WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
Yeah, just leftover folders, we'll remove them soon.
Please post a new Hijack This log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 DXwU4
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 VvYDg

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 3:56:22 PM, on 1/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\dldncoms.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0061019
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [combofix] "C:\Combo-Fix\CF19193.cfxxe" /c "C:\Combo-Fix\C.bat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: dldn_device - - C:\WINDOWS\system32\dldncoms.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6265 bytes

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
Hello.

You can delete those two .db files.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [combofix] "C:\Combo-Fix\CF19193.cfxxe" /c "C:\Combo-Fix\C.bat"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe



  • Press "Fix Checked"
  • Close Hijack This.

I recommend you remove the Java Quick Starter because it's not needed.
To do so, follow these instructions.

Go to Start > Control Panel > Java.
In the Java control panel, open the click the Advanced tab. Click the + in front of Miscellaneous and uncheck the Java Quick Starter box.

See here for more info.

Please download the OTMoveIt by OldTimer.

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :files
    c:\documents and settings\All Users\Application Data\avg9
    c:\documents and settings\Vangie\Application Data\AVG8
    c:\documents and settings\All Users\Application Data\McAfee
    c:\program files\Common Files\Symantec Shared
    c:\documents and settings\All Users\Application Data\Symantec
    c:\program files\AVG


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 DXwU4
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 VvYDg

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
========== FILES ==========
c:\documents and settings\All Users\Application Data\avg9\Log folder moved successfully.
c:\documents and settings\All Users\Application Data\avg9 folder moved successfully.
c:\documents and settings\Vangie\Application Data\AVG8 folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\Supportability\MVT folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\Supportability folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MSC\Cache folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MSC folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MBK\92948b65-08a6-4ac1-8cea-513bfa06ca9d folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\MBK folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee\dspwrp folder moved successfully.
c:\documents and settings\All Users\Application Data\McAfee folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\TextHub folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\incoming folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\BinHub folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20071026.021 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20071025.021 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs\20061116.036 folder moved successfully.
c:\program files\Common Files\Symantec Shared\VirusDefs folder moved successfully.
c:\program files\Common Files\Symantec Shared\SPManifests folder moved successfully.
c:\program files\Common Files\Symantec Shared\EENGINE folder moved successfully.
c:\program files\Common Files\Symantec Shared\CCPD-LC folder moved successfully.
c:\program files\Common Files\Symantec Shared folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{6A90DE7F-6F89-4703-ABD9-CEBAD0C38E93} folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate folder moved successfully.
c:\documents and settings\All Users\Application Data\Symantec folder moved successfully.
c:\program files\AVG\AVG8\log folder moved successfully.
c:\program files\AVG\AVG8\avgam folder moved successfully.
c:\program files\AVG\AVG8 folder moved successfully.
c:\program files\AVG folder moved successfully.

OTM by OldTimer - Version 3.1.4.0 log created on 01022010_203223

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 DXwU4
INFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 VvYDg

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
appears to be better... Thank you so much.. and I dont know what that file was you had me remove that was part of my zboard when we first started this but it is working fine also so it didnt seem to effect it =).. I love this site and am recommending it to all my friends.. I thank you so very much.. I would have thrown it out the window if it wasnt for you Hooray!

descriptionINFECTED ...  Internet Security 2010 ... of course...lol  HELP please - Page 2 EmptyRe: INFECTED ... Internet Security 2010 ... of course...lol HELP please

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum