KeithLDick Posted January 26, 2006 Report Share Posted January 26, 2006 My long time friend has 6 kids rangijng from 17 - 25 so you can image the mess this thing is in..I already ran Spybot, SpywareBlaster, Ad-Aware, Stinger & E-Wido Suite and set him up with AVG & Sygate (Got rid of Norton).. I forgot to do A-Squared, will do that the next time I am there..Here's his log... (Thanks!!)..Logfile of HijackThis v1.99.1Scan saved at 6:47:00 PM, on 1/25/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Symantec Shared\ccProxy.exeC:\Program Files\Common Files\Symantec Shared\ccSetMgr.exeC:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\CyberLink\PowerDVD\PowerDVD.exeC:\program files\qttask.exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\Ahead\InCD\InCD.exeC:\Program Files\Common Files\Symantec Shared\ccApp.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\Yahoo!\Messenger\ymsgr_tray.exeC:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeC:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeC:\Program Files\Norton Internet Security\ISSVC.exeC:\Program Files\ewido anti-malware\ewidoctrl.exeC:\Program Files\Outlook Express\msimn.exeC:\Program Files\Messenger\msmsgs.exeE:\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =http://results.dashbar.com/search?c=27440&...3.0.1.8〈=enR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL= http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =res://C:\PROGRA~1\SEARCH~1\toolbar.dll/saR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =http://red.clientapps.yahoo.com/customize/...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =http://www.yahoo.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title =Microsoft Internet Explorer provided by Verizon OnlineR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\InternetSettings,ProxyOverride = 127.0.0.1O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}- C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} -C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A}- C:\Program Files\Yahoo!\Common\YIeTagBm.dllO2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\ProgramFiles\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dllO2 - BHO: Norton Internet Security -{9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\CommonFiles\Symantec Shared\AdBlocking\NISShExt.dllO2 - BHO: Viewpoint Toolbar BHO -{A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\ProgramFiles\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dllO2 - BHO: Google Toolbar Helper -{AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programfiles\google\googletoolbar2.dllO2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dllO2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} -C:\Program Files\Norton Internet Security\NortonAntiVirus\NavShExt.dllO3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} -C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -c:\program files\google\googletoolbar2.dllO3 - Toolbar: Viewpoint Toolbar -{F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\ProgramFiles\Viewpoint\Viewpoint Toolbar\ViewBar.dllO3 - Toolbar: Norton Internet Security -{0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\CommonFiles\Symantec Shared\AdBlocking\NISShExt.dllO3 - Toolbar: Norton AntiVirus -{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\NortonInternet Security\Norton AntiVirus\NavShExt.dllO4 - HKLM\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\ViewpointManager\ViewMgr.exeO4 - HKLM\..\Run: [PowerDVD] C:\ProgramFiles\CyberLink\PowerDVD\PowerDVD.exe /autostartO4 - HKLM\..\Run: [343763395] D:\Reg\Pentax_Win_GM_12062004.exe /r"D:\Reg\Pentax_Win_GM_12062004.rpd"O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\qttask.exe" -atboottimeO4 - HKLM\..\Run: [ML1HelperStartUp] C:\PROGRA~1\MIDNIG~1\ML1HEL~1.EXE/partner ML1O4 - HKLM\..\Run: [HPDJ Taskbar Utility]C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exeO4 - HKLM\..\Run: [ErrorSafe] C:\Program Files\ErrorSafe\ers.exe /minO4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\SymantecShared\ccApp.exe"O4 - HKLM\..\Run: [iS CfgWiz] C:\Program Files\Norton InternetSecurity\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODECfgWiz /CMDLINE "REBOOT"O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton InternetSecurity\UrlLstCk.exeO4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\CommonFiles\Symantec Shared\Security Center\UsrPrmpt.exeO4 - HKCU\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exeO4 - HKCU\..\Run: [Free MP3 Direct] C:\Program Files\Free MP3Direct\Free MP3 Direct.exe /hideO4 - HKCU\..\Run: [Yahoo! Pager] "C:\ProgramFiles\Yahoo!\Messenger\ypager.exe" -quietO4 - HKCU\..\Run: [ErrorSafe] C:\Program Files\ErrorSafe\ers.exe /minO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSNMessenger\msnmsgr.exe" /backgroundO8 - Extra context menu item: &Google Search - res://c:\programfiles\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: &Viewpoint Search - res://C:\ProgramFiles\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTMLO8 - Extra context menu item: &Yahoo! Search - file:///C:\ProgramFiles\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Backward Links - res://c:\programfiles\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page -res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: Similar Pages - res://c:\programfiles\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English -res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\ProgramFiles\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: Yahoo! &Maps - file:///C:\ProgramFiles\Yahoo!\Common/ycmap.htmO8 - Extra context menu item: Yahoo! &SMS - file:///C:\ProgramFiles\Yahoo!\Common/ycsms.htmO9 - Extra button: Yahoo! Services -{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\ProgramFiles\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683}- C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\ProgramFiles\Messenger\msmsgs.exeO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: Yahoo! Chat -http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cabO16 - DPF: Yahoo! Euchre -http://download.games.yahoo.com/games/clients/y/et1_x.cabO16 - DPF: Yahoo! Graffiti -http://download.games.yahoo.com/games/clients/y/grt5_x.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)O23 - Service: Symantec Event Manager (ccEvtMgr) - SymantecCorporation - C:\Program Files\Common Files\SymantecShared\ccEvtMgr.exeO23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation- C:\Program Files\Common Files\Symantec Shared\ccProxy.exeO23 - Service: Symantec Password Validation (ccPwdSvc) - SymantecCorporation - C:\Program Files\Common Files\SymantecShared\ccPwdSvc.exeO23 - Service: Symantec Settings Manager (ccSetMgr) - SymantecCorporation - C:\Program Files\Common Files\SymantecShared\ccSetMgr.exeO23 - Service: ewido security suite control - ewido networks -C:\Program Files\ewido anti-malware\ewidoctrl.exeO23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\ProgramFiles\Ahead\InCD\InCDsrv.exeO23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\ProgramFiles\Norton Internet Security\ISSVC.exeO23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. -C:\WINDOWS\system32\LEXBCES.EXEO23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) -Symantec Corporation - C:\Program Files\Norton InternetSecurity\Norton AntiVirus\navapsvc.exeO23 - Service: SAVScan - Symantec Corporation - C:\ProgramFiles\Norton Internet Security\Norton AntiVirus\SAVScan.exeO23 - Service: ScriptBlocking Service (SBService) - SymantecCorporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - SymantecCorporation - C:\Program Files\Common Files\SymantecShared\SNDSrvc.exeO23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation -C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exeO23 - Service: Symantec Core LC - Symantec Corporation - C:\ProgramFiles\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Link to post Share on other sites
Dan Posted January 26, 2006 Report Share Posted January 26, 2006 Hi,Open HijackThis, click the "Scan" button, and check the following items:R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =http://results.dashbar.com/search?c=27440&...3.0.1.8〈=enR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL= http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =res://C:\PROGRA~1\SEARCH~1\toolbar.dll/saR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =http://red.clientapps.yahoo.com/customize/...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =http://red.clientapps.yahoo.com/customize/...//www.yahoo.comO2 - BHO: Viewpoint Toolbar BHO -{A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\ProgramFiles\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dllO4 - HKLM\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exeO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\ViewpointManager\ViewMgr.exeO4 - HKCU\..\Run: [MyWebSearch Email Plugin]C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exeO4 - HKCU\..\Run: [Free MP3 Direct] C:\Program Files\Free MP3Direct\Free MP3 Direct.exe /hideClose all windows Except HijackThis, and click the "Fix Checked" button. Close HijackThis.Click "Start --> Control Panel --> Add Remove Programs" Uninstall:ViewpointMyWebSearchFree MP3 DirectNow, Please go HERE to run Panda's ActiveScanOnce you are on the Panda site click the Scan your PC buttonA new window will open...click the Check Now buttonEnter your CountryEnter your State/ProvinceEnter your e-mail address and click sendSelect either Home User or CompanyClick the big Scan Now buttonIf it wants to install an ActiveX component allow itIt will start downloading the files it requires for the scan (Note: It may take a couple of minutes)When download is complete, click on My Computer to start the scanWhen the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan reportReboot, and post a new HijackThis log as well as the ActiveScan log.Danny Link to post Share on other sites
KeithLDick Posted January 26, 2006 Author Report Share Posted January 26, 2006 Thanks Danny, I will be going over there tomorrow nite and get it done.. Cheers.. Link to post Share on other sites
KeithLDick Posted January 26, 2006 Author Report Share Posted January 26, 2006 Couldn't get get Active Scan to Run... It said it was running but sat here for an hour and a half..here's the new log..Logfile of HijackThis v1.99.1Scan saved at 6:14:09 PM, on 1/26/2006Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\CyberLink\PowerDVD\PowerDVD.exeC:\program files\qttask.exeC:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exeC:\Program Files\Ahead\InCD\InCD.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\Yahoo!\Messenger\ymsgr_tray.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeC:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeC:\Program Files\ewido anti-malware\ewidoctrl.exeC:\WINDOWS\System32\svchost.exeC:\HighJackThis\HijackThis.exeR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon OnlineR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dllO2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dllO3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [PowerDVD] C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe /autostartO4 - HKLM\..\Run: [343763395] D:\Reg\Pentax_Win_GM_12062004.exe /r "D:\Reg\Pentax_Win_GM_12062004.rpd"O4 - HKLM\..\Run: [QuickTime Task] "C:\program files\qttask.exe" -atboottimeO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exeO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exeO4 - HKLM\..\Run: [ErrorSafe] C:\Program Files\ErrorSafe\ers.exe /minO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUPO4 - HKLM\..\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startguiO4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quietO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /backgroundO8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.htmlO8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htmO8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.htmlO8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.htmlO8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.htmlO8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.htmlO8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htmO8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htmO8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htmO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/cha...t/c381/chat.cabO16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cabO16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exeO23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exeO23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exeO23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXEO23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe Link to post Share on other sites
Dan Posted January 28, 2006 Report Share Posted January 28, 2006 Hi,Open HijackThis, click the Scan button and check the following items:R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = Close all windows except HijackThis, and click the "Fix Checked" button.Please do an online scan with Kaspersky WebScannerClick on Kaspersky Online ScannerYou will be promted to install an ActiveX component from Kaspersky, Click Yes.The program will launch and then begin downloading the latest definition files:Once the files have been downloaded click on NEXTNow click on Scan SettingsIn the scan settings make that the following are selected:Scan using the following Anti-Virus database:Extended (if available otherwise Standard)Scan Options:Scan ArchivesScan Mail Bases[*]Click OK[*]Now under select a target to scan:Select My Computer[*]This will program will start and scan your system.[*]The scan will take a while so be patient and let it run.[*]Once the scan is complete it will display if your system has been infected.Now click on the Save as Text button:[*]Save the file to your desktop.[*]Copy and paste that information in your next post.Reboot and post the Kaspersky Log as well as how your computer is doing.Danny Link to post Share on other sites
therock247uk Posted April 5, 2006 Report Share Posted April 5, 2006 Inactive topic...If you still need help on this problem, contact me or one of the Moderators to re-open this up.Topic closed. Link to post Share on other sites
Recommended Posts