WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptioni have PersonalAV, help please Emptyi have PersonalAV, help please

more_horiz
I downloaded malwarebytes anti malwave
app is on my screen and in my programmes but can not get it to do anything

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hello.
Download Hijack This from here;
http://www.sendspace.com/pro/dl/fpzz64

Run it, then do a system scan with logfile.
Copy/paste the log back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
i have PersonalAV, help please DXwU4
i have PersonalAV, help please VvYDg

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hope you can help im not sure i done this right, thanks in advance

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:06:01, on 03/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ADMJOXGP\winlogon[1].scr

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 92.63.97.167 www.postbank.de
O1 - Hosts: 92.63.97.167 postbank.de
O1 - Hosts: 92.63.97.167 banking.postbank.de
O1 - Hosts: 92.63.97.167 direkt.postbank.de
O1 - Hosts: 92.63.97.167 www.smile.co.uk
O1 - Hosts: 92.63.97.167 smile.co.uk
O1 - Hosts: 92.63.97.167 cahoot.com
O1 - Hosts: 92.63.97.167 www.cahoot.com
O1 - Hosts: 92.63.97.167 www.cahoot.co.uk
O1 - Hosts: 92.63.97.167 cahoot.co.uk
O1 - Hosts: 92.63.97.167 www.co-operativebank.co.uk
O1 - Hosts: 92.63.97.167 co-operativebank.co.uk
O1 - Hosts: 92.63.97.167 www.co-operativebank.com
O1 - Hosts: 92.63.97.167 co-operativebank.com
O1 - Hosts: 92.63.97.167 personal.barclays.co.uk
O1 - Hosts: 92.63.97.167 barclays.co.uk
O1 - Hosts: 92.63.97.167 ibank.barclays.co.uk
O1 - Hosts: 92.63.97.167 www.barclays.co.uk
O1 - Hosts: 92.63.97.167 barclays.touchclarity.com
O1 - Hosts: 92.63.97.167 hsbc.co.uk
O1 - Hosts: 92.63.97.167 www.hsbc.co.uk
O1 - Hosts: 92.63.97.167 hsbc.touchclarity.com
O1 - Hosts: 92.63.97.167 www1.member-hsbc-group.com
O1 - Hosts: 92.63.97.167 lloydstsb.co.uk
O1 - Hosts: 92.63.97.167 www.lloydstsb.co.uk
O1 - Hosts: 92.63.97.167 lloydstsb.com
O1 - Hosts: 92.63.97.167 www.lloydstsb.com
O1 - Hosts: 92.63.97.167 mi.lloydstsb.com
O1 - Hosts: 92.63.97.167 www.woolwich.co.uk
O1 - Hosts: 92.63.97.167 woolwich.co.uk
O1 - Hosts: 92.63.97.167 www.deutsche-bank.de
O1 - Hosts: 92.63.97.167 deutsche-bank.de
O1 - Hosts: 92.63.97.167 meine.deutsche-bank.de
O1 - Hosts: 92.63.97.167 www.anbusiness.com
O1 - Hosts: 92.63.97.167 anbusiness.com
O1 - Hosts: 92.63.97.167 www.abbeyinternational.com
O1 - Hosts: 92.63.97.167 www.barclays.com
O1 - Hosts: 92.63.97.167 barclays.com
O1 - Hosts: 92.63.97.167 ibank.internationalbanking.barclays.com
O1 - Hosts: 92.63.97.167 offshore.hsbc.com
O1 - Hosts: 92.63.97.167 www.lloydstsb-offshore.com
O1 - Hosts: 92.63.97.167 lloydstsb-offshore.com
O1 - Hosts: 92.63.97.167 citibank.de
O1 - Hosts: 92.63.97.167 www.citibank.de
O1 - Hosts: 92.63.97.167 www.natwest.com
O1 - Hosts: 92.63.97.167 natwest.com
O1 - Hosts: 92.63.97.167 www.nwolb.com
O1 - Hosts: 92.63.97.167 nwolb.com
O1 - Hosts: 92.63.97.167 rbs.co.uk
O1 - Hosts: 92.63.97.167 www.rbs.co.uk
O1 - Hosts: 92.63.97.167 www.rbsdigital.com
O1 - Hosts: 92.63.97.167 rbsdigital.com
O1 - Hosts: 92.63.97.167 www.ybonline.co.uk
O1 - Hosts: 92.63.97.167 ybonline.co.uk
O2 - BHO: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P0.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msxmlm.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P0.dll
O3 - Toolbar: ToggleEN Toolbar - {038cb5c7-48ea-4af9-94e0-a1646542e62b} - C:\Program Files\ToggleEN\tbTog0.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [NovaBackup 7 Tray Control] "C:\Program Files\StompSoft\PC BackUp\NbkCtrl.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Network Services Controller] C:\WINDOWS\system32\mmsvc32.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\PAV.exe
O4 - HKLM\..\Run: [MSDRV] NetFilter.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{45D261B5-AB43-4796-B4CB-EDA490FEFF08}: NameServer = 85.255.112.190,85.255.112.232
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.190,85.255.112.232
O17 - HKLM\System\CS1\Services\Tcpip\..\{45D261B5-AB43-4796-B4CB-EDA490FEFF08}: NameServer = 85.255.112.190,85.255.112.232
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.190,85.255.112.232
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\StompSoft\PC BackUp\NMSAccess.exe
O23 - Service: NsEngine - Unknown owner - C:\Program Files\StompSoft\PC BackUp\NSENGINE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - SupportSoft, Inc. - C:\Program Files\TalkTalk\bin\sprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\ssrc.exe
O23 - Service: SupportSoft Repair Service (TalkTalk) (tgsrvc_TalkTalk) - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

--
End of file - 9231 bytes

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P0.dll
    O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare\BearShareIEHelper.dll
    O2 - BHO: &Helper - {A77D3539-581D-450C-9E44-A84C415A6172} - C:\WINDOWS\system32\msxmlm.dll
    O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P0.dll
    O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
    O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
    O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
    O4 - HKLM\..\Run: [Microsoft Network Services Controller] C:\WINDOWS\system32\mmsvc32.exe
    O4 - HKLM\..\Run: [PersonalAV] C:\Program Files\PersonalAV\PAV.exe
    O4 - HKLM\..\Run: [MSDRV] NetFilter.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{45D261B5-AB43-4796-B4CB-EDA490FEFF08}: NameServer = 85.255.112.190,85.255.112.232
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.190,85.255.112.232
    O17 - HKLM\System\CS1\Services\Tcpip\..\{45D261B5-AB43-4796-B4CB-EDA490FEFF08}: NameServer = 85.255.112.190,85.255.112.232
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.190,85.255.112.232


  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
i have PersonalAV, help please DXwU4
i have PersonalAV, help please VvYDg

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hi this is as far as i get everytime

.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

Done this but the next step doesn't load up after i pressed finnish

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hello.

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    i have PersonalAV, help please CF_download_FF

    i have PersonalAV, help please CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    i have PersonalAV, help please Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    i have PersonalAV, help please Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
i have PersonalAV, help please DXwU4
i have PersonalAV, help please VvYDg

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hi, i came out of safe mode earlier after downloading malwarebytes anti malwave and hijack this, once i restarted my computer in normal mode the personnal av was gone and computer running better but never got to the part where i started the scan as nothing came up after i pressed finish when installed, but as its gone im fine with that but will it come back?
Thanks for your help

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Likely so if we haven't fully removed it.

Did you scan with MBAM?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
i have PersonalAV, help please DXwU4
i have PersonalAV, help please VvYDg

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hi, i did download mbam followed the step by step guide but got as far as press finish then nothing no scan pic come up like on the other forum,
mbam is now on my computer in my programs but cant do nothing with it.
But like i said all working smoothly at the mo no sign of personnal av?

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
Hello.

  • Download combofix from here
    Link 1
    Link 2

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:

    i have PersonalAV, help please CF_download_FF

    i have PersonalAV, help please CF_download_rename

    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See HERE for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    i have PersonalAV, help please Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes

    i have PersonalAV, help please Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
i have PersonalAV, help please DXwU4
i have PersonalAV, help please VvYDg

descriptioni have PersonalAV, help please EmptyRe: i have PersonalAV, help please

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum