Help, please.

2»

Comments

  • TroganTrogan London, UK
    edited February 2007
    Hi Bogus

    What happened to your Anti-Virus program? I do not see it in your HijackThis log.


    Please do the following...

    1. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
    This program is for XP and Windows 2000 only!

    Double-click ATF Cleaner.exe to open it.

    Under Main select the following:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Java Cache
    *The other boxes are optional*
    Then click the Empty Selected button.

    Click Exit on the Main menu to close the program.

    2. Make sure you can view hidden files and folders:
    • Click Start.
    • Open My Computer.
    • Select the Tools menu and click Folder Options.
    • Select the View Tab.
    • Under the Hidden files and folders heading select Show hidden files and folders.
    • Uncheck the Hide protected operating system files (recommended) option.
    • Click Yes to confirm.
    • Click OK.
    3. Reboot back into Safe Mode and then delete the follwoing in RED, if present:

    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\GFB8OZXD\sia[1].txt
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\GFB8OZXD\sia[2].txt
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\I8M5VXGW\enter[2].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\KL4DO1WR\ysb_regular[2].cab
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\KLCPM7CH\main[1].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\Q2LT2NDE\ysb_prompt[1].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\Q2LT2NDE\ysb_prompt[2].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\S9K12ZGX\ysb_prompt[1].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\S9K12ZGX\ysb_prompt[2].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\SDAZ09AV\dia233[1].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\SX8BOL4P\a0y7NYkib5FmcPf7tAo[2].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\SX8BOL4P\index[8].html
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\SX8BOL4P\main[3].html
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VMKZJ905\ied_s7[1].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VMKZJ905\ied_s7[2].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VMKZJ905\ied_s7[3].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VMKZJ905\main[1].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\VMKZJ905\prompt[1].htm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\YVA329W9\J6Oel78aYdGzgtzubsE[1].chm
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\YVA329W9\on-line[1].exe
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\ZAZX9HBZ\ldr[1].txt
    C:\Documents and Settings\Michael\Local Settings\Temporary Internet Files\Content.IE5\ZAZX9HBZ\ldr[2].txt

    3. Reboot back into Normal Mode

    4. I need to see another log from HijackThis.
    • Run Hijackthis.
    • Click on Open the Misc Tools section.
    • Next click on Open uninstall manager.
    • Press the Save list button.
    • Save the file to your desktop, with the default name of uninstall_list
    • Copy & Paste the entire contents of that file in your in your next post.
    5. Post the uninstall list, along with a new HijackThis log.
  • edited February 2007
    I don't know what happened to it. Does where it's saved affect whether HijackThis picks it up? It's in Desktop.

    The ATF Cleaner froze. It says "(Not Responding)" I think it's because of the Temporary Internet Files bull****. Deleting those never works.
  • TroganTrogan London, UK
    edited February 2007
    I don't know what happened to it. Does where it's saved affect whether HijackThis picks it up? It's in Desktop.
    HijackThis should have nothing to with your Anti-Virus. Did you uninstall? Which Anti-Virus program do you have? Last time I saw it was Nod32. Do you see this on your computer?
    The ATF Cleaner froze. It says "(Not Responding)" I think it's because of the Temporary Internet Files bull****. Deleting those never works.
    Give ATF Cleaner about 10 mins to run. If you keep clicking on the Window it will freeze. If that doesn't work, try running it in Safe Mode.
  • edited February 2007
    I got rid of Nod so I could have the AVG thing you linked me to. It looked like AVG was better, anyway.
  • edited February 2007
    I left the ATF thing alone while I took a shower, and came back to find that, after moving the mouse to get the screensaver away, the program was white and not responding. So I rebooted in Safe Mode, ran it again, and it seemed to be going okay, but when I pressed Ctrl Alt Delete, nothing happened. So I pressed again, still nothing, and when I tried to move the mouse, the cursor didn't react at all. This happens in Safe Mode sometimes. I try to use the keyboard, and then the mouse and keyboard cease to do anything at all, yet the computer doesn't freeze. I held the power button to turn it off, and it still began to end the ATF task before it shut down and everything. Sometimes when I get on AOL in Safe Mode with Networking, I click on the search, and the moment I begin to type, everything freezes except the screen. The line'll still be linking, as if I'm going to type something, whatever was loading will keep loading, etc.
  • TroganTrogan London, UK
    edited February 2007
    AVG anti-spyware is NOT an anti-virus. Please reinstall Nod32 immediately.

    As for the Temp files, try cleaning them out manually by doing the following...

    [FONT=&quot]Navigate to C:\Windows\Temp
    Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

    Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
    Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

    Clean out your Temporary Internet files. Proceed like this:
    • Quit Internet Explorer and quit any instances of Windows Explorer.
    • Click Start, click Control Panel, and then double-click Internet Options.
    • On the General tab, click Delete Files under Temporary Internet Files.
    • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
    • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
    • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
    • Click OK.
    Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin. [/FONT]
  • edited February 2007
    Ad-Aware SE Personal
    Adobe Flash Player 9 ActiveX
    Adobe Reader 7.0
    AIM 6.0
    AOL Coach Version 1.0(Build:20040229.1 en)
    AOL Coach Version 2.0(Build:20041026.5 en)
    AOL Deskbar
    AOL Instant Messenger
    AOL Spyware Protection
    AOL Toolbar
    AOL Uninstaller (Choose which Products to Remove)
    AOL You've Got Pictures Screensaver
    Apple Software Update
    ArcSoft Software Suite
    AV Music Morpher 2.0.106 Gold
    AVG Anti-Spyware 7.5
    BitComet 0.79
    Classic PhoneTools
    Dell ResourceCD
    DivX
    DivX Player
    Download Accelerator Plus
    Easy CD Creator 5 Basic
    em-pee three player 4.8
    HijackThis 1.99.1
    Intel(R) PRO Network Adapters and Drivers
    iPod for Windows 2005-09-23
    iTunes
    Java 2 Runtime Environment, SE v1.4.2
    Kaspersky Online Scanner
    Learn2 Player (Uninstall Only)
    Macromedia Shockwave Player
    Microsoft Office Professional Edition 2003
    Modem Helper
    Mozilla Firefox (2.0.0.1)
    MyDVD
    Nikon Message Center
    NOD32 antivirus system
    NVIDIA Windows 2000/XP Display Drivers
    Paltalk Messenger
    Pure Networks Port Magic
    QuickTime
    RealPlayer Basic
    RTC Client API v1.2
    Skype 2.0
    Sound Blaster Live!
    System Requirements Lab
    TeamSpeak 2 RC2
    Update for Windows XP (KB898461)
    Viewpoint Media Player
    Windows Installer 3.1 (KB893803)
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows XP Hotfix - KB842773
    WinRAR archiver
    XBC 5.1
    Yahoo! extras
    Yahoo! Internet Mail
    Yahoo! Messenger
    Yahoo! Messenger Explorer Bar
    Yahoo! Toolbar
  • edited February 2007
    Logfile of HijackThis v1.99.1
    Scan saved at 5:58:33 PM, on 2/24/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\QuickTime\bak\bak\qttask.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\America Online 9.0d\waol.exe
    C:\Program Files\America Online 9.0d\shellmon.exe
    C:\Program Files\iTunes\iTunes.exe
    C:\Documents and Settings\Michael\My Documents\iPod\bin\iPodService.exe
    C:\Documents and Settings\Michael\Desktop\Backup Thing\HijackThis.exe
    O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_6_0_0.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_6_0_0.dll
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\bak\bak\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0d\AOL.EXE" -b
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
    O8 - Extra context menu item: &Yahoo! Search - [URL]file:///C:\Program[/URL] Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
    O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - [URL]file:///C:\Program[/URL] Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - [URL]file:///C:\Program[/URL] Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra button: Microsoft AntiSpyware helper - {6D888E74-CCD0-4006-B4F1-B5FA419CF8D2} - (no file) (HKCU)
    O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {6D888E74-CCD0-4006-B4F1-B5FA419CF8D2} - (no file) (HKCU)
    O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
    O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
    O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\aolserv.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Documents and Settings\Michael\My Documents\iPod\bin\iPodService.exe
    O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
  • TroganTrogan London, UK
    edited February 2007
    Hi Bogus. Almost done...

    1. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

    Updating Java:
    • Download the latest version of Java Runtime Environment (JRE) 6 .
    • Click the "Download" button to the right.
    • Check the box that says: "Accept License Agreement."
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Control Panel double-click on Add/Remove programs and remove the following...
      • ava 2 Runtime Environment, SE v1.4.2
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

    Your log is clean. How is the computer? :)
  • edited February 2007
    Thanks a lot. It's starting up faster now, but other than that, I don't really know what I did. Should I run any other scans now? Like AVG, Ad-Aware, or Nod?
  • TroganTrogan London, UK
    edited February 2007
    You should scan with AVG anti-spyware and Nod32 atleast once a week. Ad-aware, now and again I'd say. :)

    Do you have any other questions or can mark this resolved?
  • edited February 2007
    I think that's it. Thanks again.
  • TroganTrogan London, UK
    edited February 2007
    You're welcome! :)

    This topic is now closed. If you wish it reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

    Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.

    If you are not the user who started this thread, you must start a new Thread instead :)

    Would you also be interested to join Short-Media (Team #93) with the Folding@Home Project? More information available here
This discussion has been closed.