This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HJT

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
could you please help me to get rid of this trojan. I have attached my HJT report and Kaspersky scan also.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:17, on 27/01/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Wyless DataSpeed\p_client_service.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
C:\PROGRA~1\THOMSO~1\SPEEDT~1\PRISMSVR.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ya.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer proporcionado por Ya.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Zone Alarm] vsmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.ya.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{666AE0A1-C675-4BFE-BD3E-8AAC6DD0BF07}: NameServer = 62.151.2.8,62.151.8.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DEEA8F8-6A6D-487F-99D6-FB2E9D09FA8C}: NameServer = 62.151.2.8,62.151.8.100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
O23 - Service: NetDDE Server (NetDDEsrv) - Unknown owner - C:\WINDOWS\System32\netddesrv.exe (file missing)
O23 - Service: DataSpeed Service (pClientService) - Wyless Plc. - C:\Program Files\Wyless DataSpeed\p_client_service.exe
O24 - Desktop Component 0: (no name) - http://www.pandasoftware.com/activescan/co…/02_act_chk.gif
O24 - Desktop Component 1: (no name) - http://www.quick2fit.co.uk/images/security.jpg
O24 - Desktop Component 2: (no name) - http://houseweb.com/photo/thumb.php?photo=…on.161165.3.jpg

–
End of file - 5827 bytes


Thank you in advance📎kasperskyVirus.html
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!

  • All hijackthis logs I ask for should be done in normal mode ( not safe mode)
  • These logs should be done last after you have followed my instructions in the previous post.


Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!



!!!! IMPORTANT INFORMATION !!!!

It looks like you have been infected by a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.

If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Should you decide to clean this machine start by doing the following.




__________________________________
OTMoveIt2 -

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    C:\WINDOWS\system32\i
    C:\WINDOWS\system32\TFTP2200
    C:\WINDOWS\system32\TFTP3156


  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    <>


  • Return to OTMoveIt2, right click in the "Paste List Of Files/Patterns To Search For and Move" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.






____________________________________________________

Download SDFix and save it to your Desktop.

Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • In Safe Mode, right click the SDFix.zip folder and choose Extract All,
  • Open the extracted folder and double click RunThis.bat to start the script.
  • Type Y to begin the script.
  • It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • Your system will take longer that normal to restart as the fixtool will be running and removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
  • Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log

________________________________

I DO NOT want you to do anything about this yet. But why do you not have service Pack 2 installed for windows. Without doing so you are leaving yourself open to infection. Microsoft quit supporting updates for sevice pack 1 over a yr ago. Whedn we are done you really need to get that in place. As I said you do not want to do this now. We should get you cleaned first.



___________________________________________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from S&D fix
  • The log from OTMOVEIT
Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 05:42:39, on 28/01/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Wyless DataSpeed\p_client_service.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
C:\PROGRA~1\THOMSO~1\SPEEDT~1\PRISMSVR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ya.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer proporcionado por

Ya.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Zone Alarm] vsmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch

121g Wireless USB Monitor\st121g.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.ya.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{666AE0A1-C675-4BFE-BD3E-8AAC6DD0BF07}: NameServer =

62.151.2.8,62.151.8.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DEEA8F8-6A6D-487F-99D6-FB2E9D09FA8C}: NameServer =

62.151.2.8,62.151.8.100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: DataSpeed Service (pClientService) - Wyless Plc. - C:\Program Files\Wyless

DataSpeed\p_client_service.exe
O24 - Desktop Component 0: (no name) - http://www.pandasoftware.com/activescan/co…/02_act_chk.gif
O24 - Desktop Component 1: (no name) - http://www.quick2fit.co.uk/images/security.jpg
O24 - Desktop Component 2: (no name) - http://houseweb.com/photo/thumb.php?photo=…on.161165.3.jpg

–
End of file - 5568 bytes

OTMoveIt

[Custom Input]
< C:\WINDOWS\system32\i >
File/Folder C:\WINDOWS\system32\i not found.
< C:\WINDOWS\system32\TFTP2200 >
File/Folder C:\WINDOWS\system32\TFTP2200 not found.
< C:\WINDOWS\system32\TFTP3156 >
File/Folder C:\WINDOWS\system32\TFTP3156 not found.

OTMoveIt2 v1.0.15 log created on 01282008_050642


SDFix: Version 1.131

Run by [removed] on 28/01/2008 at 05:16

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\REGIST~1\Desktop\SDFix

Safe Mode:
Checking Services:

Name:
lsass
NetDDEsrv

Path:
"C:\WINDOWS\lsass.exe"
C:\WINDOWS\System32\netddesrv.exe

lsass - Deleted
NetDDEsrv - Deleted



Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS\system32\TFTP1308 - Deleted
C:\WINDOWS\system32\TFTP2628 - Deleted
C:\WINDOWS\system32\TFTP2640 - Deleted
C:\WINDOWS\system32\TFTP2728 - Deleted
C:\WINDOWS\system32\TFTP2760 - Deleted
C:\WINDOWS\system32\TFTP2776 - Deleted
C:\WINDOWS\system32\TFTP2784 - Deleted
C:\WINDOWS\system32\TFTP3168 - Deleted
C:\WINDOWS\system32\TFTP3364 - Deleted
C:\WINDOWS\system32\TFTP3748 - Deleted
C:\WINDOWS\system32\TFTP816 - Deleted
C:\WINDOWS\system32\TFTP880 - Deleted
C:\WINDOWS\system32\TFTP948 - Deleted





Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\explorer.exe
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-28 05:24:46
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

Remaining Files:
—————

File Backups: - C:\DOCUME~1\REGIST~1\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:

Fri 4 Jan 1980 92,672 A..H. — "C:\alarms\~WRL0005.tmp"
Fri 4 Jan 1980 5,297,976 A..H. — "C:\Program Files\Picasa2\setup.exe"
Fri 4 Jan 1980 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 16 Jan 1980 162 A..H. — "C:\Documents and Settings\Registered User\My Documents\~$RL0974.tmp"
Sat 12 Jan 1980 40,960 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL0001.tmp"
Tue 26 Jul 2005 63,488 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL0841.tmp"
Wed 16 Jan 1980 40,448 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL0974.tmp"
Thu 28 Jul 2005 39,936 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL2752.tmp"
Thu 28 Jul 2005 55,296 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL2827.tmp"
Mon 7 Jan 1980 145,408 A..H. — "C:\Documents and Settings\Registered User\My Documents\~WRL2856.tmp"
Wed 10 May 2006 21,504 …H. — "C:\Documents and Settings\User\My Documents\~WRL1418.tmp"
Wed 10 May 2006 496,128 …H. — "C:\Documents and Settings\User\My Documents\~WRL1772.tmp"
Wed 10 May 2006 23,552 …H. — "C:\Documents and Settings\User\My Documents\~WRL1839.tmp"
Wed 10 May 2006 35,840 …H. — "C:\Documents and Settings\User\My Documents\~WRL2736.tmp"
Wed 10 May 2006 34,816 …H. — "C:\Documents and Settings\User\My Documents\~WRL3960.tmp"
Mon 28 Mar 2005 162 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~$RL3064.tmp"
Wed 17 Nov 2004 284,672 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL0005.tmp"
Thu 10 Feb 2005 105,984 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL0704.tmp"
Thu 10 Feb 2005 218,624 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL1354.tmp"
Thu 10 Feb 2005 168,960 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL2133.tmp"
Thu 10 Feb 2005 217,088 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL2542.tmp"
Thu 10 Feb 2005 178,176 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL2651.tmp"
Thu 10 Feb 2005 220,160 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL3064.tmp"
Wed 16 Feb 2005 19,968 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL3960.tmp"
Thu 10 Feb 2005 221,696 A..H. — "C:\Documents and Settings\Registered User\Desktop\worddocs\~WRL3998.tmp"
Wed 14 Apr 2004 1,206 A..HR — "C:\Program Files\Common Files\Symantec Shared\Registry Backup\ccReg.reg"
Wed 14 Apr 2004 12,368 A..HR — "C:\Program Files\Common Files\Symantec Shared\Registry Backup\CommonClient.reg"
Sat 6 Jan 2080 23,552 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL0005.tmp"
Tue 8 Jan 1980 19,968 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL0006.tmp"
Tue 8 Jan 1980 22,016 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL0634.tmp"
Tue 17 May 2005 38,912 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL0873.tmp"
Thu 17 Feb 2005 409,088 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL1089.tmp"
Tue 15 Jan 1980 19,456 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL1309.tmp"
Wed 16 Jan 1980 59,392 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL2025.tmp"
Tue 8 Jan 1980 20,992 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL2347.tmp"
Wed 16 Jan 1980 60,416 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL2531.tmp"
Tue 8 Jan 1980 19,968 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL2683.tmp"
Thu 19 May 2005 23,552 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL3425.tmp"
Thu 19 May 2005 19,456 A..H. — "C:\Documents and Settings\Registered User\Application Data\Microsoft\Word\~WRL3909.tmp"
Wed 10 May 2006 362,496 …H. — "C:\Documents and Settings\User\Application Data\Microsoft\Word\~WRL0005.tmp"
Wed 10 May 2006 36,864 …H. — "C:\Documents and Settings\User\Application Data\Microsoft\Word\~WRL1009.tmp"
Wed 10 May 2006 361,472 …H. — "C:\Documents and Settings\User\Application Data\Microsoft\Word\~WRL2469.tmp"
Wed 10 May 2006 358,400 …H. — "C:\Documents and Settings\User\Application Data\Microsoft\Word\~WRL2660.tmp"

Finished!
Ok looks better.

______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O24 - Desktop Component 0: (no name) - http://www.pandasoftware.com/activescan/co…/02_act_chk.gif
O24 - Desktop Component 1: (no name) - http://www.quick2fit.co.uk/images/security.jpg
O24 - Desktop Component 2: (no name) - http://houseweb.com/photo/thumb.php?photo=…on.161165.3.jpg



______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.

  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Registry function to clean anything with this program. Having anything auto clean your regisrty is risky).


AVG Anti-Spyware:
________________________________________
Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open. Do not run a scan yet.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).



    Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
  • Open up AVG anti Malware
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
  • Make sure that Set all elements to: shows Quarantine
  • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
  • When the program has finished, it will display the message All actions have been applied.
  • Then click the Save Scan Report button.
  • Click the Save Report as button.
  • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
  • Reboot in normal mode.

___________________________________-


I have a question I need answered.

1. Is "Ya.com Internet Factory" your internet service provider ?



_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from AVG anti Spyware
  • Please answer the above question
Hi bob4,
here are the items you have requested but i will also include an error generated by AVG whilst scanning in "safe mode". About half way through the scan the operating system crashed and this is the error log that was generated:

//=====================================
Exception code: C0000005 ACCESS_VIOLATION
Fault address: 10004577 01:00003577 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
Module Date: 06/06/2007 13:51:18
File Version of C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll: 4.2.0.19
Exception Date: 01/29/2008 15:07:49
File Version of C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe: 7.5.1.36

MiniDump Information Saved to C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.dmp

Registers:
EAX:00000000
EBX:00000000
ECX:00000000
EDX:100B84B8
ESI:10086724
EDI:20000000
CS:EIP:001B:10004577
SS:ESP:0023:007BE2F4 EBP:00000000
DS:0023 ES:0023 FS:0038 GS:0000
Flags:00010206

Intel specific method

Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Logical addr Module
10004577 00000000

ImageHelp specific method

Call stack:
Address Frame Param 0 Param 1 Param 2 Param 3 Symbol/Logical address


Loaded Modules:
Base Size Module
00400000 04E000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
77F50000 0A7000 5.01.2600.1106 C:\WINDOWS\System32\ntdll.dll
77E60000 0E6000 5.01.2600.1560 C:\WINDOWS\system32\kernel32.dll
10000000 0DE000 4.02.0000.0019 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\engine.dll
76780000 008000 6.00.2800.1106 C:\WINDOWS\System32\SHFOLDER.dll
77DD0000 08D000 5.01.2600.1106 C:\WINDOWS\system32\ADVAPI32.dll
78000000 087000 5.01.2600.1361 C:\WINDOWS\system32\RPCRT4.dll
70A70000 069000 6.00.2800.1584 C:\WINDOWS\system32\SHLWAPI.dll
7F000000 041000 5.01.2600.1561 C:\WINDOWS\system32\GDI32.dll
77D40000 08D000 5.01.2600.1634 C:\WINDOWS\system32\USER32.dll
77C10000 053000 7.00.2600.1106 C:\WINDOWS\system32\msvcrt.dll
76B40000 02C000 5.01.2600.1106 C:\WINDOWS\System32\WINMM.dll
76BF0000 00B000 5.01.2600.1106 C:\WINDOWS\System32\PSAPI.DLL
77C00000 007000 5.01.2600.0000 C:\WINDOWS\system32\VERSION.dll
76D60000 017000 5.01.2600.0002 C:\WINDOWS\System32\iphlpapi.dll
71AB0000 015000 5.01.2600.0000 C:\WINDOWS\System32\WS2_32.dll
71AA0000 008000 5.01.2600.0000 C:\WINDOWS\System32\WS2HELP.dll
771B0000 124000 5.01.2600.1362 C:\WINDOWS\system32\ole32.dll
77120000 08B000 3.50.5016.0000 C:\WINDOWS\system32\OLEAUT32.dll
007C0000 102000 5.82.2800.1106 C:\WINDOWS\system32\comctl32.dll
77340000 08B000 5.82.2800.1106 C:\WINDOWS\system32\comctl32.dll
76CE0000 01F000 5.01.2600.1106 C:\WINDOWS\System32\NTMARTA.DLL
76F60000 02C000 5.01.2600.1106 C:\WINDOWS\system32\WLDAP32.dll
71BF0000 011000 5.01.2600.1106 C:\WINDOWS\System32\SAMLIB.dll
6D510000 07D000 5.01.2600.1106 C:\WINDOWS\System32\DBGHELP.DLL

Now items:
i)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:07:26, on 04/01/1980 (lost time and data due to above crash)
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Wyless DataSpeed\p_client_service.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
C:\PROGRA~1\THOMSO~1\SPEEDT~1\PRISMSVR.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ya.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer proporcionado por Ya.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Zone Alarm] vsmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.ya.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{666AE0A1-C675-4BFE-BD3E-8AAC6DD0BF07}: NameServer = 62.151.2.8,62.151.8.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DEEA8F8-6A6D-487F-99D6-FB2E9D09FA8C}: NameServer = 62.151.2.8,62.151.8.100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: DataSpeed Service (pClientService) - Wyless Plc. - C:\Program Files\Wyless DataSpeed\p_client_service.exe

–
End of file - 5712 bytes

ii)

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 17:31:32 29/01/2008

+ Scan result:



C:\_OTMoveIt\MovedFiles\01282008_044026\WINDOWS\system32\TFTP2200 -> Backdoor.Rbot : Cleaned.
C:\_OTMoveIt\MovedFiles\01282008_044026\WINDOWS\system32\TFTP3156 -> Backdoor.Rbot : Cleaned.
C:\KINGSTONFILES\Gonuts4free_beta.exe -> Heuristic.Win32.Dialer : Cleaned.
C:\KINGSTONFILES\Gonuts4free_beta2.exe -> Heuristic.Win32.Dialer : Cleaned.
C:\KINGSTONFILES\Gonuts4free_beta2.zip/Gonuts4free_beta2.exe -> Heuristic.Win32.Dialer : Cleaned.
:mozilla.73:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\User\Cookies\user@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\User\Cookies\user@marksandspencer.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\User\Cookies\user@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.140:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.152:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.153:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.154:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.138:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\User\Cookies\user@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.19:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\User\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.92:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.93:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.94:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.95:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.139:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
C:\Documents and Settings\User\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.20:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.21:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.81:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.84:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\User\Cookies\[removed][2].txt -> TrackingCookie.Msn : Cleaned.
:mozilla.79:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.80:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.141:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.142:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.117:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.118:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.119:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.120:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.121:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.122:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.123:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.59:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.38:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.39:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.40:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.41:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\User\Cookies\user@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.100:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.102:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.103:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.104:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.105:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.97:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.89:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.90:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.91:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.44:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.106:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.107:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.108:C:\Documents and Settings\Registered User\Application Data\Mozilla\Firefox\Profiles\3e7qxn70.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\User\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end

iii)

Yes YA.COM is my Internet Service Provider, i live in Spain.
Thanks for the heads up on your reply.
I did not receive an e mail on your posting back.




___________________________________________

I can't find alot of info on a program let's have it scanned.


Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\Program Files\Wyless DataSpeed\p_client_service.exe


Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html
C:\Program Files\Wyless DataSpeed\p_client_service.exe


__________________________________



You need to update SunJava for security reasons.
Updating Java:
Download the latest version of
Java Runtime Environment (JRE) 6 Update 4

  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 4
    … allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the [external image: Posted Image] icon next to it.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe
    to install the newest version.




_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Jottis/Virus total
  • Let me know how things seem to be running.
Hi bob4,

I have completed the task you require, see below:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:38:21, on 12/01/1980(7/02/2008) loose date/time when power removed.
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Wyless DataSpeed\p_client_service.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
C:\PROGRA~1\THOMSO~1\SPEEDT~1\PRISMSVR.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ya.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer proporcionado por Ya.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Zone Alarm] vsmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.ya.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{666AE0A1-C675-4BFE-BD3E-8AAC6DD0BF07}: NameServer = 62.151.2.8,62.151.8.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DEEA8F8-6A6D-487F-99D6-FB2E9D09FA8C}: NameServer = 62.151.2.8,62.151.8.100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: DataSpeed Service (pClientService) - Wyless Plc. - C:\Program Files\Wyless DataSpeed\p_client_service.exe

–
End of file - 5777 bytes





Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1
File to upload & scan: Virus

Service
Service load:
0% 100%
File: p_client_service.exe
Status:
OK
MD5: 446a1cbe05deefec5aadc671f9500515
Packers detected:
-
Bit9 reports: File not found
Scanner results
Scan taken on 07 Feb 2008 09:10:53 (GMT)
A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Rising Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

Powered by
images/asquared.png images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/cpsecure.gif images/drweb.gif images/f-prot.png images/f-secure_logo.gif images/fortinet.gif images/ikarus.gif images/kaspersky.png images/nod32.gif images/norman.png images/panda.png images/rising.gif images/sophos.gif images/virusbuster.gif images/vba32.png Bit9

Debian

Page generated by JTPL

© 2004-2008 Jordi Bosveld <[removed]>

The laptop is running fine but, like most people i would like it to run faster. Do you have any suggestions?

Thank you
can you tell me something ? The part in red are you editing this or did HJT put thi s in ?
Is you computer doing something funny ?
Battery low ?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:38:21, on 12/01/1980(7/02/2008) loose date/time when power removed.
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

____________________________
Also did you install the java update ?

I still only see update 3 installed.
Hi bob4,

I wrote to tell you that when i loose power that time/date reverts back to 1980. The reason for this is the battery is old and does not hold its charge.

I will send you another HJT log. I believe i generated the log first before removing the old java entries.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:32, on 07/02/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
C:\PROGRA~1\THOMSO~1\SPEEDT~1\PRISMSVR.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Wyless DataSpeed\p_client_service.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ya.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer proporcionado por

Ya.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search &

Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Zone Alarm] vsmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch

121g Wireless USB Monitor\st121g.exe
O8 - Extra context menu item: Download with Star Downloader - C:\Program Files\Star Downloader\sdie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.ya.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - http://www.creative.com/su/ocx/15009/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{666AE0A1-C675-4BFE-BD3E-8AAC6DD0BF07}: NameServer =

62.151.2.8,62.151.8.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DEEA8F8-6A6D-487F-99D6-FB2E9D09FA8C}: NameServer =

62.151.2.8,62.151.8.100
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: DataSpeed Service (pClientService) - Wyless Plc. - C:\Program Files\Wyless

DataSpeed\p_client_service.exe

–
End of file - 5795 bytes
I thought that might of been a bad battery. Been meaning to ask you but kept slipping my mind.



___________________________
Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!




___________________________________
This process is going to clean up some of the tools we have used.

  • Open OTmoveit.
  • Click on Cleanup!.
  • Allow it to access the internet if any security software asks about it.

    It will ask you if you want to start the clean up process :
  • Click yes.
  • When it's ready it will ask you to reboot.
    Do so now.
    Then finish up with the rest of the instructions.


___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK


_________________________________________



Update Your Windows XP.
You are currently using an unsupported version of Windows XP. Service Pack 1.
Microsoft quit supporting sevice pack 1 last october.
You will recieve no more security updates or any other updates from Microsoft unless you get Service pack 2 installed.
Your computer is at a higher risk of infection without it.

This can be done 2 ways.
You can download it if your on high speed internet . Dial up would take a really long time.
or
You can have Microsoft send you the CD if your on dial up.

Please visit this site and get this done.
Or I'm affraid you'll be back in no time.



\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\





A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.





Safe and Happy Surfing. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI