This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HELP PLEASE

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi;
I had antispyware soldier and i achieved to remove it by using noadware , AVG etc. under safe mode.
But i keep receiving IE pages indicating;



"System Security Center Alert:



Warning! Spyware files are detected on your computer!

It’s highly recommended to scan the system immediately to remove all dangerous spyware/adware programs.



Spyware gathers your private information without your consent.

This information includes passwords and credit card details, as well as other sensitive data.



Once installed, spyware keeps track of your surfing habits, which makes it possible for unsolicited ads and SPAM messages.

Spyware can not be removed by antivirus and firewalls.

These programs are not even able to find evidence of spyware being installed on the computer.

Spyware also uses your computer’s memory and system resources making your PC incredibly slow."


what should i do for removing this headache completely?
my hijackthis information;
Logfile of HijackThis v1.99.1
Scan saved at 23:36:15, on 22.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\Program Files\Winamp\winampa.exe
E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
E:\WINDOWS\system32\rundll32.exe
E:\Program Files\MessengerPlus! 3\MsgPlus.exe
E:\WINDOWS\system32\ctfmon.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\BITWARE\NT\bwprnmon.exe
E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
E:\WINDOWS\system32\ntvdm.exe
E:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\Microsoft Office\Office10\EXCEL.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\WINDOWS\system32\rundll32.exe
E:\Documents and Settings\SEMIH\Desktop\SEM Belgelerim\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11904ce8-632a-4856-a7cc-00b33fe71bd8} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ASGP32.ASGP - {89923A78-1DEA-41DC-A323-88DA2DE7B5AE} - E:\WINDOWS\system32\asgp32.dll
O2 - BHO: (no name) - {8dc8f96d-34f7-1501-a2a4-631341aa3ac1} - (no file)
O2 - BHO: (no name) - {d1ac752e-883f-4ed8-8828-b618c3a72152} - (no file)
O2 - BHO: (no name) - {e2b2b5a1-b48c-4886-a318-723916a01024} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e6d5237d-a6c7-4c83-a67f-f9f15586fa62} - (no file)
O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PE2CKFNT SE] E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Picasa Media Detector] E:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "E:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - Startup: MemTurbo.lnk = ?
O4 - Global Startup: BitWare Print Monitor.lnk = E:\BITWARE\NT\bwprnmon.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: MynetOkey - http://212.101.96.23/game/WebRoot/Okey.CAB
O16 - DPF: MynetTavla - http://212.101.96.33/game/WebRoot/Tavla.CAB
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {4975D552-DB29-4E77-BFDA-84B6E8B16304} (RTNetLauncher Control) - http://www.kocanalist.com/RealTrade/RTNetLauncher.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sadsem.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "E:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performans Bağdaştırıcısı (WmiApSrv) - Unknown owner - E:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)


PLEASE HELP ME!
REGARDS
Hi and welcome to TomCoyote. I need to take some time to look over your Hijack This log to come up with a fix. Please remember that I am an undergraduate which means I need to have my posts to you checked by a teacher or moderator to make sure I'm giving you the proper instructions. This process won't take long and I thank you for your patience. I'll be back with you soon.
Hi. Could you please rename the file HijackThis.exe to scanner.exe and use that filename for Hijack This for the remainder of this fix. Some malware can hide from Hijack This and renaming it can tell us a lot. Apart from that please follow the instructions below:

I would like to see an uninstall list from HijackThis.
  • Run Hijackthis.
  • Click on Open the Misc Tools section.
  • Next click on Open uninstall manager.
  • Press the Save list button. It will open a Notepad file.
  • Save the file to your desktop, with the default name of uninstall_list
  • Copy & Paste the entire contents of that file in your in your next post.
Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd

[external image: Posted Image]

Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log, the uninstall list and a fresh Hijack This log in your next reply.

IMPORTANT: Do NOT run any other options until you are asked to do so!
SmitFraudFix v2.102 Scan done at 21:43:46,95, 26.10.2006 Run from E:\Documents and Settings\SEMIH\Desktop\SmitfraudFix OS: Microsoft Windows XP [Srm 5.1.2600] - Windows_NT Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» E:\ »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system32 E:\WINDOWS\system32\kernels64.exe FOUND ! E:\WINDOWS\system32\ot.ico FOUND ! E:\WINDOWS\system32\ts.ico FOUND ! E:\WINDOWS\system32\vxgamet?.exe FOUND ! E:\WINDOWS\system32\vxh8jkdq?.exe FOUND ! E:\WINDOWS\system32\winmuse.exe FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\SEMIH »»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\SEMIH\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» E:\DOCUME~1\SEMIH\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» E:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Ad-Aware SE Personal Adobe Reader 6.0.1 Adobe Shockwave Player Advanced GET Ares 1.9.0 At Yarışı Tahmin ve Analiz Programı 3.0 avast! Antivirus AVG Anti-Spyware 7.5 BitComet 0.60 Deluxe Classic Cam HijackThis 1.99.1 hp deskjet 656c series (Remove only) J2SE Runtime Environment 5.0 Update 6 K-Lite Codec Pack 2.25 Standard LiveReg (Symantec Corporation) LiveUpdate 2.6 (Symantec Corporation) Macromedia Flash Player 8 Messenger Plus! 3 Messenger Plus! Live & Sponsor Microsoft Office XP Professional mIRC Nero 6 Enterprise Edition NoAdware v4.0 Nokia Connectivity Cable Driver Nokia PC Suite Norton WMI Update ParaMarket Veri Picasa 2 Scan 300 / 600 Driver Skype 2.0 Summus maxxAttractor TEKAREDi - Veri 1.0.7 Ulead Photo Express 2.0 SE VIA Platform Device Manager Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Live Sign-in Assistant Windows Media Player (KB911564) için Güvenlik Güncelleştirmesi Windows Media Player 9 (KB911565) için Güvenlik Güncelleştirmesi Windows Media Player 9 (KB917734) için Güvenlik Güncelleştirmesi Windows XP Düzeltme - KB873333 Windows XP Düzeltme - KB873339 Windows XP Düzeltme - KB885250 Windows XP Düzeltme - KB885835 Windows XP Düzeltme - KB885836 Windows XP Düzeltme - KB885884 Windows XP Düzeltme - KB886185 Windows XP Düzeltme - KB887472 Windows XP Düzeltme - KB887742 Windows XP Düzeltme - KB888113 Windows XP Düzeltme - KB888302 Windows XP Düzeltme - KB890859 Windows XP Düzeltme - KB891781 Windows XP Düzeltme - KB893086 Windows XP için Güncelleştirme (KB894391) Windows XP için Güncelleştirme (KB896727) Windows XP için Güncelleştirme (KB898461) Windows XP için Güncelleştirme (KB900485) Windows XP için Güncelleştirme (KB910437) Windows XP için Güncelleştirme (KB916595) Windows XP için Güncelleştirme (KB920872) Windows XP için Güncelleştirme (KB922582) Windows XP için Güvenlik Güncelleştirmesi (KB890046) Windows XP için Güvenlik Güncelleştirmesi (KB893066) Windows XP için Güvenlik Güncelleştirmesi (KB893756) Windows XP için Güvenlik Güncelleştirmesi (KB896358) Windows XP için Güvenlik Güncelleştirmesi (KB896422) Windows XP için Güvenlik Güncelleştirmesi (KB896423) Windows XP için Güvenlik Güncelleştirmesi (KB896424) Windows XP için Güvenlik Güncelleştirmesi (KB896428) Windows XP için Güvenlik Güncelleştirmesi (KB896688) Windows XP için Güvenlik Güncelleştirmesi (KB899587) Windows XP için Güvenlik Güncelleştirmesi (KB899588) Windows XP için Güvenlik Güncelleştirmesi (KB899589) Windows XP için Güvenlik Güncelleştirmesi (KB899591) Windows XP için Güvenlik Güncelleştirmesi (KB900725) Windows XP için Güvenlik Güncelleştirmesi (KB901017) Windows XP için Güvenlik Güncelleştirmesi (KB901214) Windows XP için Güvenlik Güncelleştirmesi (KB902400) Windows XP için Güvenlik Güncelleştirmesi (KB904706) Windows XP için Güvenlik Güncelleştirmesi (KB905414) Windows XP için Güvenlik Güncelleştirmesi (KB905749) Windows XP için Güvenlik Güncelleştirmesi (KB905915) Windows XP için Güvenlik Güncelleştirmesi (KB908519) Windows XP için Güvenlik Güncelleştirmesi (KB908531) Windows XP için Güvenlik Güncelleştirmesi (KB911280) Windows XP için Güvenlik Güncelleştirmesi (KB911562) Windows XP için Güvenlik Güncelleştirmesi (KB911567) Windows XP için Güvenlik Güncelleştirmesi (KB911927) Windows XP için Güvenlik Güncelleştirmesi (KB912812) Windows XP için Güvenlik Güncelleştirmesi (KB912919) Windows XP için Güvenlik Güncelleştirmesi (KB913446) Windows XP için Güvenlik Güncelleştirmesi (KB913580) Windows XP için Güvenlik Güncelleştirmesi (KB914388) Windows XP için Güvenlik Güncelleştirmesi (KB914389) Windows XP için Güvenlik Güncelleştirmesi (KB916281) Windows XP için Güvenlik Güncelleştirmesi (KB917159) Windows XP için Güvenlik Güncelleştirmesi (KB917344) Windows XP için Güvenlik Güncelleştirmesi (KB917422) Windows XP için Güvenlik Güncelleştirmesi (KB917953) Windows XP için Güvenlik Güncelleştirmesi (KB918439) Windows XP için Güvenlik Güncelleştirmesi (KB918899) Windows XP için Güvenlik Güncelleştirmesi (KB919007) Windows XP için Güvenlik Güncelleştirmesi (KB920214) Windows XP için Güvenlik Güncelleştirmesi (KB920670) Windows XP için Güvenlik Güncelleştirmesi (KB920683) Windows XP için Güvenlik Güncelleştirmesi (KB920685) Windows XP için Güvenlik Güncelleştirmesi (KB921398) Windows XP için Güvenlik Güncelleştirmesi (KB921883) Windows XP için Güvenlik Güncelleştirmesi (KB922616) Windows XP için Güvenlik Güncelleştirmesi (KB922819) Windows XP için Güvenlik Güncelleştirmesi (KB923191) Windows XP için Güvenlik Güncelleştirmesi (KB923414) Windows XP için Güvenlik Güncelleştirmesi (KB924191) Windows XP için Güvenlik Güncelleştirmesi (KB924496) Windows XP için Güvenlik Güncelleştirmesi (KB925486) ZioCam
Hi again; here is the my hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 19:44:32, on 27.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Winamp\winampa.exe
E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
E:\Program Files\QuickTime\qttask.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
E:\WINDOWS\system32\rundll32.exe
E:\Program Files\Picasa2\PicasaMediaDetector.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Internet Explorer\iexplore.exe
e:\progra~1\intern~1\iexplore.exe
e:\progra~1\intern~1\iexplore.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\BITWARE\NT\bwprnmon.exe
E:\WINDOWS\system32\ntvdm.exe
E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\explorer.exe
E:\Documents and Settings\SEMIH\Desktop\SEM Belgelerim\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11904ce8-632a-4856-a7cc-00b33fe71bd8} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ASGP32.ASGP - {89923A78-1DEA-41DC-A323-88DA2DE7B5AE} - E:\WINDOWS\system32\asgp32.dll
O2 - BHO: (no name) - {8dc8f96d-34f7-1501-a2a4-631341aa3ac1} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {d1ac752e-883f-4ed8-8828-b618c3a72152} - (no file)
O2 - BHO: (no name) - {e2b2b5a1-b48c-4886-a318-723916a01024} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e6d5237d-a6c7-4c83-a67f-f9f15586fa62} - (no file)
O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PE2CKFNT SE] E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Picasa Media Detector] E:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [deadmeetslowgrid] E:\Documents and Settings\All Users\Application Data\OOZE DATE DEAD MEET\webfile.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "E:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Balm jump] E:\DOCUME~1\SEMIH\APPLIC~1\LOGSPA~1\first meet ford.exe
O4 - Startup: MemTurbo.lnk = ?
O4 - Global Startup: BitWare Print Monitor.lnk = E:\BITWARE\NT\bwprnmon.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: MynetOkey - http://212.101.96.23/game/WebRoot/Okey.CAB
O16 - DPF: MynetTavla - http://212.101.96.33/game/WebRoot/Tavla.CAB
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {4975D552-DB29-4E77-BFDA-84B6E8B16304} (RTNetLauncher Control) - http://www.kocanalist.com/RealTrade/RTNetLauncher.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sadsem.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performans Bağdaştırıcısı (WmiApSrv) - Unknown owner - E:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)
I'm also getting below IE pages during internet surfing and some pop-ups. The page cannot be displayed ——————————————————————————– Search The Web: ——————————————————————————– Internet Online Gaming, Music, Sports, Casino, Movies, DVD, Mp3, Travel… Business & Economy Home Business, Internet Marketing, Long Distance, Online Advertising… Computers & Internet Internet, Hardware, Software, Games, Domain Names, Laptops, Printers,… Business Opportunities Making Money, Market Research, Affiliate Programs, Home Business… Entertainment Movies, Viagra, Music, MP3, Games, Playstation… Automotive Car Insurance, Financing, Auto Dealers… Health Medicine, Viagra, Drugs, Fitness, Pills,… Online Casino Gambling, Multi Player, Sports Books, Black Jack, Roulette Poker, Slots… E-Business Online Trading, Web Design, Hosting, Servers, Advertising, Bulk Email, Business Opportunities… Recreation & Sports Sports, Travel, Autos, Golf, Baseball Football, Tickets… Your Home Gardening, Pets, Real Estate, Home Loans… Travel Air Travel, Lodging, Cruises, Flight… Other Email, Celebrities, Religion, Education… ——————————————————————————– The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings. Please try the following: Click the Refresh button, or try again later. If you typed the page address in the Address bar, make sure that it is spelled correctly. To check your connection settings, click the Tools menu, and then click Internet Options. On the Connections tab, click Settings. The settings should match those provided by your local area network (LAN) administrator or Internet service provider (ISP). If you are trying to reach a secure site, make sure your Security settings can support it. Click the Tools menu, and then click Internet Options. On the Advanced tab, scroll to the Security section and check settings for SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. Click the Back button to try another link. Cannot find server or DNS Error - Internet Explorer
Hi. Another infection has crept into your log since you first posted it. It is very important that you try to answer back as quickly as possible when instructions are posted so as to minimize any chance of new infection during the fix.
:)

Step 1

Please run this tool:

It seems that there may possibly be some security updates missing from your system and this may cause problems with cleaning your PC.

Accordingly, please do the following:
  • Download a diagnostic tool (MGADiag.exe) from >here< and save this to your Desktop.
  • Double-click on MGADiag.exe.
  • When the program has finished, click on the Validation tab and then click on Copy to Clipboard
  • Please post the results in your next reply.
Step 2

Download ATF cleaner from here.

Locate ATF Cleaner.exe and open it.

Under Main select the following:

Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.

Step 3

Next, I notice that you have AVG Anti-Spyware already installed on your PC. Make certain that it's database is updated and run a full scan with it, but follow the instructions below when you run it:

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button.(4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

Please post the MGADiag log, the AVG Log and a fresh Hijack This log in your next reply.
thank you very much for your kind approach to me.Right now, i am working at the office (I will be on night shift during this week) and away from my PC. Tomorrow, i will follow your instructions on my PC at home and send the information you have requested from me. Thx
Unfortunately, It didn't work.

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 17:32:43 30.10.2006

+ Scan result:



C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083936.dll -> Adware.SideFind : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083932.exe -> Downloader.Small.dam : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083935.exe -> Downloader.VB.aeq : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083933.exe -> Downloader.VB.anw : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083934.exe -> Downloader.VB.anw : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP491\A0086665.exe -> Downloader.VB.apa : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083937.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083938.exe -> Not-A-Virus.Hoax.Win32.Renos.fe : Cleaned with backup (quarantined).
E:\Documents and Settings\SEMIH\Local Settings\Temp\NoadwareBkupTemp\semih@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083924.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083925.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083926.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083927.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083928.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083929.hta -> Trojan.LowZones.a : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083930.exe -> Trojan.Small : Cleaned with backup (quarantined).
E:\System Volume Information\_restore{DC946591-29A1-4CC2-8C3D-1A95471CD4B9}\RP485\A0083931.exe -> Trojan.Small : Cleaned with backup (quarantined).
E:\WINDOWS\system32\msmapi32.exe -> Trojan.VB.atw : Cleaned with backup (quarantined).


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 17:40:56, on 30.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Winamp\winampa.exe
E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
E:\WINDOWS\system32\rundll32.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\MSN Messenger\msnmsgr.exe
E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Internet Explorer\iexplore.exe
e:\progra~1\intern~1\iexplore.exe
E:\BITWARE\NT\bwprnmon.exe
E:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
E:\WINDOWS\system32\ntvdm.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Documents and Settings\SEMIH\Desktop\SEM Belgelerim\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {11904ce8-632a-4856-a7cc-00b33fe71bd8} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ASGP32.ASGP - {89923A78-1DEA-41DC-A323-88DA2DE7B5AE} - E:\WINDOWS\system32\asgp32.dll
O2 - BHO: (no name) - {8dc8f96d-34f7-1501-a2a4-631341aa3ac1} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {d1ac752e-883f-4ed8-8828-b618c3a72152} - (no file)
O2 - BHO: (no name) - {e2b2b5a1-b48c-4886-a318-723916a01024} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e6d5237d-a6c7-4c83-a67f-f9f15586fa62} - (no file)
O4 - HKLM\..\Run: [WinampAgent] E:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] E:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PE2CKFNT SE] E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] E:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [DataLayer] E:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] E:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Picasa Media Detector] E:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [deadmeetslowgrid] E:\Documents and Settings\All Users\Application Data\OOZE DATE DEAD MEET\webfile.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MessengerPlus3] "E:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "E:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Balm jump] E:\DOCUME~1\SEMIH\APPLIC~1\LOGSPA~1\first meet ford.exe
O4 - Startup: MemTurbo.lnk = ?
O4 - Global Startup: BitWare Print Monitor.lnk = E:\BITWARE\NT\bwprnmon.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = E:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: MynetOkey - http://212.101.96.23/game/WebRoot/Okey.CAB
O16 - DPF: MynetTavla - http://212.101.96.33/game/WebRoot/Tavla.CAB
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {4975D552-DB29-4E77-BFDA-84B6E8B16304} (RTNetLauncher Control) - http://www.kocanalist.com/RealTrade/RTNetLauncher.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://sadsem.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - E:\WINDOWS\
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - E:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WMI Performans Bağdaştırıcısı (WmiApSrv) - Unknown owner - E:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)
validation status :Blocked VLK validation status:114 I cannot send you the remaining information because i printed screen. If you want to know particular item information, i can send you afterwards. .But I have still got the problem.
In my opinion , while i was reaching www.seriall.com, my PC was infected. In my IE favorites section, i have some constant items(which are not removed or deleted) occured recently. It's quite weird.
There are indications that you have an issue with properly validating Windows XP. That issue needs to be addressed prior to cleaning your system as in your present state you will be unable to obtain all needed updates.

Currently, it is not possible to secure your system to any degree as it will just keep getting reinfected. Therefore, I suggest you contact Microsoft regarding your validation issue, either by telephone or at their forum that they have established especially for handling this type of problem…

http://forums.microsoft.com/genuine/default.aspx?siteid=25

Please feel free to return here and start a new topic after your validation issue has been resolved.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI