This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help! Trojan virus

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This is a tricky one, very new so isn't detected by anything, and also doesn't seem to show itself anywhere.

OK, open MBAM, update it, and run a quick scan. May have been added to their database since we started.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Post a new HijackThis log as well.

Sorry about this, we are working in the dark on this one.

Thanks.
Please don't apologise, I really appreciate you guys having a look at my problem to begin with :)

MBAM scan was updated but no Malware found

DDS report


DDS (Version 1.0) - NTFSx86
Run by [removed] at 21:32:54.35 on 2008-12-02
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.893.356 [GMT 0:00]

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\seannewton2000\AppData\Roaming\Google\dwm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\seannewton2000\Desktop\dds.scr
C:\Users\seannewton2000\Desktop\dds.scr
C:\Users\seannewton2000\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg8\avgssie.dll
BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [dwm] "c:\users\seannewton2000\appdata\roaming\google\dwm.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\update.exe -silent
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [COMODO SafeSurf] "c:\program files\comodo\safesurf\cssurf.exe" -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~3.0_0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll c:\windows\system32\guard32.dll c:\windows\system32\cssdll32.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-16 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2008-11-16 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-11-16 231704]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-11-23 809296]
R3 AvgWfpX;AVG Free8 Firewall Driver x86;c:\windows\system32\drivers\avgwfpx.sys [2008-11-16 69128]
R3 rt61x86;Ralink RT61 Wireless Driver for Windows Vista;c:\windows\system32\drivers\netr61.sys [2007-9-28 316928]

=============== Created Last 30 ================

2008-12-02 20:25 244 a—h— C:\sqmnoopt01.sqm
2008-12-02 20:25 232 a—h— C:\sqmdata01.sqm
2008-12-02 19:49 244 a—h— C:\sqmnoopt00.sqm
2008-12-02 19:49 232 a—h— C:\sqmdata00.sqm
2008-11-28 22:11 151,525,786 a——- c:\windows\MEMORY.DMP
2008-11-28 21:58 318,976 a——- c:\windows\system32\CF15747.exe
2008-11-28 21:58 –d—– C:\ComboFix
2008-11-27 20:50 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-11-27 17:48 161,792 a——- c:\windows\SWREG.exe
2008-11-27 17:48 98,816 a——- c:\windows\sed.exe
2008-11-27 03:08 625,152 a——- c:\windows\system32\drivers\dxgkrnl.sys
2008-11-27 03:08 565,248 a——- c:\windows\system32\emdmgmt.dll
2008-11-27 03:08 148,480 a——- c:\windows\system32\drivers\nwifi.sys
2008-11-27 03:08 45,056 a——- c:\windows\system32\dataclen.dll
2008-11-27 03:08 36,864 a——- c:\windows\system32\cdd.dll
2008-11-27 03:08 147,456 a——- c:\windows\system32\Faultrep.dll
2008-11-27 03:08 125,952 a——- c:\windows\system32\wersvc.dll
2008-11-27 03:08 784,896 a——- c:\windows\system32\rpcrt4.dll
2008-11-27 03:07 891,448 a——- c:\windows\system32\drivers\tcpip.sys
2008-11-27 03:07 72,192 a——- c:\windows\system32\drivers\pacer.sys
2008-11-27 03:07 15,360 a——- c:\windows\system32\pacerprf.dll
2008-11-27 03:07 430,080 a——- c:\windows\system32\vbscript.dll
2008-11-27 03:07 180,224 a——- c:\windows\system32\scrobj.dll
2008-11-27 03:07 172,032 a——- c:\windows\system32\scrrun.dll
2008-11-27 03:07 155,648 a——- c:\windows\system32\wscript.exe
2008-11-27 03:07 135,168 a——- c:\windows\system32\wshom.ocx
2008-11-27 03:07 135,168 a——- c:\windows\system32\cscript.exe
2008-11-27 03:07 90,112 a——- c:\windows\system32\wshext.dll
2008-11-26 22:06 –d—– C:\PerfLogs
2008-11-26 20:21 –d—– c:\windows\pss
2008-11-26 20:13 –d—– C:\c3d6c22010c10b7a9c55552e
2008-11-26 20:12 –d—– c:\windows\CheckSur
2008-11-25 22:28 712,704 a——- c:\windows\system32\WindowsCodecs.dll
2008-11-25 22:28 425,472 a——- c:\windows\system32\PhotoMetadataHandler.dll
2008-11-25 22:28 347,136 a——- c:\windows\system32\WindowsCodecsExt.dll
2008-11-25 22:27 1,645,568 a——- c:\windows\system32\connect.dll
2008-11-23 20:40 249,592 a——- c:\windows\system32\cssdll32.dll
2008-11-23 20:36 –d—– c:\programdata\Spybot - Search & Destroy
2008-11-23 20:36 –d—– c:\program files\Spybot - Search & Destroy
2008-11-23 20:36 –d—– c:\progra~2\Spybot - Search & Destroy
2008-11-23 20:35 –d—– c:\programdata\comodo
2008-11-23 20:35 –d—– c:\progra~2\comodo
2008-11-23 20:35 –d—– c:\program files\COMODO
2008-11-23 20:30 a-d—– c:\programdata\TEMP
2008-11-23 20:30 –d—– c:\program files\SpywareBlaster
2008-11-23 20:27 –d—– c:\users\seanne~1\appdata\roaming\WinPatrol
2008-11-23 20:27 –d—– c:\program files\BillP Studios
2008-11-22 20:21 250 a——- c:\windows\gmer.ini
2008-11-19 21:34 –d—– c:\programdata\NortonInstaller
2008-11-19 21:34 –d—– c:\progra~2\NortonInstaller
2008-11-16 20:56 –d—– C:\My Documents
2008-11-16 20:36 –d—– c:\users\seanne~1\appdata\roaming\Malwarebytes
2008-11-16 20:36 15,504 a——- c:\windows\system32\drivers\mbam.sys
2008-11-16 20:36 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-16 20:36 –d—– c:\programdata\Malwarebytes
2008-11-16 20:36 –d—– c:\program files\Malwarebytes' Anti-Malware
2008-11-16 20:36 –d—– c:\progra~2\Malwarebytes
2008-11-16 09:53 –d-h— C:\$AVG8.VAULT$
2008-11-16 09:28 10,520 a——- c:\windows\system32\avgrsstx.dll
2008-11-16 09:28 69,128 a——- c:\windows\system32\drivers\avgwfpx.sys
2008-11-16 09:28 97,928 a——- c:\windows\system32\drivers\avgldx86.sys
2008-11-16 09:28 –d—– c:\windows\system32\drivers\Avg
2008-11-16 09:28 –d—– c:\program files\AVG
2008-11-16 09:28 –d—– c:\programdata\avg8
2008-11-16 09:28 –d—– c:\progra~2\avg8
2008-11-14 18:32 1,524,736 a——- c:\windows\system32\wucltux.dll
2008-11-14 18:31 162,064 a——- c:\windows\system32\wuwebv.dll
2008-11-14 18:31 31,232 a——- c:\windows\system32\wuapp.exe
2008-11-11 19:25 212,480 a——- c:\windows\system32\drivers\mrxsmb10.sys
2008-11-11 19:25 1,191,936 a——- c:\windows\system32\msxml3.dll
2008-11-11 19:10 1,334,272 a——- c:\windows\system32\msxml6.dll
2008-11-03 19:06 428,544 a——- c:\windows\system32\EncDec.dll
2008-11-03 19:06 217,088 a——- c:\windows\system32\psisrndr.ax
2008-11-03 19:06 177,664 a——- c:\windows\system32\mpg2splt.ax
2008-11-03 19:06 80,896 a——- c:\windows\system32\MSNP.ax
2008-11-03 19:06 293,376 a——- c:\windows\system32\psisdecd.dll

==================== Find3M ====================

2008-11-26 22:11 –d—– c:\program files\Windows Collaboration
2008-11-26 22:11 –d—– c:\program files\Windows Journal
2008-11-26 21:21 101,888 a——- c:\windows\system32\ifxcardm.dll
2008-11-26 21:20 82,432 a——- c:\windows\system32\axaltocm.dll
2008-11-19 21:35 –d—– c:\program files\common files\Symantec Shared
2008-11-18 21:01 –d—– c:\program files\MestRe-C
2008-11-16 22:51 –d—– c:\program files\Roxio
2008-11-16 21:58 –d—– c:\program files\LimeWire
2008-11-15 22:16 –d—– c:\users\seanne~1\appdata\roaming\Dcads Advanced Toolbar
2008-11-10 20:13 –d—– c:\users\seanne~1\appdata\roaming\LimeWire
2008-11-01 11:32 –d—– c:\program files\common files\aol
2008-11-01 11:24 –d—– c:\program files\AOL 9.0 VR
2008-11-01 11:23 –d—– c:\users\seanne~1\appdata\roaming\AOL
2008-10-02 03:49 827,392 a——- c:\windows\system32\wininet.dll
2008-09-30 16:43 1,286,152 a——- c:\windows\system32\msxml4.dll
2008-09-18 05:09 3,601,464 a——- c:\windows\system32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 a——- c:\windows\system32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 a——- c:\windows\system32\win32k.sys
2007-07-15 10:40 –d—– c:\users\seanne~1\appdata\roaming\Packard Bell
2007-09-03 21:15 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2007-09-03 21:15 32,768 a–sh— c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2007-09-03 21:15 16,384 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2007-05-30 18:00 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012007053020070531\index.dat

============= FINISH: 21:33:28.61 ===============

HiJackThis report

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:36, on 2008-12-02
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\seannewton2000\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [dwm] "C:\Users\seannewton2000\AppData\Roaming\Google\dwm.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1227563474827
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227683734235
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll C:\Windows\system32\guard32.dll C:\Windows\system32\cssdll32.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

–
End of file - 6758 bytes


Sill getting the warning pop up at the beginning. Not sure if I mentioned this earlier but it also pops up every now and then when Im working away at my computer.

Many thanks!!!!!

Attachments:

Hi :)

Let's check a file out.

You need to show all files and folders.
  • Click Start.
  • Open My Computer.
  • Select Folder and Search Options
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck Hide file extensions for known file types
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
We need to upload a file to Jotti

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

C:\Users\seannewton2000\AppData\Roaming\Google\dwm.exe

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

Thanks.
Could be onto a winner here!!!! :)

Scanner Results are below


Scanner results

Scan taken on 03 Dec 2008 19:45:19 (GMT)

A-Squared Found Trojan-Downloader.Win32.Dabew!IK

AntiVir Found TR/Drop.Agent.aajt

ArcaVir Found Trojan.Dropper.Agent.Aajt

Avast Found Win32:Trojan-gen {Other}

AVG Antivirus Found nothing

BitDefender Found Trojan.Generic.1200330

ClamAV Found nothing

CPsecure Found nothing

Dr.Web Found nothing

F-Prot Antivirus Found nothing

F-Secure Anti-Virus Found Trojan-Dropper.Win32.Agent.aajt

G DATA Found Win32:Trojan-gen

Ikarus Found nothing

Kaspersky Anti-Virus Found Trojan-Dropper.Win32.Agent.aajt

NOD32 Found Win32/TrojanDownloader.FakeAlert.SL

Norman Virus Control Found nothing

Panda Antivirus Found nothing

Sophos Antivirus Found Mal/Generic-A

VirusBuster Found nothing

VBA32 Found Trojan-Dropper.Win32.Agent.aajt
Hi :)

Do'h! My apologies, that was staring me in the face the whole time and I missed it.

Disable Spybot TeaTimer, open HijackThis and fix this line:
O4 - HKCU\..\Run: [dwm] "C:\Users\seannewton2000\AppData\Roaming\Google\dwm.exe"

Find and delete this file:
C:\Users\seannewton2000\AppData\Roaming\Google\dwm.exe

You may need to show all hidden folders to see the AppData folder. To do this, follow the below instructions:
  • Click Start.
  • Open My Computer.
  • Select Folder and Search Options
  • Select the View Tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck Hide file extensions for known file types
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.

After this, reboot, post a new HijackThis log and let me know if you still get the warnings.

Thanks, and sorry again.
Done and done :woot: Everything seems to be working really well now!!!! No warning sign and no crashes so I reckon we can probably close this one, unless there's any more tests you want me to run?!?! If not, then thank you very much for your time and help and I'll be sure to make a wee donation and recommend this site to others :) Many thanks!!!!! :notworthy:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI