This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New computer already infected! Please help

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I recently purchased a new HP Pavilion (dv9010ca) notebook with Windows XP SP2 Media Center Edition. I immediately started applying all of the Windows Update patches I could find, but it seems something got in here before I could finish.

The first thing I noticed was that I was being prompted over and over again to install Windows updates KB924191 and KB927978, both having to do with XML core services possibly allowing remote code execution. Each time I would try to install this update, restart, and get prompted again to install it. Following this, the sound and microphone capabilities stopped functioning. After investigation, the audio drivers still appear to be there, but are disabled somehow and I can no longer access their properties from the system tray. When I go to Audio properties it shows that no audio or recording devices are installed. I am also getting a svchost.exe error every time upon startup and whenever I try to manually search for and install windows updates, and occasionally a 'Generic Win32' error.

I have run AdAware, which only produces negligible objects at this time. I have run full system scans of Norton Anti-Virus, which does not find anything. I ran Spybot S&D, which did find that the registry keys for Windows Update had been modified to disable them, as well as 2 other keys for Norton Live Update I believe. Upon subsequent S&D scans, those no longer appear after fixing (I've rebooted several times as well). I have also tried running XoftSpySE, which has only found WildTangent products (which came installed on the machine when I purchased it). All virus/malware scanning tools have been updated to their latest definition files.

I have also run the Trend Micro House Call scan which only identified the 2 vulnerabilities from the XML updates. From links in the scan results I was finally able to manually install the exes for the Windows fixes for the XML vulnerabilities, but upon reboot, still receive the svchost.exe error and have no sound.

I've now downloaded and run AVG Anti-Spyware. Please see below for that log and the HJT log.

Thank you in advance for your help!

Chris


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 9:46:03 PM 19/01/2007

+ Scan result:



C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned.
:mozilla.117:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.118:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.220:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.50:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.52:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.123:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.329:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.330:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.34:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.54:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.19:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.163:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.13:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.124:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.125:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.126:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.403:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.404:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.405:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.406:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.407:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.14:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.15:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.16:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.21:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.331:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.332:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.333:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.342:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.343:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.344:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.323:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.20:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.226:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.238:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.127:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.128:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.129:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.130:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.240:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.241:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.242:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.156:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.252:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.253:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.254:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.255:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.256:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.270:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.271:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.272:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.290:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.291:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.292:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.313:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.243:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.244:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.245:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.246:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.247:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.304:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.305:C:\Documents and Settings\Chris Taylor\Application Data\Mozilla\Firefox\Profiles\l28dcfvu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 9:51:55 PM, on 19/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Chris Taylor\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cbc.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Reminder] C:\Windows\CREATOR\Remind_XP.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_CA&c=64&bd=pavilion&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1168129916352
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Hello and welcome to the Forum

I'm not seeing any spyware/malware in your log but lets see if we can find anything.

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    [external image: Posted Image]
    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Thank you very much for your reply. Three things were detected when running Dr. Web: GTDownHP.ocx;C:\Program Files\HP\HPNetworkAssistant\BrowserPlugins;Probably DLOADER.Trojan;Incurable.Moved.; brandit.exe;C:\SWSetup\BrandIt\Disk1;Probably STPAGE.Trojan;Incurable.Moved.; HPISDataManager.dll;C:\WINDOWS\Downloaded Program Files\CONFLICT.1;Probably DLOADER.Trojan;Incurable.Moved.; As well, after reboot I received a warning from Spybot that a registry value had been changed: Category: System Startup global entry Change: Value deleted Entry: UserFaultCheck Old Data: %systemroot%\system32\dumprep 0 -u Since I thought this may have been a change made through the 'curing' process, I allowed it. As well, when I rebooted, I don't think I received the svchost.exe error I had been getting, but I did get 2 of the Generic Win32 process errors. Again, thank you for your continued help! Chris
Hello again, Thanks for your suggestion. I downloaded and installed the Windows HotFix. Upon reboot, I got the svchost.exe error again, immediately followed by a Generic Win32 process error. In my system tray the Windows Update icon actually appeared notifying me that there were updates ready for my computer, but as soon as I put my mouse cursor on it, the icon disappeared, as it has done in the past. Following that, my computer wouldn't launch any applications from the QuickLaunch toolbar (not sure about regular shortcuts), nor could I shut it down using the Start Menu - only by pressing the power button. This freezing is the same behaviour I see if I try to manually go to the Windows Update web site and download updates. In those cases I'm not sure if it's just the act of launching IE (I'm using Firefox for everything else), or that I'm trying to go to the Windows site that's triggering the strange behaviour. I started up again now to write this reply and got the svchost.exe error only (though if I were to launch IE & go to the Windows site, I think I would get more errors). I'm really at a loss - I don't know if it's paranoia, but something that's preventing me from getting Windows updates seems eerily premeditated. But if you're not seeing anything that worries you in these posts, then I guess I'll have to explore other avenues. If you have any other ideas, I'm certainly open to any further suggestions at this point. Thanks so much, Chris
1. Locate the file "host" and renaming it to "host.old" (all without the quotation marks). "host" was located in the C:\Windows\system32\drivers\etc folder in my case. The "host" file has no extension associated with it. 2. If you're running Windows XP Pro, NT or 2000, the "host" file should be located in your C:\winnt\system32\drivers\etc folder. Windows Update should now work without even rebooting. You could have a realtime protection stopping it also. Like teatimer.
Hi again, Thanks for plugging away on this with me. I tried changing the hosts file and unfortunately it didn't change anything. I still experienced the same strange behaviour when I went to the Windows update page and when I move to the Windows update icon in my system tray. When you mentioned TeaTimer it rang a bell - when I was installing Spybot S&D I believe it said something about TeaTimer. I tried closing the Spybot resident in my system tray then going to the Windows update page and once again got the same results :( Similar svchost.exe errors in all cases too. Thanks again for the suggestions. Chris
I don't get the CPU utilization problem, but the other things definitely sound like the problem. I'll definitely give this a try. Thanks again for all of your help! Chris
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI