Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Need advice before I can proceed  (Read 14859 times)

0 Members and 1 Guest are viewing this topic.

simplegirl

    Topic Starter


    Rookie

    Re: Need advice before I can proceed
    « Reply #15 on: January 28, 2010, 11:04:30 AM »
    It's running better than it was.  ;)

    What's next captain?

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Need advice before I can proceed
    « Reply #16 on: January 28, 2010, 11:06:01 AM »
    Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copy and pasting it into the reply.

    simplegirl

      Topic Starter


      Rookie

      Re: Need advice before I can proceed
      « Reply #17 on: January 28, 2010, 11:14:42 AM »

      UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT

      DDS (Ver_09-12-01.01)

      Microsoft Windows XP Home Edition
      Boot Device: \Device\HarddiskVolume1
      Install Date: 11/10/2005 5:43:03 PM
      System Uptime: 1/28/2010 11:40:33 AM (1 hours ago)

      Motherboard: Intel Corporation               |  | D845GVSR                       
      Processor:                 Intel(R) Celeron(R) CPU 2.26GHz | X1 | 2266/133mhz

      ==== Disk Partitions =========================

      A: is Removable
      C: is FIXED (NTFS) - 37 GiB total, 27.919 GiB free.
      D: is CDROM ()

      ==== Disabled Device Manager Items =============

      ==== System Restore Points ===================

      No restore point in system.

      ==== Installed Programs ======================

      7-Zip 4.57
      Acrobat.com
      Adobe AIR
      Adobe Download Manager
      Adobe Flash Player 10 ActiveX
      Adobe Flash Player 10 Plugin
      Adobe Reader 9
      Apple Software Update
      AVG Free 9.0
      CCleaner
      CleanUp!
      Critical Update for Windows Media Player 11 (KB959772)
      Data Lifeguard
      Defraggler (remove only)
      DupeFree Pro
      FileZilla Client 3.3.0.1
      HighMAT Extension to Microsoft Windows XP CD Writing Wizard
      HijackThis 2.0.2
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
      Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
      Hotfix for Windows Internet Explorer 7 (KB947864)
      Hotfix for Windows Media Format 11 SDK (KB929399)
      Hotfix for Windows Media Format SDK (KB902344)
      Hotfix for Windows Media Player 11 (KB939683)
      Hotfix for Windows XP (KB952287)
      Hotfix for Windows XP (KB954550-v5)
      Hotfix for Windows XP (KB961118)
      Hotfix for Windows XP (KB970653-v3)
      Hotfix for Windows XP (KB976098-v2)
      Intel Application Accelerator
      Intel(R) 536EP Modem
      Intel(R) Extreme Graphics Driver Software
      Intel(R) PRO Network Adapters and Drivers
      J2SE Runtime Environment 5.0 Update 10
      J2SE Runtime Environment 5.0 Update 5
      Lexmark 6200 Series
      Lexmark Fax Solutions
      Macromedia Flash Player
      Malwarebytes' Anti-Malware
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Security Update (KB953297)
      Microsoft .NET Framework 2.0 Service Pack 2
      Microsoft .NET Framework 3.0 Service Pack 2
      Microsoft .NET Framework 3.5 SP1
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft National Language Support Downlevel APIs
      Microsoft OpenType Font File Properties Extension
      Microsoft Silverlight
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Works 7.0
      Mozilla Firefox (3.5.7)
      MSXML 4.0 SP2 (KB925672)
      MSXML 4.0 SP2 (KB927978)
      MSXML 4.0 SP2 (KB936181)
      MSXML 4.0 SP2 (KB954430)
      MSXML 4.0 SP2 (KB973688)
      MSXML 4.0 SP2 Parser and SDK
      Nero Digital
      Nero Media Player
      Nero OEM
      Nikon Message Center
      NTREGOPT 1.1j
      Prism Video Converter
      QuickBooks Simple Start Edition
      QuickTime
      Realtek AC'97 Audio
      Security Update for Windows Internet Explorer 7 (KB938127)
      Security Update for Windows Internet Explorer 7 (KB942615)
      Security Update for Windows Internet Explorer 7 (KB944533)
      Security Update for Windows Internet Explorer 7 (KB953838)
      Security Update for Windows Internet Explorer 7 (KB956390)
      Security Update for Windows Internet Explorer 7 (KB958215)
      Security Update for Windows Internet Explorer 7 (KB960714)
      Security Update for Windows Internet Explorer 7 (KB961260)
      Security Update for Windows Internet Explorer 7 (KB974455)
      Security Update for Windows Internet Explorer 7 (KB976325)
      Security Update for Windows Internet Explorer 7 (KB978207)
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player (KB952069)
      Security Update for Windows Media Player (KB954155)
      Security Update for Windows Media Player (KB968816)
      Security Update for Windows Media Player (KB973540)
      Security Update for Windows Media Player 10 (KB911565)
      Security Update for Windows Media Player 10 (KB917734)
      Security Update for Windows Media Player 11 (KB936782)
      Security Update for Windows Media Player 11 (KB954154)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows XP (KB923561)
      Security Update for Windows XP (KB923689)
      Security Update for Windows XP (KB938464)
      Security Update for Windows XP (KB941569)
      Security Update for Windows XP (KB946648)
      Security Update for Windows XP (KB950762)
      Security Update for Windows XP (KB950974)
      Security Update for Windows XP (KB951066)
      Security Update for Windows XP (KB951376-v2)
      Security Update for Windows XP (KB951698)
      Security Update for Windows XP (KB952004)
      Security Update for Windows XP (KB952954)
      Security Update for Windows XP (KB953839)
      Security Update for Windows XP (KB954211)
      Security Update for Windows XP (KB954459)
      Security Update for Windows XP (KB954600)
      Security Update for Windows XP (KB955069)
      Security Update for Windows XP (KB956391)
      Security Update for Windows XP (KB956572)
      Security Update for Windows XP (KB956744)
      Security Update for Windows XP (KB956802)
      Security Update for Windows XP (KB956841)
      Security Update for Windows XP (KB956844)
      Security Update for Windows XP (KB957095)
      Security Update for Windows XP (KB957097)
      Security Update for Windows XP (KB958644)
      Security Update for Windows XP (KB958687)
      Security Update for Windows XP (KB958690)
      Security Update for Windows XP (KB958869)
      Security Update for Windows XP (KB959426)
      Security Update for Windows XP (KB960225)
      Security Update for Windows XP (KB960715)
      Security Update for Windows XP (KB960803)
      Security Update for Windows XP (KB960859)
      Security Update for Windows XP (KB961371-v2)
      Security Update for Windows XP (KB961501)
      Security Update for Windows XP (KB968537)
      Security Update for Windows XP (KB969059)
      Security Update for Windows XP (KB969947)
      Security Update for Windows XP (KB970238)
      Security Update for Windows XP (KB970430)
      Security Update for Windows XP (KB971486)
      Security Update for Windows XP (KB971557)
      Security Update for Windows XP (KB971633)
      Security Update for Windows XP (KB971657)
      Security Update for Windows XP (KB971961)
      Security Update for Windows XP (KB972270)
      Security Update for Windows XP (KB973354)
      Security Update for Windows XP (KB973507)
      Security Update for Windows XP (KB973525)
      Security Update for Windows XP (KB973869)
      Security Update for Windows XP (KB973904)
      Security Update for Windows XP (KB974112)
      Security Update for Windows XP (KB974318)
      Security Update for Windows XP (KB974392)
      Security Update for Windows XP (KB974571)
      Security Update for Windows XP (KB975025)
      Security Update for Windows XP (KB975467)
      SpywareBlaster 4.2
      SpywareGuard v2.2
      Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
      Update for Microsoft Windows (KB971513)
      Update for Windows XP (KB951072-v2)
      Update for Windows XP (KB951978)
      Update for Windows XP (KB955759)
      Update for Windows XP (KB955839)
      Update for Windows XP (KB967715)
      Update for Windows XP (KB968389)
      Update for Windows XP (KB971737)
      Update for Windows XP (KB973687)
      Update for Windows XP (KB973815)
      WebFldrs XP
      Windows Genuine Advantage Notifications (KB905474)
      Windows Genuine Advantage v1.3.0254.0
      Windows Genuine Advantage Validation Tool (KB892130)
      Windows Internet Explorer 7
      Windows Media Connect
      Windows Media Format 11 runtime
      Windows Media Format SDK Hotfix - KB891122
      Windows Media Player 11
      Windows XP Service Pack 3
      XMLinst
      ZoneAlarm

      ==== Event Viewer Messages From Past Week ========

      1/27/2010 12:43:01 AM, error: Service Control Manager [7034]  - The AVG Free E-mail Scanner service terminated unexpectedly.  It has done this 1 time(s).
      1/27/2010 12:43:01 AM, error: Service Control Manager [7031]  - The AVG Free WatchDog service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
      1/27/2010 10:19:30 PM, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.
      1/27/2010 10:19:29 PM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  atapi IntelIde PCIIde
      1/26/2010 5:01:34 PM, error: Service Control Manager [7023]  - The Application Management service terminated with the following error:  The specified module could not be found.
      1/26/2010 3:08:43 PM, error: Service Control Manager [7023]  - The HID Input Service service terminated with the following error:  The system cannot find the file specified.
      1/26/2010 3:08:42 PM, error: Service Control Manager [7023]  - The IPSEC Services service terminated with the following error:  The authentication service is unknown.
      1/26/2010 2:56:09 PM, error: Dhcp [1002]  - The IP address lease 10.0.0.141 for the Network Card with network address 0013209C1FDC has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).

      ==== End Of File ===========================



      DDS (Ver_09-12-01.01) - NTFSx86 
      Run by Carey at 12:10:27.62 on Thu 01/28/2010
      Internet Explorer: 7.0.5730.13
      Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1015.619 [GMT -6:00]

      AV: Authentium Antivirus *On-access scanning disabled* (Outdated)   {A4E803B3-4E6E-4271-B1CD-56FBC0992D36}
      AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)   {17DDD097-36FF-435F-9E1B-52D74245D6BF}
      FW: ZoneAlarm Firewall *enabled*   {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
      FW: COMODO Firewall Pro *enabled*   {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

      ============== Running Processes ===============

      C:\WINDOWS\system32\svchost -k DcomLaunch
      svchost.exe
      C:\WINDOWS\System32\svchost.exe -k netsvcs
      svchost.exe
      C:\Program Files\AVG\AVG9\avgchsvx.exe
      C:\Program Files\AVG\AVG9\avgrsx.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\AVG\AVG9\avgcsrvx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\AVG\AVG9\avgwdsvc.exe
      C:\WINDOWS\system32\svchost.exe -k imgsvc
      C:\Program Files\AVG\AVG9\avgemc.exe
      C:\Program Files\AVG\AVG9\avgnsx.exe
      C:\Program Files\AVG\AVG9\avgcsrvx.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\PROGRA~1\AVG\AVG9\avgtray.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      svchost.exe
      C:\Documents and Settings\Carey\Desktop\dds.pif

      ============== Pseudo HJT Report ===============

      uStart Page = hxxp://www.google.com/
      uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
      mWindow Title = Microsoft Internet Explorer provided by CenturyTel
      BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
      BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
      BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
      BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_10\bin\ssv.dll
      mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
      mRun: [LXBUCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBUtime.dll,_RunDLLEntry@16
      mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
      StartupFolder: c:\docume~1\carey\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
      Trusted Zone: microsoft.com\*.update
      Trusted Zone: microsoft.com\windowsupdate
      DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263950951187
      DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1263950666500
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
      DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
      DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
      Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
      Notify: avgrsstarter - avgrsstx.dll
      Notify: igfxcui - igfxsrvc.dll
      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
      SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
      SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File

      ================= FIREFOX ===================

      FF - ProfilePath - c:\docume~1\carey\applic~1\mozilla\firefox\profiles\krrd3s4l.default\
      FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
      FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava11.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava12.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava13.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava14.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJava32.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPJPI150_10.dll
      FF - plugin: c:\program files\java\jre1.5.0_10\bin\NPOJI610.dll
      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

      ---- FIREFOX POLICIES ----
      c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

      ============= SERVICES / DRIVERS ===============

      R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-20 333192]
      R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-20 28424]
      R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-20 360584]
      R1 KLIF;KLIF;c:\windows\system32\drivers\klif.sys [2008-2-24 127768]
      R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2008-2-24 394952]
      R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-1-20 906520]
      R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-20 285392]
      R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
      S3 AL_ADSFilter;AL_ADSFilter - (Aluria Filter Driver);c:\windows\system32\drivers\al_adsfilter.sys --> c:\windows\system32\drivers\AL_ADSFilter.sys [?]
      S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2004-6-24 26624]

      =============== Created Last 30 ================

      2010-01-28 17:38:37   0   d-----w-   C:\_OTM
      2010-01-25 22:55:18   21504   -c--a-w-   c:\windows\system32\dllcache\hidserv.dll
      2010-01-25 22:55:18   21504   ----a-w-   c:\windows\system32\hidserv.dll
      2010-01-25 22:55:14   14592   -c--a-w-   c:\windows\system32\dllcache\kbdhid.sys
      2010-01-25 22:55:14   14592   ----a-w-   c:\windows\system32\drivers\kbdhid.sys
      2010-01-21 05:37:18   0   d-sha-r-   C:\cmdcons
      2010-01-21 05:35:39   98816   ----a-w-   c:\windows\sed.exe
      2010-01-21 05:35:39   77312   ----a-w-   c:\windows\MBR.exe
      2010-01-21 05:35:39   261632   ----a-w-   c:\windows\PEV.exe
      2010-01-21 05:35:39   161792   ----a-w-   c:\windows\SWREG.exe
      2010-01-21 04:19:50   0   d--h--w-   C:\$AVG
      2010-01-21 04:19:30   360584   ----a-w-   c:\windows\system32\drivers\avgtdix.sys
      2010-01-21 04:19:30   12464   ----a-w-   c:\windows\system32\avgrsstx.dll
      2010-01-21 04:19:20   333192   ----a-w-   c:\windows\system32\drivers\avgldx86.sys
      2010-01-21 04:19:04   0   d-----w-   c:\windows\system32\drivers\Avg
      2010-01-21 04:18:44   0   d-----w-   c:\program files\AVG
      2010-01-21 04:18:42   0   d-----w-   c:\docume~1\alluse~1\applic~1\avg9
      2010-01-20 01:35:38   471552   -c----w-   c:\windows\system32\dllcache\aclayers.dll
      2010-01-20 01:30:44   15064   ----a-w-   c:\windows\system32\wuapi.dll.mui
      2010-01-05 17:55:53   0   d-----w-   c:\docume~1\carey\applic~1\NCH Software
      2010-01-05 17:36:55   0   d-----w-   c:\program files\NCH Software

      ==================== Find3M  ====================

      2010-01-28 18:10:25   152016928   --sha-w-   c:\windows\system32\drivers\fidbox.dat
      2010-01-28 17:40:22   1783304   --sha-w-   c:\windows\system32\drivers\fidbox.idx
      2010-01-07 22:07:14   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
      2010-01-07 22:07:04   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
      2010-01-05 10:00:29   832512   ----a-w-   c:\windows\system32\wininet.dll
      2010-01-05 10:00:21   78336   ----a-w-   c:\windows\system32\ieencode.dll
      2010-01-05 10:00:20   17408   ----a-w-   c:\windows\system32\corpol.dll
      2006-02-15 05:05:48   532480   ----a-w-   c:\program files\CWShredder.exe
      2008-09-19 04:14:28   16384   --sha-w-   c:\windows\system32\config\systemprofile\cookies\index.dat
      2008-09-19 04:14:28   32768   --sha-w-   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
      2008-06-21 01:47:42   32768   --sha-w-   c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008062020080621\index.dat

      ============= FINISH: 12:11:57.32 ===============
      « Last Edit: January 28, 2010, 11:22:21 AM by evilfantasy »

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Need advice before I can proceed
      « Reply #18 on: January 28, 2010, 11:21:39 AM »
      Looks good. Just some updating and finishing steps.


      Your Java is out of date.
       
      Older versions have vulnerabilities that malicious sites can use to infect your system.
       
      First install the new Sun Java Runtime Environment

      Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

      Be sure to close all browser windows before beginning the install.
       
      Remove the old version(s)
       
      Download JavaRa
      * Unzip the file and open the JavaRa.exe
      * Click Remove Older Versions
      * JavaRa will search for and remove any outdated version of Java and remove any that are found.
      * Click Additional Tasks
      * Place a check next to Remove Useless JRE Files and click Go
      * Exit JavaRa
      * Delete the JavaRa files from the desktop

      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

      ----------

      1. Double click OTM to launch it.
      Vista users right click and choose Run As Administrator
      2. Click on the CleanUp! button.
      3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
      4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
      • When finished exit out of OTM
      .
      ----------

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan.

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

      simplegirl

        Topic Starter


        Rookie

        Re: Need advice before I can proceed
        « Reply #19 on: January 28, 2010, 12:24:33 PM »
        I got as far as the OTM Cleanup.

        Internet connection is starting to freeze up now. It's taken me 15 minutes to finally get to post this. I've never had any problems with my dsl connection. It will run for about a minute then locks up.

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Need advice before I can proceed
        « Reply #20 on: January 28, 2010, 12:27:41 PM »
        Have you called your ISP to have them check your connection?

        simplegirl

          Topic Starter


          Rookie

          Re: Need advice before I can proceed
          « Reply #21 on: January 28, 2010, 12:35:14 PM »
          It's not in the internet connection. I hooked up an older computer I have here and the internet is working fine on it. Hooked this one back up and it started freezing up. It's never done that before.

          I'm still trying to do the secunia scan but it's hanging saying loading java applet.

          Should I do an avg scan to see if those trojans are still on this?


          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Need advice before I can proceed
          « Reply #22 on: January 28, 2010, 12:38:55 PM »
          What browser are you using with Secunia?

          Is this an old computer? Have you checked that everything is plugged in securely? Or tried unplugging everything but the mouse and keyboard?

          simplegirl

            Topic Starter


            Rookie

            Re: Need advice before I can proceed
            « Reply #23 on: January 28, 2010, 12:44:54 PM »
            I don't understand what you're asking. This computer that we're working with is not all that old. The internet just starting locking up on it.

            I disconnected and hooked up old computer and it worked fine. Hooked this one back up and internet connection locks up. Hooked old computer back up and internet works fine. Hook this computer back up again and internet is locking up.

            I don't think it's any connections or it wouldn't work with the old one?


            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Need advice before I can proceed
            « Reply #24 on: January 28, 2010, 12:47:37 PM »
            It sounds like there is something wrong with the computer. (obviously) But what... I have no idea.

            You can run AVG again for a double check. If it does find anything let me know the location that it is reporting.

            simplegirl

              Topic Starter


              Rookie

              Re: Need advice before I can proceed
              « Reply #25 on: January 28, 2010, 02:02:39 PM »
              Okay.....I disabled internet explorer add ons 1 at a time and when I disabled
              SpywareGuardDLBLOCK.CBrowserHelper I haven't had any trouble with my connection. Maybe SpywareGuard is finding something that's not right?

              I had 3 programs that Secunia found that needed to be updated.
              Adobe Reader
              Apple Quicktime
              Adobe Acrobat Reader (when I tried to update this, it went to the exact same download as Adobe Reader which had just been updated) so I didn't update that one. Adobe uninstalled that anyway when it updated the first one.

              Ok, I'm gonna do a scan with AVG here shortly. It takes a long time for that to complete so I might not hear back from you until tomorrow or so.

              I did have a couple quick questions. I am using Zone Alarm and I don't allow any programs to access the internet without my approval first. The only things I give internet access to without permission are

              Generic Host Process for Win32 Services
              Internet Explorer


              Is that wrong? Is Zone Alarm even worth having?

              Last question. Quicktime and java put themselves in my startup services. Can I safely uncheck them to not launch at startup or do you recommend I keep it as is.

              Crossing my fingers AVG scan finds nothing.

              Thank you so much.

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Need advice before I can proceed
              « Reply #26 on: January 28, 2010, 02:28:02 PM »
              Nice investigation!  ;) Spyware Guard is actually very dated and has not updated in many years, not that it needs to, but uninstalling it will not be a big deal.

              Use Revo to uninstall Adobe Reader and Adobe Acrobat Reader.

              Download Revo Uninstaller

              * Open Revo and let the list populate (can take several seconds to finish).
              * Right click what you want to uninstall and choose Uninstall
              * Next choose Advanced then click Next
              * This will (try to) launch the programs built in uninstaller and go through the normal uninstall process.
              * If the uninstaller fails just continue on with the Revo instructions.
              * Once complete: In Revo Uninstaller click Next and Revo will scan the registry for leftovers.
              * This scan can take several seconds.
              * Once the results are shown look at each one to ensure they are all related to the program that was uninstalled.
              * Choose Select All then click Delete
              * Click Next and Revo will scan for any files or folders that were not removed.
              * If any files/folders are found choose Select all > Delete

              Now install the new version of the Adobe Reader. http://get.adobe.com/reader/

              Important Note: Be sure to uncheck Free McAfee Security Scan Plus (optional) before installing the Adobe Reader.

              ----------

              Quote
              Generic Host Process for Win32 Services
              Internet Explorer

              Is that wrong? Is Zone Alarm even worth having?

              Yes ZA is good but allowing 'Generic Host Process for Win32 Services' is probably not the best idea. malware can easily exploit that.

              ----------

              Quote
              Last question. Quicktime and java put themselves in my startup services. Can I safely uncheck them to not launch at startup or do you recommend I keep it as is.

              Run a new HijackThis scan and post the log please.

              simplegirl

                Topic Starter


                Rookie

                Re: Need advice before I can proceed
                « Reply #27 on: January 28, 2010, 02:44:21 PM »
                I downloaded Revo and the old adobe acrobat reader wasn't there. It surprised me that adobe uninstalled the old versions on it's own. Here's the latest HJT log.

                Argh...I still haven't scanned with avg yet.

                Code: [Select]
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 3:41:07 PM, on 1/28/2010
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16981)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\AVG\AVG9\avgchsvx.exe
                C:\Program Files\AVG\AVG9\avgrsx.exe
                C:\Program Files\AVG\AVG9\avgcsrvx.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\AVG\AVG9\avgwdsvc.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\AVG\AVG9\avgemc.exe
                C:\Program Files\AVG\AVG9\avgnsx.exe
                C:\Program Files\AVG\AVG9\avgcsrvx.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\wscntfy.exe
                C:\PROGRA~1\AVG\AVG9\avgtray.exe
                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\Documents and Settings\Carey\Desktop\HijackThis.exe

                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
                O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                O4 - HKLM\..\Run: [LXBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16
                O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263950951187
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1263950666500
                O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
                O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
                O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
                O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                --
                End of file - 4070 bytes

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: Need advice before I can proceed
                « Reply #28 on: January 28, 2010, 02:58:04 PM »
                Quote
                Argh...I still haven't scanned with avg yet.

                Don't worry. I don't think it will find much, if anything.

                Unnecessary startups.

                Open HijackThis and select Do a system scan only

                Place a check mark next to the following entries: (if there)

                • O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Common Files\Java\Java Update\jusched.exe\"
                • O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] \"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe\"
                • O4 - HKLM\..\Run: [Adobe ARM] \"C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe\"
                • O4 - HKLM\..\Run: [QuickTime Task] \"C:\Program Files\QuickTime\QTTask.exe\" -atboottime
                .
                Important: Close all open windows except for HijackThis and then click Fix checked.

                Once completed, exit HijackThis.

                ----------

                To disable the Java Quick Starter, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

                simplegirl

                  Topic Starter


                  Rookie

                  Re: Need advice before I can proceed
                  « Reply #29 on: January 29, 2010, 08:22:00 AM »
                  Well, did a full system scan with AVG and it found another nasty Trojan. It was called

                  Trojan . EvilFantasyIsAStudMuffin    ;D


                  You were right! AVG found nothing. YeeHaww!!!!!


                  Only question I have left is what do I do with the TFC program that's still on my desktop?

                  Thank you so much! I'm a happy camper today.  ;)