Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

p2pnetworking.exe on WinMe ... I can't get rid of it!


  • This topic is locked This topic is locked

#1
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Member
  • PipPip
  • 29 posts
Seriously it's like four am where I am and I just want to sleep but I'm really worried about my computer. My brother was smartly using Limewire on my computer and now I come back to this wonderful p2pnetworking.exe virus. (I uninstalled LimeWire as it kept trying to run itself every other minute) My anti-virus software (AntiVir Classic) found it but can't delete it. And I tried to do all that system restore stuff? But it just confused me. I did a HijackThis log, so if anyone can point me in the right direction to even get started somewhere, that would really really help me. I really want some sleep, lol.

Logfile of HijackThis v1.99.1
Scan saved at 3:57:01 AM, on 12/31/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSMPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\P2PNETWORKING.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\DIT.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\DITEXP.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRAM FILES\COMMON FILES\{3A71120A-0000-1033--POPO0001}\BAR888.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRAM FILES\COMMON FILES\{3A71120A-0000-1033--POPO0001}\BAR888.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CICache] CICache.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [p2p networking] P2PNETWORKING.EXE
O4 - HKLM\..\Run: [{1A71120A-0000-1033--popo0001}] "C:\Program Files\Common Files\{1A71120A-0000-1033--popo0001}\Update.exe" mc-110-12-0000137
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [p2p networking] P2PNETWORKING.EXE
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_06\BIN\SSV.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {CA0B9B6D-C2AF-11D3-B376-0800460222F0} - http://www.iwon.com/...nbar1,0,2,1.cab
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://www.iwon.com/...onpm1,0,2,3.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcaf...can/mcasupd.cab


  • 0

Advertisements


#2
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Tenshi No Reyire

Welcome to G2Go. :whistling:
My name is Kahdah and I will be helping you with your Malware problem.
As I am still in training I will be helping you under supervision of our expert teachers,so there may be a delay between posts.

I will be back with you as soon as possible.
  • 0

#3
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Tenshi No Reyire

I do not see a firewall on your computer please download and install this firewall.
Outpost.

This link will explain how to use firewalls to better understand them Firewall tutorial

**Please print out these instructions or save it to your desktop by using notepad.**


Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).



After that please download the Killbox by Option^Explicit.
Note:In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.


    After that Download Superantispyware save it to your desktop.
    1. Install it and double-click the icon on your desktop to run it.
    2. It will ask if you want to update the program definitions, click Yes.
    3. Under Configuration and Preferences, click the Preferences button.
    4. Click the Scanning Control tab.
    5. Under Scanner Options make sure the following are checked:
    1. Close browsers before scanning
    2. Scan for tracking cookies
    3. Terminate memory threats before quarantining.
    4. Please leave the others unchecked.
    5. Click the Close button to leave the control center screen.

    Close SuperAntiSpyware.

    Download and install CleanUp!
    NOTE: Do NOT run this program if you have XP Professional 64 bit edition. If you're unsure please do not run it!
    .

    Please re-open Hjthis and hit scan only.
    Check the items listed below in HijackThis.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapp...//www.yahoo.com
    O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRAM FILES\COMMON FILES\{3A71120A-0000-1033--POPO0001}\BAR888.DLL
    O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRAM FILES\COMMON FILES\{3A71120A-0000-1033--POPO0001}\BAR888.DLL
    O4 - HKLM\..\Run: [p2p networking] P2PNETWORKING.EXE
    O4 - HKLM\..\Run: [{1A71120A-0000-1033--popo0001}] "C:\Program Files\Common Files\{1A71120A-0000-1033--popo0001}\Update.exe" mc-110-12-0000137
    O4 - HKLM\..\RunServices: [p2p networking] P2PNETWORKING.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {CA0B9B6D-C2AF-11D3-B376-0800460222F0} - http://www.iwon.com/...nbar1,0,2,1.cab
    O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://www.iwon.com/...onpm1,0,2,3.cab


    Now close all windows except HijackThis and click Fix checked then close Hjt.


    Run Killbox
    To do this:
  • Please double-click Killbox.exe to run it. (It is located on your Desktop)
  • Select:
    • "Delete on Reboot
    • then Click on the "All Files" button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

    C:\PROGRAM FILES\COMMON FILES\{3A71120A-0000-1033--POPO0001}
    C:\WINDOWS\SYSTEM\P2PNETWORKING.EXE
    C:\Program Files\Common Files\{1A71120A-0000-1033--popo0001}
    C:\WINDOWS\web\related.htm


  • Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "OK" at any PendingRenameOperations prompt.
If your computer does not restart automatically, please restart it manually

*Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon Posted Image and select alcanshorty.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
After that run Cleanup!
To do this:
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
  • Empty Recycle Bins
  • Delete Cookies
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

It may ask you to log-off/reboot at the end click yes and let it boot into normal Windows.



After that please run SuperAntiSpyware.
To do this:
*double-click the icon on your desktop to run it
*On the main screen, under Scan for Harmful Software click Scan your computer.
*On the left check C:\Fixed Drive.
*On the right, under Complete Scan, choose Perform Complete Scan.
*Click Next to start the scan. Please be patient while it scans your computer.
*After the scan is complete a summary box will appear. Click OK.
*Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click Yes.
To retrieve the removal information for me please do the following:
1. After reboot, double-click the SUPERAntispyware icon on your desktop.
2. Click Preferences. Click the Statistics/Logs tab.
3. Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
4. It will open in your default text editor (such as Notepad/Wordpad).
5. Please highlight everything in the notepad, then right-click and choose copy.
Click close and close again to exit the program.
Save the log information. If needed (still infected) paste this info along with your HijackThis log.


After that please update your Java.
Updating Java and Clearing Cache
[*]Go to Start > Control Panel double-click on the Java Icon (coffee cup) in the Control Panel.
[*]It will say "Java Plug-in" under the icon.
Please find the update button or tab in the Java Control Panel. Update your Java then reboot.
[*]If you are unable to update you can manually update by going here:http://www.java.com/en/download/manual.jsp
[*]After the reboot, go back into the Control Panel and double-click the Java Icon.
[*]Under Temporary Internet Files, click the Delete Files button.
[*]There are three options in the window to clear the cache - Leave ALL 3 CheckedDownloaded Applets
Downloaded Applications
Other Files

[*]Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
[*]Click OK to leave the Java Control Panel.

After that please go HERE to run Panda's ActiveScan
  • (This will only work with Internet Explorer browser)
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
.

After that please post back here with these logs.
*New hjt log
*SuperAntiSpyware log
*Panda Active scan
.
  • 0

#4
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Okay, after I posted that, I shut down my computer and went to sleep. When I got up and turned the compy on this morning, the computer did one of the odd things it had been doing yesterday. It loads partway and then suddendly the screen just goes black. And I know it's not my moniter. So I unplugged everything except the keyboard, mouse and moniter and did get windows to load. But less than a minute after I re-plug in the USB cord for my internet, the screen goes black again. So I'm not sure if I can exactly get online anymore from that computer. I'm replying from my older brother's computer.

Are there any routes I can go without using the internet? Since I got it to work twice yesterday after the screen blackout things, I am going to attempt to get online and go through the procedure, but I am doubtful that it is going to work. I'll check back on this thread from my brother's compy shortly. Thanks for the help so far though. ^^;

  • 0

#5
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Ah, yet another update. It took me about ten minutes to even get windows loaded because it kept freezing, either when I logged into my name on windows or when the ScanDisc thing was running because to turn off the computer when it freezes, I have to pull the powercord out of the back. -_-; So, of course, on time, less than a minute after I plug in the USB cord, the screen goes black and I get nowhere. Is there anyway I can burn the programs to a data CD and install them from there? Windows works okay mainly as long as I don't try to get online with it. -_-;
  • 0

#6
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Using my own advice (LOL) I put the recommended files on a CD-RW from my brother's computer and printed out the directions. I did everything on the list, so here's what happened.

Logfile of HijackThis v1.99.1
Scan saved at 10:07:06 PM, on 12/31/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSMPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\DELAYRUN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\DIT.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\DITEXP.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CICache] CICache.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /service
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\PLUGINS\BROWSERBAR\IE_BAR.DLL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcaf...can/mcasupd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL

SUPERAntiSpyware Scan Log
Generated 12/31/2006 at 09:07 PM

Application Version : 3.4.1000

Core Rules Database Version : 3143
Trace Rules Database Version: 1159

Scan type : Complete Scan
Total Scan Time : 00:38:43

Memory items scanned : 167
Memory threats detected : 0
Registry items scanned : 3656
Registry threats detected : 1
File items scanned : 15472
File threats detected : 5

Adware.180solutions/ZangoSearch
HKU\.DEFAULT\Software\Zango

RelevantKnowledge Spyware Component
C:\WINDOWS\SYSTEM\RK.BIN

Trojan.Freeprod
C:\WINDOWS\SYSTEM\INSTALL.EXE
C:\INSTALL.EXE

Trojan.Hacktool
C:\PROGRAM FILES\COMMON FILES\{1A71120A-0000-1033--POPO0001}\SYSTEM.DLL

Trojan.Update-Mcboo
C:\PROGRAM FILES\COMMON FILES\{1A71120A-0000-1033--POPO0001}\UPDATE.EXE


But ... Panda wouldn't work. o_o; In fact, when it was installing Active X stuff, AntiVir got upset and said something about a virus so ... yeah. ^^; But yey the internet works again! Thanks for your help and I hope you can tell me what else is wrong with my compy? Thank you so much for your time.

  • 0

#7
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Tenshi No Reyire
Looks better. :whistling:

But ... Panda wouldn't work. o_o; In fact, when it was installing Active X stuff, AntiVir got upset and said something about a virus so

Sometimes Panda doesn't work right and Antivir in my opinion is buggy as well.

It appears that you have 2 anti-virus programs installed on your computer.(Antivir and eTrust Internet Security Suite).
These alone can cause system instability.

Unless you have an up to date version of eTrust Internet Security suite then uninstall it.
To do this:
Go to Start>Control Panel>Add\Remove programs >select eTrust and click remove.

If it is up to date and you want to keep it then uninstall AntiVir using the same method as before.

It is of upmost importance that you do this first as it may be causing a sytem slowdown.


After that try this scan.
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Please also I will need you to post a Uninstall list.
To do this:
Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

please post back with these logs.
*Kaspersky online scan
*Uninstall list
*New Hjt log.

  • 0

#8
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
I know you're not supposed to run two Anti-Virus programs at once. I'm not ... eTrust was my old anti-virus but that ran out so I uninstalled it and got Anti-Vir. eTrust doesn't even show up in my Add/Remove programs list. *shrugs*

KASPERSKY ONLINE SCANNER REPORT
Monday, January 01, 2007 2:10:02 PM
Operating System: Microsoft Windows Millennium Edition
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 1/01/2007
Kaspersky Anti-Virus database records: 255410
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
a:\
c:\
m:\
n:\
Scan Statistics
Total number of scanned objects 59449
Number of viruses found 18
Number of infected objects 76 / 0
Number of suspicious objects 0
Duration of the scan process 02:39:28

Infected Object Name Virus Name Last Action
c:\WINDOWS\TEMP\JET9DA5.TMP Object is locked skipped
c:\WINDOWS\SYSTEM\CatRoot\SYSMAST.cbd Object is locked skipped
c:\WINDOWS\SYSTEM\CatRoot\SYSMAST.cbk Object is locked skipped
c:\WINDOWS\SYSTEM\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATMAST.cbd Object is locked skipped
c:\WINDOWS\SYSTEM\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATMAST.cbk Object is locked skipped
c:\WINDOWS\SYSTEM\SBUtils\SBWebCtl.dll Infected: not-a-virus:AdWare.Win32.WindowEnhancer.d skipped
c:\WINDOWS\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
c:\WINDOWS\Sti_Trace.log Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\cert8.db Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\key3.db Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\Cache\_CACHE_MAP_ Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\Cache\_CACHE_001_ Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\Cache\_CACHE_002_ Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\Cache\_CACHE_003_ Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\history.dat Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\formhistory.dat Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Mozilla\Firefox\Profiles\n4icizlv.default\parent.lock Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Aim\ptjsemux\YuuyaxxYanagi\cert8.db Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\Aim\ptjsemux\YuuyaxxYanagi\key3.db Object is locked skipped
c:\WINDOWS\Profiles\Sakura\Application Data\yahoo!\Mail\attach\kiwialphafree.exe/data0026 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
c:\WINDOWS\Profiles\Sakura\Application Data\yahoo!\Mail\attach\kiwialphafree.exe Inno: infected - 1 skipped
c:\WINDOWS\Profiles\Sakura\Cookies\index.dat Object is locked skipped
c:\WINDOWS\Profiles\Sakura\History\History.IE5\index.dat Object is locked skipped
c:\WINDOWS\Profiles\Sakura\History\History.IE5\MSHist012007010120070102\index.dat Object is locked skipped
c:\WINDOWS\wiaservc.log Object is locked skipped
c:\WINDOWS\WIN386.SWP Object is locked skipped
c:\WINDOWS\SchedLog.Txt Object is locked skipped
c:\WINDOWS\Application Data\AntiVir PersonalEdition Classic\LOGFILES\AVGUARD.LOG Object is locked skipped
c:\WINDOWS\Sti_Event.log Object is locked skipped
c:\_RESTORE\TEMP\A0139731.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\TEMP\A0140727.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\TEMP\P2PNET~1.0 Infected: Backdoor.Win32.IRCBot.qc skipped
c:\_RESTORE\TEMP\A0136729.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069241.CPY Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069252.CPY/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069252.CPY Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069254.CPY/WISE0026.BIN/clientax.dll Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069254.CPY/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB/A0069254.CPY Infected: not-a-virus:AdWare.Win32.180Solutions.ao skipped
c:\_RESTORE\ARCHIVE\FS475.CAB CAB: infected - 6 skipped
c:\_RESTORE\ARCHIVE\FS488.CAB/W0086711.CPY Infected: not-a-virus:AdWare.Win32.180Solutions.au skipped
c:\_RESTORE\ARCHIVE\FS488.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS529.CAB/A0071713.CPY/WISE0045.BIN/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.aa skipped
c:\_RESTORE\ARCHIVE\FS529.CAB/A0071713.CPY/WISE0045.BIN/stream Infected: not-a-virus:AdWare.Win32.Softomate.aa skipped
c:\_RESTORE\ARCHIVE\FS529.CAB/A0071713.CPY/WISE0045.BIN Infected: not-a-virus:AdWare.Win32.Softomate.aa skipped
c:\_RESTORE\ARCHIVE\FS529.CAB/A0071713.CPY Infected: not-a-virus:AdWare.Win32.Softomate.aa skipped
c:\_RESTORE\ARCHIVE\FS529.CAB CAB: infected - 4 skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084267.CPY/data0026 Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084267.CPY Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084274.CPY/Acm.dll Infected: not-a-virus:AdTool.Win32.WhenU.i skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084274.CPY/Save.exe Infected: not-a-virus:AdTool.Win32.WhenU.i skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084274.CPY Infected: not-a-virus:AdTool.Win32.WhenU.i skipped
c:\_RESTORE\ARCHIVE\FS626.CAB/A0084282.CPY Infected: not-a-virus:AdWare.Win32.RK.l skipped
c:\_RESTORE\ARCHIVE\FS626.CAB CAB: infected - 6 skipped
c:\_RESTORE\ARCHIVE\FS627.CAB/A0084297.CPY Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
c:\_RESTORE\ARCHIVE\FS627.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS629.CAB/A0084351.CPY Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
c:\_RESTORE\ARCHIVE\FS629.CAB/A0084358.CPY Infected: not-a-virus:AdTool.Win32.WhenU.i skipped
c:\_RESTORE\ARCHIVE\FS629.CAB/A0084359.CPY Infected: not-a-virus:AdTool.Win32.WhenU.i skipped
c:\_RESTORE\ARCHIVE\FS629.CAB CAB: infected - 3 skipped
c:\_RESTORE\ARCHIVE\FS641.CAB/A0086781.CPY Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
c:\_RESTORE\ARCHIVE\FS641.CAB/A0086784.CPY Infected: not-a-virus:AdWare.Win32.RK.l skipped
c:\_RESTORE\ARCHIVE\FS641.CAB CAB: infected - 2 skipped
c:\_RESTORE\ARCHIVE\FS643.CAB/W0107382.CPY Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
c:\_RESTORE\ARCHIVE\FS643.CAB/W0107383.CPY Infected: not-a-virus:AdWare.Win32.RK.k skipped
c:\_RESTORE\ARCHIVE\FS643.CAB CAB: infected - 2 skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0047.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0049.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0050.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0052.BIN Infected: Trojan-Downloader.Win32.Agent.avz skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0053.BIN Infected: Trojan-Downloader.Win32.Agent.avz skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY/WISE0054.BIN Infected: Trojan-Downloader.Win32.Agent.avz skipped
c:\_RESTORE\ARCHIVE\FS894.CAB/A0114382.CPY Infected: Trojan-Downloader.Win32.Agent.avz skipped
c:\_RESTORE\ARCHIVE\FS894.CAB CAB: infected - 7 skipped
c:\_RESTORE\ARCHIVE\FS1128.CAB/A0133813.CPY Infected: Backdoor.Win32.IRCBot.qc skipped
c:\_RESTORE\ARCHIVE\FS1128.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1123.CAB/A0131750.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1123.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1125.CAB/A0132750.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1125.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1129.CAB/A0133824.CPY Infected: not-a-virus:AdWare.Win32.SaveNow.cb skipped
c:\_RESTORE\ARCHIVE\FS1129.CAB/A0133843.CPY Infected: not-a-virus:AdWare.Win32.IWon skipped
c:\_RESTORE\ARCHIVE\FS1129.CAB/A0133846.CPY Infected: not-a-virus:AdWare.Win32.Excite.a skipped
c:\_RESTORE\ARCHIVE\FS1129.CAB/A0133847.CPY Infected: not-a-virus:AdWare.Win32.Excite.a skipped
c:\_RESTORE\ARCHIVE\FS1129.CAB CAB: infected - 4 skipped
c:\_RESTORE\ARCHIVE\FS1132.CAB/A0134220.CPY Infected: Backdoor.Win32.IRCBot.qc skipped
c:\_RESTORE\ARCHIVE\FS1132.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1133.CAB/A0134235.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1133.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1145.CAB/A0135724.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1145.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1147.CAB/A0137723.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1147.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1148.CAB/A0138723.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1148.CAB CAB: infected - 1 skipped
c:\_RESTORE\ARCHIVE\FS1120.CAB/A0130915.CPY Infected: Backdoor.Win32.IRCBot.qc skipped
c:\_RESTORE\ARCHIVE\FS1120.CAB/A0130923.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1120.CAB/A0130927.CPY Infected: Backdoor.Win32.IRCBot.qc skipped
c:\_RESTORE\ARCHIVE\FS1120.CAB CAB: infected - 3 skipped
c:\_RESTORE\ARCHIVE\FS1121.CAB/A0130985.CPY Infected: Trojan-Downloader.Win32.Agent.bca skipped
c:\_RESTORE\ARCHIVE\FS1121.CAB CAB: infected - 1 skipped
c:\_RESTORE\LOGS\vxdsfp.log Object is locked skipped
c:\_RESTORE\LOGS\vxdalt1.log Object is locked skipped
c:\Program Files\Agnitum\Outpost Firewall\op_data.mdb Object is locked skipped
c:\Program Files\Agnitum\Outpost Firewall\op_data.ldb Object is locked skipped
c:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
Scan process completed.

Adaptec DirectCD
Adaptec Easy CD Creator 4
Adaptec UDF Reader
Adobe Acrobat 4.0
Adobe Flash Player 9 ActiveX
Adobe Photoshop 7.0
Agnitum Outpost Firewall Pro
AOL Instant Messenger
Avira AntiVir PersonalEdition Classic
BitTornado 0.3.7
CleanUp!
Combined Community Codec Pack 2006-07-28 (Remove Only)
Core FTP LE 1.3c
DivX
DivX Player
EphPod
Graphics-Pad MD 41217
HijackThis 1.99.1
hp deskjet 930c series
hp deskjet 930c series (Remove only)
hp instant support
HP Memories Disc
Internet Explorer Q916281
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 6
Japanese Language Support
Kaspersky Online Scanner
Korean Language Support
MGI PhotoSuite 8.06 (Remove Only)
Microsoft .NET Framework 1.1
Microsoft Global IME for Japanese
Microsoft Global IME for Korean
Microsoft Internet Explorer 6 SP1 and Internet Tools
Microsoft Money 2000 Standard Edition
Microsoft Outlook Express 6
Microsoft VGX Q833989
Microsoft Web Publishing Wizard 1.6
Microsoft Works 2000
mIRC
Mozilla Firefox (1.5.0.9)
MSN Messenger 7.0
Multi-Card Reader & Flash Disk
MySpaceIM
Nero Digital
Nero OEM
One-touch Multimedia Keyboard
Outlook Express Q837009
Palm Desktop
QuickTime
QuickTime for Windows (32-bit)
Sanyo Utility 5.0
SUPERAntiSpyware Free Edition
Viewpoint Media Player
Winamp (remove only)
Windows Millennium Edition KB891711 Update
Windows Millennium Edition Q823559 Update
WinRAR archiver
Yahoo! Anti-Spy

Logfile of HijackThis v1.99.1
Scan saved at 2:14:09 PM, on 1/1/2007
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSMPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\DIT.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\DITEXP.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\AIM\AIM.EXE
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CICache] CICache.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /service
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\PLUGINS\BROWSERBAR\IE_BAR.DLL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcaf...can/mcasupd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...ebscan_ansi.cab
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL

Once again, thank you for your help.

  • 0

#9
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Tenshi No Reyire
Almost done :whistling:

I see you have BitTornado installed.
This is likely the cause of malware being dropped into your computer as well as Limewire.
See Here for details on P2P file sharing programs.
But this program is optional for you if you choose to want to keep it.

Also I see Viewpoint is installed.I highly recommend you remove this program as well.
See Here for more details on Viewpoint.

Please re-open Hjthis and hit scan only.
Check the items listed below in HijackThis.

O3 - Toolbar: (no name) - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe


Now close all windows except HijackThis and click Fix checked then close Hjt.

Run Killbox
To do this:
[*] Please double-click Killbox.exe to run it. (It is located on your Desktop)
[*] Select:
  • "Delete on Reboot
  • then Click on the "All Files" button.
[*]Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

c:\WINDOWS\SYSTEM\SBUtils
c:\WINDOWS\Profiles\Sakura\Application Data\yahoo!\Mail\attach\kiwialphafree.exe
C:\Program Files\CA


[*] Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
[*]Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "OK" at any PendingRenameOperations prompt.
If your computer does not restart automatically, please restart it manually

*Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Then please go to the Control Panel > Add/Remove Programs and remove the following:
BitTornado 0.3.7 <<<>>At your option for this
J2SE Runtime Environment 5.0 Update 6
Viewpoint Media Player


Close Control Panel.

Using Windows Explorer (to get there right-click your Start button and go to "Explore")
Delete these folders:

C:\Program Files\BitTornado <<At your option
C:\Program Files\Viewpoint

Close windows explorer.

reboot into normal windows.

Delete any tools I had you download
(ie:C:\Killbox,cleanup,Bfu etc...)

***Empty your recycle bin***

Then Clean your restore points

Follow the instructions below to disable System Restore
Disabling System Restore on Windows ME

1. Click Start, Settings, and then click Control Panel.
2. Double-click the System icon. The System Properties dialog box appears.

NOTE: If the System icon is not visible, click "View all Control Panel options" to display it.

3. Click the Performance tab, and then click File System.
4. Click the Troubleshooting tab, and then check Disable System Restore.
5. Click OK. Click Yes, when you are prompted to restart Windows.

****Reboot

Then 1. Click Start, point to Settings, and then click Control Panel.
2. Double-click System, and then click the Performance tab.
3. Click File System, and then click the Troubleshooting tab.
4. Uncheck Disable System Restore.
5. Click OK. Click Yes, when you are prompted to restart Windows.

****Reboot a final time and post back with a new hjt log and let me know of any questions and also let me know how things are running. :blink:
  • 0

#10
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Logfile of HijackThis v1.99.1
Scan saved at 2:06:13 PM, on 1/3/2007
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MSMPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHEDM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\OUTPOST.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\HPSYSDRV.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\KEYBDMGR.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\DIT.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGCTRL.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
C:\WINDOWS\DITEXP.EXE
C:\PROGRAM FILES\NETROPA\ONE-TOUCH MULTIMEDIA KEYBOARD\MMUSBKB2.EXE
C:\HJT\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?.home=ytie
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?.home=ytie
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [Keyboard Manager] C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [HPScanPatch] C:\WINDOWS\SYSTEM\HPScanFix.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Delay] C:\WINDOWS\delayrun.exe
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CICache] CICache.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [avgctrl] "C:\Program Files\AntiVir PersonalEdition Classic\avgctrl.exe" /min
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb04.exe
O4 - HKLM\..\Run: [KodakCCS] C:\WINDOWS\System32\Drivers\KodakCCS.exe
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /waitservice
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
O4 - HKLM\..\RunServices: [schedm] "C:\Program Files\AntiVir PersonalEdition Classic\schedm.exe"
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\outpost.exe /service
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\PROGRAM FILES\SUPERANTISPYWARE\SUPERANTISPYWARE.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRAM FILES\AGNITUM\OUTPOST FIREWALL\PLUGINS\BROWSERBAR\IE_BAR.DLL
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRAM FILES\JAVA\JRE1.5.0_10\BIN\SSV.DLL
O14 - IERESET.INF: START_PAGE_URL=http://hp.my.yahoo.com
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcaf...can/mcasupd.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\PROGRAM FILES\SUPERANTISPYWARE\SASWINLO.DLL

The only problem I have is with shutting down and booting up. Alot of times it won't shut down, it freezes and I have to pull the cord out of the back. And Outpost keeps asking me if I want to shut it off when I'm shutting the computer down and it didn't used to do that. And then when it starts up again it wants to run scandisc since I couldn't shut it down right and usually scandisc takes like four minutes but now it's taking like a half an hour. And even then, sometimes after I log into my windows name, it freezes and I have to go through the process all over again. It's rather frustrating. Do you have any clues? Thank you for all your continuous help.

  • 0

#11
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Hello Tenshi No Reyire

Your log is clean. :help:

Thank you for all your continuous help.

Glad to help.


The only problem I have is with shutting down and booting up. Alot of times it won't shut down, it freezes and I have to pull the cord out of the back. And Outpost keeps asking me if I want to shut it off when I'm shutting the computer down and it didn't used to do that. And then when it starts up again it wants to run scandisc since I couldn't shut it down right and usually scandisc takes like four minutes but now it's taking like a half an hour. And even then, sometimes after I log into my windows name, it freezes and I have to go through the process all over again. It's rather frustrating. Do you have any clues?


I do not think that this issue is malware related.
You could try posting in the Windows 95, 98, ME forum here at G2Go.
They may be able to help.

You could try Here it is a free pc diagnostic test it may help.

As for the slowing and freezing up of your computer I can suggest to run Disk Cleanup and Disk Defragmenter this can help things as far as the optimal performance of your pc.

Disk Cleanup Tutorial
Disk Defragmenter Tutorial

You could also go Here for general computer health for Windows ME.

Your all set. :blink:

The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.

Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

Ad-Aware-Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.

Spyware Blaster - Great prevention tool to keep nasties from installing on your system.

Sywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

Cleanup-Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

Google- Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.

Trillian or Miranda-These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

Castle Cops To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

If you have any further problems please feel free to contact G2Go.:whistling:
  • 0

#12
Tenshi No Reyire

Tenshi No Reyire

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Thank you so much~! I'll definitely look into all your suggestions. I may return next week for some help for my friend's computer because she actually didn't have a virus scanner for a long time, and I'd like to clean it up for her. :whistling: I'll definitely recommend this site to others. *bows* Thanks again!
  • 0

#13
OwNt

OwNt

    Malware Expert

  • Retired Staff
  • 7,457 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :whistling:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP