just fixed system want to see if its clean [CLOSED] |
![]() ![]() |
just fixed system want to see if its clean [CLOSED] |
Oct 3 2008, 07:43 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
Scan saved at 8:42:00 PM, on 10/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKCU\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1137973561640 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138136544494 O18 - Filter hijack: text/html - (no CLSID) - (no file) O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe -- End of file - 6799 bytes |
|
|
Oct 3 2008, 07:53 PM
Post
#2
|
|
![]() Trusted Helper Posts: 837 From: Massachusetts, USA OS: Vista |
Hello painter1982 and welcome to Geeks to go! My name is Dave and I'll be helping you out with your log. Please be advised that I'm still a trainee here and so my instructions need to be approved by an expert before I post them to you. I've finished looking over your log and should have instructions for you soon, please be patient
- Dave |
|
|
Oct 4 2008, 07:40 AM
Post
#3
|
|
![]() Trusted Helper Posts: 837 From: Massachusetts, USA OS: Vista |
Painter -
Good news: Your HijackThis log is essentially clean. However, there are still a few things you need to take care of: 1. Uninstall extra antivirus programs You're running three antivirus programs - Avast, AVG, and AntiVir. All of these programs are good on their own, but running several at the same time can cause conflicts between the programs which are generally undesirable. Also, having 3 resident antivirus programs active will hog a large amount of your system resources, slowing down your computer. Please choose one of the above programs to keep and uninstall the other two from the Add/Remove Programs menu in your control panel. My recommendation would be AntiVir, as it is the lightest on system resources and has performed the best of the 3 in recent tests. 2. Install a firewall I don't see any firewall installed on your computer. Such a program is your first line of defense in browsing safety, as it will alert you to any attempts to access your computer and allow you to block malicious activity. Comodo, Outpost, and ZoneAlarm. Of these three, I would recommend Comodo as it has been performing the best recently. Ultimately, the choice is yours, and all of them will protect you very well. Please choose one of the above firewalls and install it. If you need any help with the installation process, please let me know. 3. Viewpoint Viewpoint is a media player program that is considered foistware instead of outright malware. It is typically installed without your knowledge, and is generally mistrusted throughout the security community. There are conflicting reports about the extent to which it spies on its users, but it is certainly not good computing practice to have such programs installed on your computer. You're best off to remove any entries that say Viewpoint in them from the Add/Remove Programs menu in your control panel. 4. Update Java Your java is out of date, old version of Java have vulnerabilities that can be exploited by malware. To update it, please download JavaRa to your desktop and unzip it to its own folder
And finally, I'd like you to run a little more in-depth scan to be sure there isn't anything hiding from us: 5. Kaspersky Online Scan Next we need to do an online scan with Kaspersky WebScanner
So perform the steps above, let me know if you need more help with any of them, and post back with the Kaspersky log when you can (It will take a long time to run). - Dave |
|
|
Oct 4 2008, 01:16 PM
Post
#4
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
Thank you for your help. Tried to go and uninstall a few items one being AIM from add remove. When i click remove avast picked up a virus that we deleted but still pops up when we click remove. AIM is still on machine. Here is a new hijack this log along with a screenshot of the warning.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:07:18 PM, on 10/4/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1137973561640 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1138136544494 O18 - Filter hijack: text/html - (no CLSID) - (no file) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe -- End of file - 6875 bytes wont let me upload file. file will be at http://hijackthis.synthasite.com |
|
|
Oct 5 2008, 01:19 PM
Post
#5
|
|
![]() Trusted Helper Posts: 837 From: Massachusetts, USA OS: Vista |
Hi painter -
That avast warning is just a generic detection, nothing serious. 1. Run ATF Cleaner Please download ATF Cleaner by Atribune to your desktop. This tool will clean out your temp files, taking out any malware hiding in them, saving you space, and speeding up our scans. This program is for XP and Windows 2000 only
If you use Firefox browser
If you use Opera browser
Click Exit on the Main menu to close the program. For Technical Support, double-click the e-mail address located at the bottom of each menu. After you have run ATF cleaner, please follow the instructions from my earlier post for uninstalling Viewpoint (and any other programs you wish to remove), updating Java, and running Kaspersky Online Scanner. In your next reply, please post the log from Kaspersky for me to take a look at. - Dave |
|
|
Oct 6 2008, 05:35 PM
Post
#6
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
just got done with the scan. sorry for the delay kinda busy ty for waiting.
Attached File(s)
|
|
|
Oct 7 2008, 03:22 PM
Post
#7
|
|
![]() Trusted Helper Posts: 837 From: Massachusetts, USA OS: Vista |
Hi painter -
We're almost there. Kaspersky has picked up some infected music files, the only place those come from is peer-to-peer file sharing software. I'm sure you know about the legality issues of such programs so I won't dwell on them, but you're also putting your computer at risk when you use them. Many of the programs themselves are infected with malware, and even if your program itself is clean, you're sharing completely uncertified files: anybody can download and upload files through these programs, and it is very easy to become infected. If you wish to continue using p2p programs, you should at least be very very careful about scanning files before you download them and remaining vigilant for any problems. If you wish to remove your p2p programs, please follow these steps: 1. Uninstall Programs You should uninstall any p2p file sharing programs that you're using from the Add/Remove Programs menu in your control panel. Programs like LimeWire and uTorrent and others are the most common, but any programs that are used for file sharing over the internet should be uninstalled. Whether or not you intend to continue using p2p programs, the infected files you've downloaded can't stay. Several infected files were found in the D:\ drive by Kaspersky - is that your CD drive or another hard drive? 2. Delete files using OTMoveIt2 Please download OTMoveIt2 by OldTimer.
Please post back with OTMoveIt report, let me know how the p2p program removal went, and answer my question about the D:\ drive. |
|
|
Oct 7 2008, 05:01 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
sorry did not remove p2p progams before otmoveit. they are used quite common but do right click and scan files b4 use. Yes the D drive is a secondary drive from another system that crashed. Hooked up as slave to c drive. c drive is the sytem file. here is the otmoveit log. if we need to remove the p2p programs to fix this please let me know.
Explorer killed successfully C:\Documents and Settings\kelly\Desktop\My Music\Britney Spears - I love Rock n Roll.mp3 moved successfully. C:\Documents and Settings\kelly\Desktop\My Music\dont want to be a player.mp3 moved successfully. C:\Documents and Settings\kelly\Desktop\My Music\every light in the house is on.mp3 moved successfully. C:\Documents and Settings\kelly\Desktop\My Music\My Boyfriends back The Angels.mp3 moved successfully. File/Folder C:\Documents and Settings\kelly\Desktop\My Music\piece of me.zip not found. C:\hjt\backups\backup-20070719-183207-969.dll unregistered successfully. C:\hjt\backups\backup-20070719-183207-969.dll moved successfully. < Purity > < EmptyTemp > File delete failed. C:\DOCUME~1\kelly\LOCALS~1\Temp\~DF76CC.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~1\kelly\LOCALS~1\Temp\hsperfdata_kelly\3220 scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4d8.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Temp folders emptied. IE temp folders emptied. Explorer started successfully OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 10072008_175415 Files moved on Reboot... C:\DOCUME~1\kelly\LOCALS~1\Temp\~DF76CC.tmp moved successfully. File C:\DOCUME~1\kelly\LOCALS~1\Temp\hsperfdata_kelly\3220 not found! C:\WINDOWS\temp\Perflib_Perfdata_4d8.dat moved successfully. File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found! |
|
|
Oct 7 2008, 05:05 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
Still cannot unistall aim. when i do get the following attached virus report form avast. tried to do no action and everything else but will not uninsatll aim. will post on the websie and post the new address later on give me a bout 2 hours.
|
|
|
Oct 7 2008, 05:08 PM
Post
#10
|
|
|
Member ![]() ![]() Posts: 53 OS: xp media |
|
|
|
Oct 8 2008, 12:01 PM
Post
#11
|
|
![]() Trusted Helper Posts: 837 From: Massachusetts, USA OS: Vista |
Hi painter -
We don't require you to remove your p2p programs here in order for you to be deemed clean, but you do have to know the risks of using them and accept the likely event of reinfection. Also, scanning the files before you use them isn't a guarantee of safety either - you can be infected by the files just by downloading them, you don't have to run them in order for them to do their dirty work. It's odd that ATF Cleaner didn't take care of the file causing that Avast warning - are you sure you ran it exactly as I instructed? Let's try getting at it another way: 1. Delete files using OTMoveIt2
2. Run Malwarebytes' Anti-Malware Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Let me know if you still get that warning when trying to uninstall AIM as well as any other problems you're still having in your next post. Please also post the logs from OTMoveIt and MBAM. - Dave |
|
|
Oct 12 2008, 01:55 PM
Post
#12
|
|
![]() GeekU Teacher Posts: 19,716 From: Dublin OS: XP |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
1 / 201 | 18th May 2005 - 03:43 PM wakasaki started - last by thatman |
|||||
![]() |
5 / 171 | 31st October 2005 - 06:51 AM mannu started - last by Excal |
|||||
![]() |
14 / 388 | 5th February 2006 - 10:13 PM krusader69 started - last by Kat |
|||||
![]() |
2 / 118 | 25th September 2008 - 03:33 PM tripleh started - last by miekiemoes |
|||||