The FIAT Forum
iNETFX Domain Registration - COM/NET/ORG £6.50 a year!

Go Back   The FIAT Forum > General > Leisure Lounge > Computing


Reply
 
Thread Tools Search this Thread
Old 30-06-2008   #1
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
virus fun

so i downlaoded
http://www.download.com/Trend-Micro-...-10227353.html

and it told me to find a brain box


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:52, on 30/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\ASUS\AI Direct Link\AsShare.exe
C:\Program Files\ASUS\PC Probe II\Probe2.exe
C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\ASUS\AASP\1.00.46\aaCenter.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [CPU Power Monitor] "C:\Program Files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe"
O4 - HKLM\..\Run: [Cpu Level Up help] C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Launch Direct Link] "C:\Program Files\ASUS\AI Direct Link\AsShare.exe"
O4 - HKLM\..\Run: [Launch As Cmd Runner] "C:\Program Files\ASUS\AI Direct Link\AsCmd.exe" -reg
O4 - HKLM\..\Run: [Launch PC Probe II] "C:\Program Files\ASUS\PC Probe II\Probe2.exe" 1
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "G:\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger .exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1210110429062
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
--
End of file - 8844 bytes
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code
Daz_Rich is offline  
Reply With Quote
Old 30-06-2008   #2
Chasing Cars
 
ChrisUK's Avatar
 
Join Date: Apr 2004
Location: Newton Aycliffe
Posts: 5,311
Thanks: 185
Trader Rating: (0)
ChrisUK has donated! United Kingdom 
Re: virus fun

What about it?. I don't understand what you want.
__________________


Present: 05 Punto Sporting 1.4 16v
ChrisUK is offline  
Reply With Quote
Old 30-06-2008   #3
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,722
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus fun

Originally Posted by ChrisUK View Post
What about it?. I don't understand what you want.
exactly what i thought.

but i havent got daz_rich translator installed at work
__________________
Mikeee is offline  
Reply With Quote
Old 30-06-2008   #4
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
Re: virus fun

soap will know i hope
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code
Daz_Rich is offline  
Reply With Quote
Old 30-06-2008   #5
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,722
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus fun

Originally Posted by Daz_Rich View Post
soap will know i hope
i hope not just to teach u a lesson
__________________
Mikeee is offline  
Reply With Quote
Old 30-06-2008   #6
Chasing Cars
 
ChrisUK's Avatar
 
Join Date: Apr 2004
Location: Newton Aycliffe
Posts: 5,311
Thanks: 185
Trader Rating: (0)
ChrisUK has donated! United Kingdom 
Re: virus fun

Originally Posted by Daz_Rich View Post
soap will know i hope
All I need to know is WHAT YOUR ASKING then I can help you. What is it you want to know all you say in your original post is something about brainbox?, You don't actually say what you want?.
__________________


Present: 05 Punto Sporting 1.4 16v
ChrisUK is offline  
Reply With Quote
Old 30-06-2008   #7
jug
blessed are the apostates
 
jug's Avatar
 
Join Date: Nov 2005
Posts: 13,342
Thanks: 461
Trader Rating: (1)
jug has donated! United Kingdom 
Re: virus fun

he posted a hijackthis report, so i would assume he wants ppl to check it to see if you can spot the baddy. i cant see anything.

what makes you think you have an infection rich?
__________________
jug is offline  
Reply With Quote
The following user says "Thank You!" to jug for this useful post:
Daz_Rich (30-06-2008)
Old 30-06-2008   #8
Chasing Cars
 
ChrisUK's Avatar
 
Join Date: Apr 2004
Location: Newton Aycliffe
Posts: 5,311
Thanks: 185
Trader Rating: (0)
ChrisUK has donated! United Kingdom 
Re: virus fun

Only ones I can see that are 'suspect' are these:

C:\WINDOWS\CameraFixer.exe
C:\WINDOWS\tsnp2std.exe
C:\WINDOWS\vsnp2std.exe

Could be legit I just cant be arsed to google them at the moment.
__________________


Present: 05 Punto Sporting 1.4 16v
ChrisUK is offline  
Reply With Quote
The following user says "Thank You!" to ChrisUK for this useful post:
Daz_Rich (30-06-2008)
Old 30-06-2008   #9
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
Re: virus fun

i got a desktop changed
to say i got spywhare would upload a photo but im being stupid enouth to even use it on net

well i got a mate round and i was busy chatting for a few mins while composing a post
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code

Last edited by Daz_Rich : 30-06-2008 at 12:29.
Daz_Rich is offline  
Reply With Quote
Old 30-06-2008   #10
(I Love Brackets)
 
Mikeee's Avatar
 
Join Date: Oct 2007
Posts: 3,722
Thanks: 166
Trader Rating: (0)
Mikeee has donated! United Kingdom 
Re: virus fun

Originally Posted by Daz_Rich View Post
whoops took me ages to post back in a mo
__________________
Mikeee is offline  
Reply With Quote
Old 30-06-2008   #11
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
Re: virus fun

Originally Posted by ChrisUK View Post
Only ones I can see that are 'suspect' are these:

C:WINDOWSCameraFixer.exe
C:WINDOWStsnp2std.exe
C:WINDOWSvsnp2std.exe

Could be legit I just cant be arsed to Google them at the moment.
camera fixer is the web cam
and i think the other 2 is avast or zone alarm they appeared about thenish
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code
Daz_Rich is offline  
Reply With Quote
Old 30-06-2008   #12
Rev 1.0B 2008 Update
 
soap_dodger's Avatar
 
Join Date: Nov 2006
Posts: 289
Thanks: 36
Trader Rating: (0)
soap_dodger has donated! United Kingdom 
Re: virus fun

The other 2 are your webcam as well.
__________________
I never drink, I never gamble, I never take drugs, and I never lie.
soap_dodger is offline  
Reply With Quote
Old 30-06-2008   #13
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
Re: virus fun

cheers soaps
OK then technical advisers how do i remove
i cant do it by right clicking and settings since my only options are
themes, appearance and settings
I'm running avast done a boot time scan and zone alarm.
this is what says

warning spy ware found on your computer in yellow on a blue background with below it against a blue background but with a white border around saying please install an antivirus or spyware program. any ideas?
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code
Daz_Rich is offline  
Reply With Quote
Old 30-06-2008   #14
Rev 1.0B 2008 Update
 
soap_dodger's Avatar
 
Join Date: Nov 2006
Posts: 289
Thanks: 36
Trader Rating: (0)
soap_dodger has donated! United Kingdom 
Re: virus fun

Boot into safe mode and run a Spybot scan and ad-aware.
__________________
I never drink, I never gamble, I never take drugs, and I never lie.
soap_dodger is offline  
Reply With Quote
Old 30-06-2008   #15
likes polls
 
Daz_Rich's Avatar
 
Join Date: Jun 2007
Location: In a house
Posts: 726
Thanks: 25
Trader Rating: (0)
Daz_Rich has donated! United Kingdom 
Re: virus fun

just isntalling them but i dont like either of these programs
__________________
^Please excuse the above writing as it lacks English^
Punto mk2 1.2 8 valve 2000 Xreg silver
Knows a small amount about cars http://www.fiatforum.com/classifieds/showproduct.php?product=10396 sell me the parts now make the code
Daz_Rich is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
virus Mikeee Computing 24 29-04-2008 09:53
virus- help!! beau Leisure Lounge 6 10-11-2006 20:58
PC Virus, who knows about them? Steven Computing 24 08-02-2006 20:45
ahhh VIRUS! help me please marky23 Leisure Lounge 10 04-05-2005 20:17


All times are GMT +1. The time now is 03:51.

Copyright ©2002 - 2008 FIAT Forum
Proudly hosted by iNETFX Message Boards and Forums Directory