| | #1 | ||
| likes polls | virus fun so i downlaoded http://www.download.com/Trend-Micro-...-10227353.html and it told me to find a brain box Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:45:52, on 30/06/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZONELABS\vsmon.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\ASUS\AI Direct Link\AsShare.exe C:\Program Files\ASUS\PC Probe II\Probe2.exe C:\WINDOWS\CameraFixer.exe C:\WINDOWS\tsnp2std.exe C:\WINDOWS\vsnp2std.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\ASUS\AASP\1.00.46\aaCenter.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe" O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [Launch Direct Link] "C:\Program Files\ASUS\AI Direct Link\AsShare.exe" O4 - HKLM\..\Run: [Launch As Cmd Runner] "C:\Program Files\ASUS\AI Direct Link\AsCmd.exe" -reg O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Steam] "G:\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe -- End of file - 8844 bytes
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code | ||
| |
|
| | #2 | ||
| Chasing Cars | Re: virus fun What about it?. I don't understand what you want.
__________________ ![]() Present: 05 Punto Sporting 1.4 16v | ||
| |
|
| | #3 | ||
| (I Love Brackets) | Re: virus fun | ||
| |
|
| | #4 | ||
| likes polls | Re: virus fun soap will know i hope
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code | ||
| |
|
| | #5 | ||
| (I Love Brackets) | Re: virus fun | ||
| |
|
| | #6 | ||
| Chasing Cars | Re: virus fun
__________________ ![]() Present: 05 Punto Sporting 1.4 16v | ||
| |
|
| | #7 | ||
| blessed are the apostates | Re: virus fun he posted a hijackthis report, so i would assume he wants ppl to check it to see if you can spot the baddy. i cant see anything. what makes you think you have an infection rich? | ||
| |
|
| The following user says "Thank You!" to jug for this useful post: | ||
Daz_Rich (30-06-2008) | ||
| | #8 | ||
| Chasing Cars | Re: virus fun Only ones I can see that are 'suspect' are these: C:\WINDOWS\CameraFixer.exe C:\WINDOWS\tsnp2std.exe C:\WINDOWS\vsnp2std.exe Could be legit I just cant be arsed to google them at the moment.
__________________ ![]() Present: 05 Punto Sporting 1.4 16v | ||
| |
|
| The following user says "Thank You!" to ChrisUK for this useful post: | ||
Daz_Rich (30-06-2008) | ||
| | #9 | ||
| likes polls | Re: virus fun i got a desktop changed to say i got spywhare would upload a photo but im being stupid enouth to even use it on net well i got a mate round and i was busy chatting for a few mins while composing a post
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code Last edited by Daz_Rich : 30-06-2008 at 12:29. | ||
| |
|
| | #10 | ||
| (I Love Brackets) | Re: virus fun | ||
| |
|
| | #11 | |||
| likes polls | Re: virus fun
and i think the other 2 is avast or zone alarm they appeared about thenish
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code | |||
| |
|
| | #12 | ||
| Rev 1.0B 2008 Update | Re: virus fun The other 2 are your webcam as well.
__________________ I never drink, I never gamble, I never take drugs, and I never lie. | ||
| |
|
| | #13 | ||
| likes polls | Re: virus fun cheers soaps OK then technical advisers how do i remove i cant do it by right clicking and settings since my only options are themes, appearance and settings I'm running avast done a boot time scan and zone alarm. this is what says warning spy ware found on your computer in yellow on a blue background with below it against a blue background but with a white border around saying please install an antivirus or spyware program. any ideas?
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code | ||
| |
|
| | #14 | ||
| Rev 1.0B 2008 Update | Re: virus fun Boot into safe mode and run a Spybot scan and ad-aware.
__________________ I never drink, I never gamble, I never take drugs, and I never lie. | ||
| |
|
| | #15 | ||
| likes polls | Re: virus fun just isntalling them but i dont like either of these programs
__________________ ^Please excuse the above writing as it lacks English^ Punto mk2 1.2 8 valve 2000 Xreg silver Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code | ||
| |
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | Search this Thread |
|
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| virus | Mikeee | Computing | 24 | 29-04-2008 09:53 |
| virus- help!! | beau | Leisure Lounge | 6 | 10-11-2006 20:58 |
| PC Virus, who knows about them? | Steven | Computing | 24 | 08-02-2006 20:45 |
| ahhh VIRUS! help me please | marky23 | Leisure Lounge | 10 | 04-05-2005 20:17 |