What has gone wrong?
Microsoft word will not run properly now. It was working fine earlier. Also I cant scan things. I can print etc so coommunication is fine. The applications run fine too but when i try to scan it lets me do a preview and also will start the scan but then it all goes blank and says. This program is not respponding. Or this program has encountered a problem and needs to close!
I would send screen prints of what is happening if i could but it wont let me paste because it just says it has encountered a problem.
Yesterday i ran a program called eraser. Is this the cause?
this program, http://www.heidi.ie/eraser/
I ran this in the belief that it would free what it calls unused disk space. am i wrong?
I have also just remove a virus!! details:
Spyware Scan Details
Start Date: 22/06/2005 14:17:47
End Date: 22/06/2005 14:20:26
Total Time: 2 mins 39 secs
Detected Threats
My Way Speedbar Browser Plug-in more information...
Status: Removed
Moderate threat - Moderate threats may profile users online habits or broadcast data back to a server with 'opt-out' permission. In most cases this type of threat is more along the lines of commercial type adware that offer a premium service in exchange for tracking your user online performance.
Infected registry keys/values detected
HKEY_CLASSES_ROOT\clsid\{014DA6CD-189F-421a-88CD-07CFE51CFF10}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin.1\CLSID {0494D0DB-F8E0-41ad-92A3-14154ECE70AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin.1 My Way Settings Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin\CLSID {0494D0DB-F8E0-41ad-92A3-14154ECE70AC}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin\CurVer MyWayToolBar.SettingsPlugin.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MyWayToolBar.SettingsPlugin My Way Settings Plugin
HKEY_CLASSES_ROOT\clsid\{014DA6CD-189F-421a-88CD-07CFE51CFF10}\InProcServer32 E:\Program Files\MyWay\myBar\2.bin\MYBAR.DLL
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin.1
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin.1\CLSID {0494D0DB-F8E0-41ad-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin.1 My Way Settings Plugin
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin\CLSID {0494D0DB-F8E0-41ad-92A3-14154ECE70AC}
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin\CurVer MyWayToolBar.SettingsPlugin.1
HKEY_CLASSES_ROOT\MyWayToolBar.SettingsPlugin My Way Settings Plugin
is this anything to do with the problem?
Also here is a hjt log.
Logfile of HijackThis v1.99.1
Scan saved at 14:47:01, on 22/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
E:\WINDOWS\System32\SnoopFreeSvc.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\ZoneLabs\vsmon.exe
E:\WINDOWS\SnoopFreeUI.exe
E:\Program Files\Microsoft AntiSpyware\gcasServ.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
E:\WINDOWS\system32\VTTimer.exe
E:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
E:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
E:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Microsoft Office\Office\OSA.EXE
E:\Program Files\12Ghosts\12wash.exe
E:\Program Files\ntl\broadband medic\bin\mpbtn.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\WINDOWS\explorer.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Documents and Settings\Dennis\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://E:\DOCUME~1\Dennis\LOCALS~1\Temp\sp.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://E:\DOCUME~1\Dennis\LOCALS~1\Temp\sp.dll/sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = hwww.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O4 - HKLM\..\Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM\..\Run: [gcasServ] "E:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PrinTray] E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Monitor] E:\PROGRA~1\LEXMAR~1\ACMonitor_X83.exe
O4 - HKLM\..\Run: [Lexmark X83 Button Manager] E:\PROGRA~1\LEXMAR~1\AcBtnMgr_X83.exe
O4 - HKLM\..\Run: [NeroCheck] E:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] E:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - Startup: 12Ghosts Wash.lnk = E:\Program Files\12Ghosts\12wash.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: broadband medic.lnk = E:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: Microsoft Find Fast.lnk = E:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = E:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - E:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - E:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - E:\WINDOWS\System32\SnoopFreeSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
please help because im afraid that if this gets worse maybe my internet explorer will not work and i will then not be able to request assistance.