This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] tried everything, can someone please check over my log

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I downloaded and ran all the programs I was supposed to. I also deleted AVG since I have avast and it said to have only one anti-virus program installed. It seems to be running faster, but I want to be sure I didn't miss anything.

Here is my hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 5:45:19 AM, on 11/3/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Users\AggroFemme\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)



Thank you so much!!!
:welcome:

Hello and welcome to What the Tech! My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again.


Your log looks fine to me…. lets do a little clean up and make sure everything is good…

Download & Run CCleaner

Please download CCleaner from Here
1. Starting with v1.27.260, CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
  • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
  • Clean all the entries in the "Windows Explorer" section.
  • Clean all entries in the "System" section.
  • Clean all entries in the "Advanced" section.
  • Clean any others that you choose.
In the Applications Tab:
  • Clean all except cookies in the Firefox/Mozilla section if you use it.
  • Clean all in the Opera section if you use it.
  • Clean Sun Java in the Internet Section.
  • Clean any others that you choose.
4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

===============================================


Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply, along with a fresh HijackThis log.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Thank you very much. I did what you asked. I had an older version of CCleaner so I updated it.

Here is the mbam log.

Malwarebytes' Anti-Malware 1.30
Database version: 1358
Windows 6.0.6001 Service Pack 1

11/3/2008 7:39:14 AM
mbam-log-2008-11-03 (07-39-14).txt

Scan type: Quick Scan
Objects scanned: 40972
Time elapsed: 3 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


And here is the new hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 7:43:41 AM, on 11/3/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\AggroFemme\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)



Thank you!!
hi ,

looks good to me lets do this…..

Update Java

Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
Upgrading Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 10.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u7-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
===============================================

Kaspersky WebScanner
please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Ok, that took a bit but here is the kaspersky report. :) ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Monday, November 3, 2008 Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Monday, November 03, 2008 19:39:50 Records in database: 1369113 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 85183 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:48:08 File name / Threat name / Threats count C:\Users\AggroFemme\Music\LimeWire\Saved\weapon matthew good sexy girl has shaking orgasm during sex.mp3 Infected: Trojan-Downloader.WMA.Wimad.o 1 The selected area was scanned.
Hi compchick,

Not to bad just a couple more steps….

OTMoveIt3 by OldTimer

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\Users\AggroFemme\Music\LimeWire\Saved\weapon matthew good sexy girl has shaking orgasm during sex.mp3
    :Reg
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

===============================================

P2P Warning!

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur. Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current problem/infection. I would strongly suggest you remove LimeWire. Removing can be done through Add/Remove Programs.

Please go to Start > Control Panel > Add/Remove Programs and remove the following :

LimeWire


===============================================

CleanUp

Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

===============================================

This is my standard post for when you are clear - which you now are - or seem to be. Please advise me of any problems you still have. . I know you already have some of these items like antivirus or firewall, but I like to include them anyway incase you ever need them or want to change them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

[external image: Posted Image] 1.) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use.

[external image: Posted Image] 2.) Go to Intenet Explorer > Tools > Windows Update > Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections.

It's important to always keep current with the latest security fixes from Microsoft.
Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

[external image: Posted Image] 3.) Open Intenet Explorer and go to Internet Options > Security > Internet, then press "Default Level", then OK. Now press "Custom Level." In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option > Security.

So why is ActiveX so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

[external image: Posted Image] 4.) Install Javacool's SpywareBlaster

It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.

Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer) Press "Enable All Protection", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer. Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

[external image: Posted Image] 5.) Let's also not forget that Spybot Search & Destroy has the Immunize feature which works roughly the same way. Another feature within Spybot is the TeaTimer option. This option immediately detects known malicious processes wanting to start and terminates them. TeaTimer also detects when something wants to change some critical registry keys and gives you an option to allow them or not.

[external image: Posted Image] 6.) Microsoft now offers their own free malicious software blocking tool. Windows Defender improves Internet browsing safety by guarding over fifty (50) ways spyware can enter your PC.

[external image: Posted Image] 7.) Another excellent program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

[external image: Posted Image] 8.) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Another good hosts program is mvpshosts. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial.

*It is important to note that all of the above programs/files can be run simultaneously on your system. They will work together in layers, so to speak, to help protect your computer. However, the following suggestions are designed to only run one of each. It is not a good idea to run more than one firewall, and one anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

[external image: Posted Image] 9.) It is critical that you use a firewall to protect your computer from hackers. We don't recommend the firewall that comes built in to Windows. It doesn't block everything that may try to get in, and the entire firewall is written to the registry. As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions. Three good ones that are freeware to boot are ZoneAlarm, Kerio and Sygate

[external image: Posted Image] 10.) An Anti-Virus product is a necessity. There are many excellent programs that you can purchase. However, we choose to advocate the use of free programs whenever possible. Some very good and easy-to-use free A/V programs are AVG, Avast, and AntiVir. It's a good idea to set these to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program. They will conflict, and provide less protection, not more.


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Thanks for letting us help you!
Newest Moveit log. This is after reboot. ========== FILES ========== C:\Users\AggroFemme\Music\LimeWire\Saved\weapon matthew good sexy girl has shaking orgasm during sex.mp3 moved successfully. ========== REGISTRY ========== ========== COMMANDS ========== File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Arj.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\avlib.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Avp1.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\AvpMgr.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\btimages.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\CAB.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\dmap.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\dtreg.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FSSync.dll scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HashCont.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HashMD5.PPL scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HCCMP.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\ichk2.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\iChkSA.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Inflate.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\IWGen.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kave.dll scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\lha.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\L_llio.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\mdb.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MDMAP.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MemModSc.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MemScan.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\minizip.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MKavIO.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\msoe.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\nfio.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\NTFSstrm.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prKernel.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prLoader.dll scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prseqio.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\PrUtil.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Quantum.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\rar.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\ScanningProcess.exe scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\sfdb.PPL scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\TempFile.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\thpimpl.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UniArc.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UnLZX.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UnStored.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\WDiskIO.ppl scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\hsperfdata_AggroFemme\3312 scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\hsperfdata_AggroFemme\632 scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\etilqs_G6OmKDm7MlvdmVgApaW6 scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\~DF2CC9.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\AGGROF~1\AppData\Local\Temp\~DFDA01.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. Windows Temp folder emptied. File delete failed. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11032008_201717 Files moved on Reboot… C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Arj.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\avlib.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Avp1.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\AvpMgr.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\btimages.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\CAB.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\dmap.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\dtreg.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FsDrvPlg.ppl moved successfully. DllUnregisterServer procedure not found in C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FSSync.dll C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FSSync.dll NOT unregistered. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\FSSync.dll moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HashCont.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HashMD5.PPL moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\HCCMP.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\ichk2.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\iChkSA.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Inflate.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\IWGen.ppl moved successfully. DllUnregisterServer procedure not found in C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kave.dll C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kave.dll NOT unregistered. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kave.dll moved successfully. DllUnregisterServer procedure not found in C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kosglue-7.0.25.0.dll C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kosglue-7.0.25.0.dll NOT unregistered. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\kosglue-7.0.25.0.dll moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\lha.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\L_llio.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\mdb.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MDMAP.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MemModSc.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MemScan.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\minizip.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\MKavIO.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\msoe.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\nfio.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\NTFSstrm.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prKernel.ppl moved successfully. DllUnregisterServer procedure not found in C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prLoader.dll C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prLoader.dll NOT unregistered. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prLoader.dll moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\prseqio.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\PrUtil.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\Quantum.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\rar.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\ScanningProcess.exe moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\sfdb.PPL moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\TempFile.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\thpimpl.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UniArc.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UnLZX.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\UnStored.ppl moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\jkos-AggroFemme\binaries\WDiskIO.ppl moved successfully. File C:\Users\AGGROF~1\AppData\Local\Temp\hsperfdata_AggroFemme\3312 not found! File C:\Users\AGGROF~1\AppData\Local\Temp\hsperfdata_AggroFemme\632 not found! File C:\Users\AGGROF~1\AppData\Local\Temp\etilqs_G6OmKDm7MlvdmVgApaW6 not found! C:\Users\AGGROF~1\AppData\Local\Temp\~DF2CC9.tmp moved successfully. C:\Users\AGGROF~1\AppData\Local\Temp\~DFDA01.tmp moved successfully. File move failed. C:\Windows\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_001_ moved successfully. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_002_ moved successfully. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_003_ moved successfully. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\AggroFemme\AppData\Local\Mozilla\Firefox\Profiles\du7wvs12.default\urlclassifier3.sqlite moved successfully. Uninstalled Limeware and ran Cleanup. After second reboot the folder is no longer in the C:folder. to specify the entire moveit program is gone.

After second reboot the folder is no longer in the C:folder. to specify the entire moveit program is gone.

Thats correct, it deletes it self in the cleaning process. You are good to go :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI