This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus found Exploit!

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

AVG found this on my computer I'm just wondering if it is anything to worry about?
[attachment removed]


Regards

___________________________




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:08:50, on 30/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\DOCUME~1\Dan\LOCALS~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dan\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/def…://uk.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def…://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.tiscali.co.uk/broadband
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe /idle
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://ca.com/gb/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1198420554875
O17 - HKLM\System\CCS\Services\Tcpip\..\{33D9EC4D-B530-4C05-AC98-529E7921395C}: NameServer = 212.139.132.11 212.139.132.10
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

–
End of file - 7527 bytes
Hello manicd :)

Welcome to the Whatthetech Malware Removal Forum, sorry about the delay, but the amount of people posting with infected computers is through the roof and sometimes we can't get to logs as fast as we would like to.

The exploit was found in your Temporary Internet Files, lets flush it all out.


Download CCleaner from here to clean temp files from your computer.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
  • Click on the "Options" icon at the left side of the window, then click on "Advanced."
    deselect "Only delete files in Windows Temp folders older than 48 hours."
  • Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
  • After CCleaner has completed its process, click Exit.

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!
**Note** Go to Options> Cookies and any you want to keep move them to The Keep window


The rest of your log looks fine :thumbup: To be on the safeside, run this free scan from Kaspersky and post the log along with a new HJT log as the one you posted is a little old.

Run this free online scan using Internet Explorer:
Kaspersky Online Virus Scanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan: Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Post the log along with a New HJT Log into your next reply.
Hi & thanks for the reply

While visiting this website "lyricsfreak.com" I got a pop up saying something along the lines of the following:
"Your PC is at risk … scanning now"

It was blatantly spyware of some sort so I disconnected from the internet and shut down firefox using task manager so I hope I'm not infected.
Also done a more recent AVG scan which showed a "Host" file had changed in the following location:

C:\WINDOWS\system32\drivers\ect\hosts

Anything to worry about?


HJT Log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:15:29, on 24/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Documents and Settings\Dan\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def…://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://en.uk.acer.yahoo.com/
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe /idle
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://ca.com/gb/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1199550286531
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe

–
End of file - 7257 bytes



KASPERSKY LOG

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, February 24, 2008 7:06:37 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 24/02/2008
Kaspersky Anti-Virus database records: 534360
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 35516
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:05:02

Infected Object Name / Virus Name / Last Action
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{34994407-E588-4ADB-B021-2A13BFF57BE8}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Temp\ZLT007c2.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT062ef.TMP Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\ACER-FD6B6B72E3.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\Dan\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\History\History.IE5\MSHist012008022420080225\index.dat Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Application Data\ApplicationHistory\ePower_DMC.exe.3ca0acde.ini.inuse Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Temp\~DF1530.tmp Object is locked skipped
C:\Documents and Settings\Dan\Local Settings\Temp\~DF1561.tmp Object is locked skipped
C:\Documents and Settings\Dan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dan\UserData\index.dat Object is locked skipped
C:\Documents and Settings\Dan\ntuser.dat Object is locked skipped
C:\System Volume Information\_restore{AFCD12E9-F77C-4DEE-BF16-FB0F4173E613}\RP46\change.log Object is locked skipped
D:\0b2609176fe3aa04143381c8\admparse.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\admparse.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\advpack.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\advpack.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\browseui.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\corpol.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\custsat.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\dxtmsft.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\dxtrans.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\extmgr.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\extmgr.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\feeddisc.wav Object is locked skipped
D:\0b2609176fe3aa04143381c8\hmmapi.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\hmmapi.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\html.iec Object is locked skipped
D:\0b2609176fe3aa04143381c8\html.iec.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\icardie.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\icardie.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\icrav03.rat Object is locked skipped
D:\0b2609176fe3aa04143381c8\ie4uinit.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\ie4uinit.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieakeng.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieakeng.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieakmmc.chm Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieaksie.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieaksie.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieakui.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieakui.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieapfltr.dat Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieapfltr.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iedkcs32.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iedkcs32.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\iedw.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\iedw.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieencode.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieeula.chm Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieframe.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieframe.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\iepeers.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iepeers.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieproxy.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iernonce.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iernonce.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\iertutil.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iesetup.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\iesetup.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\iesupp.chm Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieudinit.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieui.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieui.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieuinit.inf Object is locked skipped
D:\0b2609176fe3aa04143381c8\ieunatt.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\iexplore.chm Object is locked skipped
D:\0b2609176fe3aa04143381c8\iexplore.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\iexplore.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\imgutil.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\inetcorp.iem Object is locked skipped
D:\0b2609176fe3aa04143381c8\inetcpl.cpl Object is locked skipped
D:\0b2609176fe3aa04143381c8\inetcpl.cpl.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\inetres.adm Object is locked skipped
D:\0b2609176fe3aa04143381c8\inetset.iem Object is locked skipped
D:\0b2609176fe3aa04143381c8\infobar.wav Object is locked skipped
D:\0b2609176fe3aa04143381c8\inseng.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\inseng.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\install.ins Object is locked skipped
D:\0b2609176fe3aa04143381c8\jscript.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\jsproxy.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\licmgr10.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\licmgr10.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeeds.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeeds.mof Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeedsbs.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeedsbs.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeedsbs.mof Object is locked skipped
D:\0b2609176fe3aa04143381c8\msfeedssync.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshta.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshta.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtml.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtml.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtml.tlb Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtmled.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtmled.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtmler.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\mshtmler.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\msls31.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\msrating.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\msrating.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\mstime.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\navstart.wav Object is locked skipped
D:\0b2609176fe3aa04143381c8\occache.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\occache.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\occache.ini Object is locked skipped
D:\0b2609176fe3aa04143381c8\pngfilt.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\popupblk.wav Object is locked skipped
D:\0b2609176fe3aa04143381c8\shdocvw.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\shlwapi.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\spmsg.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\spuninst.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\spupdsvc.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\tdc.ocx Object is locked skipped
D:\0b2609176fe3aa04143381c8\ticrf.rat Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\eula.rtf Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\idndl.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\ie7.cat Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\iecustom.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\iereseticons.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\iesetup.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\legitlibm.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\nlsdl.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\update.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\update.exe.manifest Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\update.inf Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\update.ver Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\updspapi.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\update\xmllitesetup.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\url.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\urlmon.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\urlmon.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\vbscript.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\vgx.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\webcheck.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\webcheck.dll.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\webcheck.ini Object is locked skipped
D:\0b2609176fe3aa04143381c8\winfxdocobj.exe Object is locked skipped
D:\0b2609176fe3aa04143381c8\winfxdocobj.exe.mui Object is locked skipped
D:\0b2609176fe3aa04143381c8\wininet.dll Object is locked skipped
D:\0b2609176fe3aa04143381c8\wininet.dll.mui Object is locked skipped
D:\115d3c77144c35d6c044\msxml4-KB927978-enu.log Object is locked skipped
D:\1846a77c7d975b959f\msxml4-KB927978-enu.log Object is locked skipped
D:\19fbb0d4550a5d2fe359\msxml4-KB927978-enu.log Object is locked skipped
D:\2249e8a1316d5173fb891f\msxml4-KB927978-enu.log Object is locked skipped
D:\27712dab1f223432895e7c5e4d4eccaf\msxml4-KB927978-enu.log Object is locked skipped
D:\32d5980ed866864109a2e9\msxml4-KB927978-enu.log Object is locked skipped
D:\33eca1d7468868e4bca028c3\$shtdwn$.req Object is locked skipped
D:\33eca1d7468868e4bca028c3\update\eula.txt Object is locked skipped
D:\36f78abe2e14a4a2a2572ee76da41d\msxml4-KB927978-enu.log Object is locked skipped
D:\3e22d2ad8af1ff918656ac38945bfc\%temp%dd_msxml_retMSI.txt Object is locked skipped
D:\430e39d8e51f58dc457bd50f\msxml4-KB927978-enu.log Object is locked skipped
D:\455dccbd02e9b78373e44b28113b\msxml4-KB927978-enu.log Object is locked skipped
D:\476ba29a92ad7704bfda4888dee2e137\msxml4-KB927978-enu.log Object is locked skipped
D:\4997640e3427be4745c0\msxml4-KB927978-enu.log Object is locked skipped
D:\4dbd1ab6295522861d00cd4fe3af\msxml4-KB927978-enu.log Object is locked skipped
D:\562846da1ba7fdadbb0985dc057a02\msxml4-KB927978-enu.log Object is locked skipped
D:\5cebf87774e19cecc395121542\msxml4-KB927978-enu.log Object is locked skipped
D:\6a6b37c0aa094247572623\msxml4-KB927978-enu.log Object is locked skipped
D:\6b913d2935e53fd04c2088de\msxml4-KB927978-enu.log Object is locked skipped
D:\7877dcc360c43925c8\msxml4-KB927978-enu.log Object is locked skipped
D:\7a5afbf374f55e393a7abf\msxml4-KB927978-enu.log Object is locked skipped
D:\851ea26126dff8706c527b261682\msxml4-KB927978-enu.log Object is locked skipped
D:\8cfb496164d3685172c92302e4\%temp%dd_msxml_retMSI.txt Object is locked skipped
D:\a46f8be03cb122ca21d27bf0e1\msxml4-KB927978-enu.log Object is locked skipped
D:\a4a00d15167f9af75dfb2fa647\msxml4-KB927978-enu.log Object is locked skipped
D:\a8ee42a7d613e3ac41\msxml4-KB927978-enu.log Object is locked skipped
D:\b0ca1e3d20306642f2\msxml4-KB927978-enu.log Object is locked skipped
D:\b1d7b8417957de00b1ec\msxml4-KB927978-enu.log Object is locked skipped
D:\b2a0188b601c2128a6126e\msxml4-KB927978-enu.log Object is locked skipped
D:\b6f4ef249d953aa5102d1e669a8474\msxml4-KB927978-enu.log Object is locked skipped
D:\b8432df12a0a463fc6\msxml4-KB927978-enu.log Object is locked skipped
D:\bdae31a6bc6cce8f6c151c7c7914\msxml4-KB927978-enu.log Object is locked skipped
D:\d70b03deeb7f0c859b95586c00521a81\msxml4-KB927978-enu.log Object is locked skipped
D:\d7c763cbdec2467a6526ea3118d28e7b\msxml4-KB927978-enu.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.







Regards
Hello,

Looks like you got out of that lyrics site in time, your log looks fine, I would not visit that site anymore. It looks like it may have been hacked and imbeded with bad code, if you would have clicked on the scan you would have most likely gotten infected,

Kaspersy came back clean also.

C:\WINDOWS\system32\drivers\ect\hosts <– This is exactly where your hosts file resides and I don't see anything on your log to suggest it has been changed. But you can run this quick tool to set it back to defaults.

Download the HostsXpert 4.2.0.0. - Hosts File Manager.
  • Unzip HostsXpert 4.2.0.0 - Hosts File Manager to a convenient folder such as C:\HostsXpert
  • Click HostsXpert.exe to Run HostsXpert - Hosts File Manager from its new home
  • Click "Make Hosts Writable?" in the upper right corner (If available).
  • Click Restore Microsoft's Hosts file and then click OK.
  • Click the X to exit the program.
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.



  • How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports

Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster, you can still install Spybot Search and Destroy but do not enable the TeaTimer in Spybot.


Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.5
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0.0.12 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.

Glad we could help

Safe Surfn
Ken
Hi

Seems everything is ok now, cheers :thumbup:

HostsXpert 4.2.0.0. - Hosts File Manager.

What does this do by the way?

Ive now used it but access a website that I used to be able to.
http://www.mvps.org/winhelp2002/hosts.htm

This program just resets your hosts file back to the Microsoft defaults, its possible that the site you went into tried to make an entry in there.

Take care,
Ken
Sorry to be a pain but can you tell me what this is I forgot to mention it in my previous post:[attachment removed] Its something I keep getting in iexplorer when trying to run "Pest Scan" from CA.com. :thumbup:
Hello,

A pain you are not so don't even worry about it. It's a DAX Error and from what I can find out that program may be corrupted. You may want to uninstall it and then reinstall it and see if that corrects it. If not I am linking you to some windows support sites that deal with issues like that as this forum is for malware removal only.


Windows Tech Support Forums


It's Not Always Malware
Speedup Windows
Windows Tips

Computer Associates has a forum also, you may want to post there to , they may have more info on that error.
http://forums.ca.com/disclaimer.html

Ken :)
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI