Options

Strange computer problems

Hello everyrone, my pc been acting strangely in the past few weeks.
it all started when mcafee virusscan found some trojans in the internet temp directory and couldn't clean and delete tham, i removed mcafee and installed avg, after a scan he assured me the files have been deleted but still he find's and deletes them everyday, there are some kind of video(nubmer).exe files in the temp which i try to delete but the get born again every once in a while., when i try to run adaware it freezes in the C:\Documents and Settings\VAdim\Local Settings\Temp\Temporary Internet Files\Content.IE5
directory.
and i can't access this directory, when i try to open this directory windows just gets stuck, i also can delete the temp with all kinds of cleaning tools i have, they all get stuck.
the computer isn't stable and the internet connection always uploading something at full speed, internet works slow.
i'm sure i catched something from bad sites:-P
i will be very happy if someone could help me
her's the hijackthis log which seems ok to me.
Logfile of HijackThis v1.99.1
Scan saved at 21:19:27, on 02/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NetLimiter\NetLimiter.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\nvsvc32.exe
D:\lhEMULE 4.2\emule.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Vadimpc\Local Settings\Temporary Internet Files\Content.IE5\02JQWKHL\VundoFix[1].exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Startup: Shortcut to emule.lnk = D:\lhEMULE 4.2\emule.exe
O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.25\IExifMap.htm
O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.25\IExifCom.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141743660203
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1141743646703
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CBF2C04B-50B5-4C7B-8D49-ACB62582F8E6} (LauncherV1 Class) - http://chat-basic.nana.co.il/Cabs/launcher.cab
O16 - DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} (LauncherV1 Class) - http://www.tapuz.co.il/irc/main/launcher.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\partnership.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Davstbvvp - Creative Technology Ltd - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: ieupdater (Microsoft IE Updater) - Unknown owner - C:\Documents and Settings\Vadimpc\~tmp0374.exe (file missing)
O23 - Service: Nvnentlte - NVIDIA Corporation - (no file)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

Comments

  • TroganTrogan London, UK
    edited February 2007
    Hi Vad70im and welcome to Short Media! :)

    Can I get you to scan a file
    • Go to VirusTotal
    • Copy and paste the following file path into the Search Box at the top of the page:
    • C:\Documents and Settings\Vadimpc\~tmp0374.exe
    • Click on the Send button
    • Please post the results in your next reply.
  • edited February 2007
    thank you for your fast reply.
    couldn't do what you asked me as explorer crashed when i try to access the directory thru the file browser :-\
    but i scanned this file manually thru avg and got a positive with the name
    " trojan.horse downloader generic3.kji "
    i made some purchases online few weeks ago, any chance someone got the info?
  • TroganTrogan London, UK
    edited February 2007
    To be honest, I'm not sure. There is a possibility, though.

    With that said, I need to give you this warning.

    The infection you have is a variant of the SDBot Trojan, which has Backdoor functionality. This can give intruders complete control of your computer, logging key strokes, stealing information, etc. :(

    You are strongly advised to do the following immediately!:
    • Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.
    • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    • From a clean computer, change *all* of your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
        Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
      Because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure it can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

      To help you make a more informed decision, please read the following articles: Should you have any questions, please feel free to ask

      Please let me know your decision and we'll get started with clean up if that's what you choose.
    • edited February 2007
      i made a scan with spybot few minutes ago and he have found

      --- Search result list ---
      Microsoft.WindowsSecurityCenter.FirewallBypass: Settings (Registry value, nothing done)
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\explorer.exe




      and in the same time AVG have opened a window titled threat detected
      c:\documents and setting\all users.windows\documents\setting\partnership.dll
      trojan horse proxy.ki0
    • TroganTrogan London, UK
      edited February 2007
      Please stop doing scans on your own. It will make things harder for us both.

      Read what I wrote above and let me know.
    • edited February 2007
      i will go with the cleaning option :rolleyes2
    • TroganTrogan London, UK
      edited February 2007
      Please do the following...

      1. Download SDFix and save it to your Desktop.

      Double click SDFix.exe and it will extract the files to %systemdrive%
      (Drive that contains the Windows Directory, typically C:\SDFix)

      Please then reboot your computer in Safe Mode by doing the following :
      • Restart your computer
      • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
      • Instead of Windows loading as normal, the Advanced Options Menu should appear;
      • Select the first option, to run Windows in Safe Mode, then press Enter.
      • Choose your usual account.
      • Open the extracted SDFix folder and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
        (Report.txt will also be copied to Clipboard ready for posting back on the forum).
      • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log in your next reply
      2. I need to see another log from HijackThis.
      • Run Hijackthis.
      • Click on Open the Misc Tools section.
      • Next click on Open uninstall manager.
      • Press the Save list button.
      • Save the file to your desktop, with the default name of uninstall_list
      • Copy & Paste the entire contents of that file in your in your next post.
      3. Please post the following...
      • SDFix report.txt
      • Uninstall list
      • New HijackThis log
    • edited February 2007
      Ok , did what you asked me to, here is the results:

      SDFix: Version 1.63

      Fri 02/02/2007 - 23:01:26.70

      Microsoft Windows XP [Version 5.1.2600]

      Running From: C:\SDFix

      Safe Mode:
      Checking Services:

      Name:
      Microsoft IE Updater
      msgegh

      Path:
      C:\Documents and Settings\Vadimpc\~tmp0374.exe /start
      \??\C:\WINDOWS\system32\drivers\msgegh.sys

      Microsoft IE Updater Deleted
      msgegh Deleted

      Restoring Windows Registry Entries
      Restoring Default Hosts File


      Rebooting...

      Normal Mode:
      Checking Files:

      ogfile of HijackThis v1.99.1
      Scan saved at 23:31:44, on 02/02/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\NetLimiter\NetLimiter.exe
      C:\WINDOWS\system32\CTHELPER.EXE
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Logitech\G-series Software\LGDCore.exe
      C:\Program Files\Logitech\G-series Software\LCDMon.exe
      C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
      C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      D:\lhEMULE 4.2\emule.exe
      C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Program Files\Hijackthis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
      O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
      O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
      O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
      O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
      O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - Startup: Shortcut to emule.lnk = D:\lhEMULE 4.2\emule.exe
      O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.25\IExifMap.htm
      O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.25\IExifCom.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
      O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
      O9 - Extra button: מחקר - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
      O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141743660203
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1141743646703
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {CBF2C04B-50B5-4C7B-8D49-ACB62582F8E6} (LauncherV1 Class) - http://chat-basic.nana.co.il/Cabs/launcher.cab
      O16 - DPF: {D79B6F43-F214-4E7A-9ECB-CCC8771F2416} (LauncherV1 Class) - http://www.tapuz.co.il/irc/main/launcher.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
      O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
      O23 - Service: Davstbvvp - Creative Technology Ltd - (no file)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Nvnentlte - NVIDIA Corporation - (no file)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    • TroganTrogan London, UK
      edited February 2007
      Good job.

      Can I see the Uninstall list?
    • edited February 2007
      where do i find it :-O ?
    • TroganTrogan London, UK
      edited February 2007
      Look back at the instructions; its number 2...right under SDFix, which you managed to do.
    • edited February 2007
      oh sorry :-|
      here it is

      3114 SATARAID5
      AC3Filter (remove only)
      Ad-Aware SE Personal
      Adobe Bridge 1.0
      Adobe Common File Installer
      Adobe Download Manager 2.0 (הסרה בלבד)
      Adobe Flash Player 9 ActiveX
      Adobe Help Center 1.0
      Adobe Photoshop CS2
      Adobe Reader 7.0.8
      Adobe Reader for Pocket PC 2.0
      Adobe Stock Photos 1.0
      Adobe® Photoshop® Album Starter Edition 3.0
      Advanced System Optimizer 2.01
      Advanced System Optimizer 2.10
      AGEIA PhysX v2.5.0
      AVG Free Edition
      Babylon
      BlackJack
      Capture NX
      Carom 3D
      Chix
      DIMIN Hotkeys (remove only)
      Direct Show Ogg Vorbis Filter (remove only)
      DivX ;-) Audio Compressor 4.02
      DivX Codec
      DivX Converter
      DivX Player
      DivX Web Player
      Easy CD-DA Extractor 8.2.1
      Easy CD-DA Extractor 9.0.1
      elicomp-warezfaw
      eMule
      Google Earth
      GTA San Andreas
      GTR 2 1.0.0.0
      Hijackthis 1.99.1
      HijackThis 1.99.1
      Hotfix for Windows XP (KB915865)
      ICQ 5.1
      J2SE Runtime Environment 5.0 Update 4
      Joint Task Force
      K-Lite Codec Pack 2.32 Full
      Logitech Gaming Software
      Logitech G-series Keyboard Software
      Logitech SetPoint
      LucasArts' Grim Fandango
      Macromedia Dreamweaver 8
      Macromedia Extension Manager
      Macromedia Fireworks 8
      Macromedia Shockwave Player
      Marvell Miniport Driver
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Hotfix (KB886903)
      Microsoft .NET Framework 2.0
      Microsoft ActiveSync 3.7
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft National Language Support Downlevel APIs
      Microsoft Office Professional Edition 2003
      Microsoft Text-to-Speech Engine 4.0 (English)
      Mirsham
      MSN Messenger 7.5
      Nero 6 Ultra Edition
      NetLimiter 1.30 (remove only)
      Nikon Message Center
      Nokia Connectivity Cable Driver
      Nokia PC Suite
      NVIDIA Drivers
      NVIDIA WDM Drivers
      Opanda IExif 2.25
      PC Connectivity Solution
      PerfectDisk
      Photomatix Pro version 2.3.1
      PhotoMix 5.3
      PowerDVD
      Race Driver 3
      Sam and Max - Situation Comedy 1.0
      San Andreas Mod Installer
      San Andreas Mod Installer
      Sound Blaster Live! Web 2K/XP
      Spybot - Search & Destroy 1.4
      SWAT 4
      WildTangent Web Driver
      Winamp (remove only)
      Windows Driver Package - Nokia (WUDFRd) WPD (11/03/2006 6.82.26.2)
      Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
      Windows Internet Explorer 7
      Windows Media Format Runtime
      Windows Media Player 10
      WinRAR archiver
      ZoneAlarm Pro
    • TroganTrogan London, UK
      edited February 2007
      Thanks for the list.

      Please do the following...

      1. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

      Updating Java:
      • Download the latest version of Java Runtime Environment (JRE) 6.
      • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
      • Click the "Download" button to the right.
      • Check the box that says: "Accept License Agreement."
      • The page will refresh.
      • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
      • Close any programs you may have running - especially your web browser.
      • Go to Start > Control Panel double-click on Add/Remove programs and remove the following...
        • J2SE Runtime Environment 5.0 Update 4
      • Reboot your computer once all Java components are removed.
      • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.
      2. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
      This program is for XP and Windows 2000 only!

      Double-click ATF Cleaner.exe to open it.

      Under Main select the following:
      • Windows Temp
      • Current User Temp
      • All Users Temp
      • Temporary Internet Files
      • Prefetch
      • Java Cache
      *The other boxes are optional*
      Then click the Empty Selected button.

      Click Exit on the Main menu to close the program.

      3. You may wish to Print or Save the following instructions, as the internet will not be available once in Safe Mode!

      Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
      http://www.ewido.net/en/download/
      • Install AVG Anti-Spyware by double clicking the installer.
      • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
      • On the main screen under Your Computer's security.
        • Click on Change state next to Resident shield. It should now change to inactive.
        • Click on Change state next to Automatic updates. It should now change to inactive.
        • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
        • Wait until you see the Update succesfull message.
      • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
      • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
      If you are having problems with the updater, you can use this link to manually update ewido.
      AVG Anti-Spyware manual updates.
      Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

      Reboot your computer in Safe Mode.
      • If the computer is running, shut down Windows, and then turn off the power.
      • Wait 30 seconds, and then turn the computer on.
      • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
      • Ensure that the Safe Mode option is selected.
      • Press Enter. The computer then begins to start in Safe mode.
      • Login on your usual account.
      Once in Safe Mode:

      Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
      • Click on Scanner on the toolbar.
      • Click on the Settings tab.
        • Under How to act?
          • Click on Recommended Action and choose Quarantine from the popup menu.
        • Under How to scan?
          • All checkboxes should be ticked.
        • Under Possibly unwanted software:
          • All checkboxes should be ticked.
        • Under Reports:
          • Select Automatically generate report after every scan and uncheck Only if threats were found.
        • Under What to scan?
          • Select Scan every file.
      • Click on the Scan tab.
      • Click on Complete System Scan to start the scan process.
      • Let the program scan the machine.
      • When the scan has finished, follow the instructions below.
        IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
        • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
        • At the bottom of the window click on the Apply all Actions button. (3)
          scanavgjk2.jpg
      • When done, click the Save Scan Report button. (4)
        • Click the Save Report as button.
        • Save the report to your Desktop.
      • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
      Reboot back into Normal Mode, and post a new HJT log, along with the AVG Anti-Spyware log.
    • edited February 2007
      unfortunately i can't complete a full scan with any software i have beacuse they all crash when they get to C:\Documents and Settings\VAdim\Local Settings\Temp\Temporary Internet Files\Content.IE5
      any ideas?
    • TroganTrogan London, UK
      edited February 2007
      Go to the following folder (Content.IE5)

      C:\Documents and Settings\VAdim\Local Settings\Temp\Temporary Internet Files\Content.IE5

      If there are other folders within Content.IE5, then empty (delete) the contents. Do NOT delete the folders themselves.
    • edited February 2007
      i can't access these folders in anyway.
      when i try to delete one of the subfolders or when i try to access it , the computer just freezes, same thing happening when an antivirus or some other scan program tries to scan the folder , it just freezes and display a " this program have preformed an illegal operation" window.
    • TroganTrogan London, UK
      edited February 2007
      Sorry for the delay.

      Does this happen in Safe Mode?
    • edited February 2007
      Trogan wrote: »
      Sorry for the delay.

      Does this happen in Safe Mode?

      unfortunately yes
    • TroganTrogan London, UK
      edited February 2007
      Let's try running CCleaner and hope it works.

      *NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!

      Download CCleaner from here It will start to download automatically. Save to your Desktop.
      Note: If you get and Error page from this link.
      Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
      • Double click on the file to start the installation of the program.
      • Select your language and click OK, then next.
      • Follow prompts to install finish to complete installation.
      • Double click the CCleaner shortcut on the desktop to start the program.
      • Before first use, select Options > Advanced and UNCHECK Only delete files in Windows Temp folder older than 48 hours
      • Then select the items you wish to clean up.
        • In the Windows Tab:
          • Clean all entries in the Internet Explorer section except Cookies
          • Clean all the entries in the Windows Explorer section
          • Clean all entries in the System section
          • Clean all entries in the Advanced section
          • Clean any others that you choose
        • In the Applications Tab:
          • Clean all except cookies in the Firefox/Mozilla section if you use it
          • Clean all in the Opera section if you use it
          • Clean Sun Java in the Internet Section
          • Clean any others that you choose
      • Click the Run Cleaner button.
      • A pop up box will appear advising this process will permanently delete files from your system.
      • Click OK and it will scan and clean your system.
      • Click exit when done.
      • If it asks you to reboot at the end, click NO
      CCleaner should be run with the above settings for each User Account!

      Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
      ____________________

      Let me know if that solved the problem.
    Sign In or Register to comment.