My computer's been causing me all kinds of litttle/big problems since i installed NAV. Needless to say ive uninstalled it but it seems to have changed ALOT of my settings ( cant get msconfig to open, cant open a link in OE, slow boot, cant change some of the 'wallpapers' (desktop), etc. too much to list.
This baby's been running almost error free for 6 yrs. (i use go-Back alot), then BOOM. 1 after Another. Problem City!
I would very much appreciate any help. I've included a copy of HJT and a scan report of Ewido Ant-imalware.
Thanx, much
Logfile of HijackThis v1.99.1
Scan saved at 11:53:21 AM, on 1/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTSvcCDA.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\unzipped\hijackthis-3\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - blank (file missing)
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\Shdocvw.dll
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} - http://rd1.surfernet...urferplugin.ocx
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by107fd.bay10...ex/HMAtchmt.ocx
O16 - DPF: {F5820AD3-9B20-423E-B2AA-7AF2B4055746} (CRegistryDownload Class) - http://download.palt....x/regdload.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/...s/msnchat45.cab
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: GBPoll - Unknown owner - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe (file missing)
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
-------------------------------------------------------------------------------------------------------------------------
Ewido scan report...
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 11:20:18 AM, 1/29/2006
+ Report-Checksum: C5EDB5F2
+ Scan result:
:mozilla.13:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sexlist : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\si7d0rji.default\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\x8zsb327.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\x8zsb327.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Unknown User\Application Data\Mozilla\Firefox\Profiles\x8zsb327.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
::Report End