This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

First Scan log ,Please Help

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello-
My computer seams like it has been taken over. It is very slow, always locking up and when im on the internet it’s almost every website I try to go to I get redirected its driving me crazy. If you could help in any way it would be greatly appreciated. Thanks in advance
Pat

Logfile of HijackThis v1.99.1
Scan saved at 1:07:40 PM, on 9/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\BACKUP\System32\smss.exe
C:\BACKUP\system32\csrss.exe
C:\BACKUP\system32\winlogon.exe
C:\BACKUP\system32\services.exe
C:\BACKUP\system32\lsass.exe
C:\BACKUP\system32\svchost.exe
C:\BACKUP\system32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\Explorer.EXE
C:\BACKUP\system32\spoolsv.exe
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasDtServ.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\BACKUP\SYSTEM\DRIVER\ntuser.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe
C:\BACKUP\system\driver\csrss.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\alg.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\BACKUP\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\MSN\MSNIA\msniasvc.exe
C:\Documents and Settings\Midwest Compost\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE /STANDALONE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120243276548
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E3103-BF86-4A2D-9F4A-FD3ADF86EC7E}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA663C71-C47B-4BC5-9AA6-1A80E2CD4638}: NameServer = 69.50.176.196,195.225.176.110
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NTBOOTMGR (NTBOOT) - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntuser.exe
O23 - Service: NTLOAD - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe
O23 - Service: NTSVCMGR - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe
Greetings and welcome to TomCoyote.org!

Please go to these free online file checkers:

Kaspersky Online File Scanner

Jotti Online File Scanner

VirusTotal Online File Scanner

And submit these files for a virus scan:

c:\backup\system\driver\csrss.exe

c:\backup\system\driver\ntsrv.exe

c:\backup\system\driver\ntuser.exe

Let me know what the scans say.

I believe these are at the root of your problems.
:)
Miach here are the results from the scans, i also wanted to say thank you for taking the time out of your day to help me with this Pat RESULTS FROM KASPERSKY csrss.exe - infected by not-a-virus:Server-FTP.Win32.Serv-U.gen ntsrv.exe - OK ntuser.exe - OK ————————————————————————– RESULTS FROM JOTTI File: csrss.exe Status: INFECTED/MALWARE MD5 dee02ab15d2431bd7627b43df870a964 Packers detected: ASPACK Scanner results AntiVir Found Backdoor-Server/Iroffer.14b2.C ArcaVir Found Trojan.Servu-based Avast Found Win32:Trojano-1331 AVG Antivirus Found nothing BitDefender Found Trojan.Servu.AZ ClamAV Found nothing Dr.Web Found not a virus Program.ServUServer.60 F-Prot Antivirus Found security risk or a "backdoor" program Fortinet Found HackerTool/ServUDmn Kaspersky Anti-Virus Found not-a-virus:Server-FTP.Win32.Serv-U.gen NOD32 Found Win32/ServU-Daemon application Norman Virus Control Found nothing UNA Found Backdoor.ServU VBA32 Found nothing —————————————————————————- File: ntsrv.exe Status: INFECTED/MALWARE MD5 906510472f226daf373a500ddfdd7560 Packers detected: ASPACK Scanner results AntiVir Found Backdoor-Server/Iroffer.14b2.A ArcaVir Found Trojan.Small.Wp.A16 Avast Found Win32:Trojano-1332 AVG Antivirus Found nothing BitDefender Found Trojan.Runas.A ClamAV Found nothing Dr.Web Found Trojan.Runas F-Prot Antivirus Found nothing Fortinet Found Misc/G6service Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing UNA Found nothing VBA32 Found Trojan.Runas —————————————————————————— File: ntuser.exe Status: INFECTED/MALWARE MD5 80858f87275634946eed13b514222cdb Packers detected: ASPACK Scanner results AntiVir Found Backdoor-Server/Iroffer.14b2.B ArcaVir Found Trojan.Small.Wp.A16 Avast Found Win32:Trojano-1333 AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing Fortinet Found nothing Kaspersky Anti-Virus Found nothing NOD32 Found nothing Norman Virus Control Found nothing UNA Found Backdoor.Noer VBA32 Found BackDoor.Noer ————————————————————————————– RESULTS FROM VIRUSTOTAL This is a report processed by VirusTotal on 09/22/2005 at 00:17:06 (CET) after scanning the file "csrss.exe" file. Antivirus Version Update Result AntiVir 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.C Avast 4.6.695.0 09.21.2005 Win32:Trojano-1331 AVG 718 09.21.2005 no virus found Avira 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.C BitDefender 7.2 09.21.2005 Trojan.Servu.AZ CAT-QuickHeal 8.00 09.21.2005 RiskWare.FTP.Serv-U.gen (Not a Virus) ClamAV devel-20050917 09.21.2005 no virus found DrWeb 4.32b 09.21.2005 no virus found eTrust-Iris 7.1.194.0 09.22.2005 no virus found eTrust-Vet 11.9.1.0 09.21.2005 no virus found F-Prot 3.16c 09.21.2005 security risk or a "backdoor" program Ikarus 0.2.59.0 09.21.2005 no virus found Kaspersky 4.0.2.24 09.21.2005 not-a-virus:Server-FTP.Win32.Serv-U.gen McAfee 4587 09.21.2005 potentially unwanted program ServU-Daemon NOD32v2 1.1229 09.21.2005 Win32/ServU-Daemon Norman 5.70.10 09.21.2005 no virus found Panda 8.02.00 09.21.2005 Application/ServUBased.A Sophos 3.97.0 09.21.2005 Troj/ServU-Gen Symantec 8.0 09.21.2005 no virus found TheHacker 5.8.2.113 09.21.2005 Aplicacion/Serv-U.gen VBA32 3.10.4 09.21.2005 no virus found ————————————————————————————- This is a report processed by VirusTotal on 09/22/2005 at 00:21:19 (CET) after scanning the file "ntsrv.exe" file. Antivirus Version Update Result AntiVir 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.A Avast 4.6.695.0 09.21.2005 Win32:Trojano-1332 AVG 718 09.21.2005 no virus found Avira 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.A BitDefender 7.2 09.21.2005 Trojan.Runas.A CAT-QuickHeal 8.00 09.21.2005 no virus found ClamAV devel-20050917 09.21.2005 no virus found DrWeb 4.32b 09.21.2005 Trojan.Runas eTrust-Iris 7.1.194.0 09.22.2005 no virus found eTrust-Vet 11.9.1.0 09.21.2005 no virus found F-Prot 3.16c 09.21.2005 no virus found Ikarus 0.2.59.0 09.21.2005 no virus found Kaspersky 4.0.2.24 09.21.2005 no virus found McAfee 4587 09.21.2005 potentially unwanted program G6Service NOD32v2 1.1229 09.21.2005 no virus found Norman 5.70.10 09.21.2005 no virus found Panda 8.02.00 09.21.2005 HackTool/Disilitra.B Sophos 3.97.0 09.22.2005 no virus found Symantec 8.0 09.21.2005 no virus found TheHacker 5.8.2.113 09.21.2005 Aplicacion/ServiceRunner.d VBA32 3.10.4 09.21.2005 Trojan.Runas ————————————————————————————– This is a report processed by VirusTotal on 09/22/2005 at 00:24:03 (CET) after scanning the file "ntuser.exe" file. Antivirus Version Update Result AntiVir 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.B Avast 4.6.695.0 09.21.2005 Win32:Trojano-1333 AVG 718 09.21.2005 no virus found Avira 6.32.0.6 09.21.2005 BDS/Iroffer.14b2.B BitDefender 7.2 09.21.2005 no virus found CAT-QuickHeal 8.00 09.21.2005 no virus found ClamAV devel-20050917 09.21.2005 no virus found DrWeb 4.32b 09.21.2005 no virus found eTrust-Iris 7.1.194.0 09.22.2005 no virus found eTrust-Vet 11.9.1.0 09.21.2005 Win32.Identdhack.A F-Prot 3.16c 09.21.2005 no virus found Ikarus 0.2.59.0 09.21.2005 Backdoor.Win32.Noer Kaspersky 4.0.2.24 09.21.2005 no virus found McAfee 4587 09.21.2005 no virus found NOD32v2 1.1229 09.21.2005 no virus found Norman 5.70.10 09.21.2005 no virus found Panda 8.02.00 09.21.2005 no virus found Sophos 3.97.0 09.22.2005 no virus found Symantec 8.0 09.21.2005 no virus found TheHacker 5.8.2.113 09.21.2005 Trojan/Small VBA32 3.10.4 09.21.2005 BackDoor.Noer
We need to disable your Microsoft AntiSpyware Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft AntiSpyware.
  • Click on Options, Settings.
  • In the left pane, click on Real-time Protection.
  • Under Startup Options uncheck Enable the Microsoft AntiSpyware Security Agents on startup (recommended).
  • Under Real-time spyware threat protection uncheck Enable real-time spyware threat protection (recommended).
  • After you uncheck these, click on the Save button and close Microsoft AntiSpyware.
  • Right click on the Microsoft AntiSpyware icon on the taskbar and select Shutdown Microsoft AntiSpyware.
After all of the fixes are complete it is very important that you enable Real-time Protection again.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm

O15 - Trusted Zone: http://www.neededware.com

O23 - Service: NTBOOTMGR (NTBOOT) - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntuser.exe

O23 - Service: NTLOAD - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe

O23 - Service: NTSVCMGR - Unknown owner - C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe

Then click "Fix checked" and close Hijack This!.

Now, please go to:

Start –> Run

In the box type in services.msc then hit < Enter > (or click OK)

In the Name column for:

NTBOOTMGR (NTBOOT)

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\BACKUP\SYSTEM\DRIVER\ntuser.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

In the Name column for:

NTLOAD

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

In the Name column for:

NTSVCMGR

< Double-click > it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\BACKUP\SYSTEM\DRIVER\ntsrv.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Delete all of the following noted (in red) file(s)/FOLDER(s) you can find:

c:\backup\system\driver\csrss.exe <— file

c:\backup\system\driver\ntsrv.exe <— file

c:\backup\system\driver\ntuser.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
Micah I am now at home and not at work any more(that’s the comp im having trouble with) I did do every thing that you told me to be for I left but when I went to reboot in safe mode it would lock up I tried it 5 times but it did the same thing every time. It didn’t allow me to gain access in to widows at all. I then rebooted in debugging mode and removed the file threw that. Then I rebooted and ran hijackthis and the csrss.exe was still there but it had moved it self in to c:\backup\system32. I will post the log file tomorrow morning but if you have any ideas about why it locks up while trying to boot in safe. Thank you so much
This is a legitimate windows file:

C:\BACKUP\system32\csrss.exe

This one was the "bad" one:

c:\backup\system\driver\csrss.exe

I'm not sure why it won't boot in "safe" mode…. :scratch:

There may be some malware yet on it.

I guess we'll work on it tomorrow.
Micah
I am sorry for the delayed response but I have not been able to access the forum from the computer we are working on. It tells me the page can not be found. I can get to the tomcoyote home page but it won’t let me go to the forum. I am on my home computer but I e-mailed my self the log file so here it is
Thank you
Pat

Logfile of HijackThis v1.99.1
Scan saved at 12:03:56 PM, on 9/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\BACKUP\System32\smss.exe
C:\BACKUP\system32\csrss.exe
C:\BACKUP\system32\winlogon.exe
C:\BACKUP\system32\services.exe
C:\BACKUP\system32\lsass.exe
C:\BACKUP\system32\svchost.exe
C:\BACKUP\system32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\system32\spoolsv.exe
C:\BACKUP\Explorer.EXE
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasDtServ.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\BACKUP\System32\svchost.exe
C:\BACKUP\System32\alg.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\BACKUP\system32\hpoipm07.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\MSN\MSNIA\msniasvc.exe
C:\Documents and Settings\Midwest Compost\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\GIANT Company Software\GIANT AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE /STANDALONE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: HPAiODevice(hp officejet k series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1120243276548
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E3103-BF86-4A2D-9F4A-FD3ADF86EC7E}: NameServer = 69.50.176.196,195.225.176.110
O17 - HKLM\System\CCS\Services\Tcpip\..\{CA663C71-C47B-4BC5-9AA6-1A80E2CD4638}: NameServer = 69.50.176.196,195.225.176.110
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
There's nothing in the log showing (all the known malware is gone :thumbup: )

Try this:

Please download and run Spybot-Search&Destroy and Ad-Aware; they are the standard programs for finding and cleaning malware off your system. Here are links to both programs, and instructions for their use.

Get Spybot - Search & Destroy from Spybot Search and Destroy
(This is the NEW Version 1.4)
Get AdAware SE Personal from Lavasoft
(This is the NEW Build 1.6)

Download and install these programs if you don't already have them. If you do have them, make sure they are UPDATED AND CONFIGURED AS DESCRIBED here:

Configure Adaware

Configure Spybot

Reboot after running each program.

Try this online virus scan:

Trend-Micro Housecall

Choose "fix" or "clean".

Let it remove any infections found.

Reboot and "copy/paste" a new Hijack This! log file into this thread. :)
Glad we could help.

:) :thumbup:

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?"

Download/install IE-Spyad

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings at Qualsys.com

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI