Help please : keep getting "Your computer is infected!" |
![]() ![]() |
Help please : keep getting "Your computer is infected!" |
Jan 11 2006, 01:36 AM
Post
#1
|
|
|
New Member ![]() Posts: 2 OS: Windows Xp |
seems i installed spyware striker . i removed it from add/remove programs. i also used i dont know how many spyware removal programs, none of them worked. one showed 59 problems and solved them, but it's still the same. by the way, i deleted nvctrl.exe, mssearchnet.exe, mscornet.exe, sa1, sa2.exe etc from system32, etc and some .dll files. Here is my hijack this log. Logfile of HijackThis v1.99.1 Scan saved at 1:30:55 AM, on 1/12/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\hijack this\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [GW Port Controller] C:\Program Files\Samsung\SmarThru\PORTCTRL.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{26EBD7A4-4ABC-458F-9F56-6709645C058D}: NameServer = 202.79.32.35 202.79.32.33 O17 - HKLM\System\CS1\Services\Tcpip\..\{26EBD7A4-4ABC-458F-9F56-6709645C058D}: NameServer = 202.79.32.35 202.79.32.33 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe Help please, thank you in advance. |
|
|
Jan 12 2006, 02:36 PM
Post
#2
|
|
|
Retired Staff Posts: 5,661 OS: Windows |
Hi mulrav and Welcome to GeekstoGo!
Download WinPFind: http://www.bleepingcomputer.com/files/winpfind.php Right Click the Zip Folder and Select "Extract All" Don't use it yet Download Spyware-Strike-Removal.exe from Here Double Click Spyware-Strike-Removal.exe and click run tool, then reboot your computer. Reboot into SAFE MODE(Tap F8 when restarting) Here is a link on how to boot into Safe Mode: http://service1.symantec.com/SUPPORT/tsgen...src=sec_doc_nam From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan" It will scan the entire System, so please be patient One you see "Scan Complete"-> a log (WinPFind.txt) will be automatically generated in the WinPFind folder Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> type in MSCONFIG -> click OK! Under the "General" Tab Make Sure "Normal Startup-load all device drivers and services" has a green tick by it Click Apply->Close->Follow the Prompts to Restart Restart Normal and have the PC Scanned here: Panda Active Scan You will need to be using Internet Explorer for the Scan to work Save the Report it generates Post back with a fresh HijackThis log and the reports from WinPFind and Panda |
|
|
Jan 12 2006, 09:02 PM
Post
#3
|
|
|
New Member ![]() Posts: 2 OS: Windows Xp |
hi,
i just deleted the "wiatwain.dll" file from system32 folder(one of my friend told me), and the problem is solved, i now dont get that "infected" message, anyway, thank you very much for your trouble. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
9 / 1,727 | 5th July 2005 - 09:30 PM Spotted Dog started - last by Trevuren |
|||||
![]() |
35 / 1,712 | 4th November 2008 - 04:08 AM m2008 started - last by kahdah |
|||||
![]() |
20 / 677 | 22nd October 2008 - 03:43 AM vincel3489 started - last by kahdah |
|||||
![]() |
15 / 526 | 15th November 2008 - 01:23 PM Azn started - last by Egwene |
|||||
|
Time is now: 1st December 2008 - 04:48 PM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |