This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

help please =(

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

this is my second time coming here for help… ive been carefull since the first time last year when i was infected and got help here. obviously something still got me.
I use spyware guard, spywareblaster, spybot s&d, adaware se, etc.
i have configured my IE settings the best i can using this site:
https://netfiles.uiuc.edu/ehowes/www/btw/ie/ie-opts.htm

still somehow i got infected by a trojan which has been downloading tons of carp**, altered my IE security settings, and added unwanted sites to my trusted zone. Some of the items listed i know are bad and i have removed repeatedly but the trojan keeps reinstalling them. I appreciate any help and thank you in advance for your assistance.

here is my hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 7:54:40 PM, on 5/19/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\paytime.exe
C:\WINDOWS\System32\paytime.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\dffuhf.exe
C:\Program Files\Internet Optimizer\optimize.exe
c:\program files\180solutions\sais.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\WINDOWS\System32\cmd.exe
C:\Documents and Settings\Scotts\My Documents\hjt and backup fiels\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://cgi.verizon.net/bookmarks/bmredir.a….0&bm=ho_search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://81.222.131.49/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [ifanqb] C:\WINDOWS\ifanqb.exe
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [annaT3f] C:\WINDOWS\dffuhf.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sais] c:\program files\180solutions\sais.exe
O4 - HKLM\..\Run: [jubgvyp] C:\WINDOWS\jubgvyp.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [DeleteISTbar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbarcm.dll"
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O15 - Trusted Zone: http://www.angelfire.com
O15 - Trusted Zone: *.cattco.org
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.ea.com
O15 - Trusted Zone: *.ebaumsworld.com
O15 - Trusted Zone: *.ebgames.com
O15 - Trusted Zone: http://www.erie.gov
O15 - Trusted Zone: *.erie.gov
O15 - Trusted Zone: *.fandango.com
O15 - Trusted Zone: http://www.sims2shoppe.freewebsitehosting.com
O15 - Trusted Zone: http://www.geico.com
O15 - Trusted Zone: *.co.genesee.ny.us
O15 - Trusted Zone: *.healthcaresource.com
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.forums.jedi-tech.com
O15 - Trusted Zone: http://www.limewire.com
O15 - Trusted Zone: *.Logfile of HijackThis v1.98.2
O15 - Trusted Zone: http://www.lucasarts.com
O15 - Trusted Zone: *.lucasarts.com
O15 - Trusted Zone: http://www.mediaplay.com
O15 - Trusted Zone: *.mediaplay.com
O15 - Trusted Zone: *.hotmail.msn.com
O15 - Trusted Zone: http://by103fd.bay103.hotmail.msn.com
O15 - Trusted Zone: http://www.mtv.com
O15 - Trusted Zone: *.netflix.com
O15 - Trusted Zone: *.niagaracounty.com
O15 - Trusted Zone: *.nvidia.com
O15 - Trusted Zone: *.orleansny.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.login.passport.net
O15 - Trusted Zone: http://login.passport.net
O15 - Trusted Zone: *.www.psheddy.com
O15 - Trusted Zone: http://www.rochesternypolice.com
O15 - Trusted Zone: *.rochesternypolice.com
O15 - Trusted Zone: *.rottentomatoes.com
O15 - Trusted Zone: *.salliemae.com
O15 - Trusted Zone: http://www.secretservice.gov
O15 - Trusted Zone: *.secretservice.gov
O15 - Trusted Zone: *..station.sony.com
O15 - Trusted Zone: *.starwarsgalaxies.station.sony.com
O15 - Trusted Zone: http://starwarsgalaxies.station.sony.com
O15 - Trusted Zone: *.state.ny.us
O15 - Trusted Zone: *.station.com
O15 - Trusted Zone: *.thesims2.com
O15 - Trusted Zone: http://www.thesimsresource.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.housecall.trendmicro.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O15 - Trusted Zone: *.verizon.com
O15 - Trusted Zone: http://cgi.verizon.net
O15 - Trusted Zone: *.verizon.net
O15 - Trusted Zone: *.wyomingco.net
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 81.222.131.59 (HKLM)
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/MediaAcc…bridge-c293.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4…006_regular.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: sdktemp - Unknown owner - C:\WINDOWS\sdktemp.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
I have downloaded ms Antispyware beta.
it has eliminated some problems but some things still persist.

here is my latest hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 8:06:34 AM, on 5/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Verizon Online\SupportCenter\bin\mpbtn.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Scotts\My Documents\hjt and backup fiels\HijackThis.exe
C:\WINDOWS\wkssvc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O15 - Trusted Zone: http://www.angelfire.com
O15 - Trusted Zone: *.cattco.org
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.ea.com
O15 - Trusted Zone: *.ebaumsworld.com
O15 - Trusted Zone: *.ebgames.com
O15 - Trusted Zone: http://www.erie.gov
O15 - Trusted Zone: *.erie.gov
O15 - Trusted Zone: *.fandango.com
O15 - Trusted Zone: http://www.sims2shoppe.freewebsitehosting.com
O15 - Trusted Zone: http://www.geico.com
O15 - Trusted Zone: *.co.genesee.ny.us
O15 - Trusted Zone: *.healthcaresource.com
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.forums.jedi-tech.com
O15 - Trusted Zone: http://www.limewire.com
O15 - Trusted Zone: *.Logfile of HijackThis v1.98.2
O15 - Trusted Zone: http://www.lucasarts.com
O15 - Trusted Zone: *.lucasarts.com
O15 - Trusted Zone: http://www.mediaplay.com
O15 - Trusted Zone: *.mediaplay.com
O15 - Trusted Zone: *.hotmail.msn.com
O15 - Trusted Zone: http://by103fd.bay103.hotmail.msn.com
O15 - Trusted Zone: http://www.mtv.com
O15 - Trusted Zone: *.niagaracounty.com
O15 - Trusted Zone: *.nvidia.com
O15 - Trusted Zone: *.orleansny.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.login.passport.net
O15 - Trusted Zone: http://login.passport.net
O15 - Trusted Zone: http://www.rochesternypolice.com
O15 - Trusted Zone: *.rochesternypolice.com
O15 - Trusted Zone: *.rottentomatoes.com
O15 - Trusted Zone: *.salliemae.com
O15 - Trusted Zone: http://www.secretservice.gov
O15 - Trusted Zone: *.secretservice.gov
O15 - Trusted Zone: *..station.sony.com
O15 - Trusted Zone: *.starwarsgalaxies.station.sony.com
O15 - Trusted Zone: http://starwarsgalaxies.station.sony.com
O15 - Trusted Zone: *.state.ny.us
O15 - Trusted Zone: *.station.com
O15 - Trusted Zone: *.thesims2.com
O15 - Trusted Zone: http://www.thesimsresource.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.housecall.trendmicro.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O15 - Trusted Zone: http://www22.verizon.com
O15 - Trusted Zone: *.verizon.com
O15 - Trusted Zone: http://cgi.verizon.net
O15 - Trusted Zone: *.verizon.net
O15 - Trusted Zone: *.wyomingco.net
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O17 - HKLM\System\CS1\Services\Tcpip\..\{0B714D75-9E59-4E12-83FE-BF0E4FF447C8}: NameServer = 151.202.0.84 151.203.0.84
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
yeah that program found several trojan downloaders and also found a virus named Win32/Parite. I had suspected it was there because it is a known virus that prevents an online game i play from starting (star wars galaxies). Tech support for the game mentioned it specifically under several aliases. that virus attaches itself to many exe files over time. it succeeded in infecting 25,796 / 84053 files. AVG is currently running and attempting to heal all 25K + files. It will prolly take another hour or so and ill repost the results.
:blink: ok apparently AVG only was able to fix about 17 k of the 25,000 infected files… the virus detected window is interfering with me doing much else as it is prolly going to try to open about 9000 more times. the virus has moved into many more of my exe files and even hijack this has now been taken over and is unusable. i am afraid to reboot and possibly not be able to do anything at all then. many system files have been infected and moving them to the vault could cause the OS to become inoperable completely, as the warning keeps telling me. i could attempt to uninstall hijack this and reinstall it… then try to get a scan off before it is infected again. I had done this once with the online game i play, i got it to run once then that was it because it was reinfected again in no time. I dont know if ill even be able to uninstall it at this point. Ill check back to see what you want me to do before i attempt to reinstall it or reboot or anything.
You can use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)

This should replace any missing windows files.

As far as rebooting, I don't think you have any other choice.
k.. ive healed another 8000 files but there is still a lot which cannot be healed. the infection has spread into my dsl dialer and i can no longer connect to the internet on that computer. I just plugged another computer along side it to use the connection and post while being at that pc. ms antispyware beta was also infected now along with pretty much all my protective software. W32/Parite is what is attacking everything… i did see instructions on how to get rid of it at station.com - tech support - one of the threads. im gonna look at that now while windows is checking all those system files. then ill reboot and check back here to see what you want me to do next.
ok.. i cant run online scans because the dsl dialer on the infected computer has been attacked. I did dl the quick remover utility and transfered to that computer by disc. It said it detected parite and went through the whole system looking for the files to repair. when it was done it said there was no traces of parite left. however AVG is still detecting files which are infected and the pop up window for the virus detected keeps coming up. it's still saying its w32/parite still. Im not sure if i missed something somewhere.. im still looking to see if i missed a step somehow or something… but when i clicked on the quick remover again it said it was clean which obviously its not. :ph34r:
ill try to reinstall a new copy of hijack this to that computer, the one on there currently is unusable. everything the virus has infected now gives the error message "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."
Logfile of HijackThis v1.99.1
Scan saved at 3:49:15 PM, on 5/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe
C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Documents and Settings\Scotts\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www22.verizon.com/ForHomeDSL/channe…referrer=volnet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Documents and Settings\Scotts\Desktop\Misc\Anti-Crapware\MS AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O9 - Extra button: Control Pad - {28D44DAC-D1FC-4d4f-BB1B-ADF037C8DDBC} - C:\Program Files\Verizon Online\ControlPad\Misc\a_menu.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O15 - Trusted Zone: http://www.angelfire.com
O15 - Trusted Zone: *.cattco.org
O15 - Trusted Zone: *.dell.com
O15 - Trusted Zone: *.ea.com
O15 - Trusted Zone: *.ebaumsworld.com
O15 - Trusted Zone: *.ebgames.com
O15 - Trusted Zone: http://www.erie.gov
O15 - Trusted Zone: *.erie.gov
O15 - Trusted Zone: *.fandango.com
O15 - Trusted Zone: http://www.sims2shoppe.freewebsitehosting.com
O15 - Trusted Zone: http://www.geico.com
O15 - Trusted Zone: *.co.genesee.ny.us
O15 - Trusted Zone: *.healthcaresource.com
O15 - Trusted Zone: *.hotmail.com
O15 - Trusted Zone: *.forums.jedi-tech.com
O15 - Trusted Zone: http://www.limewire.com
O15 - Trusted Zone: *.Logfile of HijackThis v1.98.2
O15 - Trusted Zone: http://www.lucasarts.com
O15 - Trusted Zone: *.lucasarts.com
O15 - Trusted Zone: http://www.mediaplay.com
O15 - Trusted Zone: *.mediaplay.com
O15 - Trusted Zone: *.hotmail.msn.com
O15 - Trusted Zone: http://by103fd.bay103.hotmail.msn.com
O15 - Trusted Zone: http://www.mtv.com
O15 - Trusted Zone: *.niagaracounty.com
O15 - Trusted Zone: *.nvidia.com
O15 - Trusted Zone: *.orleansny.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.login.passport.net
O15 - Trusted Zone: http://login.passport.net
O15 - Trusted Zone: http://www.rochesternypolice.com
O15 - Trusted Zone: *.rochesternypolice.com
O15 - Trusted Zone: *.rottentomatoes.com
O15 - Trusted Zone: *.salliemae.com
O15 - Trusted Zone: http://www.secretservice.gov
O15 - Trusted Zone: *.secretservice.gov
O15 - Trusted Zone: *..station.sony.com
O15 - Trusted Zone: *.starwarsgalaxies.station.sony.com
O15 - Trusted Zone: http://starwarsgalaxies.station.sony.com
O15 - Trusted Zone: *.state.ny.us
O15 - Trusted Zone: *.station.com
O15 - Trusted Zone: *.thesims2.com
O15 - Trusted Zone: http://www.thesimsresource.com
O15 - Trusted Zone: *.tomcoyote.org
O15 - Trusted Zone: *.housecall.trendmicro.com
O15 - Trusted Zone: http://housecall.trendmicro.com
O15 - Trusted Zone: http://www22.verizon.com
O15 - Trusted Zone: *.verizon.com
O15 - Trusted Zone: http://cgi.verizon.net
O15 - Trusted Zone: *.verizon.net
O15 - Trusted Zone: *.wyomingco.net
O16 - DPF: {10ABC6DB-E091-4EAE-98DD-21B5A2460714} (DetInstaller Class) - http://www.pandasoftware.es/avchecker/cont…s/AvDetInst.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Microsoft Registry Viewer (dumpreg) - Unknown owner - C:\WINDOWS\dumpreg.exe
O23 - Service: iTunes Music Service (iTunesMusic) - Unknown owner - C:\WINDOWS\iTunesMusic.exe (file missing)
O23 - Service: Workstation Service Library (Microsoft Locator Service) - Unknown owner - C:\WINDOWS\wkssvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: WinPPPoverEthernet - iVasion, a Routerware Company - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE
Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click and select….. Save Target As….Save

To use: Right-click and select……. Install (no need to restart)
**Note** This will remove all entries in the "Trusted Zone"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI