Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Very bigs problems...I struggle against viruses and trojans
   
BullGuard Antivirus Forum > Virus Removal > Removal Tools > Very bigs problems...I struggle against viruses and trojans  
Forum Quick Jump
 
New Topic Post reply to : Very bigs problems...I struggle against viruses and trojans Printable version of : Very bigs problems...I struggle against viruses and trojans
[ << Previous Thread | Next Thread >> ]

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 10-28-2004 4:22 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Hello everydoby
I'am a french man, but I learn english at school. Then, I have succeed in understanding extracts of the others topics, but, unfortunately, I can't undestand all...
To sum up, I have windows XP "familial...home", norton (the last), Zone alarm...I think that It is an exhaustive list.
Well I know that a program ("july14_loader") was installed itself in the recovery part of my computer (C:, and another part of this hard disk, this that I am using, is called D:)
More, I find other "auto-installed" programs, for exemple :
180searchassistant, and other but I can't remember the name.
More, I am convinced that my computer-or the CPU, I don't know,- is very slow.
I have a DSL 512kb whereas internet windows never been too slow to open it.
Recently, I found a trojan, and I believe that I killed/blasted it.
But, I'm not able to know if my computer is clean...
I need you to help me...
Although I understand a lot of sentences in english, do you mind if you answer in a "basical" english....thank you
If you want, I am able to give to you diferents others informations as my problems or my configuration, or other...
Thank you for yours answers and sorry for my probably bad english...
:o))
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 10-28-2004 5:54 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Hey 7mOsmilewinkgrin
My english is´nt to good either, i´m from Denmark;-)
Download this scanner - mwav: http://home9.inet.tele.dk/le01/Sikkerhed.htm  Link nr 7
Activate all in settings, run it
 
Download newest Spybot Search and Destroy here : http://www.safer-networking.org/index.php?page=mirrors if it is not already installed on your computer
Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the Immunize "Scan System" button. When the Check is over, fix all marked with red
 
we need to configure Ad-aware SE for a full scan. Some of them should be enabled by default, while others you will need to set yourself (see below).
Click on the Gear icon (second from the left) to access the preferences/settings window
In the General window make sure the following are selected:
 Automatically save logfile
 Automatically quarantine objects prior to removal
 Safe Mode (always request confirmation)
Click on the Scanning button on the left and select :
 Scan within archives
 Scan active processes
 Scan registry
-Deep-scan registry
 Scan my IE Favorites for banned URLs
 Scan my Hosts file
Under Select drives & folders to scan, choose:
 Select all of your hard drives that are not selected already
Click on the Advanced button on the left and select:
 Include additional object information
Include negligible objects information
Include environment information
Click the Tweak button and select:
Under the Scanning Engine:
Unload recognized processes & modules during scan
Under the Cleaning Engine:Let Windows remove files in use at next reboot
Click on Proceed to save the settings.
Click Start and on the next screen choose:
 Use custom scanning options

Click Next and Ad-aware will scan your hard drive(s) with the options you have selected.
Save the log file when it asks and then click Finish.
When finished, mark everything for removal and get rid of it. (Right-click on any of the entries and choose Select All from the drop down menu and click Next).
Plug-Ins for Ad-Aware (VX2 Cleaner)
Download the free VX2 Cleaner here :  http://www.lavasoftusa.com/software/addons/vx2cleaner.shtml

Close Ad-Aware SE build 1.04 and Ad-Watch (if running)
Install the VX2 Cleaner
Start Ad-Aware SE build 1.04
Go to “Plug-ins”
Select the VX2 Cleaner plug-in and click “Run Plugin”
If your computer isn’t infected, click “Close”.

If your computer is infected:

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer

Cwshredder :
http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
 
Unzip to own folder,check for updates if needed, close all other windows-Fix


Delete files/folder from the following directories (But not the directory itself, for example delete all files/folder IN temp.
C:\Windows\Temp\
C:\Documents and Settings\<Your Profile>\Local Settings\Temp\
C:\Documents and Settings\<All other users Profile>\Local Settings\Temp\
C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\
 <<<This will delete your files in your internet cache--including cookies.
C:\Documents and Settings\<All other users Profile>\Local Settings\Temporary Internet Files\
Empty your "Recycle Bin"


There are usally a couple of files that you will not be able to delete..this is normal.

Reboot, and tell  how things are running.



Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 10-28-2004 9:51 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Thanks... I print this and I try your idea....
I take the results to you...
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 10-29-2004 9:56 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Hello mister Touch....and the others,of course
I had used your solution, and it is good, but I have enough others problems, as :
Programs who are running slowly : when I look at a film on my computer, or when I play with a game, the first half hour, I can use its, but after, I can see more moments very slows, and that is bad for a normal using (I am not sure of my last sentence)
More, I have a firewall and Norton : why this spybots and others viruses can coming on my computer?
Other thing : Can I keeping the installers of the using programs (adaware, cwshredder....
And the applications?
Other question, Can I install an autoconnect for the DSL or is it dangerous? Because I want to help search and I have another program : SETI@t hom, and my computer and my DSL line are always open...
And to finish : do you want a list of the programs infected or another thing....

But to sum up, my computer is not tha same than before your help...thank you for this and I hope that you can help me yet.
ThanX
7mO
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 10-29-2004 10:50 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Hey.
It was many questions;-)
1. Install Ccleaner: http://www.ccleaner.com/
it can be a lot of junk, crap and Temp files, there slow down your system.
And defrag-open My Computer, rightclick on C-drive-properties?
 
2. Let´s see a hijackthis log.
Download Hijackthis
http://www.download.com/3001-8022_4-10307556.html?idl=n
Do NOT run Hijack This from the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT. Scan, scan button change to-save log. Post log here
 
If no one else look to it, i´ll be back sunday evening;-)
 
If i may suggest? Deactive Norton, and install AVG:
My opinion about Norton, it is more or less useless!


Touch

Member of - Alliance of Security Analysis Professionals

Post Edited (Touch) : 10/29/2004 8:52:47 AM GMT

Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 10-29-2004 3:48 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Logfile of HijackThis v1.97.7
Scan saved at 15:42:01, on 29/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
D:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
D:\WINDOWS\System32\wuauclt.exe
D:\WINDOWS\system32\qttask.exe
D:\Program Files\ACE Mega CoDecS Pack\Media Player Classic\RealPlay.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\SETI@home\SETI@home.exe
D:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Program Files\eMule\emule.exe
D:\PROGRA~1\Netscape\NETSCA~1\Netscp.exe
D:\Documents and Settings\Renaud\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.fr"); (D:\Documents and Settings\Renaud\Application Data\Mozilla\Profiles\default\3m1pvuz6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CNetscape_France.src"); (D:\Documents and Settings\Renaud\Application Data\Mozilla\Profiles\default\3m1pvuz6.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Microsoft DirectX] PDSched.exe
O4 - HKLM\..\Run: [Microsoft Update Machine] winupdt.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [U9] D:\documents and settings\renaud\local settings\temp\U9.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [RealTray] D:\Program Files\ACE Mega CoDecS Pack\Media Player Classic\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [Msn Updater] windatemanager.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft DirectX] PDSched.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "D:\Program Files\Netscape\Netscape 6\Netscp.exe" -turbo
O4 - HKCU\..\Run: [seticlient] D:\Program Files\SETI@home\SETI@home.exe -min
O4 - Global Startup: DSLMON.lnk = D:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche (HKLM)
O12 - Plugin for .PDF: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: PackageHtmlCab - http://acces.blonde.com/package/PackageHtmlCab.CAB
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
O16 - DPF: {23912BB0-CC9F-4C69-83D4-19C2B183BA91} - http://ns-radio.netscape.com/radio/cabs/radiox.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/Sasser/20/SassCln.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{61B5A9DB-42F3-4F12-9991-282F9EE0F690}: NameServer = 80.118.192.110 80.118.196.36

Ok...but it is not a file that I put on D:Programme files/HJT, it a shortcurt...Is it good?
I have clicked on Fix too...
Here...
I hope that can be using by you....
And felicitations for your more exhaustive help...
7mO
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 10-31-2004 3:39 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Scan with Hijacktis, close all other windows, put a checkmark to these, and fix:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
O4 - HKLM\..\Run: [Microsoft Update Machine] winupdt.exe
O4 - HKLM\..\Run: [U9] D:\documents and settings\renaud\local settings\temp\U9.exe
O4 - HKLM\..\RunServices: [Msn Updater] windatemanager.exe
O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/france.exe
 
 
Reboot into Safe Mode (hit F8 key until menu shows up).
Find and delete:
D:\documents and settings\renaud\local settings\temp\U9.exe
winupdt.exe >>>>Start-Search
windatemanager.exe>>>>Start-Search
 
Reboot, and tell how things are running. I don´t need more log´s;-)


Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-2-2004 6:01 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Ok, I am to doing that, but...what mean the URL?
I do not understand what I can Do with these...
Others things are OK...
Thank you for your answer...
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-2-2004 6:34 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
I have doig that you want, but I have not find these files :
D:\document and setting\renaud\local settings\temp\U9.exe = It do not exist !
winupdt.exe = I have done the search, but It can't be found
To finish, I have erased another file : not windatemanager.exe, but windatemanager.exe-up
Here are my work.
I hope your help.
ThanX
7mO
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 11-2-2004 6:48 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Seems to be your log is clean;-)
 
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-4-2004 10:34 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
All is OK...
But maybe you can help to me again...
I have a fire wall, and it "ask" to me if I let differents programs to go on the net...
I know that Nescape, and the others programs who contains system can go to the net, but others?
For exemple, "application gateway service" or U9 or others...
What can I do about these?
TX
Otherwise, I can see messages : program downloader agent S trojan....and others sentences or words that I can't remember....
Here...
Thank you and sorry for these news problems
7mO
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 11-5-2004 10:24 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
About Firewall, you´ll have to try, if you deny for a program, and you cant use the net, it should be allowed.
application gateway service:
Description: This process is running only on the Windows XP operating system. It deals with ICF (Internet Connection Firewall) and ICS (Internet Connection Sharing) system process and also looks after some processes in the network.
It shall be allowed!
Where do you see the Trojan messages?
No need to be sorry;-)


Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-6-2004 9:31 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Well, when I am at school, I let my computer runing.
And this message can be seen when I am on the net or, and this is very strange, when I AM NOT ON THE NET too...
If I "cut" my connexion, this message can be seen too...
As I can to go to school today (this morning), I let turn on my computer, and I put on this forum the exact message for the trojan downloader.
More, I want to put on this forum all the applications who need an intrenet accès to ask to you if I can let it turn on, or if I can to disagree with my firewall...
Thanks
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 11-6-2004 10:30 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Weirdconfused
Post a new hijackthis log file;-)



Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-6-2004 2:25 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
The exact message was :
"Virus trojan horse downloader.purityscan.E
is found in file D:\System volume information\_restore{468EDC65-34A7-4083-B78B-B1F57E0D8A13}\RP134\A0069581.exe
To remove this virus, please run AVG for Windows"

I wanted to show to you this message.
Now, I'll do a new hijackthis and I put the log....
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-6-2004 2:28 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Logfile of HijackThis v1.97.7
Scan saved at 13:31:02, on 06/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\PROGRA~1\Grisoft\AVG6\avgserv.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\qttask.exe
D:\Program Files\ACE Mega CoDecS Pack\Media Player Classic\RealPlay.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Messenger\msmsgs.exe
D:\Program Files\Netscape\Netscape 6\Netscp.exe
D:\Program Files\UnH Solutions\Browser Sentinel\BrowserSentinel.exe
D:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe
D:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
D:\Program Files\SpywareGuard\sgmain.exe
D:\Program Files\SpywareGuard\sgbhp.exe
D:\WINDOWS\System32\wuauclt.exe
D:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.neuf.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.netscape.fr"); (D:\Documents and Settings\Renaud\Application Data\Mozilla\Profiles\default\3m1pvuz6.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://D%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CNetscape_France.src"); (D:\Documents and Settings\Renaud\Application Data\Mozilla\Profiles\default\3m1pvuz6.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - D:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft DirectX] PDSched.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [RealTray] D:\Program Files\ACE Mega CoDecS Pack\Media Player Classic\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG_CC] D:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft DirectX] PDSched.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "D:\Program Files\Netscape\Netscape 6\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Browser Sentinel] "D:\Program Files\UnH Solutions\Browser Sentinel\BrowserSentinel.exe" -autorun
O4 - Startup: SpywareGuard.lnk = D:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: DSLMON.lnk = D:\Program Files\modem ADSL USB\modem ADSL USB\DSLMON.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche (HKLM)
O12 - Plugin for .PDF: D:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: PackageHtmlCab - http://acces.blonde.com/package/PackageHtmlCab.CAB
O16 - DPF: {23912BB0-CC9F-4C69-83D4-19C2B183BA91} - http://ns-radio.netscape.com/radio/cabs/radiox.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/fr/games3.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/Sasser/20/SassCln.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{61B5A9DB-42F3-4F12-9991-282F9EE0F690}: NameServer = 80.118.192.111 80.118.196.36

Good luck....TX
7mO
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 11-6-2004 3:04 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Ok;-)
 
Disable System Restore
 
Run AVG and Spybot. Reboot, enable System restore again.
 
Nothing to see in the log.


Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-6-2004 4:33 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
OK. I have done all that you want.
To continue, here it is the programs founded ; maybe its can help you...
MediaPlex
Advertising.com
Avenue A,Inc
Double click
DSO exploit
Hit box.

I want talk to you about CClean who found always files... It is normal???
More, I do not know what doing about my firewall...
I accept connexion with nescape, of course, and I refuse messenger, but I do not know what doing about Generic host process for Win32 services (I think that I can let it go on the net, cause If I Do not let it, I can't go on the net...)
and about Spooler sub system...I disagree with his access, but I do not know really...
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-6-2004 9:59 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
I remember now, sorry, but Is an autoconnect a good thing?
I want to use ADSL autoconnect for my internet connexion.
Is it a risk for the viruses or the trojans?
But as I am using a program who need to internet connexion.
Of course I can remove it...
Thanks....
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-9-2004 11:56 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
???
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 17352
 
   Posted 11-9-2004 12:08 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Did´nt you get a mail from me?


Touch
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 11-13-2004 11:06 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Ok, I have got receive it.....thanks
And very good job on my computer cause I can using it.....
Sometime to time, I do Ccleaner.....
And I can confirm that AVG is a super AV...lol
TX
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 12-10-2004 1:07 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Hello touch'
You help was very precious for me....but I think that I am a new time infected by a trijan/virus.
My computer run very slowly, I can send information on the net.....and a lot of another things....
I have not any idea....
Can you help me please???
Can I put a new log???
If yes, can you put the link.....
thanks...
7mO
Back to Top
 

7mO
New Member


Date Joined Oct 2004
Total Posts : 30
 
   Posted 12-13-2004 11:50 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
To finish, I had used Kazaa to download files, and it was afeter that I had used it that I "meet" viruses...
I do not know what dsoing about its...
Thanks for your help...
Back to Top
 

Spiffy.Helper
New Member


Date Joined Nov 2004
Total Posts : 26
 
   Posted 12-18-2004 6:35 (GMT +2)    Quote: Very bigs problems...I struggle against viruses and trojansAlert an admin about: Very bigs problems...I struggle against viruses and trojans
Kazaa is what is bringing in these viruses. Talk to touch about that.
Back to Top
 
New Topic Post reply to : Very bigs problems...I struggle against viruses and trojans Printable version of : Very bigs problems...I struggle against viruses and trojans
 
Forum Information
Currently it is Friday, July 30, 2010 2:28 PM (GMT +2)
There are a total of 79.134 posts in 17.897 threads.
In the last 3 days there were 8 new threads and 53 reply posts. View Active Threads
Who's Online
This forum has 31950 registered members. Please welcome our newest member, Willow.
19 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Updates more than 6 days old - BG advised upgrade from v8.7 to v9.0 to solve problem (4)30-07-2010 11:44:42 (Alex S.)
Redirect Virus Mozilla (10)30-07-2010 11:03:56 (tanisstray)
Redirected to different sites from links on Google (3)30-07-2010 09:36:16 (Touch)
Iexplore.exe virus causing problems (18)30-07-2010 09:32:14 (Touch)
9.1 is running! (10)30-07-2010 09:15:55 (katrina0)