Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Spyware and popups on my computer !! HELP!!
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Spyware and popups on my computer !! HELP!!  
Forum Quick Jump
 
New Topic Post reply to : Spyware and popups on my computer !! HELP!! Printable version of : Spyware and popups on my computer !! HELP!!
[ << Previous Thread | Next Thread >> ]

lupita
New Member


Date Joined Jun 2006
Total Posts : 3
 
   Posted 7-24-2006 1:19 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
 
My computer is infected by some spyware that makes my explorer run automatic a anti-spyware systemdocter also all kinds of popups comming up. Here is my Hijack log:
 
Thanks in advance !!!!!smurf
 
Logfile of HijackThis v1.99.1
Scan saved at 8:02:55 PM, on 23/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\ismon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\TEMP\win16.tmp.exe
C:\WINDOWS\System32\irftp.exe
C:\DOCUME~1\Maria\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt3.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00309} - C:\WINDOWS\g1238796.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam.exe" -silent
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.jcash.biz/l/41ade4cd066db13088a5d3ca8d7677ad_13.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/en-us/wlscbase7617.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7ADEA245-8D59-43C7-8DBB-7C6EC8839E34}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F6499F6-05DF-48AD-BFEA-7D96EF34A7FB}: NameServer = 192.168.0.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmfu32 - C:\WINDOWS\SYSTEM32\winmfu32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: CeEPwrSvc - Unknown owner - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Unknown owner - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsu!!!!a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Unknown owner - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (file missing)
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Windows Media Connect (WMC) (WmcCds) - Unknown owner - c:\program files\windows media connect\mswmccds.exe (file missing)
O23 - Service: Windows Media Connect (WMC) Helper (WmcCdsLs) - Unknown owner - C:\Program Files\Windows Media Connect\mswmcls.exe (file missing)
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-24-2006 6:13 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
Hi lupita cool
 
 
 
  • Install Ewido Anti-Malware
  • Double-click the icon on Desktop to launch Ewido
You will need to update Ewido to the latest definition files.
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
 
 
Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe


 
 
 
 
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
 
 
Reboot into Safe  Mode   by tapping F8 after the BIOS has loaded.
The Windows Advanced Options Menu appears.
Ensure that the Safe mode option is selected.
Press Enter. The computer then begins to start in Safe mode.
 
 
 
 
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
 
 
 
 
 
Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
 
Click on the green screwdriver-
Uncheck –Heurestic analysis
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select –Move
Remove checkmark from – Prompt on action
 
Click on the drive(s) you want to scan  . A red dot will mark the selected drive(s) . Then hit the green arrow in lower right corner It will now scan your  drive(s), say yes to all
When the scan has finished, look if you can click next icon next to the files found
If so, click it and then click the next icon right below and select Move incurable
This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured.
After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
 
Close Dr.Web Cureit.


 
 
 
Run full scan with Ewido
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
  • When the scan is complete click Recommended Action and change it to Quarantine
  • Then click Apply all actions
Once finished, click the Save report button, then click Save Report As. This will create a text file.
Make sure you know where to find this file again (like on the Desktop).

Close ewido security suite.
Note: DO NOT USE the computer while Ewido is scanning. If Explorer or the Control Panel are opened some malware types will reinfect your system or will not be cleaned properly.


 
Then reboot normally
 
 
 
 Post fresh  log from hijackthis  and log from Ewido as well as the log from drweb (DrWeb.csv)
 


Please start your own thread by clicking the new topic button. Do NOT post your problem in someone elses thread.
Do not PM me with logfiles. They will be deleted
 

Back to Top
 

lupita
New Member


Date Joined Jun 2006
Total Posts : 3
 
   Posted 7-24-2006 4:42 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
I am not able to put the DRweb log .........but here is the Ewido and Hijackthis ones........

Still having problems with popups.... :(

hope you can help me further ....

Logfile of HijackThis v1.99.1
Scan saved at 11:37:05 AM, on 24/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\System32\irftp.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\ismon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\Maria\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt3.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00309} - C:\WINDOWS\g47454171.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [LXBYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [PCPitstop Optimize Registration Reminder] C:\Program Files\PCPitstop\Optimize\Reminder.exe
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam.exe" -silent
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.jcash.biz/l/41ade4cd066db13088a5d3ca8d7677ad_13.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/en-us/wlscbase7617.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7ADEA245-8D59-43C7-8DBB-7C6EC8839E34}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F6499F6-05DF-48AD-BFEA-7D96EF34A7FB}: NameServer = 192.168.0.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winmfu32 - C:\WINDOWS\SYSTEM32\winmfu32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - (no file)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: CeEPwrSvc - Unknown owner - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DefWatch - Unknown owner - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsu!!!!a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: lxby_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbycoms.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Unknown owner - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Unknown owner - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe (file missing)
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: Windows Media Connect (WMC) (WmcCds) - Unknown owner - c:\program files\windows media connect\mswmccds.exe (file missing)
O23 - Service: Windows Media Connect (WMC) Helper (WmcCdsLs) - Unknown owner - C:\Program Files\Windows Media Connect\mswmcls.exe (file missing)

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:20:07 AM 24/07/2006

+ Scan result:



HKLM\SOFTWARE\Classes\CLSID\{93ac7c30-3878-4eaa-9420-7977285df5b1} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\g10959968.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\WINDOWS\g1238796.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\WINDOWS\g28008968.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\WINDOWS\g34490406.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\WINDOWS\g40972000.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\WINDOWS\g757984.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
C:\Documents and Settings\Maria\Local Settings\Temp\winB5.tmp.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixt0.dll -> Downloader.Zlob.aak : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixt1.dll -> Downloader.Zlob.aak : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ixt2.dll -> Downloader.Zlob.aak : Cleaned with backup (quarantined).
C:\WINDOWS\system32\components\flx5.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.8:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.147:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.148:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.19:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.21:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Maria\Application Data\Mozilla\Firefox\Profiles\aumcsdtc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

Many thanks for the first help !!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-24-2006 5:04 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
Next step ;-)


Please download free  Trial of Superantispyware
http://www.superantispyware.com/superantispywarefreevspro.html
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it.
close the program






Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.




Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing)
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt3.dll (file missing)
O16 - DPF: {00000000-0000-0000-0000-100005000004} -
http://code.jcash.biz/l/41ade4cd066db13088a5d3ca8d7677ad_13.exe
O20 - Winlogon Notify: winmfu32 - C:\WINDOWS\SYSTEM32\winmfu32.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - (no file)



Reboot into Safe  Mode  
Delete the following files or folders (delete item in bold). Please do not be concerned if
any of the items are not found as they may have been automatically removed by actions I had
you take earlier in the cleaning process.

Open Folder Options in Controlpanel >view and check your settings:
Select
Show hidden files and folders
Display the contents of system folders
Uncheck: Hide protected operating system files
Delete:
Files:
C:\WINDOWS\SYSTEM32\winmfu32.dll



Start Superantispyware/rightclick on the black/yellow bug in tray.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next
it will scan now. When scan have finished, put a checkmark with  all items it found. Next, after cleaning, let it Reboot


Next go to Start- Search and scrolldown using the scroll bar on the right. Go down to More advanced options and click.
Be sure the first three boxes are selected:
Search System folders
Search Hidden Files and folders
Search SubFolders
And Find:
superantispyware log
 
Post this log along with fresh hijackthis log and tell how things are running













Please start your own thread by clicking the new topic button. Do NOT post your problem in someone elses thread.
Do not PM me with logfiles. They will be deleted
 

Back to Top
 

lupita
New Member


Date Joined Jun 2006
Total Posts : 3
 
   Posted 7-24-2006 11:59 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
Hi ..am back after the last check and cleans I did like you told me to (btw, Now I cannot run hijackthis anymore {it says that it's not a win32 program} , so therefor only the super antispyware log ................. ( I really hope that now the sys. is clear of those stupid popups etc.)... up until now it looks great so far... many thanks ...here is my log:

SUPERAntiSpyware Scan Log
Generated 07/24/2006 at 06:22 PM

Core Rules Database Version : 3029
Trace Rules Database Version: 1093

Memory threats detected : 4
Registry threats detected : 257
File threats detected : 43

Malware.Notifier
C:\WINDOWS\SYSTEM32\ISHOST.EXE
C:\WINDOWS\SYSTEM32\ISHOST.EXE
C:\WINDOWS\SYSTEM32\ISNOTIFY.EXE
C:\WINDOWS\SYSTEM32\ISNOTIFY.EXE
C:\WINDOWS\SYSTEM32\ISMON.EXE
C:\WINDOWS\SYSTEM32\ISMON.EXE
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#ishost.exe [ ishost.exe ]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#issearch.exe [ issearch.exe ]
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP425\A0573737.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP426\A0575849.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0575875.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0575884.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576196.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576223.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576251.exe
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576257.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576265.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576271.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576278.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576291.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576292.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576293.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576296.exe
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576297.dll

Unclassified.Unknown Origin
C:\WINDOWS\TEMP\WINB.TMP.EXE
C:\WINDOWS\TEMP\WINB.TMP.EXE
HKLM\Software\Classes\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}
HKCR\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}
HKCR\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}
HKCR\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}\InprocServer32
HKCR\CLSID\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}\InprocServer32#ThreadingModel
C:\WINDOWS\g18989875.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A4F94C0C-54A7-4DB1-9AF3-B22E63D00309}
C:\Documents and Settings\Maria\Local Settings\Temporary Internet Files\Content.IE5\0TUR4TEN\srvbaj.exe
C:\Documents and Settings\Maria\Local Settings\Temporary Internet Files\Content.IE5\8D6JGDER\srvdml.exe
C:\Documents and Settings\Maria\Local Settings\Temporary Internet Files\Content.IE5\A5ZR9U02\srvvel.exe
C:\Documents and Settings\Maria\Local Settings\Temporary Internet Files\Content.IE5\P483PL8X\srvznp.exe
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576284.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576285.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576286.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576287.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576288.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576289.dll
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP427\A0576290.dll
C:\WINDOWS\Temp\win7.tmp.exe
C:\WINDOWS\Temp\winB.tmp
C:\WINDOWS\Temp\winC.tmp.exe
C:\WINDOWS\Prefetch\WIN7.TMP.EXE-343E9BE4.pf
C:\WINDOWS\Prefetch\WINB.TMP.EXE-39553B77.pf
C:\WINDOWS\Prefetch\WINC.TMP.EXE-39CBA710.pf

Adware.Tracking Cookie
C:\Documents and Settings\Maria\Cookies\maria@indextools.txt

Trojan.MalwareWipe
HKCR\AppId\{70F17C8C-1744-41B6-9D07-575DB448DCC5}

Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
C:\Documents and Settings\Maria\Favorites\Antivirus Test Online.url

Trojan.Malware
HKCR\MezziaCodec.Chl
HKCR\MezziaCodec.Chl\CLSID

Trojan.AtmClk
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#kernel32.dll [ C:\WINDOWS\system32\isnotify.exe ]

Malware.AntiVirusGolden
HKCR\Cerberus.EngineListener
HKCR\Cerberus.EngineListener\CLSID
HKCR\Cerberus.EngineListener\CurVer
HKCR\Cerberus.EngineListener.1
HKCR\Cerberus.EngineListener.1\CLSID
HKCR\Cerberus.Scanner
HKCR\Cerberus.Scanner\CLSID
HKCR\Cerberus.Scanner\CurVer
HKCR\Cerberus.Scanner.1
HKCR\Cerberus.Scanner.1\CLSID
HKCR\Cerberus.ThreatCollection
HKCR\Cerberus.ThreatCollection\CLSID
HKCR\Cerberus.ThreatCollection\CurVer
HKCR\Cerberus.ThreatCollection.1
HKCR\Cerberus.ThreatCollection.1\CLSID
HKCR\Engine.Backup
HKCR\Engine.Backup\CLSID
HKCR\Engine.Backup\CurVer
HKCR\Engine.Backup.1
HKCR\Engine.Backup.1\CLSID
HKCR\Engine.IgnoreList
HKCR\Engine.IgnoreList\CLSID
HKCR\Engine.IgnoreList\CurVer
HKCR\Engine.IgnoreList.1
HKCR\Engine.IgnoreList.1\CLSID
HKCR\Engine.Log
HKCR\Engine.Log\CLSID
HKCR\Engine.Log\CurVer
HKCR\Engine.Log.1
HKCR\Engine.Log.1\CLSID
HKCR\Engine.LogRecord
HKCR\Engine.LogRecord\CLSID
HKCR\Engine.LogRecord\CurVer
HKCR\Engine.LogRecord.1
HKCR\Engine.LogRecord.1\CLSID
HKCR\Engine.Paths
HKCR\Engine.Paths\CLSID
HKCR\Engine.Paths\CurVer
HKCR\Engine.Paths.1
HKCR\Engine.Paths.1\CLSID
HKCR\Engine.Quarantine
HKCR\Engine.Quarantine\CLSID
HKCR\Engine.Quarantine\CurVer
HKCR\Engine.Quarantine.1
HKCR\Engine.Quarantine.1\CLSID
HKCR\Engine.RunAs
HKCR\Engine.RunAs\CLSID
HKCR\Engine.RunAs\CurVer
HKCR\Engine.RunAs.1
HKCR\Engine.RunAs.1\CLSID
HKCR\Engine.SearchItem
HKCR\Engine.SearchItem\CLSID
HKCR\Engine.SearchItem\CurVer
HKCR\Engine.SearchItem.1
HKCR\Engine.SearchItem.1\CLSID
HKCR\Engine.Threat
HKCR\Engine.Threat\CLSID
HKCR\Engine.Threat\CurVer
HKCR\Engine.Threat.1
HKCR\Engine.Threat.1\CLSID
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}#AppID
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\LocalServer32
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\LocalServer32#ThreadingModel
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\ProgID
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\Programmable
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\TypeLib
HKCR\CLSID\{020B1227-417D-4682-9AC3-61F43CB5B6B1}\VersionIndependentProgID
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}#AppID
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\LocalServer32
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\LocalServer32#ThreadingModel
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\ProgID
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\Programmable
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\TypeLib
HKCR\CLSID\{125494B2-ACAD-414c-98B9-452F3EF7703A}\VersionIndependentProgID
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}#AppID
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\LocalServer32
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\LocalServer32#ThreadingModel
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\ProgID
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\Programmable
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\TypeLib
HKCR\CLSID\{20A3D913-30EF-4e69-B3F7-93B3F1FB9D5C}\VersionIndependentProgID
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}#AppID
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}\LocalServer32
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}\LocalServer32#ThreadingModel
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}\ProgID
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}\TypeLib
HKCR\CLSID\{3D00A39C-655B-428b-AEB2-2FBA03DCC49C}\VersionIndependentProgID
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}#AppID
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}\LocalServer32
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}\LocalServer32#ThreadingModel
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}\ProgID
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}\TypeLib
HKCR\CLSID\{408F660A-9465-44a3-B557-8709DFD992BC}\VersionIndependentProgID
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}#AppID
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}\LocalServer32
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}\LocalServer32#ThreadingModel
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}\ProgID
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}\TypeLib
HKCR\CLSID\{5F6BBD8A-18CF-4d55-8B4C-C9B4C9328DFE}\VersionIndependentProgID
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}#AppID
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}\LocalServer32
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}\LocalServer32#ThreadingModel
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}\ProgID
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}\TypeLib
HKCR\CLSID\{8C56B6CE-C53F-44c4-9BDC-A9BC1711D05A}\VersionIndependentProgID
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}#AppID
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}\LocalServer32
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}\LocalServer32#ThreadingModel
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}\ProgID
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}\TypeLib
HKCR\CLSID\{8EE6BF73-B370-4d13-9126-EB0071178F2E}\VersionIndependentProgID
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}#AppID
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\LocalServer32
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\LocalServer32#ThreadingModel
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\ProgID
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\Programmable
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\TypeLib
HKCR\CLSID\{97F56E12-C706-4aeb-9FFB-133C05EE5D38}\VersionIndependentProgID
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}#AppID
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}\LocalServer32
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}\LocalServer32#ThreadingModel
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}\ProgID
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}\TypeLib
HKCR\CLSID\{9BB7E700-4E48-476d-B75C-6F47606BE988}\VersionIndependentProgID
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\eklJnzfmdwHC
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\lvdurexvqcdw
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\mzybRvktx
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\Programmable
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\qrpYO
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\tAlxpSCrzlRyM
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\whwAzx
HKCR\CLSID\{C65C3770-598C-A2FD-DBAA-C7A45C50338E}\wneZVyjMvF
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}#AppID
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}\LocalServer32
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}\ProgID
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}\Programmable
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}\TypeLib
HKCR\CLSID\{CBCACA58-1AEE-4600-8CF0-E8B30BFF1535}\VersionIndependentProgID
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}#AppID
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}\LocalServer32
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}\LocalServer32#ThreadingModel
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}\ProgID
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}\TypeLib
HKCR\CLSID\{D6D64CDF-0363-4261-B723-29A3AF365E1D}\VersionIndependentProgID
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}\1.0
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}\1.0\0
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}\1.0\0\win32
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}\1.0\FLAGS
HKCR\TypeLib\{60F94D7D-563E-4942-B5EC-2DE9C135C139}\1.0\HELPDIR
HKCR\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}
HKCR\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}\ProxyStubClsid
HKCR\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}\ProxyStubClsid32
HKCR\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}\TypeLib
HKCR\Interface\{27ED4AC2-B6D8-4079-9831-017A100B391E}\TypeLib#Version
HKCR\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}
HKCR\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}\ProxyStubClsid
HKCR\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}\ProxyStubClsid32
HKCR\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}\TypeLib
HKCR\Interface\{3F6D6C35-FB73-45E6-9473-BB4CC25CE019}\TypeLib#Version
HKCR\Interface\{715D709B-2B10-42FA-A069-297D25D93601}
HKCR\Interface\{715D709B-2B10-42FA-A069-297D25D93601}\ProxyStubClsid
HKCR\Interface\{715D709B-2B10-42FA-A069-297D25D93601}\ProxyStubClsid32
HKCR\Interface\{715D709B-2B10-42FA-A069-297D25D93601}\TypeLib
HKCR\Interface\{715D709B-2B10-42FA-A069-297D25D93601}\TypeLib#Version
HKCR\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}
HKCR\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}\ProxyStubClsid
HKCR\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}\ProxyStubClsid32
HKCR\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}\TypeLib
HKCR\Interface\{872C1B1E-3CF0-4D3A-95E5-A0C662D2854C}\TypeLib#Version
HKCR\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}
HKCR\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}\ProxyStubClsid
HKCR\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}\ProxyStubClsid32
HKCR\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}\TypeLib
HKCR\Interface\{886B1D08-B404-40F0-AA18-4E416682A2E9}\TypeLib#Version
HKCR\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}
HKCR\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}\ProxyStubClsid
HKCR\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}\ProxyStubClsid32
HKCR\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}\TypeLib
HKCR\Interface\{8B5F65CF-0B0A-4291-8DA2-86D7F7B0A6DB}\TypeLib#Version
HKCR\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}
HKCR\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}\ProxyStubClsid
HKCR\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}\ProxyStubClsid32
HKCR\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}\TypeLib
HKCR\Interface\{925B0211-A1C1-4712-8FCA-5F5B8101736D}\TypeLib#Version
HKCR\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}
HKCR\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}\ProxyStubClsid
HKCR\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}\ProxyStubClsid32
HKCR\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}\TypeLib
HKCR\Interface\{B01E37C4-5497-4D58-9FFD-D5653B8DC866}\TypeLib#Version
HKCR\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}
HKCR\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}\ProxyStubClsid
HKCR\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}\ProxyStubClsid32
HKCR\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}\TypeLib
HKCR\Interface\{CCAA201C-C48D-48A8-A1E8-846562CBF1C1}\TypeLib#Version
HKCR\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}
HKCR\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}\ProxyStubClsid
HKCR\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}\ProxyStubClsid32
HKCR\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}\TypeLib
HKCR\Interface\{D483521B-D5CC-43FF-A45A-9BE4A8E6606E}\TypeLib#Version
HKCR\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}
HKCR\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}\ProxyStubClsid
HKCR\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}\ProxyStubClsid32
HKCR\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}\TypeLib
HKCR\Interface\{ED2AFF47-B7BE-4273-A203-C796E87F72D2}\TypeLib#Version
HKCR\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}
HKCR\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}\ProxyStubClsid
HKCR\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}\ProxyStubClsid32
HKCR\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}\TypeLib
HKCR\Interface\{F0FA7ED9-5A0A-4374-B63E-BEBAFD52192E}\TypeLib#Version
HKCR\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}
HKCR\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}\ProxyStubClsid
HKCR\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}\ProxyStubClsid32
HKCR\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}\TypeLib
HKCR\Interface\{F5DEE77C-87EB-4E00-BBF9-8CBF3BDEA7AF}\TypeLib#Version
HKCR\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}
HKCR\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}\ProxyStubClsid
HKCR\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}\ProxyStubClsid32
HKCR\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}\TypeLib
HKCR\Interface\{FB5DDAB7-6AA5-4E97-9541-5A75ADDF4ABA}\TypeLib#Version
HKCR\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}
HKCR\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}\ProxyStubClsid
HKCR\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}\ProxyStubClsid32
HKCR\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}\TypeLib
HKCR\Interface\{FDDF521B-0EBE-4D15-838C-73E2D851161B}\TypeLib#Version
HKCR\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}
HKCR\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}\ProxyStubClsid
HKCR\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}\ProxyStubClsid32
HKCR\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}\TypeLib
HKCR\Interface\{FF609434-EB47-481B-BA0E-1D2B467629A5}\TypeLib#Version
HKCR\AppId\Cerberus.EXE
HKCR\AppId\Cerberus.EXE#AppID

Trojan.SpySheriff
C:\System Volume Information\_restore{94F3C6D5-96CD-4A37-B550-5D59C608811A}\RP372\A0545582.exe
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 7-25-2006 5:31 (GMT +1)    Quote: Spyware and popups on my computer !! HELP!!Alert an admin about: Spyware and popups on my computer !! HELP!!
Superantispyware have done a good job smile


Hijackthis exe can be corrupted, I therefore suggest You download and run this version -
 http://danborg.org/spy/hjt/alternativ.exe
Another name for Hijackthis exe


2 Install it in a PERMANENT folder! Example : c:\hijackthis\

3 Run hijackthis.  (alternativ exe).

Choose the "Do a system scan and save a log file" option to perform your scan.
 
Post new log


Please start your own thread by clicking the new topic button. Do NOT post your problem in someone elses thread.
Do not PM me with logfiles. They will be deleted
 

Back to Top
 
New Topic Post reply to : Spyware and popups on my computer !! HELP!! Printable version of : Spyware and popups on my computer !! HELP!!
 
Forum Information
Currently it is Saturday, November 21, 2009 3:49 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
47 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)