This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

svchost.exe in C:\WINDOWS

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know how my registry is backed up. I notice there is a registry do in My Documents that shows a content date of 6/3/05. I have been searching and deleting. I used the iSEARCH toolbar tool. I have deleted it also. I deleted several entries following instructions to manually delete AltNet. They both still show on the most recent MicroWorld scan. What else can I do? Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgctlcm.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\webscan.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\cddvdint.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Microsoft Shared\Artgalry\ARTGALRY.EXE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgctlcm.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Real\GToolbar\BarControl.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\feedingfrenzy.scr". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Enigma Software Group\SpyHunter\Uninstall.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\webscan.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0BB07B14-0CC8-11D3-B00E-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0DED49D5-A8B7-4d5d-97A1-12B0C195874D}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1696D696-A9D4-11D1-BEF6-00AA00BA6958}" refers to invalid object "C:\Program Files\Creative\SBLive\MiniDisc\MediaEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}" refers to invalid object "C:\PROGRA~1\AWS\WEATHE~1\MINIBU~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2ED977C0-0EF4-11d4-A66D-00AA00BA6958}" refers to invalid object "C:\WINDOWS\system32\CTMEDENG.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{317E8A07-8006-4416-B5DC-CF071D736AF9}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{35F7528D-D4EB-40D1-AC99-93E4421B02D6}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{3708886A-7D2C-4451-9325-0DA59C287011}" refers to invalid object "C:\Program Files\Creative\SBLive\RemoteCenter\Center\Tasks\MP3FileSink.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{37C64D52-538B-11D5-BC0B-00D0B76BF9FA}" refers to invalid object "C:\PROGRA~1\Creative\SBLive\REMOTE~1\Center\Tasks\CTAudRec.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{417EA290-71D0-43FB-87A0-8F107C549B2A}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{459E406E-B72F-11D1-A31B-00AA0061A911}" refers to invalid object "C:\Program Files\Creative\SBLive\MiniDisc\Albumsvr.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5247F650-FC3C-4C74-B59C-A3ED874F9656}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{56336BCA-3D8A-11d6-A00B-0050DA18DE71}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\InfoWindow.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5A2F3A17-A4A1-11D2-B129-00A0C98F3BCE}" refers to invalid object "C:\Program Files\Creative\SBLive\MiniDisc\MDSvr.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{611245AE-C124-428D-8267-94AEB0450024}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6981E00E-2D37-463F-B22A-A3FACFF665FC}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7D16077C-42C7-1F7D-962B-498724A05260}" refers to invalid object "C:\PROGRA~1\COMMON~1\SYMANT~1\ccProSub.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7E721BB8-7E07-4ECE-BDD6-3CECCD5ED90B}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8F8A59E4-1388-11D3-8F9D-00C04F4C3B9F}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{91DA6287-52F0-4CCF-9D67-72842C9BB367}" refers to invalid object "C:\PROGRA~1\SHOCKW~1.COM\FEEDIN~1\ui\SwDRM.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{93162670-FF1B-4844-8FBC-041F1ABB6F7A}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{93BCA1B2-C94E-11D1-BEF6-00AA00BA6958}" refers to invalid object "C:\Program Files\Creative\SBLive\MiniDisc\CDAEng.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{97E14B03-0E0C-11D3-8F9D-00C04F4C3B9F}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0528CE2-F67E-11D2-8F8E-00C04F4C3B9F}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B96-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B98-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B9A-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BBF37B9C-2F4F-11D3-B02F-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D8E7D428-5852-11D2-8061-00A0C98F3C48}" refers to invalid object "C:\Program Files\Creative\SBLive\Recorder\RECSVR.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E5D17BB2-F52F-4C6A-B318-C0D16121014B}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F3C2884C-62EF-4BC9-BA5D-75E132042F6E}" refers to invalid object "C:\DOCUME~1\JONPRI~1.JPZ\LOCALS~1\Temp\enginelte.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A234-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A236-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A238-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23A-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23C-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A23E-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A240-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A242-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F5F6A244-301B-11D3-B030-00C04F4C0826}" refers to invalid object "C:\Program Files\InterVideo\WinRip\CDDBControl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FA010552-4A27-4cb1-A1BB-3E2D697F1639}" refers to invalid object "c:\Program Files\InterMute\SpySubtract\sshook.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FD0A5AF3-B41D-11d2-9C95-00C04F7971E0}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\ComPlusMetaData.MsCorHost.2" refers to invalid object "{727CDF4F-3BA0-11D3-8738-00C04F79ED0D}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.EBankProblem" refers to invalid object "{AE612304-E8F9-45D9-A444-32409D33E954}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.QuarantinedItemProxy" refers to invalid object "{C2CE6266-0404-4C54-96B4-8829852E3537}". Action Taken: No Action Taken. Entry "HKCR\SpyDoctor.ScripterProxy" refers to invalid object "{9FEF02F5-B3B8-4D7B-8939-72A1C989D1B9}". Action Taken: No Action Taken. Entry "HKCR\SymWriter.pdb" refers to invalid object "{520DC67A-752E-11D3-8D56-00C04F680B2B}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken. File C:\Documents and Settings\Cheska\Local Settings\Temp\ImInstaller\IncrediMail\imloader.exe tagged as not-a-virus:Downloader.Win32.ImLoader.b. No Action Taken. File C:\Documents and Settings\Cheska\Local Settings\Temporary Internet Files\Content.IE5\MHEU3P3X\imloader[1].cab tagged as not-a-virus:Downloader.Win32.ImLoader.b. No Action Taken. File C:\Documents and Settings\Jon Price.JPZCOMPUTER\My Documents\LiveDrvUni-Pack(ENG).exe tagged as not-a-virus:Tool.Win32.KillApp.b. No Action Taken. File C:\Program Files\ICUII5\dwyu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\ICUII5\_dwyu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\3DAD6EEF-BC1B-45E4-A51D-6369BF tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\D0F3C410-2981-43A2-8CB6-A78CA0 tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP229\A0308512.0xe infected by "Trojan-Downloader.Win32.Braidupdate.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP231\A0309343.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313262.dll tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313263.exe tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken.
Run CC Cleaner again. When it starts, look for the ISSUES button.
Click on Scan for Issues. See if you can clean them up there.
Here is my most recent scan. What is my next step? Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\tgctlcm.dll". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\webscan.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0DED49D5-A8B7-4d5d-97A1-12B0C195874D}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken. Entry "HKCR\CLSID\{FD0A5AF3-B41D-11d2-9C95-00C04F7971E0}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken. File C:\Documents and Settings\Cheska\Local Settings\Temp\ImInstaller\IncrediMail\imloader.exe tagged as not-a-virus:Downloader.Win32.ImLoader.b. No Action Taken. File C:\Documents and Settings\Cheska\Local Settings\Temporary Internet Files\Content.IE5\MHEU3P3X\imloader[1].cab tagged as not-a-virus:Downloader.Win32.ImLoader.b. No Action Taken. File C:\Documents and Settings\Jon Price.JPZCOMPUTER\My Documents\LiveDrvUni-Pack(ENG).exe tagged as not-a-virus:Tool.Win32.KillApp.b. No Action Taken. File C:\Program Files\ICUII5\dwyu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\ICUII5\_dwyu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\3DAD6EEF-BC1B-45E4-A51D-6369BF tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\D0F3C410-2981-43A2-8CB6-A78CA0 tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP229\A0308512.0xe infected by "Trojan-Downloader.Win32.Braidupdate.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP231\A0309343.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313262.dll tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313263.exe tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken.
Making more progress. Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\Documents and Settings\Cheska\Local Settings\Temp\ImInstaller\IncrediMail\imloader.exe tagged as not-a-virus:Downloader.Win32.ImLoader.b. No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\3DAD6EEF-BC1B-45E4-A51D-6369BF tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\Program Files\Microsoft AntiSpyware\Quarantine\18C1909B-5CEF-4DBB-8EA5-19F0BE\D0F3C410-2981-43A2-8CB6-A78CA0 tagged as "not-a-virus:AdWare.ToolBar.MyWay.j". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP229\A0308512.0xe infected by "Trojan-Downloader.Win32.Braidupdate.c" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP231\A0309343.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313262.dll tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken. File C:\System Volume Information\_restore{A7E53B1D-2D16-4891-8C48-EDF2A764DD77}\RP238\A0313263.exe tagged as "not-a-virus:AdWare.ShopNav.a". Action Taken: No Action Taken.
Open C:\Documents and Settings\Cheska\Local Settings\Temp <–Delete ALL files in the temp Folder

C:\Program Files\Microsoft AntiSpyware\Quarantine\<–Empty everything in Quarantine. I don't use this program so you'll need to find out how to do this:



Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK

Reboot
Let me know if this gets rid of it.


Post a new HJT log.
Logfile of HijackThis v1.99.1
Scan saved at 9:26:07 AM, on 6/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Creative\ShareDLL\MediaDet.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Extensis\Portfolio 7\Portfolio Express.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
C:\Program Files\F-Secure Anti-Virus\backweb\4476822\Program\fspex.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\F-Secure Anti-Virus\Common\FSMB32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\F-Secure Anti-Virus\Common\FCH32.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\F-Secure Anti-Virus\Common\FAMEH32.EXE
C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsav32.exe
C:\Program Files\F-Secure Anti-Virus\FSGUI\fsguiexe.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.cox.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Anti-Virus\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Anti-Virus\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Anti-Virus\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Device Detector 2.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Portfolio Express.lnk = C:\Program Files\Extensis\Portfolio 7\Portfolio Express.exe
O4 - Global Startup: SATARaid.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab
O23 - Service: F-Secure Anti-Virus 2005 (BackWeb Plug-in - 4476822) - Unknown owner - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Anti-Virus\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\FWES\Program\fsdfwd.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Program Files\F-Secure Anti-Virus\Common\FSMA32.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
In my registry HKLM\ControlSet001\ControlSet003\Services\NetMan NetMan shows: manages objects in the Network and Dial-up connections Image Path REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe-k netsvcs Is NetMan bad?

Is NetMan bad?

NO.

http://www.net-man.us/



Good Job :thumbup:


Log looks good :D :thumbup: How is it running any issues?


Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D
Thank You for all your help LDTate. :D I did not remove svchost from the registry where I described finding it in the previos post. Does it belong in system 32? My computer is working great. Some how I deleted something that turned off my system sounds. I still have audio with players. I can work on the system sound and a minor problem with my video card TV port drivers that I likely will never use. Device Manager shows there are no drivers. I am using each tool you have recomended and saved your instructions. You have taught me a lot about Malware. Thank You, JustSayGo :D
Great job :thumbup:

You're more then welcome.
Glad we were able to help

Peace be with you :wavey:





If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI