Hello,this is my first post here.I have some problems with my computer in last ten days.It is geting slower and slower,and I receive this message every 15-20 mins.
" Messanger service
Message from security to alert
STOP!
Registry cleaner recommended
To fix errors please do the following:
1.Download registry repair from www.regpro32.com
2.install registry repair
3.run registry repair
4.reboot your computer
Failure to act ma lead to data loss and corruption."
I tried with Ghost program,and with restore operation(this was the way i solved some problems before),but didnt help this time.I tried also with Kaspersky,Norton,Ad adware,and it didnt find any viruses.Last night I installed AVG free edition and enido anti spyware.AVG didnt find any virus,but it did said that boot sector of C disc was changed,
Can Yoy help me somehow,please?What shall I do?How do I stop this message,and how to make my PC fast again?
Thanks.
Hi johnnykg,
I go by FencerGirl. I would be glad to help you solve your computer problems.
I'd be grateful if you would note the following:
I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for this issue on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Finally, please reply to this thread. Do not start a new topic.
It may take me a while to reply to you as all of my fixes are being checked by experts to ensure that you are getting a good fix. And remember, like you I have a real life, so I may not be at my computer when you are!
It sounds like you have some malware on your computer. Could you please post a HijackThis log to help me diagnose your problem?
This is the easiest way to install HijackThis to your computer
This is a complete installer that installs HijackThis on the computer to C:\Program Files\HijackThis.
It makes an entry in the start menu
It allows you to have a shortcut on your desktop as well.
HijackThis is currently at Version 1.99.1 released on 16.02.2005.
Double click on the installer's icon to install HiJackThis.
After you have installed HijackThis, please start it and choose: Do a system scan and save a log file
Copy the log file and paste it to this thread.
Do not try to fix anything yet! HijackThis shows lots of good files as well as bad.
You seem to have a couple of holes in your security software. First, you do not have Service Pack 2. Do NOT install it at this time, until we are sure your computer is clean. I'll give you further instructions when you can safely install SP2. Please be aware that you will not be able to get any more security updates unless you have SP2 installed.
From the contents of the pop-up message you've typed, it may be coming from Windows Messenger. For instructions on how to turn off Windows Messenger, please go here. Let me know if the messages persist.
I see you have FlashGet. Is this the unregistered version? If so, I would suggest uninstalling it from Add/Remove programs in Control Panel since the unregistered version serves up Ads in Internet Explorer that are downloaded from Cydoor servers, which is known adware. However, if this is the registered version then it is safe to use.
Apart from FlashGet, I do not see anything else bad in your HijackThis log…lets see what we can do.
HOUSECLEANING. Especially if your computer’s performance is heavily compromised, clean out the Temporary Internet Files and Temp folders first.
Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Navigate to the C:\Documents and Settings\username\Local Settings\Temp\ folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Finally, go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.
Empty Your Recycle Bin.
UPDATE JAVA. You are using a version of Sun Java that is prior to JRE Version 5.0 Update 6.
You are strongly urged to remove any/all versions that are prior to JRE/JSEVersion 5.0 Update 6. There are vulnerabilities in them and they are actively being exploited.
Therefore, it is highly suggested that if there are any prior versions of Sun Javato Version 5 Update 6 on the PC that they be removed and Sun Java JRE/JSE Version 5.0 Update 9 be installed ASAP.
Simple check, look under…
C:\Program Files\Java
The only folder under that folder should be the latest version…
C:\Program Files\Java\jre1.5.0_09
If it is not, go to Start>>Control Panel>>Add/Remove Programs and remove all versions of Java you find there.
Then, browse to C:\Program Files\Java and delete the whole folder.
Download the latest version of Java from here. Scroll down until you see Java Runtime Environment (JRE) 5.0 Update 9 and click "Download". Close all browser windows and install it.
CLEAN WITH EWIDO. I see that you have Ewido. It's been replaced with AVG Anti-spyware. Why don't we update your program and run a scan. Preparation
1) Download the trial version of AVG anti-spyware from here and save it to your Desktop. If you already have this program installed, skip to Updating AVG: below.
* Please note that these instructions are for the new version - AVG anti-spyware. If you have the old version - AVG anti-malware and it is the:
paid-for version - you will need to go here and obtain an updated license code before you upgrade.
free version - you will need to uninstall it and reboot before installing the new version.
Double click the AVG-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG anti-spyware will open.
Updating AVG:
By default AVG is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
Click the Update icon at the top and under "Manual Update" - click the Start update button.
Either AVG will update or inform you that no update was available.
If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
Once you have installed AVG, double click ewido-signatures-full-current.exe to update it.
Disabling the Resident Shield:
By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
(When the PC has been cleaned you can activate the shield again, if you wish.)
Click the Shield icon at the top and under "Resident shield is…" - click active.
This should now change to inactive.
Changing Recommended Actions
Click the Scanner icon at the top and then click the Settings Tab.
Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG anti-spyware.
AVG anti-spyware is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.
Log off from the internet and disconnect your modem cable for the duration of the fix. Get into Safe Mode by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.
You'll want to print out these instructions because you will not have internet access while in Safe Mode.
Removal
1) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG anti-spyware.
If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
Click "Complete System Scan"
While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
When the scan has completed, any threats that AVG has detected will be displayed.
Click the Apply all actions button at the bottom.
When AVG has finished, it will display the message "All actions have been applied".
Saving a report:
Click the Save Report button at the bottom left and the "Reports" window will open.
The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports folder.
You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG Anti-Spyware.
2) Boot into Normal Mode.
RUN AN ONLINE VIRUS SCAN Let's also run an online virus scan to see if there is anything you AVG anti-virus has missed.
Please do an online scan with Kaspersky
WebScanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky,
Click Yes.
The program will launch and then begin downloading the latest
definition files:
Once the files have been downloaded click on NEXT
Now click on Scan Settings
In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
Extended (if available otherwise
Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK
Now under select a target to scan:Select My Computer
This will program will start and scan your system.
The scan will take a while so be patient and let it run.
Once the scan is complete it will display if your system has been
infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post.
When you've completed all of these steps, please post back with an AVG Anti-malware log, the Kaspersky log, a new HijackThis log and whether you are still getting pop-ups.
Scan Statistics:
Total number of scanned objects: 36279
Number of viruses found: 2
Number of infected objects: 5 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:43:47
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AVG7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\PC!\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Temp\Perflib_Perfdata_7b0.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\History\History.IE5\MSHist012006100420061005\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\PC!\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\PC!\ntuser.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP17\change.log Object is locked skipped
D:\FILMOVI\bsplayer138.828.exe/data0011 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\FILMOVI\bsplayer138.828.exe NSIS: infected - 1 skipped
D:\FILMOVI\bsplayer200.937_clip.exe/data0011 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\FILMOVI\bsplayer200.937_clip.exe NSIS: infected - 1 skipped
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 10:37:41 PM, on 10/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Ad-Aware SE Build 1.06r1
Logfile Created on:Thursday, October 05, 2006 12:11:35 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R124 19.09.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa(TAC index:5):3 total references.
Cydoor(TAC index:7):7 total references.
MRU List(TAC index:0):22 total references.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Prior to deletion, allow unloading Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic settings in log file
Set : Include additional settings in log file
Set : Include reference summary in log file
Set : Include Alternate Datastream details in log file
Set : Play sound at scan completion if scan locates critical objects
10-5-2006 12:11:35 AM - Scan started. (Full System Scan)
MRU List Object Recognized:
Location: : C:\Documents and Settings\PC!\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized:
Location: : C:\Documents and Settings\PC!\recent
Description : list of recently opened documents
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\adobe\photoshop\7.0\visiteddirs
Description : adobe photoshop 7 recent work folders
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized:
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized:
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized:
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
MRU List Object Recognized:
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized:
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 32
12:17:33 AM Scan Complete
Summary of this scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:05:57.516
Objects scanned:117101
Objects identified:10
Objects ignored:0
New Critical Objects:10
That is it.I am not sure about the message.It didnt pops out today,but I didnt do anything ,computer was just turned on and I was out of home.It looks good so far.
Hi johnnykg,
It looks like you have a couple of malware programs on your computer. You appear to have (or had) Cydoor, WhenU and Alexa. When you ran the Ad-Aware scan, did you allow it to clean all of the critical objects?
If you didn't please re-run Ad-Aware and allow it to clean all critical objects.
Also, it appears you still have FlashGet on your system and it is not the paid version, since you have Cydoor. I would highly recommend that you uninstall FlashGet. If you decide not to uninstall it, please ignore the purple lines below.
REMOVE PROGRAMS. Some parasites can be easily and effectively removed from the Add/Remove Programs applet in the Windows Control Panel.
Please go to Start >> Control Panel >> Add/Remove Programs and remove WhenU (if it is present)
CLEAN OUT ANY REMAINING GARBAGE. We need to clean up any garbage that eluded our malware scanners.
Now, scan with HijackThis and check the following if present. O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) CLOSE ALL OTHER WINDOWS and select "Fixed Checked".
TIDY UP. Almost there!
According to Kaspersky, the following files are infected.
Please browse to the following files and delete them if present.
D:\FILMOVI\bsplayer138.828.exe
D:\FILMOVI\bsplayer200.937_clip.exe
Now, reboot into normal mode.
CREATE AN UNINSTALL LIST.
To access the Uninstall Manager you would do the following:
1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
You will now be presented with a screen similar to the one below:
[external image: Posted Image]
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file.
Finally, scan again with HijackThis and post a new log along with your uninstall list.
I did all things u told me too.I will now post all the new logs.I must say that i did unistall Flashget the last time(add/remove programs),I dont know where u seen it is still on the computer.I deleted the things u said in Your last post,but I can see the Kaspersky found again some viruses.And just one more thing,I noticed very often that all viruses and infected objects are connected with volume information files or folders.Should I delete that?Thanks in advance for Your time and answer.
The logs:
Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, October 06, 2006 8:10:30 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R125 06.10.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):21 total references.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Prior to deletion, allow unloading Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic settings in log file
Set : Include additional settings in log file
Set : Include reference summary in log file
Set : Include Alternate Datastream details in log file
Set : Play sound at scan completion if scan locates critical objects
10-6-2006 8:10:30 PM - Scan started. (Full System Scan)
MRU List Object Recognized:
Location: : C:\Documents and Settings\PC!\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized:
Location: : C:\Documents and Settings\PC!\recent
Description : list of recently opened documents
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\adobe\photoshop\7.0\visiteddirs
Description : adobe photoshop 7 recent work folders
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\ahead\nero - burning rom\recent file list
Description : list of recently used files in nero burning rom
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized:
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized:
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized:
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened
MRU List Object Recognized:
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized:
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized:
Location: : S-1-5-21-789336058-963894560-682003330-1003\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 21
8:15:36 PM Scan Complete
Summary of this scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:05:05.812
Objects scanned:118090
Objects identified:0
Objects ignored:0
New Critical Objects:0
Logfile of HijackThis v1.99.1
Scan saved at 8:22:52 PM, on 10/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Adobe Flash Player 9 ActiveX
Adobe Photoshop 7.0
Agere Systems PCI Soft Modem
Alcohol 120%
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
AVG Free Edition
Corel Uninstaller
ewido anti-spyware 4.0
Hijackthis 1.99.1
HijackThis 1.99.1
J2SE Runtime Environment 5.0 Update 9
Kaspersky Online Scanner
K-Lite Codec Pack 2.27 Full
Microsoft Office PowerPoint Viewer 2003
Microsoft Office Professional Edition 2003
mIRC
Mozilla Firefox (1.5.0.7)
MV2Player (remove only)
Nero OEM
Nokia Multimedia Player
NVIDIA Windows 2000/XP nForce Drivers
Realtek AC'97 Audio
Total Commander (Remove or Repair)
Winamp (remove only)
Windows Live Messenger
Windows XP Hotfix - KB823980
KASPERSKY ONLINE SCANNER REPORT
Friday, October 06, 2006 9:19:56 PM
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 6/10/2006
Kaspersky Anti-Virus database records: 229694
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Statistics:
Total number of scanned objects: 37255
Number of viruses found: 2
Number of infected objects: 5 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:46:56
Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\AVG7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\PC!\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\History\History.IE5\MSHist012006100620061007\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\PC!\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\PC!\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\PC!\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\PC!\UserData\index.dat Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\change.log Object is locked skipped
D:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\A0005080.exe/data0011 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\A0005080.exe NSIS: infected - 1 skipped
D:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\A0005081.exe/data0011 Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\A0005081.exe NSIS: infected - 1 skipped
D:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\change.log Object is locked skipped
E:\System Volume Information\_restore{0B4F1EB6-5C98-472D-923C-A82885AE1FCF}\RP18\change.log Object is locked skipped
Your latest logs all look clean. Don't worry about what you see in Kaspersky. You shouldn't try to delete the system and volume information files.
The few infected things in that log are all in system restore and we're going to take care of them in a minute.
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Disable and Enable System Restore. - You should disable and re-enable system restore to make sure there are no infected files found in a restore point.
You can find instructions on how to enable and re enable system restore here: Windows XP System Restore Guide
re-enable system restore with instructions from tutorial above
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an Anti Virus Software - You are using AVG. Keep up the good work!
Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below: Computer Safety On line - Software Firewalls
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
t is highly imperative that you install Service Pack 2 (SP2). It will be required to get further security updates from Microsoft in the very near future. It also has a lot of great security features built in. If you need further information, please look at this. Scroll down to "Installing from the Internet by using Windows Update" and follow the steps.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here: Instructions for - Spybot S & D and Ad-aware
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here: Computer Safety on line - Anti-Malware
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.