This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Posting my log...have possible viruses

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there. I have some kind of program running in my background all the time, and I'm not sure what it is. I get a window popup in my taskbar every hour or so that dissapears before I can click on it to see what it is. My system has been running excruciatingly slow of late too. I would appreciate an analysis of my log. Thank you kindly. Janeen

Logfile of Trend Micro

HijackThis v2.0.0 (BETA)
Scan saved at 8:11:01 PM,

on 3/27/2007
Platform: Windows XP SP2

(WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32

\smss.exe
C:\WINDOWS\system32

\winlogon.exe
C:\WINDOWS\system32

\services.exe
C:\WINDOWS\system32

\lsass.exe
C:\WINDOWS\system32

\svchost.exe
C:\WINDOWS\System32

\svchost.exe
C:\Program Files\Common

Files\Symantec

Shared\ccSvcHst.exe
C:\Program Files\Common

Files\Symantec

Shared\AppCore\AppSvc32.ex

e
C:\WINDOWS\system32

\spoolsv.exe
C:\Program

Files\Symantec\LiveUpdate\

ALUSchedulerSvc.exe
C:\WINDOWS\System32

\nvsvc32.exe
C:\WINDOWS\System32

\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program

Files\Apoint2K\Apoint.exe
C:\Program

Files\ltmoh\Ltmoh.exe
C:\PROGRA~1

\EzButton\CPLBTS88.EXE
C:\Program

Files\TOSHIBA\E-

KEY\CeEKey.exe
C:\Program

Files\TOSHIBA\Power

Management\CePMTray.exe
C:\Program

Files\TOSHIBA\TouchPad\TPT

ray.exe
C:\WINDOWS\System32

\ezSP_Px.exe
C:\toshiba\ivp\ism\pinger.

exe
C:\Program

Files\HP\hpcoretech\hpcmpm

gr.exe
C:\Program Files\HP\HP

Software

Update\HPWuSchd2.exe
C:\Program Files\Common

Files\Symantec

Shared\ccApp.exe
C:\Program Files\Visioneer

OneTouch\OneTouchMon.exe
C:\WINDOWS\system32

\ctfmon.exe
C:\Program

Files\Google\GoogleToolbar

Notifier\1.2.1128.5462

\GoogleToolbarNotifier.exe
C:\Program

Files\Apoint2K\Apntex.exe
C:\Program

Files\HP\Digital

Imaging\bin\hpqtra08.exe
C:\Program

Files\HP\Digital

Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32

\HPZipm12.exe
C:\Program Files\Internet

Explorer\iexplore.exe
C:\Documents and

Settings\Vashti\Desktop\Hi

JackThis_v2.exe

R0 -

HKCU\Software\Microsoft\In

ternet Explorer\Main,Start

Page =

http://www.etsy.com/index.

php
R1 -

HKLM\Software\Microsoft\In

ternet

Explorer\Main,Default_Page

_URL =

http://go.microsoft.com/fw

link/?LinkId=69157
R1 -

HKLM\Software\Microsoft\In

ternet

Explorer\Main,Default_Sear

ch_URL =

http://go.microsoft.com/fw

link/?LinkId=54896
R1 -

HKLM\Software\Microsoft\In

ternet

Explorer\Main,Search Bar =

http://us.rd.yahoo.com/cus

tomize/ie/defaults/sb/msgr

8/*http://www.yahoo.com/ex

t/search/search.html
R1 -

HKLM\Software\Microsoft\In

ternet

Explorer\Main,Search Page

=

http://go.microsoft.com/fw

link/?LinkId=54896
R0 -

HKLM\Software\Microsoft\In

ternet Explorer\Main,Start

Page =

http://go.microsoft.com/fw

link/?LinkId=69157
R3 - URLSearchHook: Yahoo!

Toolbar - {EF99BD32-C1FB-

11D2-892F-0090271D4F88} -

(no file)
O2 - BHO: AcroIEHlprObj

Class - {06849E9F-C8D7-

4D59-B87D-784B7D6BE0B3} -

C:\Program

Files\Adobe\Acrobat 5.0

\Reader\ActiveX\AcroIEHelp

er.ocx
O2 - BHO: (no name) -

{1E8A6170-7264-4D0F-BEAE-

D42A53123C75} - C:\Program

Files\Common

Files\Symantec

Shared\coShared\Browser\1.

0\NppBho.dll
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-

206D7942484F} - C:\Program

Files\Spybot - Search &

Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class

- {761497BB-D6F0-462C-

B6EB-D4DAF1D92D43} -

C:\Program

Files\Java\jre1.5.0_10

\bin\ssv.dll
O2 - BHO: Google Toolbar

Helper - {AA58ED58-01DD-

4d91-8333-CF10577473F7} -

c:\program

files\google\googletoolbar

2.dll
O3 - Toolbar: Show Norton

Toolbar - {90222687-F593-

4738-B738-FBEE9C7B26DF} -

C:\Program Files\Common

Files\Symantec

Shared\coShared\Browser\1.

0\UIBHO.dll
O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-

009027A5CD4F} - c:\program

files\google\googletoolbar

2.dll
O4 - HKLM\..\Run:

[NvCplDaemon] RUNDLL32.EXE

NvQTwk,NvCplDaemon

initialize
O4 - HKLM\..\Run: [nwiz]

nwiz.exe /install
O4 - HKLM\..\Run: [Apoint]

C:\Program

Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh]

C:\Program

Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run:

[CPLBTS88] C:\PROGRA~1

\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY]

C:\Program

Files\TOSHIBA\E-

KEY\CeEKey.exe
O4 - HKLM\..\Run:

[CeEPOWER] C:\Program

Files\TOSHIBA\Power

Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF]

C:\Program

Files\TOSHIBA\TouchPad\TPT

ray.exe
O4 - HKLM\..\Run:

[ezShieldProtector for Px]

C:\WINDOWS\System32

\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger]

c:\toshiba\ivp\ism\pinger.

exe /run
O4 - HKLM\..\Run: [HP

Component Manager]

"C:\Program

Files\HP\hpcoretech\hpcmpm

gr.exe"
O4 - HKLM\..\Run: [HP

Software Update]

C:\Program Files\HP\HP

Software

Update\HPWuSchd2.exe
O4 - HKLM\..\Run:

[REGSHAVE] C:\Program

Files\REGSHAVE\REGSHAVE.EX

E /AUTORUN
O4 - HKLM\..\Run:

[QuickTime Task]

"C:\Program

Files\QuickTime\qttask.exe

" -atboottime
O4 - HKLM\..\Run: [ccApp]

"C:\Program Files\Common

Files\Symantec

Shared\ccApp.exe"
O4 - HKLM\..\Run:

[osCheck] "C:\Program

Files\Norton Internet

Security\osCheck.exe"
O4 - HKLM\..\Run:

[OneTouch Monitor]

C:\Program Files\Visioneer

OneTouch\OneTouchMon.exe
O4 - HKCU\..\Run:

[ProxyWay] C:\Program

Files\ProxyWay\proxyway.ex

e
O4 - HKCU\..\Run:

[ctfmon.exe]

C:\WINDOWS\system32

\ctfmon.exe
O4 - HKCU\..\Run: [swg]

C:\Program

Files\Google\GoogleToolbar

Notifier\1.2.1128.5462

\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe

Gamma Loader.lnk =

C:\Program Files\Common

Files\Adobe\Calibration\Ad

obe Gamma Loader.exe
O4 - Global Startup: HP

Digital Imaging

Monitor.lnk = C:\Program

Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP

Image Zone Fast Start.lnk

= C:\Program

Files\HP\Digital

Imaging\bin\hpqthb08.exe
O4 - Global Startup:

Microsoft Office.lnk =

C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O8 - Extra context menu

item: E&xport to Microsoft

Excel - res://C:\PROGRA~1

\MICROS~3\Office10

\EXCEL.EXE/3000
O9 - Extra button: (no

name) - {08B0E5C0-4FCB-

11CF-AAA5-00401C608501} -

C:\Program

Files\Java\jre1.5.0_10

\bin\ssv.dll
O9 - Extra 'Tools'

menuitem: Sun Java Console

- {08B0E5C0-4FCB-11CF-

AAA5-00401C608501} -

C:\Program

Files\Java\jre1.5.0_10

\bin\ssv.dll
O9 - Extra button: ICQ

Lite - {B863453A-26C3-

4e1f-A54D-A2CD196348E9} -

C:\Program

Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools'

menuitem: ICQ Lite -

{B863453A-26C3-4e1f-A54D-

A2CD196348E9} - C:\Program

Files\ICQLite\ICQLite.exe
O9 - Extra button:

Real.com - {CD67F990-D8E9

-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32

\Shdocvw.dll
O9 - Extra button: (no

name) - {e2e2dd38-d088-

4134-82b7-f2ba38496583} -

%windir%\Network

Diagnostic\xpnetdiag.exe

(file missing)
O9 - Extra 'Tools'

menuitem: @xpsp3res.dll,-

20001 - {e2e2dd38-d088-

4134-82b7-f2ba38496583} -

%windir%\Network

Diagnostic\xpnetdiag.exe

(file missing)
O9 - Extra button: Yahoo!

Messenger - {E5D12C4E-

7B4F-11D3-B5C9-

0050045C3C96} - C:\Program

Files\Yahoo!

\Messenger\YahooMessenger.

exe
O9 - Extra 'Tools'

menuitem: Yahoo! Messenger

- {E5D12C4E-7B4F-11D3-

B5C9-0050045C3C96} -

C:\Program Files\Yahoo!

\Messenger\YahooMessenger.

exe
O9 - Extra button:

Messenger - {FB5F1910-

F110-11d2-BB9E-

00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools'

menuitem: Windows

Messenger - {FB5F1910-

F110-11d2-BB9E-

00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O12 - Plugin for .spop:

C:\Program Files\Internet

Explorer\Plugins\NPDocBox.

dll
O14 - IERESET.INF:

START_PAGE_URL=http://www.

toshiba.com
O16 - DPF: {17492023-C23A

-453E-A040-C7C580BBF700}

(Windows Genuine Advantage

Validation Tool) -

http://go.microsoft.com/fw

link/?linkid=39204
O16 - DPF: {215B8138-A3CF

-44C5-803F-8226143CFC0A}

(Trend Micro ActiveX Scan

Agent 6.6) -

http://housecall65.trendmi

cro.com/housecall/applet/h

tml/native/x86/win32/activ

ex/hcImpl.cab
O16 - DPF: {30528230-99f7

-4bb4-88d8-fa1d4f56a2ab}

(YInstStarter Class) -

C:\Program Files\Yahoo!

\Common\yinsthelper.dll
O16 - DPF: {39D420B3-E0EB

-424C-89AA-C24F8DE7EF79}

(KooPlayer Control) -

http://www.vivitv.com/KooP

layer.ocx
O16 - DPF: {6A344D34-5231

-452A-8A57-D064AC9B7862}

(Symantec Download

Manager) -

https://webdl.symantec.com

/activex/symdlmgr.cab
O16 - DPF: {745395C8-D0E1

-4227-8586-624CA9A10A8D}

(AxisMediaControl Class) -

http://217.197.149.13/acti

vex/AMC.cab
O16 - DPF: {DE625294-70E6

-45ED-B895-CFFA13AEB044}

(AxisMediaControlEmb

Class) -

http://camera.butovo.com/a

ctivex/AMC.cab
O18 - Filter hijack:

text/html - (no CLSID) -

(no file)
O22 - SharedTaskScheduler:

Browseui preloader -

{438755C2-A8BA-11D1-B96B-

00A0C90312E1} -

C:\WINDOWS\System32

\browseui.dll
O22 - SharedTaskScheduler:

Component Categories cache

daemon - {8C7461EF-2B13-

11d2-BE35-3078302C2030} -

C:\WINDOWS\System32

\browseui.dll
O23 - Service: Automatic

LiveUpdate Scheduler -

Symantec Corporation -

C:\Program

Files\Symantec\LiveUpdate\

ALUSchedulerSvc.exe
O23 - Service: Symantec

Event Manager (ccEvtMgr) -

Symantec Corporation -

C:\Program Files\Common

Files\Symantec

Shared\ccSvcHst.exe
O23 - Service: Symantec

Settings Manager

(ccSetMgr) - Symantec

Corporation - C:\Program

Files\Common

Files\Symantec

Shared\ccSvcHst.exe
O23 - Service: Symantec

Lic NetConnect service

(CLTNetCnService) -

Symantec Corporation -

C:\Program Files\Common

Files\Symantec

Shared\ccSvcHst.exe
O23 - Service: COM Host

(comHost) - Symantec

Corporation - C:\Program

Files\Common

Files\Symantec

Shared\VAScanner\comHost.e

xe
O23 - Service: Google

Updater Service (gusvc) -

Google - C:\Program

Files\Google\Common\Google

Updater\GoogleUpdaterServi

ce.exe
O23 - Service: Symantec IS

Password Validation

(ISPwdSvc) - Symantec

Corporation - C:\Program

Files\Norton Internet

Security\isPwdSvc.exe
O23 - Service: LiveUpdate

- Symantec Corporation -

C:\PROGRA~1

\Symantec\LIVEUP~1

\LUCOMS~1.EXE
O23 - Service: NVIDIA

Driver Helper Service

(NVSvc) - NVIDIA

Corporation -

C:\WINDOWS\System32

\nvsvc32.exe
O23 - Service: Pml Driver

HPZ12 - HP -

C:\WINDOWS\System32

\HPZipm12.exe
O23 - Service: Symantec

Core LC - Symantec

Corporation - C:\Program

Files\Common

Files\Symantec

Shared\CCPD-

LC\symlcsvc.exe
O23 - Service: Symantec

AppCore Service

(SymAppCore) - Symantec

Corporation - C:\Program

Files\Common

Files\Symantec

Shared\AppCore\AppSvc32.ex

e

–
End of file - 9676 bytes
jcompwiz :D

Welcome to the forum, I can't read your HJT log the way you posted it, your also using a beta version that has not been tested yet. Do this.

Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Go to where you currently have HJT installed and delete the whole folder.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis


  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use [external image: Posted Image]and not [external image: Posted Image]
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
OK I did what you requested, here is the new log file. Thank you for your help!

Logfile of HijackThis v1.99.1
Scan saved at 7:51:50 PM, on 3/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\PROGRA~1\EzButton\CPLBTS88.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.etsy.com/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [CPLBTS88] C:\PROGRA~1\EzButton\CPLBTS88.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.vivitv.com/KooPlayer.ocx
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://217.197.149.13/activex/AMC.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://camera.butovo.com/activex/AMC.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Not looking at anything earth shattering on your log, not to say something could be hidden and not showing up.

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

If you know what these are and use them then leave them otherwise fix it
O16 - DPF: {39D420B3-E0EB-424C-89AA-C24F8DE7EF79} (KooPlayer Control) - http://www.vivitv.com/KooPlayer.ocx
O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://217.197.149.13/activex/AMC.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://camera.butovo.com/activex/AMC.cab


Fix this one
O18 - Filter: text/html - (no CLSID) - (no file)



Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5



Reboot and run this system cleaner


Download and Install CCleaner
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner


Let me see the AVG log and a New HJT log please
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI