This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spyware or Paranoia?

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Firefox browser stopped opening on my selected homepage - despite having set the options to do so. This quirky behavior began after I inadvertently downloaded google toolbar and it installed. Despite uninstalling the toolbar, I still have this problem. Here is my Hijack Log:

Logfile of HijackThis v1.99.1
Scan saved at 12:51:41 PM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\PalmTether\TetherApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\PROGRA~1\PALMTE~1\PALMON~1.EXE
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Arthur Fougner MD\Desktop\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [PalmTether] "C:\Program Files\PalmTether\TetherApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'bmnet.dll' missing
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sprint PCS v3 Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe

Thanks in advance.
Hi! :wavey: and welcome to the Tom Coyote forums.
My name is John Brouwer - if it helps, you can call me John for short. I'll be glad to help you with your computer problems.

HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happens.
I am currently looking over your log. As I am a trainee, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Finally, please make a uninstall list using HijackThis
    To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.

    You will now be presented with a screen similar to the one below:

    [external image: Posted Image]

    5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
Greets, John.
Hi,

Please try the following to reset your homepage.
  • Open Firefox
  • Go to Tools
  • Go to Options
  • Under the Main tab where it says When Firefox Starts select Show a blank page from the Dropdown menu
  • Click OK
  • Close Firefox
  • Open Firefox
  • Go to Tools
  • Go to Options
  • Set the homepage to the website you want
  • Click OK
Does this work?

Greets, John.
Thank you, John The blank page startup persists with Firefox after doing what you suggested. Here is the list: 4D VIEW Ad-Aware SE Personal Adobe Flash Player 9 ActiveX Adobe Photoshop 7.0 Adobe Reader 7.0.8 ArcSoft Software Suite Atheros Client Utility Atheros Wireless LAN MiniPCI card Driver ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver Bluetooth Stack for Windows CD/DVD Drive Acoustic Silencer Documents To Go DVD-RAM Driver Easy CD Creator 5 Platinum FaxLauncher Pro GdiplusUpgrade GdPicture ToolKit Google Earth High Definition Audio Driver Package - KB888111 HijackThis 1.99.1 Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB894871) Hotfix for Windows XP (KB895200) HP Extended Capabilities 4.7 HP Image Zone 4.7 HP PSC & OfficeJet 4.7 HP Software Update InterVideo WinDVD for TOSHIBA J2SE Runtime Environment 5.0 Update 4 Logitech Desktop Messenger Logitech Print Service Logitech QuickCam Software Logitech® Camera Driver Macromedia Flash Player 8 McAfee VirusScan MetaFrame Presentation Server Web Client for Win32 Metamail (Toshiba Registration Utility) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Bootvis Microsoft Office Professional Edition 2003 Microsoft Works mIRC Mozilla Firefox (1.5.0.9) Mozilla Thunderbird (1.5.0.9) Office 2003 Trial Assistant Palm Quicken 2005 QuickTime RealPlayer REALTEK Gigabit and Fast Ethernet NIC Driver Realtek High Definition Audio Driver Roxio UDF Reader Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Sonic DLA Sonic RecordNow! Sprint PCS Connection Manager Spybot - Search & Destroy 1.4 Synaptics Pointing Device Driver TOSHIBA Assist TOSHIBA ConfigFree TOSHIBA Controls TOSHIBA Hotkey Utility TOSHIBA PC Diagnostic Tool TOSHIBA Power Saver TOSHIBA Software Modem TOSHIBA Software Upgrades TOSHIBA Speech System Applications TOSHIBA Speech System SR Engine(U.S.) Version1.0 TOSHIBA Speech System TTS Engine(U.S.) Version1.0 TOSHIBA TouchPad ON/Off Utility TOSHIBA Utilities TOSHIBA Virtual Sound TOSHIBA Zooming Utility Touch and Launch Update for Windows XP (KB894391) Viewpoint Media Player Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB884018 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885855 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893056 Yahoo! Messenger Thanks
Hi,

Hmm, lets try another option because we saw the 'blank page' button had an effect.
  • Open Firefox
  • Go to the page you want to be your new homepage
  • Go to Tools
  • Go to Options
  • Under the Main tab click the Use Current Pages button
  • Click OK
  • Close Firefox
  • Open Firefox
Does this work?

Greets, John.
It doesn't work the first time I fire up Firefox. It DOES work if I open the program again. Incidentally, I ran a Panda online scan … Incident Status Location Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.statcounter.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.zedo.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.azjmp.com/] Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[landing.domainsponsor.com/] Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.revenue.net/] Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[landing.domainsponsor.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.burstnet.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[.2o7.net/] Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Mozilla\Firefox\Profiles\4tpzgosp.default\cookies.txt[searchportal.information.com/] Virus:W32/Bagle.pwdzip Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[Dorithie.zip] Virus:W32/Bagle.pwdzip Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0001226.~][Dorithie.zip] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0002007.~] Virus:Trj/Banker.CZI Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[ID 0220712.zip][ID 0220712.exe] Virus:Trj/Nabload.GX Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[DD269901.zip][DD269901.exe] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0006857.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0007235.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0007307.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0007629.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0007742.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0008200.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0009605.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0009938.~] Virus:W32/Spamta.HV.worm Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[message.zip][message.msg.exe] Virus:Trj/SpamtaLoad.N Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[doc.zip][doc.txt.scr] Virus:Trj/SpamtaLoad.O Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[document.zip][document.log.cmd] Virus:Trj/SpamtaLoad.O Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[Update-KB8908-x86.exe] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0012353.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0012424.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0013054.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0014393.~] Virus:W32/Spamta.NO.worm Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[Update-KB4562-x86.zip][Update-KB4562-x86.exe] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0016903.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0016903.~][~0000003.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018301.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018610.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018631.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018632.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018632.~][~0000001.~] Virus:W32/Klez.I Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018632.~][other.bat] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018633.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018633.~][~0000001.~] Virus:W32/Klez.I Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018633.~][Tour.scr] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0018775.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Inbox[~0019321.~] Virus:Trj/Nabload.GX Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[DD269901.zip][DD269901.exe] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0001630.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0001857.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0001869.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0002051.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0002069.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0002981.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0002984.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0003639.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0003878.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0004136.~] Virus:W32/Spamta.NO.worm Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[Update-KB4562-x86.zip][Update-KB4562-x86.exe] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005608.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005682.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005682.~][~0000001.~] Virus:W32/Klez.I Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005682.~][Tour.scr] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005683.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005683.~][~0000001.~] Virus:W32/Klez.I Disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005683.~][other.bat] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005685.~] Hacktool:Exploit/iFrame Not disinfected C:\Documents and Settings\Arthur Fougner MD\Application Data\Thunderbird\Profiles\noxcqfah.default\Mail\Local Folders\Trash[~0005712.~] Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Documents and Settings\Arthur Fougner MD\Desktop\Desktop Files\sysreset253.exe[addons\moo.dll] Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\sysreset\addons\moo.dll Most of what it found was in either trashed or unopened email … Interestingly, the scan seemed to muck up Thunderbird in the process so all my saved email was unreadable. You may wish to pass that warning on to others. Thanks
Hi,

Can you please remove unused emails from your Inbox part in Thunderbird and delete everything in the Trash folder.

I didn't really understand if you're still encountering the problem. Every first time open Firefox after a reboot it doesn't work and the second time and after that it works?

Your system is clean so as this is a computer troubleshooting issue, not a malware issue, I suggest you use the following link to go to the CastleCops General Computer Problems forum for help from a CastleCops SRT…

http://www.castlecops.com/f120-General_Com…r_Problems.html

I recommend that you register before posting your problem. Registered members can receive notification when there has been a reply to their topic. There is no way for CCSP to notify "guests" when they have received a reply.

This list will help you stay clean. Especially because you aren't using Anti Virus software and a Firewall which is very insecure!
  • Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - Anti-Virus
    I recommend AVG Anti-Virus (Free Edition)!
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
    I recommend ZoneAlarm (Free Edition)!
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Greets, John.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI