This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

W32/Stration@MM Virus Infection

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sir, McAfee VirusScan Professional is alerting detection and cleaning of the viruses indicating the said files are deleted as part of virus removal. And the alerts appear again with the same message - as was previously experienced. Request your Help, Please. Thankyou.
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Don't run it yet.

Next:

Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All. Click the Empty Selected button. Close the program.
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware report scan along with a new HijackThis log
    .
Sir,

Please fine below both AVG scan report and new HJT log.

————————————————————————————————————

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 20:31:09 11/11/2006

+ Scan result:



C:\Program Files\Aquatica Waterworlds\AQ3Uninstaller.exe -> Adware.Gator : Cleaned with backup (quarantined).
:mozilla.140:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.130:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.131:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.132:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.133:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.48:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.49:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.74:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.76:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.75:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.88:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.89:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.90:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.91:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.84:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.129:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.144:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.112:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.47:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.50:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.236:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned.
:mozilla.237:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned.
:mozilla.220:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Matchcraft : Cleaned.
:mozilla.221:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Matchcraft : Cleaned.
:mozilla.222:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Matchcraft : Cleaned.
:mozilla.172:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.158:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.159:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.160:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.199:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.200:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.201:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.22:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.23:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.24:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.25:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.26:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.27:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.28:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.29:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.30:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.31:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.169:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.81:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.78:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.79:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.80:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.82:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\y1939t54.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{C8F2248A-7B42-4860-8242-1C23C704D6A2}\RP1\A0000115.exe -> Worm.Warezov : Cleaned with backup (quarantined).
C:\avenger\backup-10.11.2006-17.09.12.72.zip/avenger/libdcabi.dll -> Worm.Warezov : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C8F2248A-7B42-4860-8242-1C23C704D6A2}\RP1\A0000003.DLL -> Worm.Warezov.dd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{C8F2248A-7B42-4860-8242-1C23C704D6A2}\RP1\A0000114.exe -> Worm.Warezov.df : Cleaned with backup (quarantined).
C:\WINDOWS\system32\audconf.exe -> Worm.Warezov.dq : Cleaned with backup (quarantined).
C:\WINDOWS\system32\brwconf.exe -> Worm.Warezov.dq : Cleaned with backup (quarantined).
C:\avenger\backup-11.11.2006-17.24.03.74.zip/avenger/audmgr32.dll -> Worm.Warezov.dq : Cleaned with backup (quarantined).
C:\avenger\backup-11.11.2006-17.24.03.74.zip/avenger/brwmgr32.dll -> Worm.Warezov.dq : Cleaned with backup (quarantined).
C:\avenger\backup-10.11.2006-17.09.12.72.zip/avenger/vsutmsgi.dll -> Worm.Warezov.et : Cleaned with backup (quarantined).
C:\avenger\backup-11.11.2006-17.24.03.74.zip/avenger/audstat.dll -> Worm.Warezov.ex : Cleaned with backup (quarantined).
C:\avenger\backup-11.11.2006-17.24.03.74.zip/avenger/confaud.dll -> Worm.Warezov.ex : Cleaned with backup (quarantined).


::Report end

—————————————————————————————————————–


Logfile of HijackThis v1.99.1
Scan saved at 20:45:26, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\shared\mcinfo.exe
C:\My Download Files\Spyware Doctor\sdhelp.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Veoh\VeohClientService.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\IObit\Advanced WindowsCare V2\Awc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\MYDOWN~1\SPYWAR~1\swdoctor.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\USER\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mathrubhumi.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Reader 7.0.8\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\MYDOWN~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\MYDOWN~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O2 - BHO: posHelp Class - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\Toolbar.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O3 - Toolbar: 1-Click Answers - {7754C418-F62E-44aa-B169-E719E718BCFD} - C:\PROGRA~1\1-CLIC~1\IEToolbar\AnswersToolbarU.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Advanced WindowsCare V2 Personal] "C:\Program Files\IObit\Advanced WindowsCare V2\Awc.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [Spyware Doctor] C:\MYDOWN~1\SPYWAR~1\swdoctor.exe /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Adobe Reader 7.0.8\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Answers… - file:C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?7f5fea13dc914c9595f6a91f3c6d65e
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?7f5fea13dc914c9595f6a91f3c6d65e
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\MYDOWN~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1158756992267
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…881/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3D435A5F-9186-450F-A40A-4392BC8274FF}: NameServer = 213.42.20.20,195.229.241.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{3D435A5F-9186-450F-A40A-4392BC8274FF}: NameServer = 213.42.20.20,195.229.241.222
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4144\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\My Download Files\Spyware Doctor\sdhelp.exe
O23 - Service: Veoh Client Service - Veoh Networks, Inc. - C:\Program Files\Veoh\VeohClientService.exe



—————————————————————————————————————————-

Many Many thanks for helping me out.

Awaits your further instructions.

:)
:thumbup: Hello Sir, Very Many Thanks to You. Better performance now. So far No Virus Alerts. Thinks it is sorted out. But I am cautious considering my faux-pass about the first eradication. Nevertheless, I am hopeful we have succeeded. Shall I shred all those Avenger and HJT back-up files? Is there any harm in going for a "Secure PC After An Attack" process (System Restore Functions)? I take leave for the time being - I am packing for my annual vacation tomorrow , until 'X-Mas'. For further cures, if any, I will certainly need your guidance later. Until then, Bye Sir. Accept my Sincere Gratitude for the help you have extended me all this while. May God Bless You and Your Beloved. Thanking You once again…………………………………. :wavey:
Probably should create a clean restore point now.

Go to:

Start -> All Programs -> Accessories -> System Tools -> System Restore

And create a restore point.

Anything used in this removal process can be removed/uninstalled if you like.

Thank you for choosing TomCoyote for your malware removal solutions.

Here's keeping my fingers crossed that all your "gremlins" have been defeated.
M68 :) :thumbup:

Securing Your PC After An Attack
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI