|
-
February 2nd, 2010, 11:00 PM
#16
there are two entries in the taskmanager listed for iexplore.exe
With IE8 it's normal.
Please, give me fresh HJT log.
-
February 3rd, 2010, 02:06 AM
#17
Most recent Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:47:23 AM, on 2/3/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Garmin Communicator Plug-In - https://my.garmin.com/static/m/cab/2...nAxControl.CAB
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
--
End of file - 4149 bytes
Just an FYI: I have no idea what lightscribe disk labling service is. I have never heard of lightscribe nor do I print or lable any disks, (other than with a sharpee marker)
Last edited by Cowboy622; February 3rd, 2010 at 02:08 AM.
Reason: added an FYI
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 3rd, 2010, 09:20 AM
#18
-
February 3rd, 2010, 12:00 PM
#19
Did you uninstall AVG completely?
-
February 3rd, 2010, 01:09 PM
#20
Yes I uninstalled it to run the scans and when I was finished, I re-installed it. So it has been re-installed before this Hijack log.
Is it possible the 4 trojans that Mbam took out might have fixed the problem????
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 3rd, 2010, 01:16 PM
#21
It looks like....
Your computer is clean 
1. Turn off System Restore:
- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK
2. Restart computer.
3. Turn System Restore on.
4. Make sure, Windows Updates are current.
5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!
6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.
7. Run defrag at your convenience.
8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
9. Please, let me know, how is your computer doing.
-
February 4th, 2010, 01:24 AM
#22
Thank you. At the moment all is fine and thinghs appear solved. Thank you so very much for all your help.
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 4th, 2010, 01:30 AM
#23
I don't know how to mark this thread as "Resolved" but everything seems to be working, correctly so thank you very much.
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 4th, 2010, 01:37 AM
#24
You're very welcome
-
February 4th, 2010, 10:37 AM
#25
Above your first post is Thread tools, in there as as you are the initiator of the thread, is where you can mark the thread as resolved.
-
February 4th, 2010, 09:20 PM
#26
Again, thank you for the help and thank you Train for helping me mark this resolved.
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 4th, 2010, 09:52 PM
#27
Stay safe
-
February 4th, 2010, 10:22 PM
#28
One last question: Should I uninstall Ad Aware and Spybot if they are obsolete?
Cowboy622
ASUS Rampage III Formula Rev 1.xx Motherboard; 3.07 gigahertz Intel Core i7 950 CPU; 12.0 GB Ram; Windows 7 Home Premium (x64) (build 7600); NVIDIA GeForce GTX 460 [Display adapter]
You miss 100% of the shots you never take !
-
February 4th, 2010, 10:42 PM
#29
I'd do so...
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|