Options

Stange Popup.

From time to time I receive a strange popup stating that my system is infected, and tells me to "click here" to run a system scan. (Or something similar to that)

I have scanned with A2Squared, and SSD.

Here is my HJT Log:



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:11 AM, on 4/12/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Common Files\logishrd\LComMgr\Communications_Helper.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Grisoft\AVG7\avgw.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe

--
End of file - 6267 bytes

Comments

  • edited April 2008
    Hello cotton00candy,

    I don't see infection in this view, but that does appear to be infection activity. Since you have startups disabled through msconfig everything is not really showing here, so let's take a more detailed look for now.

    Download Deckard's System Scanner (dss.exe) to your Desktop. Note: You must be logged onto an account with administrator privileges.

    Making sure dss.exe is directly on your desktop, go to Start - Start Search, and copy/paste the following (then press OK):

    "%userprofile%\desktop\dss.exe" /config

    When the DSS Configuration display opens click the "Check All" button (if the "Uncheck All" button shows, click that, then click "Check All"). Next, Under Main Log, uncheck the following:

    System Restore
    Temp Cleanup
    Process Modules

    Then under Options, place a check next to the following:

    Backup Registry Hives

    Don't make any other changes at this time. Then click the "Scan!" button to start the scan.

    Once the scan has completed a textbox will appear - copy/paste those contents back here (main.txt). Also a second text file, extra.txt, will show as minimized in your Task Bar. Maximize/Open this, and copy/paste those contents back here along with the main.txt please. (The logs can also be found in the C:\Deckard\System Scanner folder)
  • edited April 2008
    Hi, thank you for your help!


    I downloaded DSS, When I went to Start and put in "%userprofile%\desktop\dss.exe" /config it said no items match your search. I tried with and without the quotes.
  • edited April 2008
    :smiles:

    Download Deckard's System Scanner (dss.exe) to your Desktop.
  • edited April 2008
    I did :)
  • edited April 2008
    When you Enter these into Start Search, what results are seen please?

    %userprofile%

    %userprofile%\desktop
  • edited April 2008
    When I put in %userprofile% it brings up a folder with my name & another folder with my name\desktop.



    On the other %userprofile%\desktop it brings up a desktop icon.

    Hope this helps.
  • edited April 2008
    I am not getting a virtual idea of what is not working for you there. The environment paths seem okay (those "%%" entries).

    Click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator. At the prompt type or copy/paste each of the following, then press Enter after each (yes, the double quotes are important, so leave them):

    cd\

    "%userprofile%\desktop\dss.exe" /config


    When the Deckards display opens follow the steps posted previously.
  • edited April 2008
    Hi, Here are the logs. Thanks again.


    Deckard's System Scanner v20071014.68
    Run by Ashely on 2008-04-15 21:59:57
    Computer is in Normal Mode.

    Backed up registry hives.

    Total Physical Memory: 1014 MiB (1024 MiB recommended).


    -- HijackThis (run as Ashely.exe)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:00:44 PM, on 4/15/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Synaptics\SynTP\SynToshiba.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\System32\cmd.exe
    C:\Users\Ashely\desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Ashely.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe

    --
    End of file - 5565 bytes

    -- File Associations

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    All drivers whitelisted.


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled

    S4 TOSHIBA Bluetooth Service - c:\program files\toshiba\bluetooth toshiba stack\tosbtsrv.exe <Not Verified; TOSHIBA CORPORATION; Bluetooth Stack for Windows by TOSHIBA>


    -- Device Manager: Disabled

    Class GUID:
    Description:
    Device ID: ACPI\TOS1900\2&DABA3FF&1
    Manufacturer:
    Name:
    PNP Device ID: ACPI\TOS1900\2&DABA3FF&1
    Service:


    -- Scheduled Tasks

    2008-04-15 20:35:29 420 --ah
    C:\Windows\Tasks\User_Feed_Synchronization-{9E314677-BA81-4221-BF40-A8E88025A75E}.job


    -- Files created between 2008-03-15 and 2008-04-15

    2008-03-29 17:46:49 98304 --a
    C:\Windows\system32\CmdLineExt.dll <Not Verified; Sony DADC Austria AG.; >
    2008-03-29 16:28:22 0 dr-h
    C:\$VAULT$.AVG
    2008-03-29 16:13:39 0 d--h
    C:\Windows\msdownld.tmp
    2008-03-29 16:13:34 0 d
    C:\Windows\system32\directx
    2008-03-23 19:32:21 0 d
    C:\Program Files\Audio Recording Studio


    -- Find3M Report

    2008-04-15 14:55:39 0 d
    C:\Users\Ashely\AppData\Roaming\AVG7
    2008-04-15 01:45:16 0 d
    C:\Users\Ashely\AppData\Roaming\Image Zone Express
    2008-04-13 04:49:12 0 d
    C:\Users\Ashely\AppData\Roaming\gtk-2.0
    2008-04-12 17:12:23 0 d
    C:\Program Files\Common Files\logishrd
    2008-04-12 03:28:12 0 d
    C:\Program Files\a-squared Free
    2008-04-09 03:07:22 0 d
    C:\Program Files\Windows Mail
    2008-03-29 17:46:56 0 dr-h
    C:\Users\Ashely\AppData\Roaming\SecuROM
    2008-03-29 16:30:24 0 d--h
    C:\Program Files\InstallShield Installation Information
    2008-03-23 19:16:51 0 d
    C:\Users\Ashely\AppData\Roaming\Audio Record Edit Toolbox
    2008-02-27 10:32:09 0 d
    C:\Program Files\Oberon Media
    2008-02-24 15:36:17 0 d
    C:\Program Files\GIMP-2.0
    2008-02-24 15:30:34 0 d
    C:\Program Files\Common Files
    2008-02-24 15:30:34 0 d
    C:\Program Files\Common Files\GTK


    -- Registry Dump

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [09/05/2007 10:35 AM]
    "MSConfig"="C:\Windows\system32\msconfig.exe" [11/02/2006 05:45 AM]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [04/15/2008 08:11 AM]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [10/10/2007 08:51 PM]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [09/25/2007 01:11 AM]
    "SynTPStart"="C:\Program Files\Synaptics\SynTP\SynTPStart.exe" [10/29/2007 07:02 AM]
    "IgfxTray"="C:\Windows\system32\igfxtray.exe" [10/18/2007 10:19 AM]
    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [10/18/2007 10:18 AM]
    "Persistence"="C:\Windows\system32\igfxpers.exe" [10/18/2007 10:18 AM]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [01/09/2008 04:01 AM]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [11/02/2006 08:35 AM]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [11/02/2006 08:36 AM]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"=2 (0x2)
    "DisableCAD"=1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
    avgwlntf.dll 09/10/2007 09:26 PM 9216 C:\Windows\System32\avgwlntf.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    C:\Windows\system32\psqlpwd.dll 11/06/2006 11:34 AM 52224 C:\Windows\System32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Notification Packages"= scecli psqlpwd

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\VDS]
    @=&quot;Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
    @=&quot;Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
    @=&quot;Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @=&quot;Volume shadow copy"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
    @=&quot;IEEE 1394 Bus host controllers"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
    @=&quot;SBP2 IEEE 1394 Devices"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
    @=&quot;SecurityDevices"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSQLLauncher]
    "C:\Program Files\Protector Suite QL\launcher.exe" /startup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalSystemNetworkRestricted hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum


    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    C:\Windows\system32\unregmp2.exe /ShowWMP

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI



    -- End of Deckard's System Scanner: finished at 2008-04-15 22:02:34



    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.

    -- System Information

    Microsoft® Windows Vista™ Home Premium (build 6000)
    Architecture: X86; Language: English

    CPU 0: Genuine Intel(R) CPU T2250 @ 1.73GHz
    Percentage of Memory in Use: 52%
    Physical Memory (total/avail): 1013.44 MiB / 476.84 MiB
    Pagefile Memory (total/avail): 3526.46 MiB / 2646.36 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1962.21 MiB

    C: is Fixed (NTFS) - 149.05 GiB total, 113.49 GiB free.
    D: is CDROM (No Media)

    \\.\PHYSICALDRIVE0 - Hitachi HTS541616J9SA00 ATA Device - 149.05 GiB - 1 partition
    \PARTITION0 (bootable) - Installable File System - 149.05 GiB - C:



    -- Security Center

    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is enabled.

    AV: AVG 7.5.524 v7.5.524 (Grisoft)
    AS: Windows Defender v1.1.1505.0 (Microsoft Corporation)

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


    -- Environment Variables

    ALLUSERSPROFILE=C:\ProgramData
    APPDATA=C:\Users\Ashely\AppData\Roaming
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=ASHELY-PC
    ComSpec=C:\Windows\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Users\Ashely
    LANG=C
    LOCALAPPDATA=C:\Users\Ashely\AppData\Local
    LOGONSERVER=\\ASHELY-PC
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Program Files\Common Files\GTK\2.0\bin
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 14 Stepping 8, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0e08
    ProgramData=C:\ProgramData
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    PUBLIC=C:\Users\Public
    SystemDrive=C:
    SystemRoot=C:\Windows
    TEMP=C:\Users\Ashely\AppData\Local\Temp
    TMP=C:\Users\Ashely\AppData\Local\Temp
    USERDOMAIN=Ashely-PC
    USERNAME=Ashely
    USERPROFILE=C:\Users\Ashely
    windir=C:\Windows


    -- User Profiles

    Ashely


    -- Add/Remove Programs

    a-squared Free 3.0 --> "C:\Program Files\a-squared Free\unins000.exe"
    Adobe Flash Player 9 ActiveX --> C:\Windows\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock
    Adobe Flash Player Plugin --> C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8.1.1 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
    AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
    Bluetooth Stack for Windows by Toshiba --> MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
    CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
    DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    GTK+ 2.10.13 runtime environment --> "C:\Program Files\Common Files\GTK\2.0\setup\unins000.exe"
    HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    HP Photosmart Essential --> MsiExec.exe /X{6994491D-D491-48F1-AE1F-E179C1FFFC2F}
    Intel(R) Graphics Media Accelerator Driver --> C:\Windows\system32\igxpun.exe -uninstall
    Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
    Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
    Microsoft Office Excel Viewer 2003 --> MsiExec.exe /I{90840409-6000-11D3-8CFE-0150048383C9}
    Microsoft Office PowerPoint Viewer 2007 (English) --> MsiExec.exe /X{95120000-00AF-0409-0000-0000000FF1CE}
    Microsoft Office Word Viewer 2003 --> MsiExec.exe /I{90850409-6000-11D3-8CFE-0150048383C9}
    Mozilla Firefox (2.0.0.13) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    Texas Instruments PCIxx21/x515/xx12 drivers. --> C:\Program Files\InstallShield Installation Information\{F7B05784-334C-4F76-8BAB-30ABEB7FD534}\setup.exe -runfromtemp -l0x0409
    The GIMP 2.2.17 --> "C:\Program Files\GIMP-2.0\unins000.exe"
    TOSHIBA Hardware Setup --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B77A308F-85F5-4D68-8CB5-313332CB2779}\setup.exe" -l0x9
    Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
    Windows Live OneCare safety scanner --> "C:\Program Files\Windows Live Safety Center\UnInstall.exe"
    Windows Live OneCare safety scanner --> MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
    Windows Live Sign-in Assistant --> MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
    Windows Media Player Firefox Plugin --> MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}


    -- Application Event Log

    Event Record #/Type13744 / Success
    Event Submitted/Written: 04/15/2008 02:55:17 PM
    Event ID/Source: 902 / Software Licensing Service
    Event Description:
    The Software Licensing service has started.

    Event Record #/Type13739 / Success
    Event Submitted/Written: 04/15/2008 02:55:15 PM
    Event ID/Source: 5617 / WinMgmt
    Event Description:


    Event Record #/Type13737 / Success
    Event Submitted/Written: 04/15/2008 02:55:12 PM
    Event ID/Source: 5615 / WinMgmt
    Event Description:


    Event Record #/Type13730 / Warning
    Event Submitted/Written: 04/15/2008 02:53:55 PM
    Event ID/Source: 1530 / profsvc
    Event Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    DETAIL -
    1 user registry handles leaked from \Registry\User\S-1-5-21-3152885117-3170835535-3604547623-1000_Classes:
    Process 864 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3152885117-3170835535-3604547623-1000_CLASSES

    Event Record #/Type13729 / Warning
    Event Submitted/Written: 04/15/2008 02:53:54 PM
    Event ID/Source: 1530 / profsvc
    Event Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    DETAIL -
    1 user registry handles leaked from \Registry\User\S-1-5-21-3152885117-3170835535-3604547623-1000:
    Process 864 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3152885117-3170835535-3604547623-1000



    -- Security Event Log

    No Errors/Warnings found.


    -- System Event Log

    Event Record #/Type55628 / Warning
    Event Submitted/Written: 04/15/2008 03:50:21 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 0019D21E5F94. The following error occurred:
    %%1223. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

    Event Record #/Type55611 / Warning
    Event Submitted/Written: 04/15/2008 03:49:52 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 0019D21E5F94. The following error occurred:
    %%1223. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

    Event Record #/Type55556 / Error
    Event Submitted/Written: 04/15/2008 02:55:16 PM
    Event ID/Source: 7000 / Service Control Manager
    Event Description:
    Parallel port driver%%1058

    Event Record #/Type55512 / Warning
    Event Submitted/Written: 04/15/2008 02:54:12 PM
    Event ID/Source: 4001 / Microsoft-Windows-WLAN-AutoConfig
    Event Description:


    Event Record #/Type55497 / Error
    Event Submitted/Written: 04/15/2008 02:41:54 PM
    Event ID/Source: 31004 / ipnathlp
    Event Description:
    The DNS proxy agent was unable to allocate 0 bytes of memory. This may indicate that the system is low on virtual memory, or that the memory manager has encountered an internal error.



    -- End of Deckard's System Scanner: finished at 2008-04-15 22:02:34
  • edited April 2008
    Not seeing active infection in that so far. I am a bit concerned about the error logs showing a registry key leak - indicates a vulnerability for malware to use (if it isn't already).


    To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs.


    Download Malwarebytes' Anti-Malware from Here or Here.

    Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    * Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.
  • edited April 2008
    Malwarebytes' Anti-Malware 1.11
    Database version: 635

    Scan type: Quick Scan
    Objects scanned: 28147
    Time elapsed: 4 minute(s), 43 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
  • edited April 2008
    Nothing in that. Is this popup occurring just when you are on web pages? If so, what web pages?
  • edited April 2008
    Well, I have had them before. It's been different sites that the Popup as been on. When it pops up, it is a little box in the corner of my screen that says something similar to your computer is infected click here to run this scan. I was having no signs of trouble before the popup showed up, nor really when I closed it and scanned.
  • edited April 2008
    Forgot to mention. When the little box pops up, the page I was on I cannot open, it's like the page is locked onto that box. On the box if I hit "OK" or "Cancel" it takes me to their site no matter if I cancel or not.
  • edited April 2008
    Really sounds like the wrong websites to go to, and not your system having infection on it. You can post a request at the Icrontic Networking and Security forum for suggestion for things like popup blocking software, but usually your browser's built-in options are enough if you don't go to questionable websites. if you suspect any you can put them in the search here (upper right corner) and see if they have some known history.
  • edited April 2008
    I was on eBay & Photobucket. Thank you for your help. I appreciate it.
  • edited April 2008
    If you get one of those popups now or in a day or so copy the link address you are at, and PM that to me please. I suggest PM so no active hyperlinks are here in the forum threads.
  • edited April 2008
    I will. Thanks so much :)
  • edited April 2008
    :thumbup
  • edited April 2008
    I received your PM, and no, you are not usually supposed to get rogue software popups like AntiSpywareDeluxe while on eBay. May indicate an infection on your system creating the popups itself. Let's check.


    Go here and run the Kaspersky online scan, and post back the log it creates (it requires IE).

    To use the scan, accept the agreement and make sure you allow the ActiveX object to download and install (check the "yellow bar" at the top of IE if needed to allow this). Once the download has completed click Next, then Scan Settings, then make sure the "extended option" is checked (leave all others as they are) and click OK. Then click "My Computer" to begin the scan. Save the Report as a text file and post that back here.

    To save it as a text file, still with the page in Internet Explorer, go to the top of the page and select File - Save As... Then make sure in the "Save as type" drop down you change it to "Text File(*.txt)".

    Post that log back here please.
  • edited April 2008
    Thank you for your response, I apologize for the delay.





    Scan settings:
    Here you can configure the scanning process.

    Scan using the following antivirus database:
    standard - detect viruses, worms, Trojans,
    rootkits
    extended - protect your computer from Spyware,
    adware, dialers and potentially dangerous
    software such as remote access utilities, prank
    programs and jokes. We do not recommend this
    option to beginners or inexperienced users.

    Scan options:
    Scan Archives - scan files inside archives
    Note: affects all targets except 'A
    File...' scan target.
    Scan Mail Bases - scan e-mails/attachments
    inside mail base files
    Note: affects all targets except 'My
    Email' and 'A File...' scan targets.







    Initialize Kaspersky Online Scanner
    (downloading and installing Kaspersky Online
    Scanner ActiveX from the server into your
    computer)





    Update Kaspersky Anti-Virus Databases [100%]:
    (downloading and installing the latest Kaspersky
    Anti-Virus Databases)





    Please wait to update the virus definitions...
    Downloading from url:
    ftp://downloads4.kaspersky-labs.com
    Downloading remote file: master.xml
    Downloading remote file: kavset.xml
    Downloading remote file: soft.xml
    Downloading remote file: updcfg.xml
    Downloading remote file: kernel.avc
    Downloading remote file: krnun001.avc
    Downloading remote file: krnun002.avc
    Downloading remote file: krnun003.avc
    Downloading remote file: krnun004.avc
    Downloading remote file: krnexe.avc
    Downloading remote file: krnmacro.avc
    Downloading remote file: krnjava.avc
    Downloading remote file: krndos.avc
    Downloading remote file: krngen.avc
    Downloading remote file: krnexe32.avc
    Downloading remote file: krnengn.avc
    Downloading remote file: krn001.avc
    Downloading remote file: krn002.avc
    Downloading remote file: krn003.avc
    Downloading remote file: krn004.avc
    Downloading remote file: krn005.avc
    Downloading remote file: smart.avc
    Downloading remote file: ocr.avc
    Downloading remote file: chuka.avc
    Downloading remote file: fa001.avc
    Downloading remote file: base001c.avc
    Downloading remote file: base002c.avc
    Downloading remote file: base003c.avc
    Downloading remote file: base004c.avc
    Downloading remote file: base005c.avc
    Downloading remote file: base006c.avc
    Downloading remote file: base007c.avc
    Downloading remote file: base008c.avc
    Downloading remote file: base009c.avc
    Downloading remote file: base010c.avc
    Downloading remote file: base011c.avc
    Downloading remote file: base012c.avc
    Downloading remote file: base013c.avc
    Downloading remote file: base014c.avc
    Downloading remote file: base015c.avc
    Downloading remote file: base016c.avc
    Downloading remote file: base017c.avc
    Downloading remote file: base018c.avc
    Downloading remote file: base019c.avc
    Downloading remote file: base020c.avc
    Downloading remote file: base021c.avc
    Downloading remote file: base022c.avc
    Downloading remote file: base023c.avc
    Downloading remote file: base024c.avc
    Downloading remote file: base025c.avc
    Downloading remote file: base026c.avc
    Downloading remote file: base027c.avc
    Downloading remote file: base028c.avc
    Downloading remote file: base029c.avc
    Downloading remote file: base030c.avc
    Downloading remote file: base031c.avc
    Downloading remote file: base032c.avc
    Downloading remote file: base033c.avc
    Downloading remote file: base034c.avc
    Downloading remote file: base035c.avc
    Downloading remote file: base036c.avc
    Downloading remote file: base037c.avc
    Downloading remote file: base038c.avc
    Downloading remote file: base039c.avc
    Downloading remote file: base040c.avc
    Downloading remote file: base041c.avc
    Downloading remote file: base042c.avc
    Downloading remote file: base043c.avc
    Downloading remote file: base044c.avc
    Downloading remote file: base045c.avc
    Downloading remote file: base046c.avc
    Downloading remote file: base047c.avc
    Downloading remote file: base048c.avc
    Downloading remote file: base049c.avc
    Downloading remote file: base050c.avc
    Downloading remote file: base051c.avc
    Downloading remote file: base052c.avc
    Downloading remote file: base053c.avc
    Downloading remote file: base054c.avc
    Downloading remote file: base055c.avc
    Downloading remote file: base056c.avc
    Downloading remote file: base057c.avc
    Downloading remote file: base058c.avc
    Downloading remote file: base059c.avc
    Downloading remote file: base060c.avc
    Downloading remote file: base061c.avc
    Downloading remote file: base062c.avc
    Downloading remote file: base063c.avc
    Downloading remote file: base064c.avc
    Downloading remote file: base065c.avc
    Downloading remote file: base066c.avc
    Downloading remote file: base067c.avc
    Downloading remote file: base068c.avc
    Downloading remote file: base069c.avc
    Downloading remote file: base070c.avc
    Downloading remote file: base071c.avc
    Downloading remote file: base072c.avc
    Downloading remote file: base073c.avc
    Downloading remote file: base074c.avc
    Downloading remote file: base075c.avc
    Downloading remote file: base076c.avc
    Downloading remote file: base077c.avc
    Downloading remote file: base078c.avc
    Downloading remote file: base079c.avc
    Downloading remote file: base080c.avc
    Downloading remote file: base081c.avc
    Downloading remote file: base082c.avc
    Downloading remote file: base083c.avc
    Downloading remote file: base084c.avc
    Downloading remote file: base085c.avc
    Downloading remote file: base086c.avc
    Downloading remote file: base087c.avc
    Downloading remote file: base088c.avc
    Downloading remote file: base089c.avc
    Downloading remote file: base090c.avc
    Downloading remote file: base091c.avc
    Downloading remote file: base092c.avc
    Downloading remote file: base093c.avc
    Downloading remote file: base094c.avc
    Downloading remote file: base095c.avc
    Downloading remote file: base096c.avc
    Downloading remote file: base097c.avc
    Downloading remote file: base098c.avc
    Downloading remote file: base099c.avc
    Downloading remote file: base100c.avc
    Downloading remote file: base101c.avc
    Downloading remote file: base102c.avc
    Downloading remote file: base103c.avc
    Downloading remote file: base104c.avc
    Downloading remote file: base105c.avc
    Downloading remote file: base106c.avc
    Downloading remote file: base107c.avc
    Downloading remote file: base108c.avc
    Downloading remote file: base109c.avc
    Downloading remote file: base110c.avc
    Downloading remote file: base111c.avc
    Downloading remote file: base112c.avc
    Downloading remote file: base113c.avc
    Downloading remote file: base114c.avc
    Downloading remote file: base115c.avc
    Downloading remote file: base116c.avc
    Downloading remote file: base117c.avc
    Downloading remote file: base118c.avc
    Downloading remote file: base119c.avc
    Downloading remote file: base120c.avc
    Downloading remote file: base121c.avc
    Downloading remote file: base122c.avc
    Downloading remote file: base123c.avc
    Downloading remote file: base124c.avc
    Downloading remote file: base125c.avc
    Downloading remote file: base126c.avc
    Downloading remote file: base127c.avc
    Downloading remote file: base128c.avc
    Downloading remote file: base129c.avc
    Downloading remote file: base130c.avc
    Downloading remote file: base131c.avc
    Downloading remote file: base132c.avc
    Downloading remote file: base133c.avc
    Downloading remote file: base134c.avc
    Downloading remote file: base135c.avc
    Downloading remote file: base136c.avc
    Downloading remote file: base137c.avc
    Downloading remote file: base138c.avc
    Downloading remote file: base139c.avc
    Downloading remote file: base140c.avc
    Downloading remote file: base141c.avc
    Downloading remote file: base142c.avc
    Downloading remote file: base143c.avc
    Downloading remote file: base144c.avc
    Downloading remote file: base145c.avc
    Downloading remote file: base146c.avc
    Downloading remote file: base147c.avc
    Downloading remote file: base148c.avc
    Downloading remote file: base149c.avc
    Downloading remote file: base150c.avc
    Downloading remote file: base151c.avc
    Downloading remote file: base152c.avc
    Downloading remote file: base153c.avc
    Downloading remote file: base154c.avc
    Downloading remote file: base155c.avc
    Downloading remote file: base156c.avc
    Downloading remote file: base157c.avc
    Downloading remote file: base158c.avc
    Downloading remote file: base159c.avc
    Downloading remote file: base160c.avc
    Downloading remote file: base161c.avc
    Downloading remote file: base162c.avc
    Downloading remote file: base163c.avc
    Downloading remote file: base164c.avc
    Downloading remote file: base165c.avc
    Downloading remote file: dailyc.avc
    Downloading remote file: ext001c.avc
    Downloading remote file: ext002c.avc
    Downloading remote file: ext003c.avc
    Downloading remote file: ext004c.avc
    Downloading remote file: ext005c.avc
    Downloading remote file: ext006c.avc
    Downloading remote file: ext007c.avc
    Downloading remote file: ext008c.avc
    Downloading remote file: ext009c.avc
    Downloading remote file: ext010c.avc
    Downloading remote file: ext011c.avc
    Downloading remote file: ext012c.avc
    Downloading remote file: ext013c.avc
    Downloading remote file: ext014c.avc
    Downloading remote file: ext015c.avc
    Downloading remote file: ext016c.avc
    Downloading remote file: ext017c.avc
    Downloading remote file: ext018c.avc
    Downloading remote file: ext019c.avc
    Downloading remote file: ext020c.avc
    Downloading remote file: ext021c.avc
    Downloading remote file: ext022c.avc
    Downloading remote file: ext023c.avc
    Downloading remote file: ext024c.avc
    Downloading remote file: ext025c.avc
    Downloading remote file: ext026c.avc
    Downloading remote file: ext027c.avc
    Downloading remote file: ext028c.avc
    Downloading remote file: ext029c.avc
    Downloading remote file: ext030c.avc
    Downloading remote file: daily-ec.avc
    Downloading remote file: base001.avc
    Downloading remote file: base002.avc
    Downloading remote file: base003.avc
    Downloading remote file: base004.avc
    Downloading remote file: base005.avc
    Downloading remote file: base006.avc
    Downloading remote file: base007.avc
    Downloading remote file: base008.avc
    Downloading remote file: base009.avc
    Downloading remote file: base010.avc
    Downloading remote file: base011.avc
    Downloading remote file: base012.avc
    Downloading remote file: base013.avc
    Downloading remote file: base014.avc
    Downloading remote file: base015.avc
    Downloading remote file: base016.avc
    Downloading remote file: base017.avc
    Downloading remote file: base018.avc
    Downloading remote file: base019.avc
    Downloading remote file: base020.avc
    Downloading remote file: base021.avc
    Downloading remote file: base022.avc
    Downloading remote file: base023.avc
    Downloading remote file: base024.avc
    Downloading remote file: base025.avc
    Downloading remote file: base026.avc
    Downloading remote file: base027.avc
    Downloading remote file: base028.avc
    Downloading remote file: base029.avc
    Downloading remote file: base030.avc
    Downloading remote file: base031.avc
    Downloading remote file: base032.avc
    Downloading remote file: base033.avc
    Downloading remote file: base034.avc
    Downloading remote file: base035.avc
    Downloading remote file: base036.avc
    Downloading remote file: base037.avc
    Downloading remote file: base038.avc
    Downloading remote file: base039.avc
    Downloading remote file: base040.avc
    Downloading remote file: base041.avc
    Downloading remote file: base042.avc
    Downloading remote file: base043.avc
    Downloading remote file: base044.avc
    Downloading remote file: base045.avc
    Downloading remote file: base046.avc
    Downloading remote file: base047.avc
    Downloading remote file: base048.avc
    Downloading remote file: base049.avc
    Downloading remote file: base050.avc
    Downloading remote file: base051.avc
    Downloading remote file: base052.avc
    Downloading remote file: base053.avc
    Downloading remote file: base054.avc
    Downloading remote file: base055.avc
    Downloading remote file: base056.avc
    Downloading remote file: base057.avc
    Downloading remote file: base058.avc
    Downloading remote file: base059.avc
    Downloading remote file: base060.avc
    Downloading remote file: base061.avc
    Downloading remote file: base062.avc
    Downloading remote file: base063.avc
    Downloading remote file: base064.avc
    Downloading remote file: base065.avc
    Downloading remote file: base066.avc
    Downloading remote file: base067.avc
    Downloading remote file: base068.avc
    Downloading remote file: base069.avc
    Downloading remote file: base070.avc
    Downloading remote file: base071.avc
    Downloading remote file: base072.avc
    Downloading remote file: base073.avc
    Downloading remote file: base074.avc
    Downloading remote file: base075.avc
    Downloading remote file: base076.avc
    Downloading remote file: base077.avc
    Downloading remote file: base078.avc
    Downloading remote file: base079.avc
    Downloading remote file: base080.avc
    Downloading remote file: base081.avc
    Downloading remote file: base082.avc
    Downloading remote file: base083.avc
    Downloading remote file: base084.avc
    Downloading remote file: base085.avc
    Downloading remote file: base086.avc
    Downloading remote file: base087.avc
    Downloading remote file: base088.avc
    Downloading remote file: base089.avc
    Downloading remote file: base090.avc
    Downloading remote file: base091.avc
    Downloading remote file: base092.avc
    Downloading remote file: base093.avc
    Downloading remote file: base094.avc
    Downloading remote file: base095.avc
    Downloading remote file: base096.avc
    Downloading remote file: base097.avc
    Downloading remote file: base098.avc
    Downloading remote file: base099.avc
    Downloading remote file: base100.avc
    Downloading remote file: base101.avc
    Downloading remote file: base102.avc
    Downloading remote file: base103.avc
    Downloading remote file: base104.avc
    Downloading remote file: base105.avc
    Downloading remote file: base106.avc
    Downloading remote file: base107.avc
    Downloading remote file: base108.avc
    Downloading remote file: base109.avc
    Downloading remote file: base110.avc
    Downloading remote file: base111.avc
    Downloading remote file: base112.avc
    Downloading remote file: base113.avc
    Downloading remote file: base114.avc
    Downloading remote file: base115.avc
    Downloading remote file: base116.avc
    Downloading remote file: base117.avc
    Downloading remote file: base118.avc
    Downloading remote file: base119.avc
    Downloading remote file: base120.avc
    Downloading remote file: base121.avc
    Downloading remote file: base122.avc
    Downloading remote file: base123.avc
    Downloading remote file: base124.avc
    Downloading remote file: base125.avc
    Downloading remote file: base126.avc
    Downloading remote file: base127.avc
    Downloading remote file: base128.avc
    Downloading remote file: base129.avc
    Downloading remote file: base130.avc
    Downloading remote file: base131.avc
    Downloading remote file: base132.avc
    Downloading remote file: base133.avc
    Downloading remote file: base134.avc
    Downloading remote file: base135.avc
    Downloading remote file: base136.avc
    Downloading remote file: base137.avc
    Downloading remote file: base138.avc
    Downloading remote file: base139.avc
    Downloading remote file: base140.avc
    Downloading remote file: base141.avc
    Downloading remote file: base142.avc
    Downloading remote file: base143.avc
    Downloading remote file: base144.avc
    Downloading remote file: base145.avc
    Downloading remote file: base146.avc
    Downloading remote file: base147.avc
    Downloading remote file: base148.avc
    Downloading remote file: base149.avc
    Downloading remote file: base150.avc
    Downloading remote file: base151.avc
    Downloading remote file: base152.avc
    Downloading remote file: base153.avc
    Downloading remote file: base154.avc
    Downloading remote file: base155.avc
    Downloading remote file: base156.avc
    Downloading remote file: base157.avc
    Downloading remote file: base158.avc
    Downloading remote file: base159.avc
    Downloading remote file: base160.avc
    Downloading remote file: base161.avc
    Downloading remote file: base162.avc
    Downloading remote file: base163.avc
    Downloading remote file: base164.avc
    Downloading remote file: base999.avc
    Downloading remote file: unp000.avc
    Downloading remote file: unp001.avc
    Downloading remote file: unp002.avc
    Downloading remote file: unp003.avc
    Downloading remote file: unp004.avc
    Downloading remote file: unp005.avc
    Downloading remote file: unp006.avc
    Downloading remote file: unp007.avc
    Downloading remote file: unp008.avc
    Downloading remote file: unp009.avc
    Downloading remote file: unp010.avc
    Downloading remote file: unp011.avc
    Downloading remote file: unp012.avc
    Downloading remote file: unp013.avc
    Downloading remote file: unp014.avc
    Downloading remote file: unp015.avc
    Downloading remote file: unp016.avc
    Downloading remote file: unp017.avc
    Downloading remote file: unp018.avc
    Downloading remote file: unp019.avc
    Downloading remote file: unp020.avc
    Downloading remote file: unp021.avc
    Downloading remote file: unp022.avc
    Downloading remote file: unp023.avc
    Downloading remote file: unp024.avc
    Downloading remote file: unp025.avc
    Downloading remote file: unp026.avc
    Downloading remote file: unp027.avc
    Downloading remote file: unp028.avc
    Downloading remote file: unp029.avc
    Downloading remote file: unp030.avc
    Downloading remote file: unp031.avc
    Downloading remote file: unp032.avc
    Downloading remote file: unp033.avc
    Downloading remote file: unp034.avc
    Downloading remote file: unp035.avc
    Downloading remote file: unp036.avc
    Downloading remote file: unp037.avc
    Downloading remote file: unp038.avc
    Downloading remote file: unp039.avc
    Downloading remote file: daily.avc
    Downloading remote file: daily-ex.avc
    Downloading remote file: urgent.avc
    Downloading remote file: mail.avc
    Downloading remote file: ext001.avc
    Downloading remote file: ext002.avc
    Downloading remote file: ext003.avc
    Downloading remote file: ext004.avc
    Downloading remote file: ext005.avc
    Downloading remote file: ext006.avc
    Downloading remote file: ext007.avc
    Downloading remote file: ext008.avc
    Downloading remote file: ext009.avc
    Downloading remote file: ext999.avc
    Downloading remote file: gen001.avc
    Downloading remote file: gen002.avc
    Downloading remote file: gen003.avc
    Downloading remote file: gen004.avc
    Downloading remote file: gen005.avc
    Downloading remote file: gen999.avc
    Downloading remote file: ca.avc
    Downloading remote file: fa.avc
    Downloading remote file: eicar.avc
    Downloading remote file: verdicts.ini
    Downloading remote file: engine.dt
    Downloading remote file: engine.cfg
    Downloading remote file: avcmhk5.mhk
    Downloading remote file: black.lst
    Downloading remote file: avp.set
    Downloading remote file: avp_ext.set
    Downloading remote file: avp_x.set
    Downloading remote file: avp.vnd
    Downloading remote file: avp.klb
    Downloading remote file: soft.ver
    Update finished. Ready to scan.
    Next
    Please select a target to scan:
    You can configure the scanning process by
    pressing "Scan Settings" button.



    Critical Areas
    scan critical areas of your hard disks
    specified in %windir% and %tmp% system variables
    Memory
    scan disk modules of running processes
    My Computer
    scan all your hard and mapped disks
    My Email
    scan all your hard and mapped disks only for the
    following extensions: *.PST; *.MSG; *.OST;
    *.MDB; *.DBX; *.EML; *.MBS
    Folders...
    scan selected folders
    A File...
    scan a one file





    Warning: The Kaspersky Online Scanner may not
    run successfully while any other Anti-Virus
    software is running. If you have Anti-Virus
    software installed, please disable your AV
    protection before running the Kaspersky Online
    Scanner.
    Scan complete.
    No malware has been detected. The sections that
    have been scanned are CLEAN.



    Report is empty.
    Please note: The free Kaspersky Online Scanner
    does not provide comprehensive protection and
    cannot prevent future infections. It only
    detects malware that has already penetrated your
    storage devices. We strongly recommend that you
    use a fully-functional antivirus solution to
    protect your computer at all times.

    Please wait, this process may take a long time
    depending on the selected target. If you want to
    continue browsing, open a new window.

    Scan Progress [44%]:







    Total number of scanned objects:69181
    Number of viruses found:0
    Number of infected objects:0
    Number of suspicious objects:0
    Duration of the scan process:00:39:42
    New Scan








    Get a Free Trial


    Buy Kaspersky Anti-Virus


    Help


    Virus Encyclopedia


    Kaspersky Lab






    Product Info
    You have Kaspersky Online Scanner version 5.0.98.0
    installed. The current anti-virus database was
    released on Friday, April 25, 2008 and contains
    725398 records.

    System Info
    Operating System: Microsoft Windows Vista Home
    Edition, (Build 6000)Please wait while the
    Kaspersky Online Scanner is initializing and
    updating...








    Copyright (C) Kaspersky Lab 1997 - 2007
    Portions Copyright (C) Lan Crypto
  • edited April 2008
    That isn't quite the Kaspersky log I was looking for, but since it also indicates no items found no need to redo it. Go ahead now and the next time you are at a website copy the address from the address bar (top of your browser) and post that back here please. Let's see if I can see what you see (see?) :wink:
  • VekaVeka Finland
    edited May 2008
    This topic is now closed due to inactivity. If you wish to reopen your topic, please send a Private Message (PM) to Trogan with a link to your thread.

    If it has been 10 days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, this topic will not be reopened. If you still require help, please start a new topic and include a fresh HijackThis log and a link to this thread in your new topic.

    If you are not the user who started this thread, you must start your own Thread instead :)
Sign In or Register to comment.