Hello,
I've followed all the instructions for beginners and have all the necessary updates that you outlined on the "READ THIS before Posting" page.
I have the Internet Security 2010 bug. Tons of pop-ups and disabling of certain programs (like Task Manager).
Below is the log file.
I was tempted to read and follow the directions on the "Remove Internet Security" thread, posted by Dr. Inferno, but I'm too chicken to restart my computer for fear it won't reboot.
Any help would be awesome....here's me crossing my fingers.....
LOG FILE is as follows...............
Logfile of Trend Micro
HijackThis v2.0.2
Scan saved at 6:18:14 AM, on
1/16/2010
Platform: Windows XP SP3
(WinNT 5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32
\winlogon.exe
C:\WINDOWS\system32
\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\System32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil
Software\Avast4\ashServ.exe
C:\WINDOWS\system32
\spoolsv.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\HPZipm12.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4
\ashDisp.exe
C:\Program Files\HP\HP
Software Update\HPWuSchd2.exe
C:\Program
Files\HP\hpcoretech\hpcmpmgr.
exe
C:\WINDOWS\system32
\ctfmon.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32
\smss32.exe
C:\Program
Files\InternetSecurity2010
\IS2010.exe
C:\WINDOWS\system32
\wscntfy.exe
C:\Program Files\Java\jre6
\bin\jqs.exe
C:\Program Files\Mozilla
Firefox\firefox.exe
C:\WINDOWS\system32
\NOTEPAD.EXE
C:\Documents and
Settings\Owner\My
Documents\Downloads\winlogon.
scr
C:\WINDOWS\system32
\wbem\wmiprvse.exe
R0 -
HKCU\Software\Microsoft\Inter
net Explorer\Main,Start Page
= http://www.yahoo.com/
R1 -
HKLM\Software\Microsoft\Inter
net
Explorer\Main,Default_Page_UR
L =
http://go.microsoft.com/fwlin
k/?LinkId=69157
R1 -
HKLM\Software\Microsoft\Inter
net
Explorer\Main,Default_Search_
URL =
http://go.microsoft.com/fwlin
k/?LinkId=54896
R1 -
HKLM\Software\Microsoft\Inter
net Explorer\Main,Search Page
=
http://go.microsoft.com/fwlin
k/?LinkId=54896
R0 -
HKLM\Software\Microsoft\Inter
net Explorer\Main,Start Page
=
http://go.microsoft.com/fwlin
k/?LinkId=69157
F2 - REG:system.ini:
UserInit=C:\WINDOWS\system32
\winlogon32.exe,C:\WINDOWS\sy
stem32\sdra64.exe,
O2 - BHO: AcroIEHelperStub -
{18DF081C-E8AD-4283-A596-
FA578C2EBDC3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\A
croIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2
SSV Helper - {DBC80044-A445-
435b-BC74-9C25C1C588A9} -
C:\Program Files\Java\jre6
\bin\jp2ssv.dll
O2 - BHO:
JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-
EABFE594F69C} - C:\Program
Files\Java\jre6
\lib\deploy\jqs\ie\jqs_plugin
.dll
O4 - HKLM\..\Run:
[IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil
/RemAdvDef /Migration32
O4 - HKLM\..\Run:
[PHIME2002ASync]
C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE
/SYNC
O4 - HKLM\..\Run:
[PHIME2002A]
C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE
/IMEName
O4 - HKLM\..\Run: [avast!]
C:\PROGRA~1\ALWILS~1\Avast4
\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime
Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [HP
Software Update] C:\Program
Files\HP\HP Software
Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP
Component Manager]
"C:\Program
Files\HP\hpcoretech\hpcmpmgr.
exe"
O4 - HKLM\..\Run: [Adobe
Reader Speed Launcher]
"C:\Program
Files\Adobe\Reader 9.0
\Reader\Reader_sl.exe"
O4 - HKLM\..\Run:
[smss32.exe]
C:\WINDOWS\system32
\smss32.exe
O4 - HKLM\..\Run:
[SunJavaUpdateSched]
"C:\Program Files\Common
Files\Java\Java
Update\jusched.exe"
O4 - HKCU\..\Run:
[ctfmon.exe]
C:\WINDOWS\system32
\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS]
"C:\Program
Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [Internet
Security 2010] C:\Program
Files\InternetSecurity2010
\IS2010.exe
O4 - Global Startup: HP
Digital Imaging Monitor.lnk =
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image
Zone Fast Start.lnk =
C:\Program Files\HP\Digital
Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name)
- {e2e2dd38-d088-4134-82b7-
f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-
f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger
- {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem:
Windows Messenger -
{FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock
LSP: c:\windows\system32
\helper32.dll
O10 - Unknown file in Winsock
LSP: c:\windows\system32
\helper32.dll
O16 - DPF: {C1FDEE68-98D5-
4F42-A4DD-D0BECF5077EB}
(EPUImageControl Class) -
http://tools.ebayimg.com/eps/
wl/activex/eBay_Enhanced_Pict
ure_Control_v1-0-27-0.cab
O23 - Service: avast! iAVS4
Control Service (aswUpdSv) -
ALWIL Software - C:\Program
Files\Alwil Software\Avast4
\aswUpdSv.exe
O23 - Service: avast!
Antivirus - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail
Scanner - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web
Scanner - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick
Starter
(JavaQuickStarterService) -
Sun Microsystems, Inc. -
C:\Program Files\Java\jre6
\bin\jqs.exe
O23 - Service: Pml Driver
HPZ12 - HP -
C:\WINDOWS\system32
\HPZipm12.exe
--
End of file - 5342 bytes
I've followed all the instructions for beginners and have all the necessary updates that you outlined on the "READ THIS before Posting" page.
I have the Internet Security 2010 bug. Tons of pop-ups and disabling of certain programs (like Task Manager).
Below is the log file.
I was tempted to read and follow the directions on the "Remove Internet Security" thread, posted by Dr. Inferno, but I'm too chicken to restart my computer for fear it won't reboot.
Any help would be awesome....here's me crossing my fingers.....
LOG FILE is as follows...............
Logfile of Trend Micro
HijackThis v2.0.2
Scan saved at 6:18:14 AM, on
1/16/2010
Platform: Windows XP SP3
(WinNT 5.01.2600)
MSIE: Internet Explorer v8.00
(8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32
\winlogon.exe
C:\WINDOWS\system32
\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\System32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\Program Files\Alwil
Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil
Software\Avast4\ashServ.exe
C:\WINDOWS\system32
\spoolsv.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\system32
\HPZipm12.exe
C:\WINDOWS\system32
\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4
\ashDisp.exe
C:\Program Files\HP\HP
Software Update\HPWuSchd2.exe
C:\Program
Files\HP\hpcoretech\hpcmpmgr.
exe
C:\WINDOWS\system32
\ctfmon.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital
Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32
\smss32.exe
C:\Program
Files\InternetSecurity2010
\IS2010.exe
C:\WINDOWS\system32
\wscntfy.exe
C:\Program Files\Java\jre6
\bin\jqs.exe
C:\Program Files\Mozilla
Firefox\firefox.exe
C:\WINDOWS\system32
\NOTEPAD.EXE
C:\Documents and
Settings\Owner\My
Documents\Downloads\winlogon.
scr
C:\WINDOWS\system32
\wbem\wmiprvse.exe
R0 -
HKCU\Software\Microsoft\Inter
net Explorer\Main,Start Page
= http://www.yahoo.com/
R1 -
HKLM\Software\Microsoft\Inter
net
Explorer\Main,Default_Page_UR
L =
http://go.microsoft.com/fwlin
k/?LinkId=69157
R1 -
HKLM\Software\Microsoft\Inter
net
Explorer\Main,Default_Search_
URL =
http://go.microsoft.com/fwlin
k/?LinkId=54896
R1 -
HKLM\Software\Microsoft\Inter
net Explorer\Main,Search Page
=
http://go.microsoft.com/fwlin
k/?LinkId=54896
R0 -
HKLM\Software\Microsoft\Inter
net Explorer\Main,Start Page
=
http://go.microsoft.com/fwlin
k/?LinkId=69157
F2 - REG:system.ini:
UserInit=C:\WINDOWS\system32
\winlogon32.exe,C:\WINDOWS\sy
stem32\sdra64.exe,
O2 - BHO: AcroIEHelperStub -
{18DF081C-E8AD-4283-A596-
FA578C2EBDC3} - C:\Program
Files\Common
Files\Adobe\Acrobat\ActiveX\A
croIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2
SSV Helper - {DBC80044-A445-
435b-BC74-9C25C1C588A9} -
C:\Program Files\Java\jre6
\bin\jp2ssv.dll
O2 - BHO:
JQSIEStartDetectorImpl -
{E7E6F031-17CE-4C07-BC86-
EABFE594F69C} - C:\Program
Files\Java\jre6
\lib\deploy\jqs\ie\jqs_plugin
.dll
O4 - HKLM\..\Run:
[IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil
/RemAdvDef /Migration32
O4 - HKLM\..\Run:
[PHIME2002ASync]
C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE
/SYNC
O4 - HKLM\..\Run:
[PHIME2002A]
C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE
/IMEName
O4 - HKLM\..\Run: [avast!]
C:\PROGRA~1\ALWILS~1\Avast4
\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime
Task] "C:\Program
Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [HP
Software Update] C:\Program
Files\HP\HP Software
Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HP
Component Manager]
"C:\Program
Files\HP\hpcoretech\hpcmpmgr.
exe"
O4 - HKLM\..\Run: [Adobe
Reader Speed Launcher]
"C:\Program
Files\Adobe\Reader 9.0
\Reader\Reader_sl.exe"
O4 - HKLM\..\Run:
[smss32.exe]
C:\WINDOWS\system32
\smss32.exe
O4 - HKLM\..\Run:
[SunJavaUpdateSched]
"C:\Program Files\Common
Files\Java\Java
Update\jusched.exe"
O4 - HKCU\..\Run:
[ctfmon.exe]
C:\WINDOWS\system32
\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS]
"C:\Program
Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [Internet
Security 2010] C:\Program
Files\InternetSecurity2010
\IS2010.exe
O4 - Global Startup: HP
Digital Imaging Monitor.lnk =
C:\Program Files\HP\Digital
Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image
Zone Fast Start.lnk =
C:\Program Files\HP\Digital
Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name)
- {e2e2dd38-d088-4134-82b7-
f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem:
@xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-
f2ba38496583} -
C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger
- {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem:
Windows Messenger -
{FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock
LSP: c:\windows\system32
\helper32.dll
O10 - Unknown file in Winsock
LSP: c:\windows\system32
\helper32.dll
O16 - DPF: {C1FDEE68-98D5-
4F42-A4DD-D0BECF5077EB}
(EPUImageControl Class) -
http://tools.ebayimg.com/eps/
wl/activex/eBay_Enhanced_Pict
ure_Control_v1-0-27-0.cab
O23 - Service: avast! iAVS4
Control Service (aswUpdSv) -
ALWIL Software - C:\Program
Files\Alwil Software\Avast4
\aswUpdSv.exe
O23 - Service: avast!
Antivirus - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashServ.exe
O23 - Service: avast! Mail
Scanner - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web
Scanner - ALWIL Software -
C:\Program Files\Alwil
Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick
Starter
(JavaQuickStarterService) -
Sun Microsystems, Inc. -
C:\Program Files\Java\jre6
\bin\jqs.exe
O23 - Service: Pml Driver
HPZ12 - HP -
C:\WINDOWS\system32
\HPZipm12.exe
--
End of file - 5342 bytes