Happy New year. Malware and adware, plz help [RESOLVED], loaded with falkag, casalemedia, casino, riverbelle |
![]() ![]() |
Happy New year. Malware and adware, plz help [RESOLVED], loaded with falkag, casalemedia, casino, riverbelle |
Jan 2 2006, 12:22 PM
Post
#1
|
|
|
New Member ![]() Posts: 7 OS: Windows xp pro |
Here is my hijack this log. Thanks for your help and Happy New Year. Logfile of HijackThis v1.99.1 Scan saved at 11:14:33 AM, on 02/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\00THotkey.exe C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\Program Files\ltmoh\Ltmoh.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\TFNF5.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\install.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\RAMASST.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Mark\Desktop\Highjackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TOSHIBA Picture Enhancement Utility] C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MyVBApp] C:\WINDOWS\install.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1122045278033 O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{20292AF6-41E7-4C5E-A204-76926463BE79}: NameServer = 200.44.32.12,200.44.32.13 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe |
|
|
Jan 5 2006, 07:14 AM
Post
#2
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Hi cogeme22,
First, download and install CleanUp! but do not run it yet. *NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups. Please download Ewido Security Suite (do NOT run it yet!)
Once in Safe Mode: Open HijackThis and click Scan. Put a check next to this: O4 - HKLM\..\Run: [MyVBApp] C:\WINDOWS\install.exe Close all other windows except HijackThis and click Fix Checked. After that, find and delete this file: C:\WINDOWS\install.exe Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: Click "Options..." Move the arrow down to "Custom CleanUp!" Put a check next to the following (Make sure nothing else is checked!):
Press the CleanUp! button to start the program. If Cleanup! asks if you want to reboot, click NO Open Ewido
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Reboot back to normal mode. Please do an online scan with Kaspersky WebScanner Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
Then please post a new HijackThis log, the Ewido log, and Kaspersky results. |
|
|
Jan 5 2006, 09:55 AM
Post
#3
|
|
|
New Member ![]() Posts: 7 OS: Windows xp pro |
Armodeluxe, Hope your holidays were good. Thank you for your quick reply and tech. expertise.
Few things I'd like to mention before posting. 1st) Yesterday AVG popped up and said I had a virus in the file you mentioned. O4 - HKLM\..\Run: [MyVBApp] C:\WINDOWS\install.exe ( C:\WINDOWS\install.exe.) I allowed it to delete the file, went through and verified it was deleted, then performed another scan. So the file could be found on the computer when doing the scans you've requested. 2nd) My computer has been running considerably slower since the pop ups first appeared. When you have time and are sure the pc is clean, could you please make some recommendations to regain performance? 3rd) Approx. a week ago, the pc stopped recognizing new documents. (word, excel) I used to make a document and name it. Now when I attempt to it warms me that without the file extension (.doc, .xls) the file may not open properly. So I have to type in "name".doc. With all the scans and deletion of files I think I screwed it up. How can I fix this? 4th) I've highlighted a couple of things in the HJT file. The iolo system mechanic. (O23 - Service: iolo System Guard ) A program I installed after researching, tested and then deleted. Completely or so I thought. I've allowed HJT to remove this key about 6 times but it keeps coming back, and I can find no other file with a search. How do I remove this completely from my pc? What is ehome, nwiz.exe, andWUWebControl Class? Sorry, know you're busy and understand if you don't have time to answer, just curious. HJT report Logfile of HijackThis v1.99.1 Scan saved at 8:43:21 AM, on 05/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\system32\00THotkey.exe C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\TFNF5.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Apoint2K\Apntex.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\RAMASST.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Mark\Desktop\Highjackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [b]O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet[/b] O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TOSHIBA Picture Enhancement Utility] C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122045278033 O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{20292AF6-41E7-4C5E-A204-76926463BE79}: NameServer = 200.44.32.12,200.44.32.13 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe Ewido Report --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 7:58:22 AM, 05/01/2006 + Report-Checksum: A43470BD + Scan result: No infected objects found. ::Report End Kasp report ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Thursday, January 05, 2006 08:41:09 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 5/01/2006 Kaspersky Anti-Virus database records: 169290 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 41326 Number of viruses found: 0 Number of infected objects: 0 Number of suspicious objects: 0 Duration of the scan process: 1525 sec No malware has been detected. The sections that have been scanned are CLEAN. Scan process completed. [u][u] Again, thanks for help. |
|
|
Jan 6 2006, 08:13 AM
Post
#4
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Since the scans came clean, I have to ask, do you have any malware related problems left now? (like popups, redirection etc.)
To answer your questions, To improve performance, visit this page and follow the recommendations there: http://safety.live.com/site/en-US/default.htm QUOTE Approx. a week ago, the pc stopped recognizing new documents. (word, excel) I used to make a document and name it. Now when I attempt to it warms me that without the file extension (.doc, .xls) the file may not open properly. So I have to type in "name".doc. With all the scans and deletion of files I think I screwed it up. How can I fix this? Open My Computer. Go to Tools > Folder Options Under the View tab is "Hide extentions for known file types" unchecked? If so, see if putting a check next to that solves this issue. QUOTE What is ehome, nwiz.exe, andWUWebControl Class? The ehome entries belong to Windows XP Media_Center_Edition 2005. nwiz.exe: Associated with the newer versions of nVidia graphics cards drivers. Allows you to immensely improve desktop layouts by setting preferences and optimizations. O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1122045278033 You can see what that is by looking at the url associated with it. To rid of iolo service: Go to Start > Run and type "Services.msc" (without quotes) then hit Ok Scroll down and find the below service: iolo System Guard (IOLO_SRV) When you find it, double-click on it. In the next window that opens, under the General tab click the Stop button, then click the drop-down box to change the Startup Type to Disabled. Now hit Apply and then Ok. Then delete the C:\Program Files\iolo folder if it wasn't deleted already. Next: Open HiJackThis, click on "None of the above, just start the program". Now, click on the "Config" button (bottom right), then click on "Misc Tools", then click on "Delete an NT Service" a window will pop up. Enter the below item into that field (make sure there are NO spaces before or after the name): IOLO_SRV Click OK. It should pull up information about the service, then ask if you want to reboot. Click YES. Post a new HiJackThis log after it reboots and let me know if you received any error messages. |
|
|
Jan 6 2006, 10:39 AM
Post
#5
|
|
|
New Member ![]() Posts: 7 OS: Windows xp pro |
Armodeluxe
Since the scans and everything yesterday, I haven't had a pop-up, so THANK YOU very much. I'm curious as to what happened though as I have done all this and more using cleanup, webroot, ewido, and others, both in safe mode and normal, numerous times over the last two weeks, and kept getting malware, expecially the falkag. I won't look a gifthorse in the mouth though, so to speak. I went to http://safety.live.com/site/en-US/default.htm and went through everything. Not much was found. 3000kb of space. While the pc isn't exactly sluggish, it's still running slower then it normally does. Any other suggestons? Checking "hide known file extensions" worked perfectly. Again, thank you and reps. And thank you for the explainations. I had looked at the url associated with it, but wasn't quite sure. Your suggestion for removing iolo worked perfectly. Can't thank you enough. Here's the latest log. Logfile of HijackThis v1.99.1 Scan saved at 9:18:35 AM, on 06/01/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\system32\00THotkey.exe C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\Apoint2K\Apoint.exe C:\Program Files\TOSHIBA\TouchED\TouchED.Exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe C:\Program Files\ltmoh\Ltmoh.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Apoint2K\Apntex.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\WINDOWS\system32\TFNF5.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\Logitech\MouseWare\system\em_exec.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\RAMASST.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Mark\Desktop\Highjackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TOSHIBA Picture Enhancement Utility] C:\Program Files\TOSHIBA\TOSHIBA Picture Enhancement Utility\TosPEHK.exe O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - https://scan.safety.live.com/resource/downl...lscbase3401.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1122045278033 O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{20292AF6-41E7-4C5E-A204-76926463BE79}: NameServer = 200.44.32.12,200.44.32.13 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe Out of curosity, which programs do you highly recommend for virus control and protection from adware, spyware, trojans etc? As I mentioned, I'm currently using AVG, spybot, ad-aware, microsoft antispyware, and tweaknow regcleaner. Obviously it wasn't enough. Thanks again for everything, I really appreciate your time and expert advice. Take care. |
|
|
Jan 7 2006, 09:13 AM
Post
#6
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
When you posted here probably all it was left was to pick up the remnants, most of the cleaning were done with the previous scans you performed. The programs you are using are the best of the free ones. You can keep Ewido as well, after the trial is over you still can update and scan with it, the only thing missing will be realtime protection. Keep in mind that there is no such thing as fullproof protection, malware is always one step ahead since these programs use signatures and a new malware is added to the database only after it is detected and analized. You can find some additional programs below.
For further on performance, adding RAM wouldn't hurt. Also check a few things. Right click on My Computer and choose Properties. Under hardware open the Device Manager and look for any problems there. If any of the drivers need updating, update. Under Advanced click on Performance Settings. In Performance Options click Advanced and see if your Virtual Memory is set to 1.5 times your actual RAM. If not change it to that value. Ie, if you have a 512 Ram, Virtual Memory should be about roughly 760. Also the below quote is from an article on performance, see if it applies to you. QUOTE If you've ever had a network with more than one computer, you probably found it useful to share files between the computers by mapping a network drive. Network drives allow one computer to read and write files to another computer's hard disk as if it were directly connected. I use network drives all the time, and for me, they were the most significant source of slowness. The problem with network drives is that Windows XP will attempt to connect to the network drives when Windows starts. If the remote computers don't respond immediately, Windows will wait patiently. Additionally, some programs will attempt to connect to the network drives when you browse for files and folders. If you've ever tried to open a file and had to wait several seconds (or minutes!), it's probably because the program was trying to establish a network connection—even if the file you are opening is on your local computer. I am not as patient as Windows, and I'd rather not wait for unused network connections to respond. To reduce this problem, disconnect any unused drives by following these steps: 1.Open My Computer. 2.On the Tools menu, click Disconnect Network Drive. 3.Select the network drives that you no longer need, and then click OK. After I disconnected the network drives on my computer, my computer was able to restart in 1 minute, 45 seconds—about 40% faster! By the way, please go to Windows Update immediately. Just yesterday a patch was released for a very serious vulnerability. Now let's reset your restore points. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK. Please take the following into consideration to maintain a clean computer. Visit Windows Update regularly to get the latest security updates.You can also enable automatic updates.Your antivirus software and antispyware programs should also be updated regularly. Make a habit of running scans on a timely basis. Be careful about what you download, scan every file before clicking on it. Additional programs to consider: Spywareblaster Prevents the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted software.Blocks spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.Restricts the actions of potentially unwanted sites in Internet Explorer. Spywareguard An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware! IE/Spyad Adds a list of malicious sites to your Restricted Sites Zone. Firefox An alternate browser safer than IE A good article to read: So how did I get infected in the first place? Regards, Armodeluxe |
|
|
Jan 7 2006, 12:47 PM
Post
#7
|
|
|
New Member ![]() Posts: 7 OS: Windows xp pro |
Hi Armodeluxe, I know you're busy, and I honestly appreciate the help so I will keep this as short as possible.
The programs you are using are the best of the free ones Then would it be better to go to programs that have to be bought? For further on performance, adding RAM wouldn't hurt. Currently running 1G of ram. Virtual memory is at 2048mb.. Should be good. Pc is 8months old. Toshiba Qosmio. Was fast up until two weeks ago.. Something with the adware/malware.. Haven't figured it out yet.. No problems in Device manager. I keep all drivers and Bios up to date monthly. And I go to windows update weekly as well as having auto update enabled. Downloaded the update as soon as it was posted. Antivirus and antispyware programs are run daily if I'm using the internet on a regular basis. Check for new updates before I run scans with each program. Also the below quote is from an article on performance, see if it applies to you. I read the quote some time ago in an article. I have a network at home, but am currently working in Venezuela outside of a network. Turned it off when I came down. Now let's reset your restore points. Good idea or bad? I turn system restore off. As most virus/malware/trojans usually install a file in that folder making it even more difficult to remove I started deactivating it. I know it doesn't use much disk space, but I like to keep as much free space as possible, and I carry all disks just in case something does goes wrong. Perhaps I'm wrong in my thinking?? Additional programs to consider: How would these programs work in conjunction with the ones I'm currently using? (spybot, ad-aware, microsoft and AVG) I've considered using Firefox before but didn't know much about it. Is it that much better thin IE? I noticed spyad doesn't mention anything about supporting firefox, only IE. unless I missed it. Do the other programs work with firefox? A good article to read: very informative article. Found it while trying to research falkag and pay pop up a few weeks ago when I first became infected and was trying to find some information on where files were installed and how to get rid of them. Again I thank you for your help. Take care and all the best. cogeme22 |
|
|
Jan 8 2006, 08:13 AM
Post
#8
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Well, performance is in fact beyond my field, I suggest you post in the Windows or Internet forums and the staff members there may be more helpful in that area than me.
If you are willing to pay a price, there are better alternatives of course, but again none of those programs are fullproof, so I would go on with the free ones instead. If you are willing to pay, for an antivirus I would suggest Kaspersky or NOD32. The antispyware programs are fine, as good as the paid ones. We always suggest against turning off System Restore, with the arguement that an infected restore point is better than none in case you may have to use that feature someday. What you can do is frequently reset the points and you may still have a good point you can go back to. QUOTE How would these programs work in conjunction with the ones I'm currently using? (spybot, ad-aware, microsoft and AVG) I've considered using Firefox before but didn't know much about it. Is it that much better thin IE? I noticed spyad doesn't mention anything about supporting firefox, only IE. unless I missed it. Do the other programs work with firefox? Spywareblaster integrates and works fine with Firefox. The advantage of Firefox over IE is that it doesn't use Activex which is one of the most common infection methods. Also you have in the options to turn off java and javascript, there are even advanced settings to turn off certain features of javascript. IESpyad adds a list of malicious sites to IE's restricted sites zone, so it doesn't work with Firefox. Another approach that will work with Firefox would be to use a hosts file. That way when you try to connect to a site listed in the hosts file a redirection is made to your local ip adress and you can't connect. Here is the best one: http://mvps.org/winhelp2002/hosts.htm I wish you some safe surfing. |
|
|
Jan 13 2006, 08:40 AM
Post
#9
|
|
|
Member 2k Posts: 2,744 OS: Windows XP SP2 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
![]() ![]() |