Please, Please
Since posting my hijack log yesterday, I have done a new virus scan and AVG found about 400 files were affected.
All but 4 were put in the vault. It said they could not be moved
I have tried various other online scans to get it fixed, but AVG resident Shield still pops up and says they are still on pc
Could some kind person please me by having a looksee at my latest HJT report i have just done. I did try to run adaware and spybot, but they both stopped responding before scan could be completed. I have also run CW Shredder.
These 4 entries seems to be where the virus/viruses are according to AVG resident Shield. I am too scared to delete these in case they are essential.
O4 - HKLM\..\RunServices: [APILE32.EXE] C:\WINDOWS\SYSTEM\APILE32.EXE
O4 - HKLM\..\RunServices: [NTES32.EXE] C:\WINDOWS\NTES32.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [APPIT.EXE] C:\WINDOWS\SYSTEM\APPIT.EXE
Thanks
Logfile of HijackThis v1.98.2
Scan saved at 12:40:00, on 27/09/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\orcto.dll/sp.html#28129
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\orcto.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\orcto.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\orcto.dll/sp.html#28129
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\orcto.dll/sp.html#28129
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\orcto.dll/sp.html#28129
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\RunServices: [APILE32.EXE] C:\WINDOWS\SYSTEM\APILE32.EXE
O4 - HKLM\..\RunServices: [NTES32.EXE] C:\WINDOWS\NTES32.EXE
O4 - HKLM\..\RunServices: [ADDCX.EXE] C:\WINDOWS\ADDCX.EXE
O4 - HKLM\..\RunServices: [APPIT.EXE] C:\WINDOWS\SYSTEM\APPIT.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.bto...twebcontrol.cab
O16 - DPF: {C56CE781-A6FC-4706-8B32-6EB4622155DF} (MediaConnect Control) - http://plugin.euro-i...ia.com/mpv0.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {DC187740-46A9-11D5-A815-00B0D0428C0C} - http://ds1.downloadt...pcpowerscan.cab
O16 - DPF: cpcScanner - http://www.crucial.c.../cpcScanner.cab