Options

computer acting up

lots of random internet explorer and firefox windows opening, have ran avast, spyware doctor, and malwarebyte's anti malware, but here is the the HJT log and uninstall list


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:32:02, on 19/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Iomega\REV System Software\RevUDF.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Iomega\REV System Software\imiconxp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\O2\O2 Broadband USB Modem\O2 Broadband.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Caroline
O17 - HKLM\Software\..\Telephony: DomainName = Caroline
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC9AE88A-CB54-4062-A1F6-DFCCD8416C70}: NameServer = 62.40.32.33 62.40.32.34
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Caroline
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Caroline
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe
--
End of file - 7298 bytes



Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Reader 8.1.3
avast! Antivirus
Compatibility Pack for the 2007 Office system
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915800)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
HP Customer Participation Program 7.0
HP Image Zone 4.2
HP Imaging Device Functions 7.0
HP Officejet All-In-One Series
HP Photosmart Essential
HP PSC & OfficeJet 4.2
HP Software Update
HP Solution Center 7.0
HP Unload DLL Patch
Iomega REV System Software
Java(TM) 6 Update 12
Java(TM) 6 Update 7
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Basic Edition 2003
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft User-Mode Driver Framework Feature Pack 1.5
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
Nero Suite
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia PC Suite
NVIDIA Drivers
O2 Broadband USB Modem
OCR Software by I.R.I.S 7.0
OpenOffice.org Installer 1.0
PC Connectivity Solution
PC Tune-Up
Realtek High Definition Audio Driver
Retrospect 7.5
Sage Instant Accounts v14
Sage MIS 3.01
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960715)
SelfService - Management System
Spybot - Search & Destroy
Thesaurus 2007 Payroll
Thesaurus 2008 Payroll
Thesaurus 2009 Payroll
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955839)
WIDCOMM Bluetooth Software
Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
Windows Driver Package - Nokia Modem (02/15/2007 3.1)
Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781




regards
tom:confused:

Comments

  • TroganTrogan London, UK
    edited February 2009
    Hi,

    Can you post the log from Malwarebytes please. You can find in at the following location:

    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

    Or

    Open Malwarebytes > click Logs > open the latest log > copy and paste it here.
  • edited February 2009
    hello, here is the first log, which showed up infected items, and i will put up the latest log. the internet explorer window / or firefox window might open 10 - 15 windows one after the other. It often happens using MS outlook. Are some other network popups that keep appearing, but none as bad as the first problem



    Malwarebytes' Anti-Malware 1.33
    Database version: 1742
    Windows 5.1.2600 Service Pack 2
    10/02/2009 11:05:39
    mbam-log-2009-02-10 (11-05-39).txt
    Scan type: Full Scan (C:\|)
    Objects scanned: 117081
    Time elapsed: 28 minute(s), 47 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 27
    Registry Values Infected: 0
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 1
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe csrcs.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    C:\Program Files\PC Tune-Up\RdvChk.exe (Spyware.OnlineGames) -> Quarantined and deleted successfully.






    Malwarebytes' Anti-Malware 1.34
    Database version: 1795
    Windows 5.1.2600 Service Pack 2
    23/02/2008 09:33:36
    mbam-log-2008-02-23 (09-33-36).txt
    Scan type: Full Scan (C:\|E:\|)
    Objects scanned: 135470
    Time elapsed: 31 minute(s), 39 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)



    Thanks again for your time
    tom
  • TroganTrogan London, UK
    edited February 2009
    Hi,

    Please do the following...

    1. Click Start > Run > type in appwiz.cpl and hit enter. From the list uninstall the following, if present:

    Java(TM) 6 Update 7

    2. Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.

    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save Report As button:
        • Change Save as type: to Text file
        • Save this as Kaspersky scan to your Desktop
        [*]Post the Kaspersky report in your next reply.


        Post the Kaspersky report back here.
      • edited March 2009
        Here is te results of the scan
        came up clean


        KASPERSKY ONLINE SCANNER 7 REPORT
        Tuesday, March 3, 2009
        Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
        Kaspersky Online Scanner 7 version: 7.0.25.0
        Program database last update: Tuesday, March 03, 2009 10:23:22
        Records in database: 1864804

        Scan settings:
        Scan using the following database: extended
        Scan archives: yes
        Scan mail databases: yes

        Scan area - My Computer:
        A:\
        C:\
        D:\
        E:\
        F:\

        Scan statistics:
        Files scanned: 58725
        Threat name: 0
        Infected objects: 0
        Suspicious objects: 0
        Duration of the scan: 01:12:46

        No malware has been detected. The scan area is clean.

        The selected area was scanned.


        the trouble started when we put another computer into the office at work and used an ethernet switch HUB to connect the 2 computers. We also share the internet using Huswei model E220. also getting popups saying you have requested information from huawei3G.02 ie under the heading network connections. Computer not that old, just seems to act up for a while every day.
        again thanks for your help
        regards
        tom
      • TroganTrogan London, UK
        edited March 2009
        Can you update Malwarebytes and run a new scan please. Post the new log back here.
      • edited March 2009
        Malwarebytes' Anti-Malware 1.34
        Database version: 1815
        Windows 5.1.2600 Service Pack 2

        04/03/2009 13:52:59
        mbam-log-2009-03-04 (13-52-59).txt

        Scan type: Full Scan (C:\|)
        Objects scanned: 136297
        Time elapsed: 31 minute(s), 49 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        (No malicious items detected)


        This is the lastest log. Showing nothing up, but see what you think.
        Again thanks for your help
        regards
        Tom
      • TroganTrogan London, UK
        edited March 2009
        Can you post a new HijackThis log please.
      • edited March 2009
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 08:46:28, on 06/03/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Iomega\REV System Software\RevUDF.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Iomega\REV System Software\imiconxp.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\WINDOWS\system32\rundll32.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\O2\O2 Broadband USB Modem\O2 Broadband.exe
        C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
        C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe
        O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Caroline
        O17 - HKLM\Software\..\Telephony: DomainName = Caroline
        O17 - HKLM\System\CCS\Services\Tcpip\..\{FC9AE88A-CB54-4062-A1F6-DFCCD8416C70}: NameServer = 62.40.32.33 62.40.32.34
        O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Caroline
        O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Caroline
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe

        --
        End of file - 7519 bytes

        Here is the hijackthis log file

        regards
        tom
      • edited March 2009
        Adobe Flash Player 10 Plugin
        Adobe Flash Player ActiveX
        Adobe Reader 8.1.3
        avast! Antivirus
        Compatibility Pack for the 2007 Office system
        High Definition Audio Driver Package - KB888111
        HijackThis 2.0.2
        Hotfix for Windows Internet Explorer 7 (KB947864)
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix for Windows Media Player 11 (KB939683)
        Hotfix for Windows XP (KB914440)
        Hotfix for Windows XP (KB915800)
        Hotfix for Windows XP (KB915865)
        Hotfix for Windows XP (KB926239)
        Hotfix for Windows XP (KB935448)
        Hotfix for Windows XP (KB952287)
        HP Customer Participation Program 7.0
        HP Image Zone 4.2
        HP Imaging Device Functions 7.0
        HP Officejet All-In-One Series
        HP Photosmart Essential
        HP PSC & OfficeJet 4.2
        HP Software Update
        HP Solution Center 7.0
        HP Unload DLL Patch
        Iomega REV System Software
        Java(TM) 6 Update 12
        Malwarebytes' Anti-Malware
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft .NET Framework 2.0
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft Internationalized Domain Names Mitigation APIs
        Microsoft National Language Support Downlevel APIs
        Microsoft Office Basic Edition 2003
        Microsoft Office PowerPoint Viewer 2007 (English)
        Microsoft User-Mode Driver Framework Feature Pack 1.5
        Microsoft Visual C++ 2005 Redistributable
        Mozilla Firefox (3.0.7)
        MSXML 4.0 SP2 (KB954430)
        Nero Suite
        Nokia Connectivity Cable Driver
        Nokia PC Suite
        Nokia PC Suite
        NVIDIA Drivers
        O2 Broadband USB Modem
        OCR Software by I.R.I.S 7.0
        OpenOffice.org Installer 1.0
        PC Connectivity Solution
        PC Tune-Up
        PW14 Drivers v.1.0
        Realtek High Definition Audio Driver
        Retrospect 7.5
        Sage Instant Accounts v14
        Sage MIS 3.01
        Security Update for CAPICOM (KB931906)
        Security Update for CAPICOM (KB931906)
        Security Update for Windows Internet Explorer 7 (KB938127)
        Security Update for Windows Internet Explorer 7 (KB939653)
        Security Update for Windows Internet Explorer 7 (KB942615)
        Security Update for Windows Internet Explorer 7 (KB944533)
        Security Update for Windows Internet Explorer 7 (KB950759)
        Security Update for Windows Internet Explorer 7 (KB953838)
        Security Update for Windows Internet Explorer 7 (KB956390)
        Security Update for Windows Internet Explorer 7 (KB958215)
        Security Update for Windows Internet Explorer 7 (KB960714)
        Security Update for Windows Internet Explorer 7 (KB961260)
        Security Update for Windows Media Player (KB911564)
        Security Update for Windows Media Player (KB952069)
        Security Update for Windows Media Player 11 (KB936782)
        Security Update for Windows Media Player 11 (KB954154)
        Security Update for Windows Media Player 6.4 (KB925398)
        Security Update for Windows Media Player 9 (KB917734)
        Security Update for Windows Media Player 9 (KB936782)
        Security Update for Windows XP (KB893756)
        Security Update for Windows XP (KB896358)
        Security Update for Windows XP (KB896423)
        Security Update for Windows XP (KB896424)
        Security Update for Windows XP (KB896428)
        Security Update for Windows XP (KB899587)
        Security Update for Windows XP (KB899591)
        Security Update for Windows XP (KB900725)
        Security Update for Windows XP (KB901017)
        Security Update for Windows XP (KB901214)
        Security Update for Windows XP (KB902400)
        Security Update for Windows XP (KB904706)
        Security Update for Windows XP (KB905414)
        Security Update for Windows XP (KB905749)
        Security Update for Windows XP (KB908519)
        Security Update for Windows XP (KB911562)
        Security Update for Windows XP (KB911927)
        Security Update for Windows XP (KB912919)
        Security Update for Windows XP (KB913580)
        Security Update for Windows XP (KB914388)
        Security Update for Windows XP (KB914389)
        Security Update for Windows XP (KB917344)
        Security Update for Windows XP (KB917422)
        Security Update for Windows XP (KB917953)
        Security Update for Windows XP (KB918118)
        Security Update for Windows XP (KB918439)
        Security Update for Windows XP (KB919007)
        Security Update for Windows XP (KB920213)
        Security Update for Windows XP (KB920670)
        Security Update for Windows XP (KB920683)
        Security Update for Windows XP (KB920685)
        Security Update for Windows XP (KB921398)
        Security Update for Windows XP (KB921503)
        Security Update for Windows XP (KB922616)
        Security Update for Windows XP (KB922819)
        Security Update for Windows XP (KB923191)
        Security Update for Windows XP (KB923414)
        Security Update for Windows XP (KB923689)
        Security Update for Windows XP (KB923694)
        Security Update for Windows XP (KB923789)
        Security Update for Windows XP (KB923980)
        Security Update for Windows XP (KB924191)
        Security Update for Windows XP (KB924270)
        Security Update for Windows XP (KB924496)
        Security Update for Windows XP (KB924667)
        Security Update for Windows XP (KB925454)
        Security Update for Windows XP (KB925902)
        Security Update for Windows XP (KB926255)
        Security Update for Windows XP (KB926436)
        Security Update for Windows XP (KB927779)
        Security Update for Windows XP (KB927802)
        Security Update for Windows XP (KB928090)
        Security Update for Windows XP (KB928255)
        Security Update for Windows XP (KB928843)
        Security Update for Windows XP (KB929123)
        Security Update for Windows XP (KB929969)
        Security Update for Windows XP (KB930178)
        Security Update for Windows XP (KB931261)
        Security Update for Windows XP (KB931768)
        Security Update for Windows XP (KB931784)
        Security Update for Windows XP (KB932168)
        Security Update for Windows XP (KB933566)
        Security Update for Windows XP (KB933729)
        Security Update for Windows XP (KB935839)
        Security Update for Windows XP (KB935840)
        Security Update for Windows XP (KB936021)
        Security Update for Windows XP (KB937143)
        Security Update for Windows XP (KB937894)
        Security Update for Windows XP (KB938127)
        Security Update for Windows XP (KB938464)
        Security Update for Windows XP (KB938829)
        Security Update for Windows XP (KB939653)
        Security Update for Windows XP (KB941202)
        Security Update for Windows XP (KB941568)
        Security Update for Windows XP (KB941569)
        Security Update for Windows XP (KB941644)
        Security Update for Windows XP (KB941693)
        Security Update for Windows XP (KB943055)
        Security Update for Windows XP (KB943460)
        Security Update for Windows XP (KB943485)
        Security Update for Windows XP (KB944653)
        Security Update for Windows XP (KB945553)
        Security Update for Windows XP (KB946026)
        Security Update for Windows XP (KB946648)
        Security Update for Windows XP (KB948590)
        Security Update for Windows XP (KB948881)
        Security Update for Windows XP (KB950749)
        Security Update for Windows XP (KB950760)
        Security Update for Windows XP (KB950762)
        Security Update for Windows XP (KB950974)
        Security Update for Windows XP (KB951066)
        Security Update for Windows XP (KB951376)
        Security Update for Windows XP (KB951376-v2)
        Security Update for Windows XP (KB951698)
        Security Update for Windows XP (KB951748)
        Security Update for Windows XP (KB952954)
        Security Update for Windows XP (KB953839)
        Security Update for Windows XP (KB954211)
        Security Update for Windows XP (KB954600)
        Security Update for Windows XP (KB955069)
        Security Update for Windows XP (KB956391)
        Security Update for Windows XP (KB956802)
        Security Update for Windows XP (KB956803)
        Security Update for Windows XP (KB956841)
        Security Update for Windows XP (KB957095)
        Security Update for Windows XP (KB957097)
        Security Update for Windows XP (KB958644)
        Security Update for Windows XP (KB958687)
        Security Update for Windows XP (KB960715)
        SelfService - Management System
        Spybot - Search & Destroy
        Thesaurus 2007 Payroll
        Thesaurus 2008 Payroll
        Thesaurus 2009 Payroll
        Update for Windows XP (KB894391)
        Update for Windows XP (KB898461)
        Update for Windows XP (KB900485)
        Update for Windows XP (KB904942)
        Update for Windows XP (KB908531)
        Update for Windows XP (KB910437)
        Update for Windows XP (KB911280)
        Update for Windows XP (KB916595)
        Update for Windows XP (KB920872)
        Update for Windows XP (KB922582)
        Update for Windows XP (KB927891)
        Update for Windows XP (KB929338)
        Update for Windows XP (KB930916)
        Update for Windows XP (KB931836)
        Update for Windows XP (KB932823-v3)
        Update for Windows XP (KB933360)
        Update for Windows XP (KB938828)
        Update for Windows XP (KB942763)
        Update for Windows XP (KB951072-v2)
        Update for Windows XP (KB955839)
        Update for Windows XP (KB967715)
        WIDCOMM Bluetooth Software
        Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
        Windows Driver Package - Nokia Modem (02/15/2007 3.1)
        Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
        Windows Installer 3.1 (KB893803)
        Windows Internet Explorer 7
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows XP Hotfix - KB873339
        Windows XP Hotfix - KB885836
        Windows XP Hotfix - KB886185
        Windows XP Hotfix - KB887472
        Windows XP Hotfix - KB888302
        Windows XP Hotfix - KB890859
        Windows XP Hotfix - KB891781



        and the uninstall list if you need it

        tom
      • TroganTrogan London, UK
        edited March 2009
        Hi,

        Please disable Spybots TeaTimer temporarly...
        • Open Spybot Search & Destroy
        • Go to the Mode menu, and make sure "Advanced Mode" is selected
        • On the left hand side, choose Tools -> Resident
        • Uncheck "Resident TeaTimer" and OK any prompts
        • Exit SpyBot

        Please do the following...

        1. Open HijackThis
        - Click the Do a system scan only button
        - Check the following entries (below)

        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

        O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)

        O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe


        - Close ALL open windows (especially Internet Explorer!)
        - Click Fix Checked
        Leave HiajckThis open

        2. Click Main Menu
        Click on Open the Misc Tools section.
        Click on Delete a file on reboot...
        Copy and paste the following into the "File name:" text box and then click Open:

        C:\WINDOWS\system32\csrcs.exe

        When you are asked "Do you want to restart your computer now?", click OK.

        Your PC MUST reboot to delete the file!

        3. Please post a new HijackThis log, and let me know if that solves the current problem.
      • edited March 2009
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 08:47:38, on 12/03/2009
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16791)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Iomega\REV System Software\RevUDF.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Iomega\REV System Software\imiconxp.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\O2\O2 Broadband USB Modem\O2 Broadband.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ie/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [YouSendIt.exe] C:\Program Files\YouSendIt\Express\YouSendIt.exe -ui none
        O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
        O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
        O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Caroline
        O17 - HKLM\Software\..\Telephony: DomainName = Caroline
        O17 - HKLM\System\CCS\Services\Tcpip\..\{FC9AE88A-CB54-4062-A1F6-DFCCD8416C70}: NameServer = 62.40.32.33 62.40.32.34
        O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Caroline
        O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Caroline
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe

        --
        End of file - 7288 bytes



        and uninstall list

        Adobe Flash Player 10 Plugin
        Adobe Flash Player ActiveX
        Adobe Reader 8.1.3
        avast! Antivirus
        Compatibility Pack for the 2007 Office system
        Critical Update for Windows Media Player 11 (KB959772)
        Donaldson Toolbox
        High Definition Audio Driver Package - KB888111
        HijackThis 2.0.2
        Hotfix for Windows Internet Explorer 7 (KB947864)
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix for Windows Media Player 11 (KB939683)
        Hotfix for Windows XP (KB914440)
        Hotfix for Windows XP (KB915800)
        Hotfix for Windows XP (KB915865)
        Hotfix for Windows XP (KB926239)
        Hotfix for Windows XP (KB935448)
        Hotfix for Windows XP (KB952287)
        HP Customer Participation Program 7.0
        HP Image Zone 4.2
        HP Imaging Device Functions 7.0
        HP Officejet All-In-One Series
        HP Photosmart Essential
        HP PSC & OfficeJet 4.2
        HP Software Update
        HP Solution Center 7.0
        HP Unload DLL Patch
        Iomega REV System Software
        Java(TM) 6 Update 12
        Malwarebytes' Anti-Malware
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft .NET Framework 2.0
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft Internationalized Domain Names Mitigation APIs
        Microsoft National Language Support Downlevel APIs
        Microsoft Office Basic Edition 2003
        Microsoft Office PowerPoint Viewer 2007 (English)
        Microsoft User-Mode Driver Framework Feature Pack 1.5
        Microsoft Visual C++ 2005 Redistributable
        Mozilla Firefox (3.0.7)
        MSXML 4.0 SP2 (KB954430)
        Nero Suite
        Nokia Connectivity Cable Driver
        Nokia PC Suite
        Nokia PC Suite
        NVIDIA Drivers
        O2 Broadband USB Modem
        OCR Software by I.R.I.S 7.0
        OpenOffice.org Installer 1.0
        PC Connectivity Solution
        PC Tune-Up
        PW14 Drivers v.1.0
        Realtek High Definition Audio Driver
        Retrospect 7.5
        Sage Instant Accounts v14
        Sage MIS 3.01
        Security Update for CAPICOM (KB931906)
        Security Update for CAPICOM (KB931906)
        Security Update for Windows Internet Explorer 7 (KB938127)
        Security Update for Windows Internet Explorer 7 (KB939653)
        Security Update for Windows Internet Explorer 7 (KB942615)
        Security Update for Windows Internet Explorer 7 (KB944533)
        Security Update for Windows Internet Explorer 7 (KB950759)
        Security Update for Windows Internet Explorer 7 (KB953838)
        Security Update for Windows Internet Explorer 7 (KB956390)
        Security Update for Windows Internet Explorer 7 (KB958215)
        Security Update for Windows Internet Explorer 7 (KB960714)
        Security Update for Windows Internet Explorer 7 (KB961260)
        Security Update for Windows Media Player (KB911564)
        Security Update for Windows Media Player (KB952069)
        Security Update for Windows Media Player 11 (KB936782)
        Security Update for Windows Media Player 11 (KB954154)
        Security Update for Windows Media Player 6.4 (KB925398)
        Security Update for Windows Media Player 9 (KB917734)
        Security Update for Windows Media Player 9 (KB936782)
        Security Update for Windows XP (KB893756)
        Security Update for Windows XP (KB896358)
        Security Update for Windows XP (KB896423)
        Security Update for Windows XP (KB896424)
        Security Update for Windows XP (KB896428)
        Security Update for Windows XP (KB899587)
        Security Update for Windows XP (KB899591)
        Security Update for Windows XP (KB900725)
        Security Update for Windows XP (KB901017)
        Security Update for Windows XP (KB901214)
        Security Update for Windows XP (KB902400)
        Security Update for Windows XP (KB904706)
        Security Update for Windows XP (KB905414)
        Security Update for Windows XP (KB905749)
        Security Update for Windows XP (KB908519)
        Security Update for Windows XP (KB911562)
        Security Update for Windows XP (KB911927)
        Security Update for Windows XP (KB912919)
        Security Update for Windows XP (KB913580)
        Security Update for Windows XP (KB914388)
        Security Update for Windows XP (KB914389)
        Security Update for Windows XP (KB917344)
        Security Update for Windows XP (KB917422)
        Security Update for Windows XP (KB917953)
        Security Update for Windows XP (KB918118)
        Security Update for Windows XP (KB918439)
        Security Update for Windows XP (KB919007)
        Security Update for Windows XP (KB920213)
        Security Update for Windows XP (KB920670)
        Security Update for Windows XP (KB920683)
        Security Update for Windows XP (KB920685)
        Security Update for Windows XP (KB921398)
        Security Update for Windows XP (KB921503)
        Security Update for Windows XP (KB922616)
        Security Update for Windows XP (KB922819)
        Security Update for Windows XP (KB923191)
        Security Update for Windows XP (KB923414)
        Security Update for Windows XP (KB923689)
        Security Update for Windows XP (KB923694)
        Security Update for Windows XP (KB923789)
        Security Update for Windows XP (KB923980)
        Security Update for Windows XP (KB924191)
        Security Update for Windows XP (KB924270)
        Security Update for Windows XP (KB924496)
        Security Update for Windows XP (KB924667)
        Security Update for Windows XP (KB925454)
        Security Update for Windows XP (KB925902)
        Security Update for Windows XP (KB926255)
        Security Update for Windows XP (KB926436)
        Security Update for Windows XP (KB927779)
        Security Update for Windows XP (KB927802)
        Security Update for Windows XP (KB928090)
        Security Update for Windows XP (KB928255)
        Security Update for Windows XP (KB928843)
        Security Update for Windows XP (KB929123)
        Security Update for Windows XP (KB929969)
        Security Update for Windows XP (KB930178)
        Security Update for Windows XP (KB931261)
        Security Update for Windows XP (KB931768)
        Security Update for Windows XP (KB931784)
        Security Update for Windows XP (KB932168)
        Security Update for Windows XP (KB933566)
        Security Update for Windows XP (KB933729)
        Security Update for Windows XP (KB935839)
        Security Update for Windows XP (KB935840)
        Security Update for Windows XP (KB936021)
        Security Update for Windows XP (KB937143)
        Security Update for Windows XP (KB937894)
        Security Update for Windows XP (KB938127)
        Security Update for Windows XP (KB938464)
        Security Update for Windows XP (KB938829)
        Security Update for Windows XP (KB939653)
        Security Update for Windows XP (KB941202)
        Security Update for Windows XP (KB941568)
        Security Update for Windows XP (KB941569)
        Security Update for Windows XP (KB941644)
        Security Update for Windows XP (KB941693)
        Security Update for Windows XP (KB943055)
        Security Update for Windows XP (KB943460)
        Security Update for Windows XP (KB943485)
        Security Update for Windows XP (KB944653)
        Security Update for Windows XP (KB945553)
        Security Update for Windows XP (KB946026)
        Security Update for Windows XP (KB946648)
        Security Update for Windows XP (KB948590)
        Security Update for Windows XP (KB948881)
        Security Update for Windows XP (KB950749)
        Security Update for Windows XP (KB950760)
        Security Update for Windows XP (KB950762)
        Security Update for Windows XP (KB950974)
        Security Update for Windows XP (KB951066)
        Security Update for Windows XP (KB951376)
        Security Update for Windows XP (KB951376-v2)
        Security Update for Windows XP (KB951698)
        Security Update for Windows XP (KB951748)
        Security Update for Windows XP (KB952954)
        Security Update for Windows XP (KB953839)
        Security Update for Windows XP (KB954211)
        Security Update for Windows XP (KB954600)
        Security Update for Windows XP (KB955069)
        Security Update for Windows XP (KB956391)
        Security Update for Windows XP (KB956802)
        Security Update for Windows XP (KB956803)
        Security Update for Windows XP (KB956841)
        Security Update for Windows XP (KB957095)
        Security Update for Windows XP (KB957097)
        Security Update for Windows XP (KB958644)
        Security Update for Windows XP (KB958687)
        Security Update for Windows XP (KB958690)
        Security Update for Windows XP (KB960225)
        Security Update for Windows XP (KB960715)
        SelfService - Management System
        Spybot - Search & Destroy
        Thesaurus 2007 Payroll
        Thesaurus 2008 Payroll
        Thesaurus 2009 Payroll
        Update for Windows XP (KB894391)
        Update for Windows XP (KB898461)
        Update for Windows XP (KB900485)
        Update for Windows XP (KB904942)
        Update for Windows XP (KB908531)
        Update for Windows XP (KB910437)
        Update for Windows XP (KB911280)
        Update for Windows XP (KB916595)
        Update for Windows XP (KB920872)
        Update for Windows XP (KB922582)
        Update for Windows XP (KB927891)
        Update for Windows XP (KB929338)
        Update for Windows XP (KB930916)
        Update for Windows XP (KB931836)
        Update for Windows XP (KB932823-v3)
        Update for Windows XP (KB933360)
        Update for Windows XP (KB938828)
        Update for Windows XP (KB942763)
        Update for Windows XP (KB951072-v2)
        Update for Windows XP (KB955839)
        Update for Windows XP (KB967715)
        WIDCOMM Bluetooth Software
        Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
        Windows Driver Package - Nokia Modem (02/15/2007 3.1)
        Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
        Windows Installer 3.1 (KB893803)
        Windows Internet Explorer 7
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows XP Hotfix - KB873339
        Windows XP Hotfix - KB885836
        Windows XP Hotfix - KB886185
        Windows XP Hotfix - KB887472
        Windows XP Hotfix - KB888302
        Windows XP Hotfix - KB890859
        Windows XP Hotfix - KB891781
        YouSendIt Express



        Will see how this goes and will report back before the end of work today.
        thanks again
        regards
        tom
      • TroganTrogan London, UK
        edited March 2009
        Hi,

        Apologies for the delay.

        The HijackThis log looks clean. Let me know if the problem is still present.
      • edited March 2009
        Hello,

        Sorry for the delay, been off for a few days. The computer seems to be ok, thank you very much. I am running avast and spybot search and destroy. Are these enough to protect the computer ?

        Thanks again,
        Regards
        Tom
      • TroganTrogan London, UK
        edited March 2009
        Yes, those are OK. Let me know if I can help with anything else or close this thread.
      • edited March 2009
        Trogan wrote:
        Yes, those are OK. Let me know if I can help with anything else or close this thread.


        Yes you can close this thread, and thanks very much for all you help. :rockon::rockon:

        Tom
      • TroganTrogan London, UK
        edited March 2009
        You're welcome! :)

        Now that your system is clean, kindly follow these simple steps in order to keep your computer clean and secure:

        You may already have some of the following programs, but I include the full list for the benefit of all the other people who will be reading this thread in the future.
        (Vista users must ensure that any programs are Vista compatible BEFORE installing )


        Online Scanners
        I would recommend a scan at one or more of the following sites at least once a month.

        http://www.pandasecurity.com/activescan
        http://www.kaspersky.com/kos/eng/partner/71706/kavwebscan.html

        !!! Make sure that all your programs are updated !!!
        Secunia Software Inspector does all the work for you, .... see HERE for details

        AntiSpyware

        • AntiSpyware is not the same thing as Antivirus.
          Different AntiSpyware programs detect different things, so in this case it is recommended that you have more than one.
          You should only have one running all the time, the other/s should be used "on demand" on a regular basis.
          Most of the programs in this list have a free (for Home Users ) and paid versions,
          it is worth paying for one and having "realtime" protection, unless you intend to do a manual scan often.


        • Spybot - Search & Destroy <<< A must have program
          • It includes host protection and registry protection
          • A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites


        • MalwareBytes Anti-malware <<< A new and effective program
        • a-squared Free <<< A good "realtime" or "on demand" scanner
        • SUPERAntiSpyware <<< A good "realtime" or "on demand" scanner


        Prevention
        • These programs don't detect malware, they help stop it getting on your machine in the first place.
          Each does a different job, so you can have more than one


        • Winpatrol
          • An excellent startup manager and then some !!
          • Notifies you if programs are added to startup
          • Allows delayed startup
          • A must have addition



        • SpywareBlaster 4.0
          • SpywareBlaster sets killbits in the registry to prevent known malicious activex controls from installing themselves on your computer.



        • SpywareGuard 2.2
          • SpywareGuard provides real-time protection against spyware.
          • Not required if you have other "realtime" antispyware or Winpatrol



        • ZonedOut
          • Formerly known as IE-SPYAD, adds a long list of sites and domains associated with known advertisers and marketers to the Restricted sites zone of Internet Explorer.



        • MVPS HOSTS
          • This little program packs a powerful punch as it blocks ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.





          • For information on how to download and install, please read this tutorial by WinHelp2002.
          • Not required if you are using other host file protections


        Windows Updates (a must!)
        It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. You can either click on the link above and bookmark the updates page, or open Internet Explorer, then go to the Tools menu -> Windows Update, and follow the online instructions from there


        Internet Browsers

        • Microsoft has worked hard to make IE.7 a more secure browser, unfortunately whilst it is still the leading browser of choice it will always be under attack from the bad guys.
          Using a different web browser can help stop malware getting on your machine.
          • Make your Internet Explorer more secure - This can be done by following these simple instructions:
            1. From within Internet Explorer click on the Tools menu and then click on Options.
            2. Click once on the Security tab
            3. Click once on the Internet icon so it becomes highlighted.
            4. Click once on the Custom Level button.
              • Change the Download signed ActiveX controls to Prompt
              • Change the Download unsigned ActiveX controls to Disable
              • Change the Initialise and script ActiveX controls not marked as safe to Disable
              • Change the Installation of desktop items to Prompt
              • Change the Launching programs and files in an IFRAME to Prompt
              • Change the Navigate sub-frames across different domains to Prompt
              • When all these settings have been made, click on the OK button.
              • If it prompts you as to whether or not you want to save the settings, press the Yes button.


            5. Next press the Apply button and then the OK to exit the Internet Properties page.


          If you are still using IE6 then either update, or get one of the following.


          • FireFox
            • With many addons available that make customization easy this is a very popular choice
            • NoScript and AdBlockPlus addons are essential



          • Opera
            • Another popular alternative



          • Netscape
            • Another popular alternative
            • Also has Addons available


        Cleaning Temporary Internet Files and Tracking Cookies

        • Temporary Internet Files are mainly the files that are downloaded when you open a web page.
          Unfortunately, if the site you visit is of a dubious nature or has been hacked, they can also be an entry point for malware.
          It is a good idea to empty the Temporary Internet Files folder on a regular basis.

          Tracking Cookies are files that websites use to monitor which sites you visit and how often.
          A lot of Antispyware scanners pick up these tracking cookies and flag them as unwanted.
          CAUTION :- If you delete all your cookies you will lose any autologin information for sites that you visit, and will need your passwords

          Both of these can be cleaned manually, but a quicker option is to use a program
        • ATF Cleaner
          • Free and very simple to use



        • CCleaner
          • Free and very flexible, you can chose which cookies to keep


        Also PLEASE read these articles: So How Did I Get Infected In The First Place and Malware Prevention: Prevent Re-infection

        The last and most important thing I can tell you is UPDATE.
        If you don't update your security programs (Antivirus, Antispyware even Windows) then you are at risk.
        Malware changes on a day to day basis. You should update every week at the very least.

        If you follow this advice then (with a bit of luck) you will never have to hear from me again :D
      Sign In or Register to comment.