This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

All kinds of problems - Help Please

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi -

We've had a bunch of problems with our computer - first, an AntiVirus Gold infection - I think I got rid of (???). I have run SpyBot, Ad-aware and AntiVir scan. Also, CWShedder - that removed one thing, but still keep getting CW.Homesearch coming back every time (even after running AboutBuster several times). The AntiVir keeps detecting a Trojan Horse called TR/StartPa.DU.DLL.1 that keeps trying to access interent with various files. Also, following instructions I read on another post here, I ran AboutBuster 5.0. Here are both my log from AboutBuster and a HijackThis log (latest version). Keep getting pop-ups "only the best" and my default web site goes to about:blank, and new links keep getting added to my "favorites" on my browser that I don't know - I delete them and they come back. I've never clicked on them. Thanks so much - please help me!!!!

Logfile of HijackThis v1.99.1
Scan saved at 10:35:21 AM, on 7/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Susie\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\RunOnce: [sysas32.exe] C:\WINDOWS\system32\sysas32.exe
O4 - HKLM\..\RunOnce: [netdn.exe] C:\WINDOWS\netdn.exe
O4 - HKLM\..\RunOnce: [apinj.exe] C:\WINDOWS\system32\apinj.exe
O4 - HKLM\..\RunOnce: [ipll.exe] C:\WINDOWS\system32\ipll.exe
O4 - HKLM\..\RunOnce: [addka32.exe] C:\WINDOWS\system32\addka32.exe
O4 - HKLM\..\RunOnce: [iezk.exe] C:\WINDOWS\system32\iezk.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: x-atng - {7E8717B0-D862-11D5-8C9E-00010304F989} - C:\Program Files\Fidelity Investments\Fidelity Active Trader\System\atngprot.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

AboutBuster log:

AboutBuster 5.0 reference file 30
Scan started on [7/7/2005] at [10:19:49 AM]
————————————————
Removed Stream! C:\WINDOWS\DESKTOP.INI:gocsdn
Removed Stream! C:\WINDOWS\install.log:yzruyu
Removed Stream! C:\WINDOWS\KB885250.log:rxwyix
Removed Stream! C:\WINDOWS\KB887742.log:mfsrwk
Removed Stream! C:\WINDOWS\kcess.txt:flbdzg
Removed Stream! C:\WINDOWS\KPCMS.INI:pskjhz
Removed Stream! C:\WINDOWS\patch.log:rtcgbc
Removed Stream! C:\WINDOWS\Q318138.log:cabkrg
Removed Stream! C:\WINDOWS\Q328310.log:cpymfs
Removed Stream! C:\WINDOWS\VB.INI:yuensn
Removed Stream! C:\WINDOWS\_DEFAULT.PIF:rbtcns
Removed Stream! C:\WINDOWS\{00000002-00000000-00000009-00001102-00000002-80221102}.CDF:dgvtk
————————————————
Removed File! : C:\Windows\yxtwl.dat
Removed File! : C:\Windows\System32\epfsy.dat
Removed File! : C:\Windows\System32\gtzct.dat
Removed File! : C:\Windows\System32\hbyvn.dat
Removed File! : C:\Windows\System32\kacbm.dat
Removed File! : C:\Windows\System32\xkatk.dat
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:20:27 AM


AboutBuster 5.0 reference file 30
Scan started on [7/7/2005] at [10:21:30 AM]
————————————————
Removed Stream! C:\WINDOWS\{00000002-00000000-00000009-00001102-00000002-80221102}.CDF:fkavp
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:21:50 AM


AboutBuster 5.0 reference file 30
Scan started on [7/7/2005] at [10:24:34 AM]
————————————————
Removed Stream! C:\WINDOWS\{00000002-00000000-00000009-00001102-00000002-80221102}.CDF:xppjf
————————————————
No Files Found!
————————————————
Scan was COMPLETED SUCCESSFULLY at 10:25:11 AM
We are sorry for the delay in replying to you. If you still require help, please Post a fresh Hijackthis log as a reply to this thread. After posting the new log, do not reboot the computer nor use Internet Explorer if possible. I'll receive an e-mail notification of your reply and will respond as soon as possible. Thank you for your patience.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI