This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Excel Shortcut - Virus Possibility

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Could someone please give me an idea of whether or not I may have a virus or trojan - or whether some of my files have become corrupted.

Whenever I try to open an Excel file or click on Excel.exe I get an applet (or whatever you call it) opening and preparing to install "Microsoft Office XP Professional with FrontPage".

When I look at the properties of the shortcuts that I have to open Access, Excel, Power Point, Word, New Document and Open Document the "target" is greyed out and shows "Microsoft Office XP Professional with FrontPage". The other programs seem to open all right even though the "target" cannot be altered.

I downloaded an update file from the Microsoft Website because of a message I got from a Virus Check by PC-Cillin but when I tried to execute it - the message said that the file was not the correct one for my system.

I have tried to do a System Restore to an earlier date but attempts have been unsuccessful.

Nothing has shown up with Spybot, Adaware, PC-Cillin or AVG. I have run HijackThis and the log is as follows:

Logfile of HijackThis v1.97.7
Scan saved at 1:13:24 a.m., on 17/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\AVG6\avgserv.exe
C:\WINDOWS\System32\CTSvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\UTILIT~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\UTILIT~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\UTILIT~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\UTILIT~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\UTILIT~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\AVG6\avgcc32.exe
C:\KMaestro\KMaestro.exe
C:\Ahead\In CD\InCD.exe
C:\PopUp Inspector\PopUpInspector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Spybot - Search & Destroy\TeaTimer.exe
C:\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Philips\LightFrame\LightFrame.exe
C:\Documents and Settings\Leith F\Start Menu\Programs\Startup\Runner.EXE
C:\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\UTILITIES\HiJack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.slingshot.co.nz/mailman.cgi
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AVG_CC] C:\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [KeyMaestro] C:\KMaestro\KMaestro.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Ahead\In CD\InCD.exe
O4 - HKLM\..\Run: [PopUpInspector.exe] "C:\PopUp Inspector\PopUpInspector.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MMTray] C:\MUSIC\MusicMatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\UTILITIES\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [PopUpInspector] C:\PopUp Inspector\PopUpInspector.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Runner.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: LightFrame.lnk = C:\Philips\LightFrame\LightFrame.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: P-touch Quick Editor.lnk.disabled
O4 - Global Startup: WinZip Quick Pick.lnk.disabled
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\UTILIT~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Allow popups from this web page - C:\PopUp Inspector\allowsite.htm
O8 - Extra context menu item: Download with Go!Zilla - file://C:\Go!Zilla\download-with-gozilla.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Stop popups from this web page - C:\PopUp Inspector\denysite.htm
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: PopUp Inspector (HKCU)
O9 - Extra 'Tools' menuitem: PopUp Inspector (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .psd: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup…er/imloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{60828511-D2B3-496A-93AC-7317D7C6A9AE}: NameServer = 202.27.184.3,202.27.184.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{60828511-D2B3-496A-93AC-7317D7C6A9AE}: NameServer = 202.27.184.3,202.27.184.5
O17 - HKLM\System\CS2\Services\Tcpip\..\{60828511-D2B3-496A-93AC-7317D7C6A9AE}: NameServer = 202.27.184.3,202.27.184.5



Regards

Leith Friend
The only thing in the log that looks "suspicious" to me is this:

O4 - Startup: Runner.EXE

Do you know what that does? :unsure:

I did find a post with a problem similar to yours. They suggested that if you log in as "administrator" on your system, and "accept the EULA", that what you are seeing will disappear.

I don't know if that will work or not. :)
Hi Micah_6:8 The Runner.exe relates to my Kinemorphics Screensaver. Do you know what the following item means ? "O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000" When you suggest logging in as "administrator" on my system, and "accept the EULA", do you mean when I first log on? Or are you suggesting that I install (or reinstall) the "Microsoft Office XP Professional with FrontPage ? Sorry that I am a bit dense. :unsure: :scratch: Regards Leith Friend :wavey:
Hi Micah_6:8 :wavey: Hee hee hee It works ! It works ! I managed to find what I had done with my installation disc and find the file that the the pop-up dialogue box wanted. I guess that is "accepting the EULA" or the equivalent. :wall: The result is that the "target" on the properties is no longer grayed out and can be changed if required. Many thanks for your time and trouble - I very much appreciate it. I am very glad there were no virii or trojans !! :D :D :D :D Regards Leith Friend New Zealand :wavey:
Great!!! :thumbup:

Nice to know I have a "Friend" in New Zealand!!! ;)

GOD bless!!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI