I *thought* my system clean - but evidently it isn't |
![]() ![]() |
I *thought* my system clean - but evidently it isn't |
Jul 31 2006, 02:03 PM
Post
#1
|
|
|
New Member ![]() Posts: 1 OS: XP |
Adaware; CCleaner; Ewido; Avast Virus Cleaner Tool; Spybot; Stinger2; CWShredder and Kill2Me, plus the Bit Defender and Panda online scans. Having gone through all of the above (in varying orders and repeatedly) I was left with 2 problems which wouldn't be fixed: a) Ewido reported 2 Trojan.DNSChangers in my registry, which subsequently I killed using Alcanshorty and Fixwareout b) An entry for Wurldmedia and Pipas .exe files reported and killed by Spybot but which recur quite frequently and therefore may not be as dead as I'd like to believe. So apart from (b), above, all these cleaners report me as 'clean': but something's still wrong, as I'm still not achieving problem-free browsing: almost, but not quite. Every now and then I'm being re- or mis-directed to a blank or unwanted webpage - not to any disturbing extent, but still evidence that things aren't quite right. I've cross-checked my own Hijack Log against Google as best I can, but if anyone could glance at the attached I would be very grateful. There are a few items on the list that I'm suspicious of. Thanks Logfile of HijackThis v1.99.1 Scan saved at 21:06:52, on 31/07/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\htpatch.exe C:\WINDOWS\System32\pctspk.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files - Gubbins\ewido anti-spyware 4.0\guard.exe c:\Program Files\Microsoft SQL Server\MSSQL$PROFORM_RACING\Binn\sqlservr.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files - Gubbins\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files - Gubbins\ewido anti-spyware 4.0\ewido.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\Program Files\NETGEAR\WG511v2\wlancfg5.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Programs - Gubbins\GoZilla\Go.exe C:\PROGRA~2\FIREFOX.EXE C:\Program Files\Outlook Express\MSIMN.EXE C:\die [bleep] die\hijack folder\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tgaf.gothere.uk.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files - Gubbins\WS_FTP Pro\wsbho2k0.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PR051D~1\FlashGet\jccatch.dll O2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Programs - Gubbins\GoZilla\GoIEHlp.dll O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [Go!Zilla dial-up fix] "C:\Program Files\Programs - Gubbins\GoZilla\Go.exe" /FIXRAS O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~2\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files - Gubbins\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [!ewido] "C:\Program Files - Gubbins\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\System32\msconfig.exe /auto O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: NETGEAR WG511v2 Wireless Assistant.lnk = ? O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PR051D~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PR051D~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\System32\shdocvw.dll O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1152970994203 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{E95016E4-EA8C-47A2-9DB9-CF2774D31704}: NameServer = 85.255.116.20,85.255.112.215 O17 - HKLM\System\CCS\Services\Tcpip\..\{F5333EF7-ACAC-4BBA-B0E4-C89460D6062E}: NameServer = 85.255.116.20 85.255.112.215 O17 - HKLM\System\CCS\Services\Tcpip\..\{F965506A-E636-4569-AAFB-607E5BAF2DDD}: NameServer = 85.255.116.20,85.255.112.215 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files - Gubbins\ewido anti-spyware 4.0\guard.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 658 | 1st July 2008 - 02:07 PM magusbuckley started - last by emapis |
|||||
![]() |
8 / 443 | 11th June 2008 - 09:47 AM sandman423 started - last by greyknight17 |
|||||
![]() |
9 / 225 | 26th September 2008 - 04:51 PM scottb started - last by Rorschach112 |
|||||
![]() |
4 / 323 | 12th November 2008 - 09:00 PM Bus Stop Messiah started - last by Broni |
|||||
|
Time is now: 7th January 2009 - 12:29 PM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |