Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Malware on My Computer Please Help [CLOSED]


  • This topic is locked This topic is locked

#1
whokiid

whokiid

    Member

  • Member
  • PipPip
  • 11 posts
I went through the Beginner's Steps and I'm still having problems. Pop-ups keep shootin up on my desktop and I don't know what I should do. If anyone could help me, I would appreciate it.

Here's my HijackThis Log:

Logfile of HijackThis v1.99.1
Scan saved at 4:49:28 PM, on 10/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\TrojanHunter 4.2\TrojanHunter.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Documents and Settings\whokiid\Desktop\My Stuff\Setup Files\virus removal\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ziPPAD] "C:\Program Files\InetGet2\CP.GH2.exe" /SHUN /PC=CP.GH2 /SHUN /PC=CP.GH2
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /auto
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-58-12-0000137.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [fqfi] C:\PROGRA~1\COMMON~1\fqfi\fqfim.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000137.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\n6n60g5se6.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: CWShredder Service - InterMute, Inc. - C:\Documents and Settings\whokiid\Desktop\My Stuff\Setup Files\virus removal\cwshredder.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
  • 0

Advertisements


#2
Rawe

Rawe

    Visiting Staff

  • Member
  • PipPipPipPipPipPipPip
  • 4,746 posts
Hello and welcome.. :)

Please download WebRoot SpySweeper from HERE (It's a 2 week trial):
  • Click the Free Trial link under to "SpySweeper" to download the program.
  • Install it. Once the program is installed, it will open.
  • It will prompt you to update to the latest definitions, click Yes.
  • Once the definitions are installed, click Options on the left side.
  • Click the Sweep Options tab.
  • Under What to Sweep please put a check next to the following:
    • Sweep Memory
    • Sweep Registry
    • Sweep Cookies
    • Sweep All User Accounts
    • Enable Direct Disk Sweeping
    • Sweep Contents of Compressed Files
    • Sweep for Rootkits
    • Please UNCHECK Do not Sweep System Restore Folder.
  • Click Sweep Now on the left side.
  • Click the Start button.
  • When it's done scanning, click the Next button.
  • Make sure everything has a check next to it, then click the Next button.
  • It will remove all of the items found.
  • Click Session Log in the upper right corner, copy everything in that window.
  • Click the Summary tab and click Finish.
  • Paste the contents of the session log you copied into your next reply. To reply, hit the Add Reply -button. :tazz:

Edited by Rawe, 08 November 2005 - 01:22 PM.

  • 0

#3
whokiid

whokiid

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
********
8:08 PM: | Start of Session, Tuesday, November 08, 2005 |
8:08 PM: Spy Sweeper started
8:08 PM: Sweep initiated using definitions version 569
8:08 PM: Starting Memory Sweep
8:10 PM: Memory Sweep Complete, Elapsed Time: 00:02:05
8:10 PM: Starting Registry Sweep
8:10 PM: Found Adware: maxifiles
8:10 PM: HKCR\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829231)
8:10 PM: HKCR\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829237)
8:10 PM: HKCR\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829241)
8:10 PM: HKCR\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829253)
8:10 PM: HKLM\software\classes\typelib\{fff24f28-3ae2-46cd-aebe-2f625133a1ca}\ (9 subtraces) (ID = 829282)
8:10 PM: HKLM\software\classes\iecatcher.iewebcatcher\ (5 subtraces) (ID = 829292)
8:10 PM: HKLM\software\classes\iecatcher.iewebcatcher.1\ (3 subtraces) (ID = 829298)
8:10 PM: HKLM\software\classes\clsid\{fff4e223-7019-4ce7-be03-d7d3c8cce884}\ (11 subtraces) (ID = 829302)
8:10 PM: Found Adware: targetsaver
8:10 PM: HKU\S-1-5-21-73586283-1004336348-839522115-1003\software\tsl2\ (1 subtraces) (ID = 143616)
8:10 PM: Registry Sweep Complete, Elapsed Time:00:00:08
8:10 PM: Starting Cookie Sweep
8:10 PM: Found Spy Cookie: adknowledge cookie
8:10 PM: whokiid@adknowledge[2].txt (ID = 2072)
8:10 PM: Found Spy Cookie: adserver cookie
8:10 PM: whokiid@adserver[1].txt (ID = 2141)
8:10 PM: Found Spy Cookie: atwola cookie
8:10 PM: whokiid@atwola[1].txt (ID = 2255)
8:10 PM: Found Spy Cookie: azjmp cookie
8:10 PM: whokiid@azjmp[2].txt (ID = 2270)
8:10 PM: Found Spy Cookie: casalemedia cookie
8:10 PM: whokiid@casalemedia[1].txt (ID = 2354)
8:10 PM: Found Spy Cookie: rn11 cookie
8:10 PM: whokiid@rn11[2].txt (ID = 3261)
8:10 PM: Found Spy Cookie: statcounter cookie
8:10 PM: whokiid@statcounter[2].txt (ID = 3447)
8:10 PM: Found Spy Cookie: www.maxifiles cookie
8:10 PM: whokiid@www.maxifiles[1].txt (ID = 3707)
8:10 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
8:10 PM: Starting File Sweep
8:10 PM: Found Trojan Horse: trojan downloader matcash
8:10 PM: c:\program files\common files\inetget2 (1 subtraces) (ID = -2147471395)
8:10 PM: c:\program files\common files\inetget (ID = -2147477182)
8:10 PM: Found Adware: apropos
8:10 PM: c:\documents and settings\whokiid\local settings\temp\~compoundinst0 (1 subtraces) (ID = -2147481413)
8:11 PM: a0008700.exe (ID = 69312)
8:11 PM: a0008713.exe (ID = 69312)
8:13 PM: 113_dollarrevenue_4_0_3_9[1].exe (ID = 166444)
8:13 PM: tsupdate[1].ini (ID = 112322)
8:14 PM: glf11f0glf11f0.exe (ID = 166444)
8:14 PM: a0005037.exe (ID = 69312)
8:16 PM: Found Adware: look2me
8:16 PM: a0008343.exe (ID = 168558)
8:16 PM: a0008342.exe (ID = 166444)
8:16 PM: class-barrel (ID = 78229)
8:17 PM: a0008727.dll (ID = 163672)
8:17 PM: a0008734.exe (ID = 156275)
8:17 PM: a0008735.exe (ID = 156275)
8:17 PM: a0008708.dll (ID = 163672)
8:18 PM: a0008556.dll (ID = 156271)
8:18 PM: fqfic.dll (ID = 78253)
8:19 PM: a0008495.dll (ID = 156271)
8:20 PM: autoit3.exe (ID = 119348)
8:21 PM: mc-58-12-0000137.exe.tcf (ID = 156275)
8:21 PM: mc-58-12-0000137.exe.tcf (ID = 156275)
8:21 PM: a0006042.exe (ID = 114256)
8:21 PM: a0006043.exe (ID = 114256)
8:21 PM: a0008726.exe (ID = 114260)
8:21 PM: a0008346.dll (ID = 69301)
8:21 PM: vocabulary (ID = 78283)
8:21 PM: a0008676.dll (ID = 156271)
8:21 PM: a0008701.dll (ID = 156271)
8:21 PM: a0008523.dll (ID = 156271)
8:22 PM: a0008598.dll (ID = 156271)
8:22 PM: mv2ol9f31.dll (ID = 163672)
8:22 PM: a0008345.dll (ID = 156267)
8:23 PM: x.bmp (ID = 69314)
8:23 PM: cwebpage.dll (ID = 69301)
8:24 PM: maxifilesdns[1].zip (ID = 69314)
8:37 PM: File Sweep Complete, Elapsed Time: 00:26:49
8:37 PM: Full Sweep has completed. Elapsed time 00:29:08
8:37 PM: Traces Found: 112
8:44 PM: Removal process initiated
8:44 PM: Quarantining All Traces: look2me
8:44 PM: Quarantining All Traces: trojan downloader matcash
8:44 PM: Quarantining All Traces: apropos
8:44 PM: Quarantining All Traces: maxifiles
8:44 PM: maxifiles is in use. It will be removed on reboot.
8:44 PM: mc-58-12-0000137.exe.tcf is in use. It will be removed on reboot.
8:44 PM: Quarantining All Traces: targetsaver
8:44 PM: Quarantining All Traces: adknowledge cookie
8:44 PM: Quarantining All Traces: adserver cookie
8:44 PM: Quarantining All Traces: atwola cookie
8:44 PM: Quarantining All Traces: azjmp cookie
8:44 PM: Quarantining All Traces: casalemedia cookie
8:44 PM: Quarantining All Traces: rn11 cookie
8:44 PM: Quarantining All Traces: statcounter cookie
8:44 PM: Quarantining All Traces: www.maxifiles cookie
8:44 PM: Removal process completed. Elapsed time 00:00:43
********
8:06 PM: | Start of Session, Tuesday, November 08, 2005 |
8:06 PM: Spy Sweeper started
8:07 PM: Your spyware definitions have been updated.
8:08 PM: | End of Session, Tuesday, November 08, 2005 |
  • 0

#4
Rawe

Rawe

    Visiting Staff

  • Member
  • PipPipPipPipPipPipPip
  • 4,746 posts
Good job, can you post a fresh HijackThis log please :tazz:
  • 0

#5
whokiid

whokiid

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Logfile of HijackThis v1.99.1
Scan saved at 10:54:10 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\CursorXP\CursorXP.exe
C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\DesktopX.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\whokiid\Desktop\My Stuff\Setup Files\virus removal\HijackThis.exe

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /auto
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [D-Link AirPlus XtremeG] C:\Program Files\D-Link\AirPlus XtremeG\AirPlusCFG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
O4 - HKCU\..\Run: [DesktopX] "C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\DesktopX.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
  • 0

#6
Rawe

Rawe

    Visiting Staff

  • Member
  • PipPipPipPipPipPipPip
  • 4,746 posts
  • Open HiJackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and paste the List from the notebook onto your post :tazz:

  • 0

#7
whokiid

whokiid

    Member

  • Topic Starter
  • Member
  • PipPip
  • 11 posts
Ad-Aware SE Personal
Adobe Reader 6.0.1
AirPlus XtremeG
ANIO Service
ANIWZCS2 Service
AOL Instant Messenger
Athlon 64 Processor Driver
avast! Antivirus
AVI Codec Pack
AVI Movie Player
Battlefield 2™
BitLord 1.1
BitTorrent 4.0.4
Creative DVD Audio Plugin for Audigy Series
CursorXP
DeadAIM
Dell Photo AIO Printer 922
DesktopX
Deus Ex - Invisible War
Diablo II
DivX
DivX Converter
DivX Converter
DivX Player
ewido security suite
ffdshow (remove only)
GameSpy Arcade
Half-Life® 2
Hero Editor V0.80
HijackThis 1.99.1
IconPackager
InterVideo WinDVD 5
iTunes
J2SE Runtime Environment 5.0 Update 3
J2SE Runtime Environment 5.0 Update 4
LimeWire 4.9.30
LiveUpdate BVRP Software
Microsoft Office 2000 Small Business
mobile PhoneTools
Need for Speed Underground 2
NFS Underground 2 Mega Trainer
NVIDIA Drivers
Opera
Picasa 2
QuickTime
RealPlayer
Realtek AC'97 Audio
RegRun Security Suite Gold
Rise of Nations
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Spy Sweeper
Spybot - Search & Destroy 1.4
Steam™
TrojanHunter 4.2
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Viewpoint Media Player
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
  • 0

#8
Rawe

Rawe

    Visiting Staff

  • Member
  • PipPipPipPipPipPipPip
  • 4,746 posts
Go to -> Start -> Control Panel -> Add/Remove programs and uninstall:

Viewpoint Media Player

Next, navigate to and delete the following folder:

C:\Program Files\Viewpoint\

Empty recycle bin.

Then, update Ewido to it's latest definitions and DISable it's Background Guard.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.


Now open Ewido and do a scan of your system.
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • Clean anything it finds.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop or a location where you can find it easily.
Close Ewido.

Reboot back into normal mode and post the log :tazz:
  • 0

#9
Rawe

Rawe

    Visiting Staff

  • Member
  • PipPipPipPipPipPipPip
  • 4,746 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP