Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Windows Security Center Virus  (Read 39427 times)

0 Members and 1 Guest are viewing this topic.

arwest

    Topic Starter


    Rookie

    Windows Security Center Virus
    « on: May 01, 2008, 08:06:30 PM »
    I have a HP Pavilion Computer running Microsoft XP. When I turned on my compute this morning a Windows Security Center box popped up telling me I was not protected with anitvirus and spyware, even though I have norton antivirus, webroot spyware and adaware, which are all run regularly. When I clicked on the Windows Security box to install, my Norton blocked it and labeled it a virus. After running all my anitvirus and several spyware programs, I cannot get rid of this. It continues to pop up boxes telling me to click on the security button on my taskbar and download.

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: Windows Security Center Virus
    « Reply #1 on: May 01, 2008, 08:22:43 PM »
    Quote
    Windows Security Center box popped up
    Most likely, fake warning...

    Print these instructions out.

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.

    arwest

      Topic Starter


      Rookie

      Re: Windows Security Center Virus
      « Reply #2 on: May 02, 2008, 01:02:17 PM »
      So I have spent all night and morning trying to run the spyware... my computer keeps crashing in the middle of the scans. Here are the error messages I am getting:

      This pops up first, but doesn't shut the computer down. I just click o.k.:
      IE7 Explorer.exe Instruction at 0x0lcf34739 referenced memory at 0x02df2e50. memory could not be read.

      Then later, this one pops up and shuts the computer down:
      System Unstable. Problem detected with windows. Shutdown buggy application to prevent damage. Kernel 32x.sys- address 0xA73C20AE base error code C03200, Date Stamp 566836A3. Kernel Debugger port Com3.

      With the SuperAntiSpyware, I paused the scan after it detected a few things and cleaned them out, but never got through a full scan. Here is the log from 2 "short"scans:

      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 05/02/2008 at 07:17 AM

      Application Version : 4.0.1154

      Core Rules Database Version : 3451
      Trace Rules Database Version: 1443

      Scan type       : Complete Scan
      Total Scan Time : 00:09:16

      Memory items scanned      : 560
      Memory threats detected   : 0
      Registry items scanned    : 6297
      Registry threats detected : 0
      File items scanned        : 4363
      File threats detected     : 123

      Adware.Tracking Cookie
         C:\Documents and Settings\Owner\Cookies\owner@insightexpress[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][3].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@bestsextoyreview[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@partner2profit[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@deadnetstore[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@windowsmedia[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@superstats[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@findarticles[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@bridgetrack[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@clickbank[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@centralmediaserver[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@qnsr[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@oddcast[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@clickaction[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@mrdealfinder[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@sixteenfeet[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@kanoodle[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@summitcounty[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@couponmountain[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@mediafire[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@eyewonder[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@mindmedia[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@lynxtrack[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected]
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@crossmediaservices[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][5].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@media6degrees[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@xxxtoyguide[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@2o7[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@collective-media[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@thefind[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@clicksmartaffiliates[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@countrymusichalloffame[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@statcounter[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@amazingadult[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@apmebf[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][3].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][4].txt
         C:\Documents and Settings\Owner\Cookies\owner@interclick[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@highcountrygardens[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][6].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@specificclick[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@optimost[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][3].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt

      #2SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 05/02/2008 at 07:24 AM

      Application Version : 4.0.1154

      Core Rules Database Version : 3451
      Trace Rules Database Version: 1443

      Scan type       : Complete Scan
      Total Scan Time : 00:05:08

      Memory items scanned      : 563
      Memory threats detected   : 0
      Registry items scanned    : 6297
      Registry threats detected : 0
      File items scanned        : 835
      File threats detected     : 9

      Adware.Tracking Cookie
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
         C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
         C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[2].txt
         C:\Documents and Settings\Owner\Cookies\owner@specificclick[1].txt
         C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt
         C:\Documents and Settings\Owner\Cookies\[email protected][1].txt

      Same with the Malware- the computer reboots before the scan finishes, so I don't have any logs on that one.

      Will post Hijack Log next.

      Thanks




      arwest

        Topic Starter


        Rookie

        Re: Windows Security Center Virus
        « Reply #3 on: May 02, 2008, 01:03:24 PM »
        Here is the HiJack Log:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 12:32:28 PM, on 5/2/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\WINDOWS\System32\gearsec.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
        C:\Program Files\Canon\CAL\CALMAIN.exe
        C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
        C:\windows\system\hpsysdrv.exe
        C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
        C:\WINDOWS\System32\hphmon05.exe
        C:\HP\KBD\KBD.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\AGRSMMSG.exe
        C:\WINDOWS\ALCXMNTR.EXE
        C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
        C:\Program Files\Yapta\YaptaClient.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Program Files\QuickTime\QTTask.exe
        C:\Program Files\DropBox\DropBox\DropBox.exe
        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
        C:\Program Files\Upromise\Upromise.exe
        C:\Program Files\Upromise\UpromiseUa.exe
        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\PIXELA\ImageMixer3\HDDCameraMonitor.exe
        C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Southwest Airlines\Ding\Ding.exe
        C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
        C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
        O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
        O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
        O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
        O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
        O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetect
        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
        O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
        O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
        O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s
        O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
        O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
        O4 - HKCU\..\Run: [Upromise] "C:\Program Files\Upromise\Upromise.exe"
        O4 - HKCU\..\Run: [Upromise Update] "C:\Program Files\Upromise\UpromiseUa.exe"
        O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
        O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
        O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: FLAC
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O4 - Global Startup: ImageMixer HDD Camera Monitor.lnk = ?
        O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
        O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
        O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
        O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
        O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
        O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
        O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
        O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
        O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
        O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
        O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
        O20 - Winlogon Notify: wmpefhkv - C:\WINDOWS\SYSTEM32\wmpefhkv.dll
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
        O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
        O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

        --
        End of file - 12845 bytes

        I have also run the SmitFraudFix program, do you want that log as well?

        Thanks so much!

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Windows Security Center Virus
        « Reply #4 on: May 02, 2008, 07:17:45 PM »
        Before I proceed any further, couple of questions.
        1. I can see some Symantec services running, but I can't see any ACTIVE antivirus, or firewall. What's the situation here?
        2. At what point are you getting IE error, and then Windows error?
        3. Superantispyware is supposed to be run from Safe Mode. Did you run it from Safe Mode?

        arwest

          Topic Starter


          Rookie

          Re: Windows Security Center Virus
          « Reply #5 on: May 02, 2008, 07:45:34 PM »
          1. When I open Norton Protection Center Window, all areas are showing a green secure label and stated active. Is there more to it???

          2. The error messages seem to be random, maybe more like a timing issue instead of the actions I am performing. My computer has been shutting down and rebooting itself all day, seemingly sometime between 1-2 hours.

          3. Yes, I ran the superantispyware from safe mode and the computer still closed down. Also, the Security center window pops up and  the shield appears in the icon taskbar during safe mode.

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Windows Security Center Virus
          « Reply #6 on: May 02, 2008, 07:50:26 PM »
          If you go to Security Center: http://www.microsoft.com/windowsxp/using/security/internet/sp2_wscintro.mspx
          are firewall, and antivirus listed as ON?

          arwest

            Topic Starter


            Rookie

            Re: Windows Security Center Virus
            « Reply #7 on: May 02, 2008, 08:19:43 PM »
            The Firewall is Off. There is no mention of antivirus but, under "Security Essentials" is the following message:

            The Security Center is currently unavailable because the "Security Center" service has not started or has stopped. Please close this window, restart the computer (or start the "Security Center" service), and then open the Security Center again.

            I restarted the computer and opened windows security center again and got the same message.

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: Windows Security Center Virus
            « Reply #8 on: May 02, 2008, 08:47:30 PM »
            Go Start>Run, type in:
            services.msc
            Click OK.
            Is Security Center listed as Started, and set to Automatic startup?

            arwest

              Topic Starter


              Rookie

              Re: Windows Security Center Virus
              « Reply #9 on: May 02, 2008, 10:05:53 PM »
              it is listed as disabled

              arwest

                Topic Starter


                Rookie

                Re: Windows Security Center Virus
                « Reply #10 on: May 02, 2008, 10:11:52 PM »
                I restarted the security center and it is now set to automatic. Then went into the windows security center (through the control panel) and it is now listing Firewall, Automatic Updates, and Virus Protection as on.

                Broni


                  Mastermind
                • Kraków my love :)
                • Thanked: 614
                  • Computer Help Forum
                • Computer: Specs
                • Experience: Experienced
                • OS: Windows 8
                Re: Windows Security Center Virus
                « Reply #11 on: May 02, 2008, 10:42:28 PM »
                Very good. Give me new HJT log.

                arwest

                  Topic Starter


                  Rookie

                  Re: Windows Security Center Virus
                  « Reply #12 on: May 03, 2008, 07:51:46 AM »
                  This morning after turning the computer on, the security center was disabled again. I have restarted it again. Then ran HJT. Here is the log:


                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 7:49:55 AM, on 5/3/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                  C:\windows\system\hpsysdrv.exe
                  C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                  C:\WINDOWS\System32\hphmon05.exe
                  C:\HP\KBD\KBD.EXE
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                  C:\WINDOWS\ALCXMNTR.EXE
                  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                  C:\Program Files\Yapta\YaptaClient.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  C:\Program Files\QuickTime\QTTask.exe
                  C:\Program Files\DropBox\DropBox\DropBox.exe
                  C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Upromise\Upromise.exe
                  C:\Program Files\Upromise\UpromiseUa.exe
                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\WINDOWS\System32\gearsec.exe
                  C:\WINDOWS\System32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                  C:\Program Files\Canon\CAL\CALMAIN.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\PIXELA\ImageMixer3\HDDCameraMonitor.exe
                  C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
                  C:\Program Files\Southwest Airlines\Ding\Ding.exe
                  C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                  O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                  O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                  O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                  O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                  O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                  O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                  O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
                  O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                  O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetect
                  O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                  O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
                  O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                  O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                  O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
                  O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s
                  O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
                  O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                  O4 - HKCU\..\Run: [Upromise] "C:\Program Files\Upromise\Upromise.exe"
                  O4 - HKCU\..\Run: [Upromise Update] "C:\Program Files\Upromise\UpromiseUa.exe"
                  O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
                  O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                  O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: FLAC
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: ImageMixer HDD Camera Monitor.lnk = ?
                  O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                  O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                  O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                  O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                  O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                  O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                  O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                  O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                  O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                  O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                  O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                  O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O20 - Winlogon Notify: wmpefhkv - C:\WINDOWS\SYSTEM32\wmpefhkv.dll
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                  O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                  O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                  O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                  O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                  O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                  --
                  End of file - 12808 bytes

                  thanks for all your help!

                  Broni


                    Mastermind
                  • Kraków my love :)
                  • Thanked: 614
                    • Computer Help Forum
                  • Computer: Specs
                  • Experience: Experienced
                  • OS: Windows 8
                  Re: Windows Security Center Virus
                  « Reply #13 on: May 03, 2008, 12:06:21 PM »
                  *** Until we fix your problem, make sure, that after each restart you go to services.msc and start Security Center service manually.

                  *** You need to update your Java:
                  http://java.sun.com/javase/downloads/index.jsp
                  Java Runtime Environment (JRE) 6 Update 6
                  Uninstall all previous versions of Java through Add\Remove.

                  *** Go Start>Control Panel\Add\Remove, and uninstall BackWeb (if listed)

                  1. Print this post out, since you won't have an access to it, at some point.

                  2. Close all windows, except for HijackThis.

                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                  - *O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                  - *O4 - HKLM\..\Run: [HPHUPD05] "c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe"
                  - *O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
                  - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  - *O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  - *O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetect
                  - O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                  - *O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb08.exe
                  - *O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
                  - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  - *O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s
                  - *O4 - HKCU\..\Run: [Upromise] "C:\Program Files\Upromise\Upromise.exe"
                  - *O4 - HKCU\..\Run: [Upromise Update] "C:\Program Files\Upromise\UpromiseUa.exe"
                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] "C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe"
                  - *O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  - O4 - Global Startup: ImageMixer HDD Camera Monitor.lnk = ?
                  - O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  - O20 - Winlogon Notify: wmpefhkv - C:\WINDOWS\SYSTEM32\wmpefhkv.dll


                  4. Click on Fix checked button.

                  5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                  7. Delete following files/folders (if present):

                  - search your computer for ALCXMNTR.EXE, and delete it
                  - BackWeb-137903.exe from C:\Program Files\Updates from HP\137903\Program
                  - wmpefhkv.dll file from C:\WINDOWS\SYSTEM32

                  8. Restart in Normal Mode.

                  9. Post new HijackThis log.

                  arwest

                    Topic Starter


                    Rookie

                    Re: Windows Security Center Virus
                    « Reply #14 on: May 03, 2008, 02:00:31 PM »
                    There was no BackWeb program listed to uninstall.

                    There were 3 alcxmntr.exe files that were deleted, the backweb-137903.exe was deleted, but when I went to delete the wmpefhkv.dll a message popped up saying, "(It) cannot be deleted, access is denied. Make sure disk is not full or write-protected and that file is not in use."

                    Here is the HijackThis log:

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 1:53:56 PM, on 5/3/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\WINDOWS\System32\gearsec.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                    C:\Program Files\Canon\CAL\CALMAIN.exe
                    C:\windows\system\hpsysdrv.exe
                    C:\HP\KBD\KBD.EXE
                    C:\WINDOWS\AGRSMMSG.exe
                    C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                    C:\Program Files\Yapta\YaptaClient.exe
                    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    C:\Program Files\Southwest Airlines\Ding\Ding.exe
                    C:\Program Files\InterMute\IMStart.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                    O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                    O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                    O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
                    O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                    O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                    O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: FLAC
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                    O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                    O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                    O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                    O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                    O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                    O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                    O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                    O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                    O20 - Winlogon Notify: wmpefhkv - C:\WINDOWS\SYSTEM32\wmpefhkv.dll
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                    O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                    --
                    End of file - 10716 bytes

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Windows Security Center Virus
                    « Reply #15 on: May 03, 2008, 02:12:13 PM »
                    Good job :)

                    Go Start>Run, type in:
                    regedit
                    Click OK.

                    Registry Editor will open.
                    Navigate to:
                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
                    You'll see following sub-key:
                    wmpefhkv
                    Right click on it, click Delete.

                    Restart in Safe mode, and try deleting wmpefhkv.dll again.
                    If it'll let you, restart in Normal Mode, and post new HJT log.
                    If it won't, let me know.

                    arwest

                      Topic Starter


                      Rookie

                      Re: Windows Security Center Virus
                      « Reply #16 on: May 03, 2008, 02:39:50 PM »
                      When I delete the folder wmpefhkv, the computer gives me a critical error message then counts down and shuts the computer down. I restart it in safe mode and it won't let me delete wmpefhkv.dll .

                      Broni


                        Mastermind
                      • Kraków my love :)
                      • Thanked: 614
                        • Computer Help Forum
                      • Computer: Specs
                      • Experience: Experienced
                      • OS: Windows 8
                      Re: Windows Security Center Virus
                      « Reply #17 on: May 03, 2008, 03:21:36 PM »
                      Download Look2Me Remover: http://majorgeeks.com/Look2Me_Remover_d4856.html
                      Follow instructions from the above page.
                      When done, restart computer, and post new HJT log.

                      arwest

                        Topic Starter


                        Rookie

                        Re: Windows Security Center Virus
                        « Reply #18 on: May 03, 2008, 03:43:31 PM »
                        Look2me remover did not find any virus. still won't let me delete the wmpefhkv subkey- it shuts my computer down.

                        Here is the hijack log

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 3:41:03 PM, on 5/3/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\windows\system\hpsysdrv.exe
                        C:\HP\KBD\KBD.EXE
                        C:\WINDOWS\AGRSMMSG.exe
                        C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                        C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                        C:\Program Files\Yapta\YaptaClient.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        C:\Program Files\Southwest Airlines\Ding\Ding.exe
                        C:\Program Files\InterMute\IMStart.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        C:\WINDOWS\System32\gearsec.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                        C:\Program Files\Canon\CAL\CALMAIN.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                        O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                        O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                        O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                        O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                        O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                        O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                        O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                        O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
                        O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                        O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                        O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: FLAC
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                        O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                        O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                        O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                        O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                        O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                        O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                        O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                        O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                        O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                        O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O20 - Winlogon Notify: wmpefhkv - C:\WINDOWS\SYSTEM32\wmpefhkv.dll
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                        O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                        O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                        O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                        O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                        O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                        --
                        End of file - 10813 bytes

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: Windows Security Center Virus
                        « Reply #19 on: May 03, 2008, 04:02:04 PM »
                        We'll have to give it couple more tries...
                        Download, and install Unlocker: http://ccollomb.free.fr/unlocker/
                        It'll install under right click menu.
                        In Windows Explorer, navigate to C:\WINDOWS\SYSTEM32, and right click on wmpefhkv.dll.
                        Click Unlocker.
                        Select Delete from drop-down menu. It won't let you delete right away, but it'll give you an option to delete the file on reboot.
                        Select that option, restart computer, and post new HJT log.

                        arwest

                          Topic Starter


                          Rookie

                          Re: Windows Security Center Virus
                          « Reply #20 on: May 03, 2008, 04:41:47 PM »
                          Using the unlock, it let me delete the subkey immediately. Once deleted, the shield on my taskbar has disappeared and upon rebooting the windows security pop up has disappeared.

                          Here is the hijack log.

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 4:35:16 PM, on 5/3/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\System32\gearsec.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                          C:\Program Files\Canon\CAL\CALMAIN.exe
                          C:\windows\system\hpsysdrv.exe
                          C:\HP\KBD\KBD.EXE
                          C:\WINDOWS\AGRSMMSG.exe
                          C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                          C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                          C:\Program Files\Yapta\YaptaClient.exe
                          C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                          C:\Program Files\Unlocker\UnlockerAssistant.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          C:\Program Files\Southwest Airlines\Ding\Ding.exe
                          C:\Program Files\InterMute\IMStart.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                          O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                          O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                          O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                          O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                          O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                          O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                          O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
                          O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                          O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                          O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O4 - Global Startup: FLAC
                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                          O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                          O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                          O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                          O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                          O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                          O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                          O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                          O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                          O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                          O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O20 - Winlogon Notify: wmpefhkv - wmpefhkv.dll (file missing)
                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                          O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                          O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                          O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                          --
                          End of file - 10895 bytes

                          Broni


                            Mastermind
                          • Kraków my love :)
                          • Thanked: 614
                            • Computer Help Forum
                          • Computer: Specs
                          • Experience: Experienced
                          • OS: Windows 8
                          Re: Windows Security Center Virus
                          « Reply #21 on: May 03, 2008, 04:44:44 PM »
                          Open HJT one more time, and checkmark:
                          - O20 - Winlogon Notify: wmpefhkv - wmpefhkv.dll (file missing)
                          Click "Fix checked".
                          Restart computer.
                          Post new log.

                          arwest

                            Topic Starter


                            Rookie

                            Re: Windows Security Center Virus
                            « Reply #22 on: May 03, 2008, 05:06:23 PM »
                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 5:06:00 PM, on 5/3/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\WINDOWS\System32\gearsec.exe
                            C:\WINDOWS\System32\nvsvc32.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                            C:\Program Files\Canon\CAL\CALMAIN.exe
                            C:\windows\system\hpsysdrv.exe
                            C:\HP\KBD\KBD.EXE
                            C:\WINDOWS\AGRSMMSG.exe
                            C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                            C:\Program Files\Yapta\YaptaClient.exe
                            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                            C:\Program Files\Unlocker\UnlockerAssistant.exe
                            C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Southwest Airlines\Ding\Ding.exe
                            C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                            O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                            O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                            O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                            O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                            O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                            O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                            O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                            O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                            O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                            O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                            O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
                            O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                            O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                            O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: FLAC
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                            O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                            O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                            O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                            O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                            O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                            O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                            O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                            O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                            O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                            O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                            O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                            O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                            O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                            O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                            O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                            --
                            End of file - 10690 bytes

                            Broni


                              Mastermind
                            • Kraków my love :)
                            • Thanked: 614
                              • Computer Help Forum
                            • Computer: Specs
                            • Experience: Experienced
                            • OS: Windows 8
                            Re: Windows Security Center Virus
                            « Reply #23 on: May 03, 2008, 05:08:35 PM »
                            Very good :)

                            HJT log is clean.

                            1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                            Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                            Run CCleaner.

                            2. Turn off System Restore:

                            - Windows XP:
                               1. Click Start.
                               2. Right-click the My Computer icon, and then click Properties.
                               3. Click the System Restore tab.
                               4. Check "Turn off System Restore".
                               5. Click Apply.   
                               6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                               7. Click OK.
                            - Windows Vista:
                               1. Click Start.
                               2. Right-click the Computer icon, and then click Properties.
                               3. Click on System Protection under the Tasks column on the left side
                               4. Click on Continue on the "User Account Control" window that pops up
                               5. Under the System Protection tab, find Available Disks
                               6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                               7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                               8. Click OK

                            3. Restart computer.

                            4. Turn System Restore on.

                            5. Let me know, how your computer is doing.

                            arwest

                              Topic Starter


                              Rookie

                              Re: Windows Security Center Virus
                              « Reply #24 on: May 04, 2008, 09:43:05 AM »
                              Thanks so much for all your help!! Computer seems to be running great! If you don't mind, I had a few remaining questions...

                              In performing the system restore, did I reset the computer to the its now current state? Just curious.

                              For my Firewall, the Norton Program is asking which firewall I want to use as the default- Windows or Norton. Which should I use?

                              Which of the spyware programs do you recommend I use on a regular basis? And should I just leave all the programs that I have recently downloaded on my computer?

                              Thanks again for all your help!

                              Amanda

                              Broni


                                Mastermind
                              • Kraków my love :)
                              • Thanked: 614
                                • Computer Help Forum
                              • Computer: Specs
                              • Experience: Experienced
                              • OS: Windows 8
                              Re: Windows Security Center Virus
                              « Reply #25 on: May 04, 2008, 11:56:46 AM »
                              Quote
                              did I reset the computer to the its now current state?
                              Yes. All old (infected) Restore Points were removed, and a new, fresh one was created.
                              Quote
                              Which should I use?
                              Go with Norton, if you paid for it.
                              Quote
                              should I just leave all the programs that I have recently downloaded on my computer?
                              That's all, you need.

                              arwest

                                Topic Starter


                                Rookie

                                Re: Windows Security Center Virus- it's back
                                « Reply #26 on: May 15, 2008, 09:05:52 PM »
                                Hi again-

                                this virus is back again. my compute has been running great, except that on occasion, it has been "running" (light by power button blinking, noises, and slows the normal computer activity down) for no apparent reason.

                                Anyway, I thought maybe I could go back through our previous steps and fix it on my own,  but could not locate the wmpefhkv.dll subkey seemed to be the problem last time.
                                 
                                Is this a virus? and how is it getting through?

                                thanks, again

                                Amanda

                                Broni


                                  Mastermind
                                • Kraków my love :)
                                • Thanked: 614
                                  • Computer Help Forum
                                • Computer: Specs
                                • Experience: Experienced
                                • OS: Windows 8
                                Re: Windows Security Center Virus
                                « Reply #27 on: May 15, 2008, 09:32:33 PM »
                                Let's do it again...

                                Print these instructions out.

                                1. Download SUPERAntiSpyware Free for Home Users:
                                http://www.superantispyware.com/

                                    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                                    * An icon will be created on your desktop. Double-click that icon to launch the program.
                                    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                                    * Close SUPERAntiSpyware.

                                Restart computer in Safe Mode.
                                To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                                    * Open SUPERAntiSpyware.
                                    * Under "Configuration and Preferences", click the Preferences button.
                                    * Click the Scanning Control tab.
                                    * Under Scanner Options make sure the following are checked (leave all others unchecked):
                                          o Close browsers before scanning.
                                          o Scan for tracking cookies.
                                          o Terminate memory threats before quarantining.
                                    * Click the "Close" button to leave the control center screen.
                                    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                                    * On the left, make sure you check C:\Fixed Drive.
                                    * On the right, under "Complete Scan", choose Perform Complete Scan.
                                    * Click "Next" to start the scan. Please be patient while it scans your computer.
                                    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                                    * Make sure everything has a checkmark next to it and click "Next".
                                    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                                    * If asked if you want to reboot, click "Yes".
                                    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                                          o Click Preferences, then click the Statistics/Logs tab.
                                          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                                          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                                          o Please copy and paste the Scan Log results in your next reply.
                                    * Click Close to exit the program.
                                Post SUPERAntiSpyware log.

                                RESTART COMPUTER!

                                2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                                    * Double-click mbam-setup.exe and follow the prompts to install the program.
                                    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                                    * If an update is found, it will download and install the latest version.
                                    * Once the program has loaded, select Perform full scan, then click Scan.
                                    * When the scan is complete, click OK, then Show Results to view the results.
                                    * Be sure that everything is checked, and click Remove Selected.
                                    * When completed, a log will open in Notepad.
                                    * Post the log back here.

                                The log can also be found here:
                                C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
                                Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

                                RESTART COMPUTER!

                                3. Download HijackThis:
                                http://www.snapfiles.com/get/hijackthis.html
                                Post HijackThis log.

                                arwest

                                  Topic Starter


                                  Rookie

                                  Re: Windows Security Center Virus
                                  « Reply #28 on: May 16, 2008, 08:51:58 AM »
                                  my computer did shut down while running this spyware, but I was able to get a log through the first 30 min., then ran the scan again and it was clean through 1 hr 45 min. before it shut down.

                                  here is the superanitspyware log from the first run:

                                  SUPERAntiSpyware Scan Log
                                  http://www.superantispyware.com

                                  Generated 05/16/2008 at 07:01 AM

                                  Application Version : 4.0.1154

                                  Core Rules Database Version : 3462
                                  Trace Rules Database Version: 1453

                                  Scan type       : Complete Scan
                                  Total Scan Time : 00:27:41

                                  Memory items scanned      : 188
                                  Memory threats detected   : 0
                                  Registry items scanned    : 6314
                                  Registry threats detected : 0
                                  File items scanned        : 28010
                                  File threats detected     : 67

                                  Adware.Tracking Cookie
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@superstats[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@media6degrees[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@qksrv[2].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@dmtracker[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@specificclick[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][4].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@qnsr[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][3].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@interclick[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@revsci[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@collective-media[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@linksynergy[1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@insightexpressai[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@adbrite[2].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@adinterax[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@hitbox[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@trafficmp[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@mediaplex[1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@overture[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@doubleclick[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@serving-sys[2].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@advertising[1].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@centralmediaserver[2].txt
                                     C:\Documents and Settings\Owner\Cookies\owner@fastclick[1].txt
                                     C:\Documents and Settings\Owner\Cookies\[email protected][1].txt

                                  Broni


                                    Mastermind
                                  • Kraków my love :)
                                  • Thanked: 614
                                    • Computer Help Forum
                                  • Computer: Specs
                                  • Experience: Experienced
                                  • OS: Windows 8
                                  Re: Windows Security Center Virus
                                  « Reply #29 on: May 16, 2008, 06:33:34 PM »
                                  I need two other logs...

                                  arwest

                                    Topic Starter


                                    Rookie

                                    Re: Windows Security Center Virus
                                    « Reply #30 on: May 16, 2008, 08:44:54 PM »
                                    sorry- been fighting with computer all day- it keeps shutting down on me and I haven't been able to catch the malware log. Here is the HJT log:

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 8:40:07 PM, on 5/16/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\WINDOWS\System32\gearsec.exe
                                    C:\WINDOWS\System32\nvsvc32.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                    C:\Program Files\Canon\CAL\CALMAIN.exe
                                    C:\windows\system\hpsysdrv.exe
                                    C:\HP\KBD\KBD.EXE
                                    C:\WINDOWS\AGRSMMSG.exe
                                    C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                                    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                                    C:\Program Files\Yapta\YaptaClient.exe
                                    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                    C:\Program Files\Unlocker\UnlockerAssistant.exe
                                    C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                    C:\Program Files\Southwest Airlines\Ding\Ding.exe
                                    C:\Program Files\InterMute\IMStart.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                                    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                                    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                                    O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                                    O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                    O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                    O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                                    O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                                    O4 - HKLM\..\Run: [Yapta Tracker] C:\Program Files\Yapta\YaptaClient.exe /onstartup
                                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                    O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                                    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                                    O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                                    O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                                    O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                    O4 - Global Startup: FLAC
                                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                    O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                    O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                    O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                    O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                    O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                    O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                    O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                                    O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                                    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                                    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                    O20 - Winlogon Notify: mnibasfl - C:\WINDOWS\SYSTEM32\mnibasfl.dll
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                    O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                                    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                    O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                                    --
                                    End of file - 10912 bytes

                                    Broni


                                      Mastermind
                                    • Kraków my love :)
                                    • Thanked: 614
                                      • Computer Help Forum
                                    • Computer: Specs
                                    • Experience: Experienced
                                    • OS: Windows 8
                                    Re: Windows Security Center Virus
                                    « Reply #31 on: May 16, 2008, 08:56:08 PM »
                                    What about Malwarebytes log?

                                    arwest

                                      Topic Starter


                                      Rookie

                                      Re: Windows Security Center Virus
                                      « Reply #32 on: May 16, 2008, 09:01:56 PM »
                                      my computer keeps crashing in the middle of running the scan. will try one more time... the virus seems to be more aggressive this time.


                                      Broni


                                        Mastermind
                                      • Kraków my love :)
                                      • Thanked: 614
                                        • Computer Help Forum
                                      • Computer: Specs
                                      • Experience: Experienced
                                      • OS: Windows 8
                                      Re: Windows Security Center Virus
                                      « Reply #33 on: May 16, 2008, 09:16:03 PM »
                                      Let me check your HJT log, first.

                                      Broni


                                        Mastermind
                                      • Kraków my love :)
                                      • Thanked: 614
                                        • Computer Help Forum
                                      • Computer: Specs
                                      • Experience: Experienced
                                      • OS: Windows 8
                                      Re: Windows Security Center Virus
                                      « Reply #34 on: May 16, 2008, 09:21:55 PM »
                                      I can't see any firewall, or antivirus running. I see some Norton services running, but firewall, and antivirus are inactive.
                                      I hope, you didn't disable them?
                                      In any case, open HJT, and checkmark:
                                      - O20 - Winlogon Notify: mnibasfl - C:\WINDOWS\SYSTEM32\mnibasfl.dll
                                      Click "Fix checked" button.

                                      Restart in Safe Mode, and delete mnibasfl.dll file from C:\WINDOWS\SYSTEM32

                                      Restart in Normal Mode, make sure, that your Norton is active, and post new HJT log.

                                      arwest

                                        Topic Starter


                                        Rookie

                                        Re: Windows Security Center Virus
                                        « Reply #35 on: May 16, 2008, 09:31:25 PM »
                                        The security center was disabled, so I started it and switched it to automatic (same issue I had before).

                                        I got the malware to finish scanning, here is the log:

                                        Malwarebytes' Anti-Malware 1.12
                                        Database version: 755

                                        Scan type: Quick Scan
                                        Objects scanned: 52627
                                        Time elapsed: 25 minute(s), 16 second(s)

                                        Memory Processes Infected: 0
                                        Memory Modules Infected: 0
                                        Registry Keys Infected: 0
                                        Registry Values Infected: 0
                                        Registry Data Items Infected: 0
                                        Folders Infected: 0
                                        Files Infected: 1

                                        Memory Processes Infected:
                                        (No malicious items detected)

                                        Memory Modules Infected:
                                        (No malicious items detected)

                                        Registry Keys Infected:
                                        (No malicious items detected)

                                        Registry Values Infected:
                                        (No malicious items detected)

                                        Registry Data Items Infected:
                                        (No malicious items detected)

                                        Folders Infected:
                                        (No malicious items detected)

                                        Files Infected:
                                        C:\Documents and Settings\Owner\Local Settings\Temp\us0105.exe (Trojan.Agent) -> Quarantined and deleted successfully.

                                        Am working on the next step and will post in a minute...

                                        arwest

                                          Topic Starter


                                          Rookie

                                          Re: Windows Security Center Virus
                                          « Reply #36 on: May 16, 2008, 09:44:48 PM »
                                          wouldn't let me delete through hjt (shut computer down), restarted in safe mode, used unlocker, then was able to delete file. restarted and then deleted in hjt. here is the new log.

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 9:41:48 PM, on 5/16/2008
                                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          C:\WINDOWS\Explorer.EXE
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                          C:\Program Files\Bonjour\mDNSResponder.exe
                                          C:\WINDOWS\System32\gearsec.exe
                                          C:\WINDOWS\System32\nvsvc32.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                          C:\Program Files\Canon\CAL\CALMAIN.exe
                                          C:\windows\system\hpsysdrv.exe
                                          C:\HP\KBD\KBD.EXE
                                          C:\WINDOWS\AGRSMMSG.exe
                                          C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                                          C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
                                          C:\Program Files\Yapta\YaptaClient.exe
                                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                          C:\Program Files\Unlocker\UnlockerAssistant.exe
                                          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\Program Files\Southwest Airlines\Ding\Ding.exe
                                          C:\Program Files\InterMute\IMStart.exe
                                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                                          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                                          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                          O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                                          O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                                          O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                          O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                          O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                                          O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                                          O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                          O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                          O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                                          O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                                          O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                                          O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                                          O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          O4 - Global Startup: FLAC
                                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                          O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                                          O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                          O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                          O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                          O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                          O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                          O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                          O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                          O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                          O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                                          O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                                          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                                          O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                          O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                          O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                          O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                                          O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                          O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                          O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                          O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                                          --
                                          End of file - 10797 bytes

                                          Broni


                                            Mastermind
                                          • Kraków my love :)
                                          • Thanked: 614
                                            • Computer Help Forum
                                          • Computer: Specs
                                          • Experience: Experienced
                                          • OS: Windows 8
                                          Re: Windows Security Center Virus
                                          « Reply #37 on: May 16, 2008, 09:46:00 PM »
                                          Very good.
                                          Try to run Malwarebytes now.

                                          arwest

                                            Topic Starter


                                            Rookie

                                            Re: Windows Security Center Virus
                                            « Reply #38 on: May 16, 2008, 10:25:51 PM »
                                            Malwarebytes' Anti-Malware 1.12
                                            Database version: 755

                                            Scan type: Full Scan (C:\|)
                                            Objects scanned: 69883
                                            Time elapsed: 36 minute(s), 17 second(s)

                                            Memory Processes Infected: 0
                                            Memory Modules Infected: 0
                                            Registry Keys Infected: 0
                                            Registry Values Infected: 0
                                            Registry Data Items Infected: 0
                                            Folders Infected: 0
                                            Files Infected: 1

                                            Memory Processes Infected:
                                            (No malicious items detected)

                                            Memory Modules Infected:
                                            (No malicious items detected)

                                            Registry Keys Infected:
                                            (No malicious items detected)

                                            Registry Values Infected:
                                            (No malicious items detected)

                                            Registry Data Items Infected:
                                            (No malicious items detected)

                                            Folders Infected:
                                            (No malicious items detected)

                                            Files Infected:
                                            C:\Documents and Settings\Owner\Application Data\Desktopicon\eBayShortcuts.exe (Trojan.Agent) -> Quarantined and deleted successfully.

                                            Broni


                                              Mastermind
                                            • Kraków my love :)
                                            • Thanked: 614
                                              • Computer Help Forum
                                            • Computer: Specs
                                            • Experience: Experienced
                                            • OS: Windows 8
                                            Re: Windows Security Center Virus
                                            « Reply #39 on: May 16, 2008, 10:31:05 PM »
                                            How is your computer doing now?

                                            arwest

                                              Topic Starter


                                              Rookie

                                              Re: Windows Security Center Virus
                                              « Reply #40 on: May 17, 2008, 09:11:06 AM »
                                              thanks, again! seems ok.

                                              only thing is the security center is still disabled whenever I restart the computer. I have to start it manually, even though I keep setting it to automatic. Could this be how the virus is keeps getting in?

                                              Broni


                                                Mastermind
                                              • Kraków my love :)
                                              • Thanked: 614
                                                • Computer Help Forum
                                              • Computer: Specs
                                              • Experience: Experienced
                                              • OS: Windows 8
                                              Re: Windows Security Center Virus
                                              « Reply #41 on: May 17, 2008, 01:04:14 PM »
                                              I'd like to see fresh HJT log.

                                              arwest

                                                Topic Starter


                                                Rookie

                                                Re: Windows Security Center Virus
                                                « Reply #42 on: May 17, 2008, 02:49:05 PM »
                                                Logfile of Trend Micro HijackThis v2.0.2
                                                Scan saved at 2:48:38 PM, on 5/17/2008
                                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                                MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                                Boot mode: Normal

                                                Running processes:
                                                C:\WINDOWS\System32\smss.exe
                                                C:\WINDOWS\system32\winlogon.exe
                                                C:\WINDOWS\system32\services.exe
                                                C:\WINDOWS\system32\lsass.exe
                                                C:\WINDOWS\system32\svchost.exe
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                C:\WINDOWS\system32\spoolsv.exe
                                                C:\WINDOWS\Explorer.EXE
                                                C:\windows\system\hpsysdrv.exe
                                                C:\HP\KBD\KBD.EXE
                                                C:\WINDOWS\AGRSMMSG.exe
                                                C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe
                                                C:\Program Files\Yapta\YaptaClient.exe
                                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                C:\Program Files\Bonjour\mDNSResponder.exe
                                                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                                C:\WINDOWS\System32\gearsec.exe
                                                C:\Program Files\Unlocker\UnlockerAssistant.exe
                                                C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                                                C:\WINDOWS\System32\nvsvc32.exe
                                                C:\WINDOWS\system32\ctfmon.exe
                                                C:\WINDOWS\System32\svchost.exe
                                                C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                                                C:\Program Files\Canon\CAL\CALMAIN.exe
                                                C:\hp\bin\cloaker.exe
                                                c:\hp\bin\commands.exe
                                                c:\windows\system32\cmd.exe
                                                C:\Program Files\Internet Explorer\iexplore.exe
                                                C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                                c:\hp\bin\Sleep.exe

                                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
                                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                                O2 - BHO: Yapta BHO - {2020dfef-8c87-4229-aa41-549d82210355} - C:\Program Files\Yapta\YaptaOverlay.dll
                                                O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
                                                O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
                                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                                O2 - BHO: ToolHelper - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll
                                                O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
                                                O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                                O3 - Toolbar: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                                O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                                O4 - HKLM\..\Run: [ReminderApp] "C:\Program Files\Nova Development\Greeting Card Factory Deluxe 6.0\ReminderApp.exe"
                                                O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
                                                O4 - HKLM\..\Run: [Yapta Tracker] "C:\Program Files\Yapta\YaptaClient.exe" /onstartup
                                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                                O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
                                                O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
                                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                                O4 - HKCU\..\Run: [BackupNotify] "c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe"
                                                O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                                                O4 - HKCU\..\Run: [QuickenBillminder] "C:\Program Files\Quicken\Billmind.exe" -startup
                                                O4 - Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                                                O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
                                                O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                                O4 - Global Startup: FLAC
                                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                                O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin\core.hp.main\SendTo.html
                                                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
                                                O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                                O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll
                                                O9 - Extra button: Yapta Settings - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                                O9 - Extra 'Tools' menuitem: Yapta Settings... - {0362b485-11fe-469c-ae98-42f478e581a0} - C:\Program Files\Yapta\YaptaSettings.exe
                                                O9 - Extra button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                                O9 - Extra 'Tools' menuitem: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll
                                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                                O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
                                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                                O9 - Extra button: Yapta - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                                O9 - Extra 'Tools' menuitem: Yapta... - {0094A600-9BDD-4019-BAFE-487284F7D476} - C:\Program Files\Yapta\YaptaSidebar.dll (HKCU)
                                                O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                                                O16 - DPF: {42C9E5EE-DA49-49B4-8ECC-1CAB1C51A2AB} (HomePrintingCtrl Class) - http://www.kodakgallery.com/downloads/hmpr/HMPR_WIN_IE_1/wiaaut.cab
                                                O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase370.cab
                                                O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
                                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                                                O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                                O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                                O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
                                                O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                                O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                                                O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                                O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                                                O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

                                                --
                                                End of file - 10753 bytes

                                                Broni


                                                  Mastermind
                                                • Kraków my love :)
                                                • Thanked: 614
                                                  • Computer Help Forum
                                                • Computer: Specs
                                                • Experience: Experienced
                                                • OS: Windows 8
                                                Re: Windows Security Center Virus
                                                « Reply #43 on: May 17, 2008, 04:49:45 PM »
                                                The log is clean.

                                                Go Start>Run, type in:
                                                regedit
                                                Click OK.
                                                Navigate to:
                                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityCenter\
                                                Let me know what keys, with what values are listed in right pane.
                                                A screenshot would be welcome.

                                                arwest

                                                  Topic Starter


                                                  Rookie

                                                  Re: Windows Security Center Virus
                                                  « Reply #44 on: May 17, 2008, 07:50:42 PM »
                                                  how do I get a screenshot?

                                                  Broni


                                                    Mastermind
                                                  • Kraków my love :)
                                                  • Thanked: 614
                                                    • Computer Help Forum
                                                  • Computer: Specs
                                                  • Experience: Experienced
                                                  • OS: Windows 8
                                                  Re: Windows Security Center Virus
                                                  « Reply #45 on: May 17, 2008, 07:55:12 PM »

                                                  arwest

                                                    Topic Starter


                                                    Rookie

                                                    Re: Windows Security Center Virus
                                                    « Reply #46 on: May 17, 2008, 08:45:16 PM »
                                                    screenshot should be attached

                                                    [recovering space - attachment deleted by admin]

                                                    Broni


                                                      Mastermind
                                                    • Kraków my love :)
                                                    • Thanked: 614
                                                      • Computer Help Forum
                                                    • Computer: Specs
                                                    • Experience: Experienced
                                                    • OS: Windows 8
                                                    Re: Windows Security Center Virus
                                                    « Reply #47 on: May 17, 2008, 09:03:34 PM »
                                                    Excellent.
                                                    In Registry Editor, go File>Export, and save your registry to safe location.

                                                    Now, right click on each of those five entries (don't touch (Default)), click Modify, and change value from 0 to 1.

                                                    Restart computer, and see, if Security Center is still disabled.

                                                    arwest

                                                      Topic Starter


                                                      Rookie

                                                      Re: Windows Security Center Virus
                                                      « Reply #48 on: May 17, 2008, 09:26:27 PM »
                                                      yes, it was still disabled

                                                      Broni


                                                        Mastermind
                                                      • Kraków my love :)
                                                      • Thanked: 614
                                                        • Computer Help Forum
                                                      • Computer: Specs
                                                      • Experience: Experienced
                                                      • OS: Windows 8
                                                      Re: Windows Security Center Virus
                                                      « Reply #49 on: May 17, 2008, 09:37:16 PM »
                                                      OK. Next step.
                                                      Go Start>Run, type in:
                                                      services.msc
                                                      Click OK.

                                                      Right click on Security Center service, click Properties, click the “Dependencies” tab. Under the heading “This service depends on the following system components” you will see a listing of the dependent services. Write these down, and then go back into the Services window and ensure all these dependent services are started and are set to automatically start.

                                                      Let me know, if any of those services were NOT started, or set to Automatic start.

                                                      arwest

                                                        Topic Starter


                                                        Rookie

                                                        Re: Windows Security Center Virus
                                                        « Reply #50 on: May 17, 2008, 09:45:42 PM »
                                                        the two listed are:

                                                        Remote Procedure Call
                                                        Windows Management Instrumentation

                                                        both were started and set to automatic

                                                        Broni


                                                          Mastermind
                                                        • Kraków my love :)
                                                        • Thanked: 614
                                                          • Computer Help Forum
                                                        • Computer: Specs
                                                        • Experience: Experienced
                                                        • OS: Windows 8
                                                        Re: Windows Security Center Virus
                                                        « Reply #51 on: May 17, 2008, 09:50:33 PM »
                                                        You sure, there were no sub-services, like on my computer:

                                                        Broni


                                                          Mastermind
                                                        • Kraków my love :)
                                                        • Thanked: 614
                                                          • Computer Help Forum
                                                        • Computer: Specs
                                                        • Experience: Experienced
                                                        • OS: Windows 8
                                                        Re: Windows Security Center Virus
                                                        « Reply #52 on: May 17, 2008, 09:54:12 PM »
                                                        If not, go here: http://windowsxp.mvps.org/wscsvcfix.htm, and get Wscfix.zip.
                                                        Unzip it, read readme.txt, and run Wscsvcfix.exe
                                                        Restart computer.

                                                        Broni


                                                          Mastermind
                                                        • Kraków my love :)
                                                        • Thanked: 614
                                                          • Computer Help Forum
                                                        • Computer: Specs
                                                        • Experience: Experienced
                                                        • OS: Windows 8
                                                        Re: Windows Security Center Virus
                                                        « Reply #53 on: May 17, 2008, 09:55:43 PM »
                                                        If the above doesn't work, visit the following website: http://www.kellys-korner-xp.com/xp_tweaks.htm . Scroll to line 338 and in the right-hand column you should see a link titled “Restore the Security Center Service”. Right-click on the link and select ‘Save Target [or Link] As...”. Select your Desktop as the save location, and this should save a .REG file to the desktop. This file contains instructions which will modify the Windows Registry and attempt to fix any invalid entries which could be causing the Security Center service not to load. Double-click the .REG file, and confirm that you wish to import the data into the registry. Once this has completed, restart the computer and check whether the Security Center service will start.

                                                        arwest

                                                          Topic Starter


                                                          Rookie

                                                          Re: Windows Security Center Virus
                                                          « Reply #54 on: May 17, 2008, 10:17:51 PM »
                                                          You sure, there were no sub-services, like on my computer:

                                                          - there was one, but it was started.

                                                          performed other 2 actions, the security center was still disabled

                                                          Broni


                                                            Mastermind
                                                          • Kraków my love :)
                                                          • Thanked: 614
                                                            • Computer Help Forum
                                                          • Computer: Specs
                                                          • Experience: Experienced
                                                          • OS: Windows 8
                                                          Re: Windows Security Center Virus
                                                          « Reply #55 on: May 17, 2008, 10:25:47 PM »
                                                          I'm starting to believe, that it has something to do with Norton.
                                                          Do you have Norton's CD, or any way to re-register it, if we uninstall it.
                                                          There is no infection involved here.

                                                          arwest

                                                            Topic Starter


                                                            Rookie

                                                            Re: Windows Security Center Virus
                                                            « Reply #56 on: May 18, 2008, 08:52:48 AM »
                                                            yes, I can redownload it.

                                                            Broni


                                                              Mastermind
                                                            • Kraków my love :)
                                                            • Thanked: 614
                                                              • Computer Help Forum
                                                            • Computer: Specs
                                                            • Experience: Experienced
                                                            • OS: Windows 8
                                                            Re: Windows Security Center Virus
                                                            « Reply #57 on: May 18, 2008, 12:02:06 PM »
                                                            Good. When does your subscription expire?
                                                            Download Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
                                                            Disconnect physically from the internet.
                                                            Run the tool.
                                                            Turn Windows firewall on.
                                                            See, if in this state, Security Center will stay enabled after restart.
                                                            We'll go from there.

                                                            arwest

                                                              Topic Starter


                                                              Rookie

                                                              Re: Windows Security Center Virus
                                                              « Reply #58 on: May 18, 2008, 02:03:46 PM »
                                                              i removed norton and restarted- windows security center was started and set to automatic upon restart!!


                                                              Broni


                                                                Mastermind
                                                              • Kraków my love :)
                                                              • Thanked: 614
                                                                • Computer Help Forum
                                                              • Computer: Specs
                                                              • Experience: Experienced
                                                              • OS: Windows 8
                                                              Re: Windows Security Center Virus
                                                              « Reply #59 on: May 18, 2008, 02:57:03 PM »
                                                              Good.
                                                              Re-download Norton.
                                                              Disconnect from the internet, disable Windows firewall, and reinstall Norton.
                                                              Check Security Center upon restart.
                                                              You didn't say, when your Norton expires...

                                                              arwest

                                                                Topic Starter


                                                                Rookie

                                                                Re: Windows Security Center Virus
                                                                « Reply #60 on: May 19, 2008, 01:57:19 PM »
                                                                Security center disabled again upon reinstallation of Norton. I have Norton Internet Security 08 and it expires Nov. this year

                                                                I am also gettting an internet explorer error message. I got a screenshot of it and am attaching it.

                                                                arwest

                                                                  Topic Starter


                                                                  Rookie

                                                                  Re: Windows Security Center Virus
                                                                  « Reply #61 on: May 19, 2008, 02:02:04 PM »
                                                                  the file is too large, but here's what it says"

                                                                  iexplorer.exe - application error
                                                                  The instruction at "0x66ff127e" referenced memory at "0x03e066d4" The memory could not be read. Click ok to terminate the program.

                                                                  Broni


                                                                    Mastermind
                                                                  • Kraków my love :)
                                                                  • Thanked: 614
                                                                    • Computer Help Forum
                                                                  • Computer: Specs
                                                                  • Experience: Experienced
                                                                  • OS: Windows 8
                                                                  Re: Windows Security Center Virus
                                                                  « Reply #62 on: May 19, 2008, 06:25:29 PM »
                                                                  Quote
                                                                  Security center disabled again upon reinstallation of Norton.
                                                                  As you can see, there is definitely some conflict between Norton, and Security Center. This, I can't help.
                                                                  I'm not surprised, though. I really dislike Norton. You'll have to wait until November to get rid of it.

                                                                  As for IE error, go Tools>Internet Options>Advanced tab, and click Reset button.
                                                                  Restart computer.

                                                                  evilfantasy

                                                                  • Malware Removal Specialist
                                                                  • Moderator


                                                                  • Genius
                                                                  • Calm like a bomb
                                                                  • Thanked: 493
                                                                  • Experience: Experienced
                                                                  • OS: Windows 11
                                                                  Re: Windows Security Center Virus
                                                                  « Reply #63 on: May 19, 2008, 06:49:22 PM »
                                                                  Norton disables Windows security center.

                                                                  Quote
                                                                  When installing NAV, you are prompted to make the Norton Security
                                                                  Center the default, overriding Windows Security Center. To avoid this
                                                                  reinstall and uncheck that option or opt to do a Custom install.

                                                                  Open NAV. On the Norton protection center window above Basic PC Security
                                                                  click OPTIONS.

                                                                  On the Norton Protection Center Options window select General Settings

                                                                  Under Windows Security Center alert settings check the box. Show messages
                                                                  from Windows Security Center. Click ok.

                                                                  Close NAV

                                                                  Then open Security Center it should be working as normal.


                                                                  If this option isn't there then see Symantec Support

                                                                  arwest

                                                                    Topic Starter


                                                                    Rookie

                                                                    Re: Windows Security Center Virus
                                                                    « Reply #64 on: May 19, 2008, 06:55:20 PM »
                                                                    is there an antivirus program that you would recommend instead of norton?

                                                                    evilfantasy

                                                                    • Malware Removal Specialist
                                                                    • Moderator


                                                                    • Genius
                                                                    • Calm like a bomb
                                                                    • Thanked: 493
                                                                    • Experience: Experienced
                                                                    • OS: Windows 11
                                                                    Re: Windows Security Center Virus
                                                                    « Reply #65 on: May 19, 2008, 06:57:51 PM »
                                                                    All fee and reliable.


                                                                    Broni


                                                                      Mastermind
                                                                    • Kraków my love :)
                                                                    • Thanked: 614
                                                                      • Computer Help Forum
                                                                    • Computer: Specs
                                                                    • Experience: Experienced
                                                                    • OS: Windows 8
                                                                    Re: Windows Security Center Virus
                                                                    « Reply #66 on: May 19, 2008, 07:14:41 PM »
                                                                    Quote
                                                                    Norton disables Windows security center.
                                                                    Ahh....thanks evil :)

                                                                    arwest

                                                                      Topic Starter


                                                                      Rookie

                                                                      Re: Windows Security Center Virus
                                                                      « Reply #67 on: May 21, 2008, 09:12:56 PM »
                                                                      thanks again for all your help.

                                                                      security center has been starting upon computer start up!

                                                                      I did reset my internet options, which got rid of the IE error message for a couple days, but it is back again. And, since making the last two changes my computer has been super slow. Specifically, I can't load my yahoo email page and my spyware and anitvirus programs are taking over 4 hours to scan my computer (before it was about an hour).

                                                                      Broni


                                                                        Mastermind
                                                                      • Kraków my love :)
                                                                      • Thanked: 614
                                                                        • Computer Help Forum
                                                                      • Computer: Specs
                                                                      • Experience: Experienced
                                                                      • OS: Windows 8
                                                                      Re: Windows Security Center Virus
                                                                      « Reply #68 on: May 21, 2008, 09:26:14 PM »
                                                                      I suspect Norton, but since you paid for it...