Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: C drive display  (Read 27667 times)

0 Members and 1 Guest are viewing this topic.

NNEagle

    Topic Starter


    Beginner

    Thanked: 1
    C drive display
    « on: October 09, 2008, 07:17:18 PM »
    When I went to my computer last evening. It showed and still showing  my C drive as %$thb$%(C). and a picture with thb creation. Is this a virus or what is it. Kindly help
    Eagle

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: C drive display
    « Reply #1 on: October 10, 2008, 03:14:40 AM »
    If you suspect a virus (sounds like it), look here:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    NNEagle

      Topic Starter


      Beginner

      Thanked: 1
      Re: C drive display
      « Reply #2 on: October 11, 2008, 07:15:40 AM »
      Your link to the file: http://www.savefile.com/files/1832974

      Your link to the file: http://www.savefile.com/files/1832975

      Your link to the file: http://www.savefile.com/files/1832976

      Hope this is what you need and thank you for your time
      Eagle

      NNEagle

        Topic Starter


        Beginner

        Thanked: 1
        Re: C drive display
        « Reply #3 on: October 12, 2008, 04:44:09 PM »
        Here are my logs
        Malwarebytes' Anti-Malware 1.28
        Database version: 1253
        Windows 5.1.2600 Service Pack 3

        10/11/2008 8:14:07 AM
        mbam-log-2008-10-11 (08-14-07).txt

        Scan type: Quick Scan
        Objects scanned: 53579
        Time elapsed: 4 minute(s), 9 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        (No malicious items detected)
        SUPERAntiSpyware Scan Log
        http://www.superantispyware.com

        Generated 10/11/2008 at 07:43 AM

        Application Version : 4.21.1004

        Core Rules Database Version : 3594
        Trace Rules Database Version: 1581

        Scan type       : Complete Scan
        Total Scan Time : 00:44:14

        Memory items scanned      : 373
        Memory threats detected   : 0
        Registry items scanned    : 5289
        Registry threats detected : 0
        File items scanned        : 41173Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 6:30:13 PM, on 10/11/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\WINDOWS\system32\CTsvcCDA.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\MsPMSPSv.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\WINDOWS\system32\igfxtray.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\CTHELPER.EXE
        C:\Program Files\TweakNow PowerPack Pro\VirDesk.exe
        C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\SearchProtocolHost.exe
        C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hotmail.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
        O4 - HKLM\..\Run: [VirtualDesk] C:\Program Files\TweakNow PowerPack Pro\VirDesk.exe
        O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
        O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - Global Startup: AutorunsDisabled
        O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
        O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{FD2B188B-527C-47DE-884F-C1CEEDEEA75D}: NameServer = 202.54.6.60,202.54.29.5
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - AppInit_DLLs: avgrsstx.dll
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

        --
        End of file - 5882 bytes

        File threats detected     : 0



        Eagle

        m_elashry74

        • Guest
        Re: C drive display
        « Reply #4 on: October 13, 2008, 01:04:58 PM »
        WHAT CAN I DO

        NNEagle

          Topic Starter


          Beginner

          Thanked: 1
          Re: C drive display
          « Reply #5 on: October 13, 2008, 01:30:54 PM »
          Don't  understand that question. I am trying to get someone to tell me something and would appreciate the help and time taken
          Eagle

          Carbon Dudeoxide

          • Global Moderator

          • Mastermind
          • Thanked: 169
            • Yes
            • Yes
            • Yes
          • Certifications: List
          • Experience: Guru
          • OS: Mac OS
          Re: C drive display
          « Reply #6 on: October 14, 2008, 02:40:36 AM »
          WHAT CAN I DO
          What???

          NNEagle, one of our Malware Specialists will be along shortly ;)

          CBMatt

          • Mod & Malware Specialist


          • Prodigy

          • Sad and lonely...and loving every minute of it.
          • Thanked: 167
            • Yes
          • Experience: Experienced
          • OS: Windows 7
          Re: C drive display
          « Reply #7 on: October 20, 2008, 07:34:20 PM »
          Sorry for the long wait, NNEagle.  Things have been busy and we're stretched pretty thin here right now.  If you still need help with this computer, please take a look at this thread and post a new HJT log along with the requested SAS and MBAM logs...
          http://www.computerhope.com/forum/index.php/topic,46313.0.html

          I know you posted a couple of logs already, but malware evolves and grows, so if this is a virus issue, we need to see if your situation has changed.  Also, I see that you have TweakNow installed on your computer.  I'm not entirely familiar with this program, but I'm wondering...how long have you had this installed?  Tweaking software is always a bit fishy to me.
          Quote
          An undefined problem has an infinite number of solutions.
          —Robert A. Humphrey

          NNEagle

            Topic Starter


            Beginner

            Thanked: 1
            Re: C drive display
            « Reply #8 on: October 22, 2008, 04:58:49 AM »
            Thank you. Currently I am not home but will be there in a day or two. Will do as you have asked me to and will re post the logs. Will remove that tweak software. Not used it in a long time.
            Eagle

            CBMatt

            • Mod & Malware Specialist


            • Prodigy

            • Sad and lonely...and loving every minute of it.
            • Thanked: 167
              • Yes
            • Experience: Experienced
            • OS: Windows 7
            Re: C drive display
            « Reply #9 on: October 22, 2008, 08:43:01 PM »
            Alrighty, I will await your next reply.  And you can expect a faster response from the malware team this time.
            Quote
            An undefined problem has an infinite number of solutions.
            —Robert A. Humphrey

            NNEagle

              Topic Starter


              Beginner

              Thanked: 1
              Re: C drive display
              « Reply #10 on: October 23, 2008, 07:37:18 PM »
              I could not uninstall Tweaknow Powerpack fully.There is a prog attached to this called VirDesk which does not allow me to delete.

              Here are my logs:-

              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 10/24/2008 at 06:20 AM

              Application Version : 4.21.1004

              Core Rules Database Version : 3607
              Trace Rules Database Version: 1593

              Scan type       : Complete Scan
              Total Scan Time : 00:52:03

              Memory items scanned      : 397
              Memory threats detected   : 0
              Registry items scanned    : 5312
              Registry threats detected : 0
              File items scanned        : 47453
              File threats detected     : 0

              Malwarebytes' Anti-Malware 1.30
              Database version: 1311
              Windows 5.1.2600 Service Pack 3

              10/24/2008 6:40:00 AM
              mbam-log-2008-10-24 (06-40-00).txt

              Scan type: Quick Scan
              Objects scanned: 55137
              Time elapsed: 4 minute(s), 45 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 0
              Registry Values Infected: 0
              Registry Data Items Infected: 0
              Folders Infected: 0
              Files Infected: 0

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              (No malicious items detected)

              Registry Values Infected:
              (No malicious items detected)

              Registry Data Items Infected:
              (No malicious items detected)

              Folders Infected:
              (No malicious items detected)

              Files Infected:
              (No malicious items detected)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 6:56:44 AM, on 10/24/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16735)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              C:\WINDOWS\system32\CTsvcCDA.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\MsPMSPSv.exe
              C:\WINDOWS\system32\SearchIndexer.exe
              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\igfxtray.exe
              C:\WINDOWS\system32\hkcmd.exe
              C:\WINDOWS\system32\CTHELPER.EXE
              C:\Program Files\TweakNow PowerPack Pro\VirDesk.exe
              C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
              C:\PROGRA~1\AVG\AVG8\avgtray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\WINDOWS\system32\sol.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hotmail.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
              O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
              O4 - HKLM\..\Run: [VirtualDesk] C:\Program Files\TweakNow PowerPack Pro\VirDesk.exe
              O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
              O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - Global Startup: AutorunsDisabled
              O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
              O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
              O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{FD2B188B-527C-47DE-884F-C1CEEDEEA75D}: NameServer = 202.54.6.60,202.54.29.5
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O20 - AppInit_DLLs: avgrsstx.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

              --
              End of file - 6473 bytes



              Eagle

              CBMatt

              • Mod & Malware Specialist


              • Prodigy

              • Sad and lonely...and loving every minute of it.
              • Thanked: 167
                • Yes
              • Experience: Experienced
              • OS: Windows 7
              Re: C drive display
              « Reply #11 on: October 24, 2008, 02:17:15 AM »
              I wouldn't worry about the TweakNow at the moment.  There aren't too many results, but your issue definitely does appear to be part of an infection.  I currently can't find much about a successful removal of this particular infection, but let's give this a try...

              Run the Kaspersky Online Scanner

              In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

              • Click on SCAN NOW
              • Click Accept.
              • The program will then begin downloading the latest definition files.
              • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
              • The scan will take a while, so be patient and let it finish.
              .
              When the scan is done, in the Scan is complete window, any infection is displayed.
              There is no option to clean/disinfect, however, we need to analyze the information on the report.

              To obtain the report:
              Click on: Save Report As
              • Next, in the Save as prompt, Save in area, select: Desktop.
              • In the File name area use KScan, or something similar.
              • In Save as type: click the drop arrow and select: Text file [*.txt]
              • Then, click: Save


              Copy and paste the Kaspersky Online Scanner Report in your next reply.

              Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
              Quote
              An undefined problem has an infinite number of solutions.
              —Robert A. Humphrey

              NNEagle

                Topic Starter


                Beginner

                Thanked: 1
                Re: C drive display
                « Reply #12 on: October 24, 2008, 08:46:05 AM »

                Here is the results.Thanks for the help

                --------------------------------------------------------------------------------
                KASPERSKY ONLINE SCANNER 7 REPORT
                 Friday, October 24, 2008
                 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
                 Kaspersky Online Scanner 7 version: 7.0.25.0
                 Program database last update: Friday, October 24, 2008 11:13:08
                 Records in database: 1341958
                --------------------------------------------------------------------------------

                Scan settings:
                   Scan using the following database: extended
                   Scan archives: yes
                   Scan mail databases: yes

                Scan area - My Computer:
                   A:\
                   C:\
                   D:\
                   E:\

                Scan statistics:
                   Files scanned: 50973
                   Threat name: 1
                   Infected objects: 1
                   Suspicious objects: 0
                   Duration of the scan: 01:45:59


                File name / Threat name / Threats count
                C:\WINDOWS\system32\win.dll\reg.bkp\autorun.inf   Infected: Backdoor.Win32.Hupigon.cfeh   1

                The selected area was scanned.
                Eagle

                CBMatt

                • Mod & Malware Specialist


                • Prodigy

                • Sad and lonely...and loving every minute of it.
                • Thanked: 167
                  • Yes
                • Experience: Experienced
                • OS: Windows 7
                Re: C drive display
                « Reply #13 on: October 25, 2008, 12:51:47 AM »
                I could be wrong, but I believe the file found by Kaspersky is related to your issue.  Was it removed?  If not, you may need to boot into Safe Mode, enable hidden files and folders, and delete C:\WINDOWS\system32\win.dll.  Or if the file was already removed...has your C drive's label gone back to normal?
                Quote
                An undefined problem has an infinite number of solutions.
                —Robert A. Humphrey

                NNEagle

                  Topic Starter


                  Beginner

                  Thanked: 1
                  Re: C drive display
                  « Reply #14 on: October 25, 2008, 08:42:25 PM »
                  I could not find the file C:\WINDOWS\system32\win.dll. And nothing has changed.Tried to manually search as well as in the Search. No luck.
                  Eagle