Welcome Guest ( Log In | Register )

      
Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide.
 
Closed TopicStart new topic
just fixed system want to see if its clean [CLOSED]
painter1982
post Oct 3 2008, 07:43 PM
Post #1


Member
**
Posts: 53
OS: xp media



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:42:00 PM, on 10/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1137973561640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138136544494
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 6799 bytes
Go to the top of the page
 
+Quote Post
Transience
post Oct 3 2008, 07:53 PM
Post #2


Trusted Helper
Group Icon
Posts: 837
From: Massachusetts, USA
OS: Vista



Hello painter1982 and welcome to Geeks to go! My name is Dave and I'll be helping you out with your log. Please be advised that I'm still a trainee here and so my instructions need to be approved by an expert before I post them to you. I've finished looking over your log and should have instructions for you soon, please be patient smile.gif.

- Dave
Go to the top of the page
 
+Quote Post
Transience
post Oct 4 2008, 07:40 AM
Post #3


Trusted Helper
Group Icon
Posts: 837
From: Massachusetts, USA
OS: Vista



Painter -

Good news: Your HijackThis log is essentially clean. However, there are still a few things you need to take care of:

1. Uninstall extra antivirus programs

You're running three antivirus programs - Avast, AVG, and AntiVir. All of these programs are good on their own, but running several at the same time can cause conflicts between the programs which are generally undesirable. Also, having 3 resident antivirus programs active will hog a large amount of your system resources, slowing down your computer. Please choose one of the above programs to keep and uninstall the other two from the Add/Remove Programs menu in your control panel. My recommendation would be AntiVir, as it is the lightest on system resources and has performed the best of the 3 in recent tests.

2. Install a firewall

I don't see any firewall installed on your computer. Such a program is your first line of defense in browsing safety, as it will alert you to any attempts to access your computer and allow you to block malicious activity. Comodo, Outpost, and ZoneAlarm. Of these three, I would recommend Comodo as it has been performing the best recently. Ultimately, the choice is yours, and all of them will protect you very well. Please choose one of the above firewalls and install it. If you need any help with the installation process, please let me know.

3. Viewpoint

Viewpoint is a media player program that is considered foistware instead of outright malware. It is typically installed without your knowledge, and is generally mistrusted throughout the security community. There are conflicting reports about the extent to which it spies on its users, but it is certainly not good computing practice to have such programs installed on your computer. You're best off to remove any entries that say Viewpoint in them from the Add/Remove Programs menu in your control panel.

4. Update Java

Your java is out of date, old version of Java have vulnerabilities that can be exploited by malware. To update it, please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts. A log will appear (JavaRa.log), please post the contents of this log on the forum.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


And finally, I'd like you to run a little more in-depth scan to be sure there isn't anything hiding from us:

5. Kaspersky Online Scan

Next we need to do an online scan with Kaspersky WebScanner

  1. Click the link above to the Kaspersky website.
  2. Read through the requirements and privacy statement and click on Accept button.
  3. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  4. When the downloads have finished, click on Settings.
  5. Make sure the following is checked.
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  6. Click on My Computer under Scan.
  7. Once the scan is complete, it will display the results. Click on View Scan Report.
  8. You will see a list of infected items there. Click on Save Report As....
  9. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  10. Please post this log in your next reply.


So perform the steps above, let me know if you need more help with any of them, and post back with the Kaspersky log when you can (It will take a long time to run).

- Dave
Go to the top of the page
 
+Quote Post
painter1982
post Oct 4 2008, 01:16 PM
Post #4


Member
**
Posts: 53
OS: xp media



Thank you for your help. Tried to go and uninstall a few items one being AIM from add remove. When i click remove avast picked up a virus that we deleted but still pops up when we click remove. AIM is still on machine. Here is a new hijack this log along with a screenshot of the warning.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:07:18 PM, on 10/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1137973561640
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138136544494
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 6875 bytes


wont let me upload file. file will be at http://hijackthis.synthasite.com
Go to the top of the page
 
+Quote Post
Transience
post Oct 5 2008, 01:19 PM
Post #5


Trusted Helper
Group Icon
Posts: 837
From: Massachusetts, USA
OS: Vista



Hi painter -

That avast warning is just a generic detection, nothing serious.

1. Run ATF Cleaner

Please download ATF Cleaner by Atribune to your desktop. This tool will clean out your temp files, taking out any malware hiding in them, saving you space, and speeding up our scans.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

After you have run ATF cleaner, please follow the instructions from my earlier post for uninstalling Viewpoint (and any other programs you wish to remove), updating Java, and running Kaspersky Online Scanner. In your next reply, please post the log from Kaspersky for me to take a look at.

- Dave
Go to the top of the page
 
+Quote Post
painter1982
post Oct 6 2008, 05:35 PM
Post #6


Member
**
Posts: 53
OS: xp media



just got done with the scan. sorry for the delay kinda busy ty for waiting.


Attached File(s)
Attached File  kapersky_scan.txt ( 1.91K ) Number of downloads: 13
 
Go to the top of the page
 
+Quote Post
Transience
post Oct 7 2008, 03:22 PM
Post #7


Trusted Helper
Group Icon
Posts: 837
From: Massachusetts, USA
OS: Vista



Hi painter -

We're almost there.

Kaspersky has picked up some infected music files, the only place those come from is peer-to-peer file sharing software. I'm sure you know about the legality issues of such programs so I won't dwell on them, but you're also putting your computer at risk when you use them. Many of the programs themselves are infected with malware, and even if your program itself is clean, you're sharing completely uncertified files: anybody can download and upload files through these programs, and it is very easy to become infected. If you wish to continue using p2p programs, you should at least be very very careful about scanning files before you download them and remaining vigilant for any problems.

If you wish to remove your p2p programs, please follow these steps:

1. Uninstall Programs
You should uninstall any p2p file sharing programs that you're using from the Add/Remove Programs menu in your control panel. Programs like LimeWire and uTorrent and others are the most common, but any programs that are used for file sharing over the internet should be uninstalled.

Whether or not you intend to continue using p2p programs, the infected files you've downloaded can't stay. Several infected files were found in the D:\ drive by Kaspersky - is that your CD drive or another hard drive?

2. Delete files using OTMoveIt2

Please download OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the text inside the box below to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    CODE
    [kill explorer]
    C:\Documents and Settings\kelly\Desktop\My Music\Britney Spears - I love Rock n Roll.mp3
    C:\Documents and Settings\kelly\Desktop\My Music\dont want to be a player.mp3
    C:\Documents and Settings\kelly\Desktop\My Music\every light in the house is on.mp3
    C:\Documents and Settings\kelly\Desktop\My Music\My Boyfriends back       The Angels.mp3
    C:\Documents and Settings\kelly\Desktop\My Music\piece of me.zip
    C:\hjt\backups\backup-20070719-183207-969.dll
    Purity
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post back with OTMoveIt report, let me know how the p2p program removal went, and answer my question about the D:\ drive.
Go to the top of the page
 
+Quote Post
painter1982
post Oct 7 2008, 05:01 PM
Post #8


Member
**
Posts: 53
OS: xp media



sorry did not remove p2p progams before otmoveit. they are used quite common but do right click and scan files b4 use. Yes the D drive is a secondary drive from another system that crashed. Hooked up as slave to c drive. c drive is the sytem file. here is the otmoveit log. if we need to remove the p2p programs to fix this please let me know.

Explorer killed successfully
C:\Documents and Settings\kelly\Desktop\My Music\Britney Spears - I love Rock n Roll.mp3 moved successfully.
C:\Documents and Settings\kelly\Desktop\My Music\dont want to be a player.mp3 moved successfully.
C:\Documents and Settings\kelly\Desktop\My Music\every light in the house is on.mp3 moved successfully.
C:\Documents and Settings\kelly\Desktop\My Music\My Boyfriends back The Angels.mp3 moved successfully.
File/Folder C:\Documents and Settings\kelly\Desktop\My Music\piece of me.zip not found.
C:\hjt\backups\backup-20070719-183207-969.dll unregistered successfully.
C:\hjt\backups\backup-20070719-183207-969.dll moved successfully.
< Purity >
< EmptyTemp >
File delete failed. C:\DOCUME~1\kelly\LOCALS~1\Temp\~DF76CC.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\kelly\LOCALS~1\Temp\hsperfdata_kelly\3220 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4d8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10072008_175415

Files moved on Reboot...
C:\DOCUME~1\kelly\LOCALS~1\Temp\~DF76CC.tmp moved successfully.
File C:\DOCUME~1\kelly\LOCALS~1\Temp\hsperfdata_kelly\3220 not found!
C:\WINDOWS\temp\Perflib_Perfdata_4d8.dat moved successfully.
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
Go to the top of the page
 
+Quote Post
painter1982
post Oct 7 2008, 05:05 PM
Post #9


Member
**
Posts: 53
OS: xp media



Still cannot unistall aim. when i do get the following attached virus report form avast. tried to do no action and everything else but will not uninsatll aim. will post on the websie and post the new address later on give me a bout 2 hours.
Go to the top of the page
 
+Quote Post
painter1982
post Oct 7 2008, 05:08 PM
Post #10


Member
**
Posts: 53
OS: xp media



just uploaded pic cause i seen u was online. here is the link.

http://hijackthis.synthasite.com
Go to the top of the page
 
+Quote Post
Transience
post Oct 8 2008, 12:01 PM
Post #11


Trusted Helper
Group Icon
Posts: 837
From: Massachusetts, USA
OS: Vista



Hi painter -

We don't require you to remove your p2p programs here in order for you to be deemed clean, but you do have to know the risks of using them and accept the likely event of reinfection. Also, scanning the files before you use them isn't a guarantee of safety either - you can be infected by the files just by downloading them, you don't have to run them in order for them to do their dirty work.

It's odd that ATF Cleaner didn't take care of the file causing that Avast warning - are you sure you ran it exactly as I instructed? Let's try getting at it another way:

1. Delete files using OTMoveIt2
  • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
  • Copy the text in the code box below to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    CODE
    [kill explorer]
    D:\Documents and Settings\Owner\My Documents\My Music\dont want to be a player.mp3
    D:\Documents and Settings\Owner\My Documents\My Music\every light in the house is on.mp3
    D:\Documents and Settings\Owner\My Documents\My Music\My Boyfriends back       The Angels.mp3
    C:\Documents and Settings\kelly\Local Settings\Temp\nsw7.tmp
    Purity
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

2. Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Let me know if you still get that warning when trying to uninstall AIM as well as any other problems you're still having in your next post. Please also post the logs from OTMoveIt and MBAM.

- Dave
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 12 2008, 01:55 PM
Post #12


GeekU Teacher
Group Icon
Posts: 19,716
From: Dublin
OS: XP



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members: