i have all these "bugs" and i can't get rid of them |
![]() ![]() |
i have all these "bugs" and i can't get rid of them |
May 23 2006, 02:05 PM
Post
#1
|
|
![]() New Member ![]() Posts: 2 OS: windows xp |
troj_tsupdate.g spyw_webhancer.I hktl_prockill.a (this one has alerts going all the time) adw_surfkick.u troj_dloader.atw adw_look2me.y adw_ndotnet.p adw_clcksprng.j pccillin say access denied when the alerts pop up but i can't seem to get rid of them. i've tried to follow some of the step given to other people but i can only do partial steps because most of the step involve the "run" option and everytime i try and use the "run" it wont let me saying they are invalid win32 options or something to that effect....regedit wont work at all.....ticks me off really...thats the major one i can downloaded clean up 4.0 and it didn't do anything...at least not that i could tell....... i downloaded kill box and tried that...deleting files that someone told someone else to delete with a similar problem as me.....i didn't notice any change..... i have hijackthis.....and all these files that other people are suppose to be deleting i dont have any of them.... one site wanted me to download p2pnetwork.zip and run it with a BHF file and i couldn't get those to work either.... i've tried ewido it found 2 items but none that i had listed....and that was after and hour and a half scan....lol aswclr was another program offered to assist in this process of removing these things and nope it didn't here is a copy of what i have tried to do from another user's post.....and it didn't work.....infact my computer is running slower Can you run everything I ask You will probably only need one fix, but run them all to make sure your clean When I ask you too download a zip file, make sure you choose SAVE TO DISK rather than Open Can you open "MyComputer" Double click to open Local Disk C: drive Right click an empty spot and left click NEW>>Folder A new folder will be placed in the C: folder , name it BFU So you now have C:\BFU Download and save p2pnetwork.zip Then UNZIP it to the BFU Folder Download and save and then UNZIP to the BFU folder BFU.zip So you now have BFU.exe extracted ==Download and Install this small program to help clean your temp folders,cookies, etc... Windows Cleanup! 4.0 Don't run it yet ==Download and then Install Ewido Security Suite When installing, under "Additional Options" Uncheck "Install background guard" and "Install scan via context menu". From the main ewido screen, click on Update in the left menu, then click the Start update button. After the update finishes (the status bar at the bottom will display "Update successful") Close out Ewido for now, we'll need it later If for some reason the Updater won't work can you manually download the Updates from this link after you have Ewido installed http://www.ewido.net/en/download/updates/ Please save these instructions to a Notepad file and save it to your Desktop for reference or Print them out! RESTART your Computer into SAFE MODE Open the BFU folder Double click to run BFU.exe Use the "Open Script file" button (the folder icon next to Scriptfile to execute) Navigate to p2pnetwork.bfu in the BFU folder Right click p2pnetwork.bfu and choose Select In Brute Force Uninstaller select Execute Let it finish then Exit Stay in safe mode ==Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: Click "Options..." Move the arrow down to "Custom CleanUp!" Put a check next to the following (Make sure nothing else is checked!): * Empty Recycle Bins * Delete Cookies * Delete Prefetch files * Cleanup! All Users Click OK Press the CleanUp! button to start the program. When it's done, decline to log off or restart the computer ==Open Ewido Security Suite Click on the Scanner button on the left menu Select Complete System Scan *If Ewido finds something it will prompt you with "Infected Object found" Ensure the following are Selected *1. Perform Action = Remove *2. Create Encrypted Backup in Quarantine (Recommended) *3. Perform action with all infections Then click OK When Ewido has finished it's scan click the "Save Report" button Save the report to desktop Exit Ewido Do another scan with Hijackthis and put a check next to these entries: R3 - Default URLSearchHook is missing O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\2.bin\IMESHBAR.DLL O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\2.bin\IMESHBAR.DLL After you have ticked the above entries, close All other open windows Leave Hijackthis open and click FIX CHECKED OK the prompt and exit Hijackthis Restart back to Normal mode --------------------------- ok i'm really hoping that someone can help me.......i'm assuming you'll want a copy of all the reports i can get so here they are............ hijackthis...... Logfile of HijackThis v1.99.1 Scan saved at 2:47:31 PM, on 5/23/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\SYSTEM32\SVCHOST.EXE C:\WINDOWS\SYSTEM32\SPOOLSV.EXE C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE C:\PROGRA~1\TRENDM~1\INTERN~1\TMPFW.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE C:\Documents and Settings\Owner\My Documents\virus protection\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us5.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us5.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us5.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us5.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srch-us5.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us5.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe" O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: Aces Up! by pogo - http://game1.pogo.com/applet-6.6.1.29/aces/aces-en_US.cab O16 - DPF: Backgammon by pogo - http://game1.pogo.com/applet-6.6.2.35/back...ammon-en_US.cab O16 - DPF: Battle Phlinx by pogo - http://game1.pogo.com/applet-6.6.2.21/batt...hlinx-en_US.cab O16 - DPF: Blackjack by pogo - http://game1.pogo.com/applet-6.6.0.27/blac...kjack-en_US.cab O16 - DPF: Bowling by pogo - http://game1.pogo.com/applet-6.6.2.21/bowl...wling-en_US.cab O16 - DPF: Buckaroo Blackjack TM by pogo - http://game1.pogo.com/applet-6.4.4.34/vide...k-ob-assets.cab O16 - DPF: Canasta by pogo - http://game1.pogo.com/applet-6.5.4.34/cana...nasta-en_US.cab O16 - DPF: Checkers by pogo - http://game1.pogo.com/applet-6.4.2.30/chec...s-ob-assets.cab O16 - DPF: Chess by pogo - http://game1.pogo.com/applet-6.5.0.45/ches...2-ob-assets.cab O16 - DPF: Cribbage by pogo - http://game1.pogo.com/applet-6.5.5.36/crib...bbage-en_US.cab O16 - DPF: Dice Derby by pogo - http://game1.pogo.com/applet-6.6.2.21/chec...dflag-en_US.cab O16 - DPF: Dominoes by pogo - http://game1.pogo.com/applet-6.5.5.29/domi...omino-en_US.cab O16 - DPF: Euchre by pogo - http://game1.pogo.com/applet-6.5.0.45/euch...e-ob-assets.cab O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.com/applet-6.6.0.34/firs...lass2-en_US.cab O16 - DPF: Fortune Bingo by pogo - http://game1.pogo.com/applet-6.6.2.21/supe...bingo-en_US.cab O16 - DPF: Greenback Bayou by pogo - http://game1.pogo.com/applet-6.6.2.35/gree...nback-en_US.cab O16 - DPF: Harvest Mania by pogo - http://game1.pogo.com/applet-6.4.4.34/harv...t-ob-assets.cab O16 - DPF: Hearts by pogo - http://game1.pogo.com/applet-6.6.2.21/hear...earts-en_US.cab O16 - DPF: High Stakes Poker by pogo - http://game1.pogo.com/applet-6.5.4.27/draw...poker-en_US.cab O16 - DPF: High Stakes Pool by pogo - http://game1.pogo.com/applet-6.2.2.51/pool...l-ob-assets.cab O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.com/applet-6.6.2.21/jigs...igsaw-en_US.cab O16 - DPF: Jungle Gin by pogo - http://game1.pogo.com/applet-6.6.0.27/gin/gin-en_US.cab O16 - DPF: Lost Temple Poker by pogo - http://game1.pogo.com/applet-6.6.0.27/mhpo...poker-en_US.cab O16 - DPF: Lottso by pogo - http://game1.pogo.com/applet-6.6.2.21/lott...ottso-en_US.cab O16 - DPF: Mah Jong Garden by pogo - http://game1.pogo.com/applet-6.6.0.34/mahj...hjong-en_US.cab O16 - DPF: Payday FreeCell by pogo - http://game1.pogo.com/applet-6.4.1.53/free...l-ob-assets.cab O16 - DPF: Penguin Blocks by pogo - http://game1.pogo.com/applet-6.5.1.24/peng...guins-en_US.cab O16 - DPF: Perfect Pair Solitaire by pogo - http://game1.pogo.com/applet-6.2.5.42/wate...l-ob-assets.cab O16 - DPF: Phlinx by pogo - http://game1.pogo.com/applet-6.6.1.37/flin...inger-en_US.cab O16 - DPF: Pinochle by pogo - http://game1.pogo.com/applet-6.5.2.33/pino...ochle-en_US.cab O16 - DPF: Pop Fu by pogo - http://game1.pogo.com/applet-6.6.0.27/popfu/popfu-en_US.cab O16 - DPF: PoppaZoppa by pogo - http://game1.pogo.com/applet-6.6.0.27/popp...zoppa-en_US.cab O16 - DPF: Poppit by pogo - http://game1.pogo.com/applet-6.6.2.21/popp...ppit2-en_US.cab O16 - DPF: Quick Quack by pogo - http://game1.pogo.com/applet-6.6.0.27/hots...treak-en_US.cab O16 - DPF: QWERTY by pogo - http://game1.pogo.com/applet-6.6.2.35/squa...uares-en_US.cab O16 - DPF: Ride The Tide by pogo - http://game1.pogo.com/applet-6.4.3.36/ride...e-ob-assets.cab O16 - DPF: Showbiz Slots 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/slot...wbiz2-en_US.cab O16 - DPF: Shuffle Bump by pogo - http://game1.pogo.com/applet-6.6.1.29/puck/puck-en_US.cab O16 - DPF: Spades 2 by pogo - http://game1.pogo.com/applet-6.6.1.29/spad...ades2-en_US.cab O16 - DPF: Spades by pogo - http://game1.pogo.com/applet-6.4.4.34/spad...s-ob-assets.cab O16 - DPF: Spider Solitaire by pogo - http://game1.pogo.com/applet-6.6.2.21/spid...pider-en_US.cab O16 - DPF: Squelchies by pogo - http://game1.pogo.com/applet-6.5.4.27/sque...chies-en_US.cab O16 - DPF: Stax by pogo - http://game1.pogo.com/applet-6.5.1.24/stax/stax-en_US.cab O16 - DPF: Stellar Sweeper by pogo - http://game1.pogo.com/applet-6.5.3.37/swee...eeper-en_US.cab O16 - DPF: Sweet Tooth TM by pogo - http://game1.pogo.com/applet-6.6.2.35/swee...tooth-en_US.cab O16 - DPF: Texas Hold'em Poker by pogo - http://game1.pogo.com/applet-6.5.1.24/hold...oldem-en_US.cab O16 - DPF: Tri-Peaks by pogo - http://game1.pogo.com/applet-6.6.1.37/peaks/peaks-en_US.cab O16 - DPF: Tumble Bees by pogo - http://game1.pogo.com/applet-6.6.2.21/jumb...umbee-en_US.cab O16 - DPF: Turbo 21 TM by pogo - http://game1.pogo.com/applet-6.6.0.34/turb...rbo21-en_US.cab O16 - DPF: Wonderland Memories by pogo - http://game1.pogo.com/applet-6.5.3.37/memo...ories-en_US.cab O16 - DPF: Word Whomp by pogo - http://game1.pogo.com/applet-6.6.2.21/word...homp2-en_US.cab O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.com/applet-6.5.3.44/whac...kdown-en_US.cab O16 - DPF: WordJong by pogo - http://game1.pogo.com/applet-6.4.2.30/word...g-ob-assets.cab O16 - DPF: World Class Solitaire by pogo - http://game1.pogo.com/applet-6.4.2.23/worl...s-ob-assets.cab O16 - DPF: Yahoo! Backgammon - http://download.games.yahoo.com/games/clients/y/at1_x.cab O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab O16 - DPF: Yahoo! Hearts - http://download.games.yahoo.com/games/clients/y/ht1_x.cab O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt3_x.cab O16 - DPF: Yahoo! Pinochle - http://download.games.yahoo.com/games/clients/y/ut2_x.cab O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt3_x.cab O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab O16 - DPF: {1A781DED-C22D-4153-3213-A3211E29DF13} (GameDesire Card Games) - http://67.15.101.3/g_bin/eng/cards_2_0_0_63.cab O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (Ganymede Board Games) - http://67.15.101.3/g_bin/eng/boards_2_0_0_20.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1129121054321 O16 - DPF: {83AFB5CA-ED35-11D4-A452-0080C8D85045} (GameDesire Poker Games) - http://67.15.101.3/g_bin/eng/poker_2_0_0_36.cab O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.freedom.net/viruscenter/onlinev...cabs/cssweb.cab O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://www.playfirst.com/play/game/dinerdash/dinerdash.cab O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_...aploader_v6.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe ---- i'm not sure how to get the report from pccillin..... i forgot to save the full scan or ewido but here is what is in quarentine... C:\WINDOWS\Downloaded Program files\cssweb.dll 5/22/2006 medium Adware.cssweb C:\WINDOWS\Downloaded Program files\popcaploader.dll 5/22/2006 high not-a-virus.downloader.win32.popcap.b i've also read to delete everything that is in quarentine........wouldn't that just put them back on my computer? oh yes......i also have adaware...... which never shows any of these things...... i hope someone can help me with this information......if you do need more information please just ask i'll do anything i need to do to make my computer work right again and get these problems fixed!!! thanks again!!!!!!! |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 378 | 3rd February 2006 - 02:16 PM coat12345 started - last by Daemon |
|||||
![]() |
0 / 261 | 15th February 2007 - 07:44 PM Ms Lovely started - last by Ms Lovely |
|||||
![]() |
1 / 267 | 23rd October 2008 - 01:24 PM wth07 started - last by starjax |
|||||
![]() |
1 / 34 | 3rd January 2009 - 05:46 PM M!(H@31 started - last by Neil Jones |
|||||
|
Time is now: 9th January 2009 - 06:17 AM |
| Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. |