ok 2 hours of scanning later and heres the results....
the message pop ups from avast have stopped(alllleyyyluuuuyaaaaaaaa)
the trojen alert at startup has stopped.
the avg program found 2 infections and heres the log.....
--------------------------------------------------------------------------------------------
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:00:14 PM 11/21/2006
+ Scan result:
C:\WINDOWS\system32\jysoaaaa.exe -> Logger.BZub.fz : Cleaned with backup (quarantined).
C:\WINDOWS\system32\sysvx.exe -> Worm.Locksky.aq : Cleaned with backup (quarantined).
::Report end
----------------------------------------------------------------------------------------------
and heres the hijack log....................
------------------------------------------------------------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 22:34:00, on 21/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00
(7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil
Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware
7.5\guard.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50
727\mscorsvw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI
Technologies\ATI.ACE\CLI.EXE
C:\Program
Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\aseoseyw.exe
C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware
7.5\avgas.exe
C:\Program Files\Mozilla
Firefox\firefox.exe
E:\downloaded programs\registry hook
analizer\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL =
http://go.microsoft....ink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL =
http://go.microsoft....ink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Search Page =
http://go.microsoft....ink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet
Explorer\Main,Start Page =
http://go.microsoft....ink/?LinkId=69157
O2 - BHO: ASP.NET Helper -
{42031715-09B2-3B51-A93F-56C308E48F38} -
C:\WINDOWS\system\ctlvxd32.dll
O2 - BHO: (no name) -
{53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) -
{73364D99-1240-4dff-B12A-67E448373148} -
C:\WINDOWS\system32\ipv6mons.dll
O2 - BHO: SSVHelper Class -
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O4 - HKLM\..\Run: [AudioDeck] C:\Program
Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [ATIPTA] C:\Program
Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SCDEmuApp.exe]
C:\Program Files\PowerISO\SCDEmuApp.exe
O4 - HKLM\..\Run: [avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program
Files\ATI
Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Program
Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [aseoseyw]
C:\WINDOWS\system32\aseoseyw.exe
O4 - HKLM\..\Run: [Zone Labs Client]
"C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware]
"C:\Program Files\Grisoft\AVG Anti-Spyware
7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [aseoseyw]
C:\WINDOWS\system32\aseoseyw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java
Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe
(file missing)
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe
(file missing)
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows
Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL]
International*
O21 - SSODL: WPDShServiceObj -
{AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control
Service (aswUpdSv) - Unknown owner -
C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI
Technologies Inc. -
C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner -
C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown
owner - C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner -
Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe" /service
(file missing)
O23 - Service: avast! Web Scanner -
Unknown owner - C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe" /service
(file missing)
O23 - Service: AVG Anti-Spyware Guard -
Anti-Malware Development a.s. - C:\Program
Files\Grisoft\AVG Anti-Spyware
7.5\guard.exe
O23 - Service: TrueVector Internet Monitor
(vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
-------------------------------------------------------------------------------------------------------------------------------
i cant find anything that relates to the 2 executables that avg found but i dont specialize in this so whats your oppinion?????
by the way i'd like to say a big thanks for the FREE help it is well apreciated.
makes u a v.good person for helping people for nothing. a very rare type to find these days im sad to say.
p.s the resident protection isnt enabled in trial version so i was wondering if its ok to keep avast running at the same time without worrying about program conflicts and what not.
is there any more "preferably free coz im broke" programs that would be usefull to have incase of emergencys???
p.p.s im guessing i can delete the crap out of the 2 infections(and crack a beer open to see them off)
p.p.p.s i will also help a few people in the forums with what i can, (links to all the software im using at the mo and links to info on how to use them. just so everyone nows that i have contributed a little in return.
Edited by skiddyness, 21 November 2006 - 04:45 PM.