C:WINDOWSSYSTEM32WgaLogon.dll

    O21 - SSODL: WPDShServiceObj -

    {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

    C:WINDOWSsystem32WPDShServiceObj.dll

    O23 - Service: Apple Mobile Device - Apple,

    Inc. - C:Program FilesCommon

    FilesAppleMobile Device

    SupportbinAppleMobileDeviceService.exe

    O23 - Service: AVG7 Alert Manager Server

    (Avg7Alrt) - GRISOFT, s.r.o. -

    C:PROGRA~1GrisoftAVG7avgamsvr.exe

    O23 - Service: AVG7 Update Service

    (Avg7UpdSvc) - GRISOFT, s.r.o. -

    C:PROGRA~1GrisoftAVG7avgupsvc.exe

    O23 - Service: AVG E-mail Scanner (AVGEMS) -

    GRISOFT, s.r.o. -

    C:PROGRA~1GrisoftAVG7avgemc.exe

    O23 - Service: Creative Labs Licensing

    Service - Creative Labs - C:Program

    FilesCommon FilesCreative Labs

    SharedServiceCreativeLicensing.exe

    O23 - Service: iPod Service - Apple Inc. -

    C:Program FilesiPodbiniPodService.exe

    O23 - Service: Trend Micro Central Control

    Component (PcCtlCom) - Trend Micro

    Incorporated. -

    C:PROGRA~1TRENDM~1INTERN~1PcCtlCom.exe

    O23 - Service: Trend Micro Real-time Service

    (Tmntsrv) - Trend Micro Incorporated. -

    C:PROGRA~1TRENDM~1INTERN~1Tmntsrv.exe

    O23 - Service: Trend Micro Personal Firewall

    (TmPfw) - Trend Micro Inc. -

    C:PROGRA~1TRENDM~1INTERN~1TmPfw.exe

    O23 - Service: Trend Micro Proxy Service

    (tmproxy) - Trend Micro Inc. -

    C:PROGRA~1TRENDM~1INTERN~1tmproxy.exe

    O23 - Service: Viewpoint Manager Service -

    Viewpoint Corporation - C:Program

    FilesViewpointCommonViewpointService.exe

    O23 - Service: Dell Wireless WLAN Tray

    Service (wltrysvc) - Unknown owner -

    C:WINDOWSSystem32WLTRYSVC.EXE