This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Need HELP!

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hey guyz, ive been having problems with my computer for the past week and a half.Basically, i was surfing Limewire and i decided to download a program from it. i executed the file and it turned out to be some kind of virus or spyware of some sort. i think it might be a trojan horse or sumthing. Anywayz, it got in to my system and it started downloading hundreds of different types of files in to my computer.most of them in to My Shared Folder.They were just random files like Nero Burning Rom, photo Shop, Clone cd etc. and then my anti virus starting going off and so did spy sweeper. Its installing all kinds of spyware in to my computer :rant2: . i finally deleted all the files it downloaded and i scanned with sooo many programs. I i scanned with Symantec antivirus 10.0 corporate edition, Spy Sweeper 4.0.3 latest version, Spy Bot, Adaware SE pro, SpyHunter, Trojan Hunter etc.I scanned with all kinds of programs that claim to be the best Trojan virus protectors. i even went to those online virus scanning sites like trend micro and panda antivirus. All these programs did find things, but they're not solving the dayam problem. Everytime i restart my system, everything is back in to my comp and im getting screwed all over again. If anyone can help, PLEASE DO. Here's my Hijackthis text file. . . . .



Logfile of HijackThis v1.99.1
Scan saved at 4:18:11 PM, on 6/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.281\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Spy Sweeper Fix.lnk = C:\Program Files\Webroot\Spy Sweeper\SpySweeperFix.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ccd.sytes.net
O17 - HKLM\Software\..\Telephony: DomainName = ccd.sytes.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ccd.sytes.net
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)
Arite, itz been more than 5 dayz, i think itz been 6 or 7 seven dayz, herez my new Highjackthis file. . . .

Logfile of HijackThis v1.99.1
Scan saved at 1:09:53 AM, on 6/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.0\YTPro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.360\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Spy Sweeper Fix.lnk = C:\Program Files\Webroot\Spy Sweeper\SpySweeperFix.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmesus.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ccd.sytes.net
O17 - HKLM\Software\..\Telephony: DomainName = ccd.sytes.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ccd.sytes.net
O20 - Winlogon Notify: MCPClient - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)


i think the virus might have been taken out by ewido security suite, but plzz check my highjackthis file for an other errors or problems.

Thanx
Hello IzallHalal and welcome to TomCoyote. :wavey:

Both logs you posted appear clean. To make sure nothing is hiding on the computer please run the following programs:

Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • Click Options < Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".
  • Click Run Cleaner to run the program.
  • After it has completed it's process, click Exit.
Caution : It is not recommended to use the 'Issues' tab as it is known to find legitimate items.


Click here to download mwavscan.
  • Double-click it to run it.
  • Read then accept the agreement.
  • Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
  • Once it finds something, it will prompt you so click OK.
  • When it is completed, anything found will be displayed in the lower pane.
  • Highlight it, copy it (CTRL+C), and paste (CTRL+V) it in your next reply.
Note : It will find many orphaned registry entries so please do not be alarmed by the amount of items that show.
Thanx for the feedback. My computer has been running kind of slow, can u please tell me what i can do or wat program i can run to help my computer run faster. Heres the MWAV text file. . . . . ok, it seems that i accidently pressed scan All files and the file is huge, and i cant paste it all on here, so ill run it again on the other option and paste it Asap.
You want mwavscan to scan all files. The upper pane shows every file that is scanned and is not necessary for us to see. The lower pane is the one that needs posted here. This should be considerably smaller and easily fit into one post.
herez the bottom part of the scan, hope this is right. . . . . File C:\PROGRA~1\RealVNC\VNC4\WinVNC4.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. File C:\PROGRA~1\RealVNC\VNC4\wm_hooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. File C:\Documents and Settings\adilabid\Desktop\BitTorrent DLs\Adaware SE pro build 1.06.rar tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\adilabid\Desktop\BitTorrent DLs\BitTorrent-4.0.1.exe tagged as not-a-virus:Tool.Win32.Processor.1001. No Action Taken. File C:\Documents and Settings\adilabid\Desktop\BitTorrent DLs\BitTorrent-4.1.2-Beta.exe tagged as not-a-virus:Tool.Win32.Processor.1001. No Action Taken. File C:\Documents and Settings\adilabid\Desktop\Filez\AV Voice Changer.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Documents and Settings\adilabid\Desktop\Filez\ewidosecuritysuiteplusv30_YaHoCdDnQgMqIcKf.zip infected by "Trojan-Downloader.Win32.IstBar.ki" Virus! Action Taken: No Action Taken. Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\\Symantec\SYMEVNT.386". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Symantec\S32STAT.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\InterVideo\Common\Bin\IVIPromotion.exe". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Jpn.nls". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart_deu.chm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero StartSmart\NeroStartSmart_jpn.chm". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\system32\pxsfs.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0713E8A2-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0713E8A8-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0713E8D2-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0713E8D8-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{0B6DC6EE-C4FD-11d1-819A-00C04FB69B4D}" refers to invalid object "C:\Program Files\Common Files\Adobe\Shell\psicon.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{11B3DA78-9E11-4B17-A879-FFE918F0D4B3}" refers to invalid object "C:\WINDOWS\System32\mscoree.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{1B58784F-D9C8-4560-BC3D-066C86FAB3B8}" refers to invalid object "C:\Documents and Settings\adilabid\Desktop\CrashFX\OscSev.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{29FF67FF-8050-480f-9F30-CC41635F2F9D}" refers to invalid object "ADMWPROX.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C}" refers to invalid object "C:\PROGRA~1\AWS\WEATHE~1\MINIBU~1.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{2C1FC073-6862-46E4-BC97-7ECBDEA86BBE}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX04.531\yexploitationv1.0\Y!eXploitation v1.0\Transframe.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{373FF7F0-EB8B-11CD-8820-08002B2F4F5A}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{373FF7F4-EB8B-11CD-8820-08002B2F4F5A}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{390CE9F2-C4A0-11D4-8A92-0090271D4F88}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\ycrwin32.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{41695A8E-6414-11D4-8FB3-00D0B7730277}" refers to invalid object "C:\Program Files\Yahoo!\Messenger\asw.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{58DA8D8A-9D6A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{58DA8D8F-9D6A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{58DA8D93-9D6A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{58DA8D96-9D6A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5ACBB955-5C57-11CF-8993-00AA00688B10}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5ACBB956-5C57-11CF-8993-00AA00688B10}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5ACBB957-5C57-11CF-8993-00AA00688B10}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{5ACBB958-5C57-11CF-8993-00AA00688B10}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6027C2D4-FB28-11CD-8820-08002B2F4F5A}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{612A8624-0FB3-11CE-8747-524153480004}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{612A8628-0FB3-11CE-8747-524153480004}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{62823C20-41A3-11CE-9E8B-0020AF039CA3}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6B7E638F-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6B7E6393-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{6B7E63A3-850A-101B-AFC0-4210102A8DA7}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{70B51430-B6CA-11D0-B9B9-00A0C922E750}" refers to invalid object "ADMWPROX.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{71839D31-3417-4F77-BADE-CBCFC88EA4BC}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.984\plugins\digital_city.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{794FE7F3-607F-4F4C-87D0-3FFADEF83DC8}" refers to invalid object "C:\Documents and Settings\adilabid\Desktop\BitTorrent DLs\booter\prjChameleon.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{7C72ED9B-276C-4C18-8F37-CC22DCAD7F27}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.984\plugins\ssl_pogo.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8298d101-f992-43b7-8eca-5052d885b995}" refers to invalid object "ADMWPROX.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{882BE13B-884D-466E-8530-89BF112DB150}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.984\plugins\digital_city.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{8C83D11B-1220-11D5-9417-0050DA82972A}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX04.531\yexploitationv1.0\Y!eXploitation v1.0\jdsFrame.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9ED94440-E5E8-101B-B9B5-444553540000}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9ED94444-E5E8-101B-B9B5-444553540000}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{A9E69612-B80D-11D0-B9B9-00A0C922E750}" refers to invalid object "ADMWPROX.DLL". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B47BE342-5D4A-11D7-84F4-000AE634B086}" refers to invalid object "C:\Documents and Settings\adilabid\Desktop\annoyeralpha1\auxSock.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{B66834C6-2E60-11CE-8748-524153480004}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX06.593\comctl32.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{BF0044DB-36F1-4E50-959C-BAD750900A8D}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.984\plugins\ftp_ht.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C2C99767-1FCB-11D4-AFEE-8B40D418D327}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX01.219\VAIM.OCX". Action Taken: No Action Taken. Entry "HKCR\CLSID\{C9052A5D-F5D7-4F0A-ABAB-36C9275F4D43}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX00.984\plugins\ftp_ht.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{D4BBE4C0-BD72-4A33-817C-2E7E16DE20BC}" refers to invalid object "C:\DOCUME~1\adilabid\LOCALS~1\Temp\Rar$EX04.531\yexploitationv1.0\Y!eXploitation v1.0\FUSIONButtons.ocx". Action Taken: No Action Taken. Entry "HKCR\CLSID\{f612954d-3b0b-4c56-9563-227b7be624b4}" refers to invalid object "ADMWPROX.DLL". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Entry "HKCR\AniGIFCtrl.AniGIF" refers to invalid object "{82351441-9094-11D1-A24B-00A0C932C7DF}". Action Taken: No Action Taken. Entry "HKCR\AniGIFPpg.AniGIFPpg.1" refers to invalid object "{6DC82D15-92F2-11D1-A255-00A0C932C7DF}". Action Taken: No Action Taken. Entry "HKCR\AniGIFPpg2.AniGIFPpg2.1" refers to invalid object "{61AB12E1-A5FF-11D1-B2E9-444553540000}". Action Taken: No Action Taken. Entry "HKCR\DAIE.DownloadAcceleratorIE" refers to invalid object "{5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E}". Action Taken: No Action Taken. Entry "HKCR\DAIE.DownloadAcceleratorIE.1" refers to invalid object "{5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E}". Action Taken: No Action Taken. Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken. Entry "HKCR\ISCThai.SymVARegQuery" refers to invalid object "{6FB4CA2C-5B48-40AB-F2E9-34F2D8BA48BA}". Action Taken: No Action Taken. Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Entry "HKCR\Messenger.MessengerApp" refers to invalid object "{FB7199AB-79BF-11d2-8D94-0000F875C541}". Action Taken: No Action Taken. Entry "HKCR\Messenger.MessengerApp.1" refers to invalid object "{FB7199AB-79BF-11d2-8D94-0000F875C541}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Entry "HKCR\SharePoint.WebPartPage.Document" refers to invalid object "{388ED91D-7FD2-11D0-A60B-00A0C90A43FF}". Action Taken: No Action Taken. Entry "HKCR\SharePoint.WebPartPage.Document.1.0" refers to invalid object "{388ED91D-7FD2-11D0-A60B-00A0C90A43FF}". Action Taken: No Action Taken. Entry "HKCR\WBOCX.WbocxCtrl.1" refers to invalid object "{55D94814-5664-4D04-9804-74DD038D4BA3}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
You were correct that Ewido removed your problem. It is a showing in the mwavscan log. :thumbup:

Your new log appears clean. :)

I suggest that you scan any file downloaded from a Peer2Peer file sharing program with your Antivirus program before opening it.

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.


I suggest that you get these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
SpywareGuard - Real-time protection from spyware installation attempts
ie-spyad - Puts over 8,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.
ZoneAlarm - Free firewall program if you currently are not using one.

Update these regularly.

You may also want to read "How did I get infected in the first place" to learn how to better secure your computer.

Be sure to keep Windows and your Anti-virus updated.
Arite, thanx for all the help, I appreciate it. Ill make sure to download those programs and keep my stuff updated. Thanx again.
As this topic has been resolved, the thread will be closed.

If you need this topic reopened, please request this by sending an email to us at the following link:
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI