Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus preventing me downloading  (Read 32163 times)

0 Members and 1 Guest are viewing this topic.

Derek Mc

    Topic Starter


    Rookie

    Virus preventing me downloading
    « on: June 21, 2008, 02:10:32 AM »
    I usually use IE7 or my AOL VR on my vista system but will not download anymore except through Firefox occasionally? I have run the usual spybot SD and AdAwareSE but apart from discovering Myweb which I duly deleted via the dos prompt method no other suspicious items are in sight.
    Any help please???????? gertting annoyed with myself on this one.

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: Virus preventing me downloading
    « Reply #1 on: June 21, 2008, 02:34:53 AM »
    I would start here:
    Post the logs and one of our malware specialists will help you.

    Derek Mc

      Topic Starter


      Rookie

      Re: Virus preventing me downloading
      « Reply #2 on: June 21, 2008, 04:27:56 AM »
      Thanks,
      The current system would not let me even download the suggestions in the link post! i have had to go drag an old desktop out of retirement and load them to a stick!
      I will try the suggestions and post the logs as soon as i can get to them.

      Derek Mc

        Topic Starter


        Rookie

        Re: Virus preventing me downloading
        « Reply #3 on: June 21, 2008, 12:55:20 PM »
        OK attached are all the logs for your consideration with the exception of SAS as I was unable to download it and won;t be able to until I cure this laptop, or borrow that old desktop unit again!
        Hope you can assist based in this lot.

        [recovering disk space -- attachment deleted by admin]

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Virus preventing me downloading
        « Reply #4 on: June 21, 2008, 01:46:59 PM »
        None of the logs are readable...a lot of Chinese fonts.

        Derek Mc

          Topic Starter


          Rookie

          Re: Virus preventing me downloading
          « Reply #5 on: June 21, 2008, 02:06:53 PM »
          mbam and avg logs

          [recovering disk space -- attachment deleted by admin]

          Derek Mc

            Topic Starter


            Rookie

            Re: Virus preventing me downloading
            « Reply #6 on: June 21, 2008, 02:09:35 PM »
            CClog as wrd doc

            [recovering disk space -- attachment deleted by admin]

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: Virus preventing me downloading
            « Reply #7 on: June 21, 2008, 03:33:47 PM »
            OK. I need Mylwarebytes log in txt format. Why are you not using Notepad to open those logs?
            Then, I need HijackThis log in same format.

            Derek Mc

              Topic Starter


              Rookie

              Re: Virus preventing me downloading
              « Reply #8 on: June 22, 2008, 01:38:54 AM »
              I had originally saved them with notepad as a txt doc, but think that they couldn't be opened here?

              I shall try both as requested now.


              [recovering disk space -- attachment deleted by admin]

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: Virus preventing me downloading
              « Reply #9 on: June 22, 2008, 11:15:10 AM »
              OK. I'm not sure what programs you're running. Mylwarebytes log looks like this:
              Quote
              Malwarebytes' Anti-Malware 1.17
              Database version: 869

              11:18:33 20/06/08 a.m
              mbam-log-6-20-2008 (11-18-33).txt

              Scan type: Full Scan (C:\|E:\|)
              Objects scanned: 127199
              Time elapsed: 18 minute(s), 18 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 23
              Registry Values Infected: 0
              Registry Data Items Infected: 0
              Folders Infected: 7
              Files Infected: 1

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

              Yours looks totally different. HJT log is not readable.
              So....let's start over...

              Print these instructions out.

              1. Download SUPERAntiSpyware Free for Home Users:
              http://www.superantispyware.com/

                  * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
                  * An icon will be created on your desktop. Double-click that icon to launch the program.
                  * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
                  * Close SUPERAntiSpyware.

              PHYSICALLY DISCONNECT  FROM THE INTERNET

              Restart computer in Safe Mode.
              To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

                  * Open SUPERAntiSpyware.
                  * Under "Configuration and Preferences", click the Preferences button.
                  * Click the Scanning Control tab.
                  * Under Scanner Options make sure the following are checked (leave all others unchecked):
                        o Close browsers before scanning.
                        o Scan for tracking cookies.
                        o Terminate memory threats before quarantining.
                  * Click the "Close" button to leave the control center screen.
                  * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
                  * On the left, make sure you check C:\Fixed Drive.
                  * On the right, under "Complete Scan", choose Perform Complete Scan.
                  * Click "Next" to start the scan. Please be patient while it scans your computer.
                  * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
                  * Make sure everything has a checkmark next to it and click "Next".
                  * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
                  * If asked if you want to reboot, click "Yes".
                  * To retrieve the removal information after reboot, launch SUPERAntispyware again.
                        o Click Preferences, then click the Statistics/Logs tab.
                        o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
                        o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
                        o Please copy and paste the Scan Log results in your next reply.
                  * Click Close to exit the program.
              Post SUPERAntiSpyware log.

              RECONNECT TO THE INTERNET

              RESTART COMPUTER!

              2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

                  * Double-click mbam-setup.exe and follow the prompts to install the program.
                  * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
                  * If an update is found, it will download and install the latest version.
                  * Once the program has loaded, select Perform full scan, then click Scan.
                  * When the scan is complete, click OK, then Show Results to view the results.
                  * Be sure that everything is checked, and click Remove Selected.
                  * When completed, a log will open in Notepad.
                  * Post the log back here.

              The log can also be found here:
              C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
              Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

              RESTART COMPUTER!

              3. Download HijackThis:
              http://www.snapfiles.com/get/hijackthis.html
              Post HijackThis log.

              Derek Mc

                Topic Starter


                Rookie

                Re: Virus preventing me downloading
                « Reply #10 on: June 22, 2008, 12:11:13 PM »
                I am saving this as a TXT file and when I click on the attachment it opens and reads fine so I suspect it might have a lot to do with my problem?
                Here is the first section with the HJT information.

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 13:20:29, on 21/06/2008
                Platform: Windows Vista  (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                Boot mode: Normal

                Running processes:
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Windows\System32\hkcmd.exe
                C:\Windows\System32\igfxpers.exe
                C:\Program Files\Apoint\Apoint.exe
                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                C:\Program Files\Apoint\ApMsgFwd.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\Google\Google Talk\googletalk.exe
                C:\Program Files\Winamp\winampa.exe
                C:\Program Files\Picasa2\PicasaMediaDetector.exe
                C:\Program Files\Sony\Network Utility\LANUtil.exe
                C:\Windows\ehome\ehtray.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\EPC\Toolbar\EPSIBar.exe
                C:\Program Files\Apoint\Apntex.exe
                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Windows\System32\GRVSA.exe
                C:\Windows\system32\igfxsrvc.exe
                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                C:\Program Files\AVG\AVG8\avgtray.exe
                C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Windows\system32\SearchFilterHost.exe

                Derek Mc

                  Topic Starter


                  Rookie

                  Re: Virus preventing me downloading
                  « Reply #11 on: June 22, 2008, 12:11:53 PM »
                  Second set of log files:-

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
                  O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
                  O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                  O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                  O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                  O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                  O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                  O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                  O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                  O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
                  O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                  O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                  O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                  O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                  O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                  O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
                  O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                  O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                  O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                  O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                  O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                  O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                  O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                  O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                  O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                  O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                  O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                  O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                  O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                  O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                  O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                  --
                  End of file - 14914 bytes

                  Derek Mc

                    Topic Starter


                    Rookie

                    Re: Virus preventing me downloading
                    « Reply #12 on: June 22, 2008, 12:13:00 PM »
                    Thanks for the patience Broni!
                    I am so frustrated with this.

                    Broni


                      Mastermind
                    • Kraków my love :)
                    • Thanked: 614
                      • Computer Help Forum
                    • Computer: Specs
                    • Experience: Experienced
                    • OS: Windows 8
                    Re: Virus preventing me downloading
                    « Reply #13 on: June 22, 2008, 12:30:21 PM »
                    No problem, but...
                    I need Superantispyware, and Malwarebytes logs, and HJT log from after you're done with Superantispyware, and Malwarebytes.

                    Derek Mc

                      Topic Starter


                      Rookie

                      Re: Virus preventing me downloading
                      « Reply #14 on: June 22, 2008, 12:43:50 PM »
                      This is the malaware log info

                      2007 Microsoft Office system
                      Actify 3D Studio Importer
                      Actify AutoCAD(TM) Importer
                      Actify Cadds Importer
                      Actify Catia V4 3D/2D Importer
                      Actify Catia V5 3D/2D Importer
                      Actify CGM Importer
                      Actify HPGL Importer
                      Actify IDEAS Importer
                      Actify Iges & VDA Importer
                      Actify Inventor Importer
                      Actify ISO Importer
                      Actify Microcadam Importer
                      Actify PRC Importer
                      Actify ProE Importer
                      Actify Rhino Importer
                      Actify SAT Importer
                      Actify SDRC Importer
                      Actify SpinFire Professional 8.3
                      Actify Step Importer
                      Actify STL Importer
                      Actify VRML 1 and 2 Importer
                      Activation Assistant for the 2007 Microsoft Office suites
                      Adobe Flash Player ActiveX
                      Adobe Flash Player Plugin
                      Adobe Reader 8.1.2
                      Alps Pointing-device for VAIO
                      AOL Pictures Tools (version 10.6.0.8)
                      AOL Uninstaller (Choose which Products to Remove)
                      Atlantis - Sky Patrol (remove only)
                      AVG Free 8.0
                      Big Fish Games Center
                      Big Fish Games Sudoku (remove only)
                      BlackBerry Desktop Software 4.2.2
                      Browser Address Error Redirector
                      Business Contact Manager for Outlook 2007 SP1
                      CCleaner (remove only)
                      Click to Disc
                      Click to Disc Editor
                      Corel Applications
                      CorelDRAW Graphics Suite 12
                      DivX Codec
                      DivX Converter
                      DivX Player
                      DivX Web Player
                      eMusic - 50 Free MP3 offer
                      EPSI Toolbar
                      Google Desktop
                      Google Earth
                      Google Talk (remove only)
                      Google Toolbar for Internet Explorer
                      Google Updater
                      HDAUDIO SoftV92 Data Fax Modem with SmartCP
                      HijackThis 2.0.2
                      Intel(R) Graphics Media Accelerator Driver
                      Java(TM) 6 Update 2
                      Java(TM) 6 Update 5
                      Java(TM) 6 Update 6
                      LimeWire 4.18.2
                      LiveUpdate 3.2 (Symantec Corporation)
                      LiveUpdate Notice (Symantec Corporation)
                      Mahjong Towers Eternity (remove only)
                      Malwarebytes' Anti-Malware
                      Microsoft Office 2003 Web Components
                      Microsoft Office 2007 Primary Interop Assemblies
                      Microsoft Office Small Business Connectivity Components
                      Microsoft Office Small Business Edition 2003
                      Microsoft SQL Server 2005
                      Microsoft SQL Server Native Client
                      Microsoft SQL Server Setup Support Files (English)
                      Microsoft SQL Server VSS Writer
                      Microsoft Visual C++ 2005 Redistributable
                      Mozilla Firefox (3.0)
                      MSXML 4.0 SP2 (KB927978)
                      MSXML 4.0 SP2 (KB936181)
                      MSXML 4.0 SP2 (KB941833)
                      Mystery Case Files - Prime Suspects (remove only)
                      Norton 360 (Symantec Corporation)
                      Norton Save and Restore
                      OpenMG Limited Patch 4.7-07-15-19-01
                      OpenMG Secure Module 4.7.00
                      OpenOffice.org 2.4
                      Picasa 2
                      RealPlayer
                      Realtek High Definition Audio Driver
                      Roxio Easy Media Creator Home
                      RTC Client API v1.2
                      Saab EPC
                      Setting Utility Series
                      Skype™ 3.5
                      Sony Video Shared Library
                      Spybot - Search & Destroy
                      VAIO Content Folder Setting
                      VAIO Content Metadata Intelligent Analyzing Manager
                      VAIO Content Metadata Manager Setting
                      VAIO Content Metadata XML Interface Library
                      VAIO Control Center
                      VAIO Data Restore Tool
                      VAIO DVD Menu Data Basic
                      VAIO Entertainment Platform
                      VAIO Event Service
                      VAIO Launcher
                      Vaio Marketing Tools
                      VAIO Media 6.0
                      VAIO Media AC3 Decoder 1.0
                      VAIO Media Content Collection 6.0
                      VAIO Media Integrated Server 6.1
                      VAIO Media Redistribution 6.0
                      VAIO Media Registration Tool 6.0
                      VAIO Movie Story
                      VAIO Movie Story Template Data
                      VAIO MusicBox
                      VAIO MusicBox Sample Music
                      VAIO Original Function Setting
                      VAIO Power Management
                      VAIO Smart Network
                      VAIO Update 3
                      VAIO Wallpaper Contents
                      Viewpoint Media Player
                      Virtual Villagers (remove only)
                      Winamp
                      Winamp Remote
                      Winamp Toolbar for Firefox
                      Winamp Toolbar for Internet Explorer
                      WinDVD for VAIO
                      Workshop Information System - WIS
                      Yahoo! Install Manager
                      Yahoo! Toolbar

                      Derek Mc

                        Topic Starter


                        Rookie

                        Re: Virus preventing me downloading
                        « Reply #15 on: June 22, 2008, 12:45:21 PM »
                        I didn't get the log saved to a location I can find it from Super Anti Spyware but it only found 6 tracking cookie issues and I deleted all of them.

                        Broni


                          Mastermind
                        • Kraków my love :)
                        • Thanked: 614
                          • Computer Help Forum
                        • Computer: Specs
                        • Experience: Experienced
                        • OS: Windows 8
                        Re: Virus preventing me downloading
                        « Reply #16 on: June 22, 2008, 01:32:52 PM »
                        This is not Malwarebytes log.

                        Derek Mc

                          Topic Starter


                          Rookie

                          Re: Virus preventing me downloading
                          « Reply #17 on: June 23, 2008, 12:26:20 AM »
                          This is the log I got from malware

                          mbam-log-6-21-2008 (13-19-12)

                          2007 Microsoft Office system
                          Actify 3D Studio Importer
                          Actify AutoCAD(TM) Importer
                          Actify Cadds Importer
                          Actify Catia V4 3D/2D Importer
                          Actify Catia V5 3D/2D Importer
                          Actify CGM Importer
                          Actify HPGL Importer
                          Actify IDEAS Importer
                          Actify Iges & VDA Importer
                          Actify Inventor Importer
                          Actify ISO Importer
                          Actify Microcadam Importer
                          Actify PRC Importer
                          Actify ProE Importer
                          Actify Rhino Importer
                          Actify SAT Importer
                          Actify SDRC Importer
                          Actify SpinFire Professional 8.3
                          Actify Step Importer
                          Actify STL Importer
                          Actify VRML 1 and 2 Importer
                          Activation Assistant for the 2007 Microsoft Office suites
                          Adobe Flash Player ActiveX
                          Adobe Flash Player Plugin
                          Adobe Reader 8.1.2
                          Alps Pointing-device for VAIO
                          AOL Pictures Tools (version 10.6.0.8)
                          AOL Uninstaller (Choose which Products to Remove)
                          Atlantis - Sky Patrol (remove only)
                          AVG Free 8.0
                          Big Fish Games Center
                          Big Fish Games Sudoku (remove only)
                          BlackBerry Desktop Software 4.2.2
                          Browser Address Error Redirector
                          Business Contact Manager for Outlook 2007 SP1
                          CCleaner (remove only)
                          Click to Disc
                          Click to Disc Editor
                          Corel Applications
                          CorelDRAW Graphics Suite 12
                          DivX Codec
                          DivX Converter
                          DivX Player
                          DivX Web Player
                          eMusic - 50 Free MP3 offer
                          EPSI Toolbar
                          Google Desktop
                          Google Earth
                          Google Talk (remove only)
                          Google Toolbar for Internet Explorer
                          Google Updater
                          HDAUDIO SoftV92 Data Fax Modem with SmartCP
                          HijackThis 2.0.2
                          Intel(R) Graphics Media Accelerator Driver
                          Java(TM) 6 Update 2
                          Java(TM) 6 Update 5
                          Java(TM) 6 Update 6
                          LimeWire 4.18.2
                          LiveUpdate 3.2 (Symantec Corporation)
                          LiveUpdate Notice (Symantec Corporation)
                          Mahjong Towers Eternity (remove only)
                          Malwarebytes' Anti-Malware
                          Microsoft Office 2003 Web Components
                          Microsoft Office 2007 Primary Interop Assemblies
                          Microsoft Office Small Business Connectivity Components
                          Microsoft Office Small Business Edition 2003
                          Microsoft SQL Server 2005
                          Microsoft SQL Server Native Client
                          Microsoft SQL Server Setup Support Files (English)
                          Microsoft SQL Server VSS Writer
                          Microsoft Visual C++ 2005 Redistributable
                          Mozilla Firefox (3.0)
                          MSXML 4.0 SP2 (KB927978)
                          MSXML 4.0 SP2 (KB936181)
                          MSXML 4.0 SP2 (KB941833)
                          Mystery Case Files - Prime Suspects (remove only)
                          Norton 360 (Symantec Corporation)
                          Norton Save and Restore
                          OpenMG Limited Patch 4.7-07-15-19-01
                          OpenMG Secure Module 4.7.00
                          OpenOffice.org 2.4
                          Picasa 2
                          RealPlayer
                          Realtek High Definition Audio Driver
                          Roxio Easy Media Creator Home
                          RTC Client API v1.2
                          Saab EPC
                          Setting Utility Series
                          Skype™ 3.5
                          Sony Video Shared Library
                          Spybot - Search & Destroy
                          VAIO Content Folder Setting
                          VAIO Content Metadata Intelligent Analyzing Manager
                          VAIO Content Metadata Manager Setting
                          VAIO Content Metadata XML Interface Library
                          VAIO Control Center
                          VAIO Data Restore Tool
                          VAIO DVD Menu Data Basic
                          VAIO Entertainment Platform
                          VAIO Event Service
                          VAIO Launcher
                          Vaio Marketing Tools
                          VAIO Media 6.0
                          VAIO Media AC3 Decoder 1.0
                          VAIO Media Content Collection 6.0
                          VAIO Media Integrated Server 6.1
                          VAIO Media Redistribution 6.0
                          VAIO Media Registration Tool 6.0
                          VAIO Movie Story
                          VAIO Movie Story Template Data
                          VAIO MusicBox
                          VAIO MusicBox Sample Music
                          VAIO Original Function Setting
                          VAIO Power Management
                          VAIO Smart Network
                          VAIO Update 3
                          VAIO Wallpaper Contents
                          Viewpoint Media Player
                          Virtual Villagers (remove only)
                          Winamp
                          Winamp Remote
                          Winamp Toolbar for Firefox
                          Winamp Toolbar for Internet Explorer
                          WinDVD for VAIO
                          Workshop Information System - WIS
                          Yahoo! Install Manager
                          Yahoo! Toolbar

                          Broni


                            Mastermind
                          • Kraków my love :)
                          • Thanked: 614
                            • Computer Help Forum
                          • Computer: Specs
                          • Experience: Experienced
                          • OS: Windows 8
                          Re: Virus preventing me downloading
                          « Reply #18 on: June 23, 2008, 02:16:53 PM »
                          It's not. Look at my reply #9 to see how Malwarebytes log looks like.

                          Derek Mc

                            Topic Starter


                            Rookie

                            Re: Virus preventing me downloading
                            « Reply #19 on: June 24, 2008, 12:35:17 PM »
                            Hmmmm,
                            OK I have re-run Malware and finally! have a log

                            Malwarebytes' Anti-Malware 1.18
                            Database version: 873

                            19:34:14 24/06/2008
                            mbam-log-6-24-2008 (19-34-14).txt

                            Scan type: Quick Scan
                            Objects scanned: 41474
                            Time elapsed: 14 minute(s), 37 second(s)

                            Memory Processes Infected: 0
                            Memory Modules Infected: 0
                            Registry Keys Infected: 0
                            Registry Values Infected: 0
                            Registry Data Items Infected: 0
                            Folders Infected: 0
                            Files Infected: 0

                            Memory Processes Infected:
                            (No malicious items detected)

                            Memory Modules Infected:
                            (No malicious items detected)

                            Registry Keys Infected:
                            (No malicious items detected)

                            Registry Values Infected:
                            (No malicious items detected)

                            Registry Data Items Infected:
                            (No malicious items detected)

                            Folders Infected:
                            (No malicious items detected)

                            Files Infected:
                            (No malicious items detected)

                            Broni


                              Mastermind
                            • Kraków my love :)
                            • Thanked: 614
                              • Computer Help Forum
                            • Computer: Specs
                            • Experience: Experienced
                            • OS: Windows 8
                            Re: Virus preventing me downloading
                            « Reply #20 on: June 24, 2008, 07:14:23 PM »
                            Very good.
                            Now, I need you to run Superantispyware, and HijackThis.
                            Post both logs.

                            Derek Mc

                              Topic Starter


                              Rookie

                              Re: Virus preventing me downloading
                              « Reply #21 on: June 25, 2008, 04:39:46 AM »
                              SAS log

                              SUPERAntiSpyware Scan Log
                              http://www.superantispyware.com

                              Generated 06/25/2008 at 10:36 AM

                              Application Version : 4.15.1000

                              Core Rules Database Version : 3487
                              Trace Rules Database Version: 1478

                              Scan type       : Complete Scan
                              Total Scan Time : 00:39:58

                              Memory items scanned      : 868
                              Memory threats detected   : 0
                              Registry items scanned    : 9228
                              Registry threats detected : 0
                              File items scanned        : 21758
                              File threats detected     : 22

                              Adware.Tracking Cookie
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@serving-sys[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@adtech[1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@revsci[1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@specificclick[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@tacoda[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@2o7[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@questionmarket[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\derek@atwola[2].txt
                                 C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Cookies\Low\derek@2o7[2].txt

                              Derek Mc

                                Topic Starter


                                Rookie

                                Re: Virus preventing me downloading
                                « Reply #22 on: June 25, 2008, 04:42:00 AM »
                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 13:20:29, on 21/06/2008
                                Platform: Windows Vista  (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\Explorer.EXE
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Windows\System32\hkcmd.exe
                                C:\Windows\System32\igfxpers.exe
                                C:\Program Files\Apoint\Apoint.exe
                                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
                                C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                C:\Program Files\Apoint\ApMsgFwd.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Google\Google Talk\googletalk.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                C:\Program Files\Sony\Network Utility\LANUtil.exe
                                C:\Windows\ehome\ehtray.exe
                                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                C:\EPC\Toolbar\EPSIBar.exe
                                C:\Program Files\Apoint\Apntex.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                C:\Windows\ehome\ehmsas.exe
                                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                C:\Windows\System32\GRVSA.exe
                                C:\Windows\system32\igfxsrvc.exe
                                C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                C:\Program Files\AVG\AVG8\avgtray.exe
                                C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                C:\Windows\system32\SearchFilterHost.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
                                O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
                                O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
                                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                                O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O13 - Gopher Prefix:
                                O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
                                O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab
                                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
                                O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                --
                                End of file - 14914 bytes

                                Derek Mc

                                  Topic Starter


                                  Rookie

                                  Re: Virus preventing me downloading
                                  « Reply #23 on: June 25, 2008, 04:42:38 AM »
                                  Hope this is the lot you require?

                                  Broni


                                    Mastermind
                                  • Kraków my love :)
                                  • Thanked: 614
                                    • Computer Help Forum
                                  • Computer: Specs
                                  • Experience: Experienced
                                  • OS: Windows 8
                                  Re: Virus preventing me downloading
                                  « Reply #24 on: June 25, 2008, 09:55:35 AM »
                                  You have two antivirus programs running: AVG 8, and Norton. One of them has to go.
                                  Let me know, which one.
                                  « Last Edit: June 25, 2008, 10:55:26 AM by Broni »

                                  Derek Mc

                                    Topic Starter


                                    Rookie

                                    Re: Virus preventing me downloading
                                    « Reply #25 on: June 25, 2008, 10:15:16 AM »
                                    Norton will go. how do I get rid as it seems imbeded?

                                    Broni


                                      Mastermind
                                    • Kraków my love :)
                                    • Thanked: 614
                                      • Computer Help Forum
                                    • Computer: Specs
                                    • Experience: Experienced
                                    • OS: Windows 8
                                    Re: Virus preventing me downloading
                                    « Reply #26 on: June 25, 2008, 10:55:10 AM »
                                    Good choice :)
                                    Use Norton Removal Tool: http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039
                                    After removing Norton, make sure to turn Windows firewall on!

                                    Derek Mc

                                      Topic Starter


                                      Rookie

                                      Re: Virus preventing me downloading
                                      « Reply #27 on: June 25, 2008, 12:03:14 PM »
                                      My laptop won't allow me to download it! again! typical,,,,,

                                      Broni


                                        Mastermind
                                      • Kraków my love :)
                                      • Thanked: 614
                                        • Computer Help Forum
                                      • Computer: Specs
                                      • Experience: Experienced
                                      • OS: Windows 8
                                      Re: Virus preventing me downloading
                                      « Reply #28 on: June 25, 2008, 06:38:25 PM »
                                      Use your old desktop, as you did before.

                                      Derek Mc

                                        Topic Starter


                                        Rookie

                                        Re: Virus preventing me downloading
                                        « Reply #29 on: June 26, 2008, 02:22:16 AM »
                                        Not that easy my four year old was asleep feet from it!
                                        I did remove it all now though.

                                        So what's next?

                                        Broni


                                          Mastermind
                                        • Kraków my love :)
                                        • Thanked: 614
                                          • Computer Help Forum
                                        • Computer: Specs
                                        • Experience: Experienced
                                        • OS: Windows 8
                                        Re: Virus preventing me downloading
                                        « Reply #30 on: June 26, 2008, 06:04:39 PM »
                                        I need fresh HJT log.

                                        Derek Mc

                                          Topic Starter


                                          Rookie

                                          Re: Virus preventing me downloading
                                          « Reply #31 on: June 27, 2008, 02:09:32 AM »
                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 13:20:29, on 21/06/2008
                                          Platform: Windows Vista  (WinNT 6.00.1904)
                                          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\Windows\system32\Dwm.exe
                                          C:\Windows\Explorer.EXE
                                          C:\Windows\system32\taskeng.exe
                                          C:\Windows\system32\taskeng.exe
                                          C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                          C:\Program Files\Windows Defender\MSASCui.exe
                                          C:\Windows\System32\hkcmd.exe
                                          C:\Windows\System32\igfxpers.exe
                                          C:\Program Files\Apoint\Apoint.exe
                                          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                          C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                          C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
                                          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                          C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                          C:\Program Files\Apoint\ApMsgFwd.exe
                                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                          C:\Program Files\Google\Google Talk\googletalk.exe
                                          C:\Program Files\Winamp\winampa.exe
                                          C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                          C:\Program Files\Sony\Network Utility\LANUtil.exe
                                          C:\Windows\ehome\ehtray.exe
                                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                          C:\EPC\Toolbar\EPSIBar.exe
                                          C:\Program Files\Apoint\Apntex.exe
                                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                          C:\Windows\ehome\ehmsas.exe
                                          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                          C:\Windows\System32\GRVSA.exe
                                          C:\Windows\system32\igfxsrvc.exe
                                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                          C:\Program Files\AVG\AVG8\avgtray.exe
                                          C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                          C:\Windows\system32\SearchFilterHost.exe

                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                          R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                          O1 - Hosts: ::1 localhost
                                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
                                          O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                          O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                          O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
                                          O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                          O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                          O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                          O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
                                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                          O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                          O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                          O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
                                          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                          O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                          O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                          O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                          O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                          O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                                          O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                                          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                          O13 - Gopher Prefix:
                                          O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
                                          O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab
                                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                          O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                          O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                          O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                          O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                          O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
                                          O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                          O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                          O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                          O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                          O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                          O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                          O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                          --
                                          End of file - 14914 bytes

                                          Broni


                                            Mastermind
                                          • Kraków my love :)
                                          • Thanked: 614
                                            • Computer Help Forum
                                          • Computer: Specs
                                          • Experience: Experienced
                                          • OS: Windows 8
                                          Re: Virus preventing me downloading
                                          « Reply #32 on: June 27, 2008, 06:44:31 PM »
                                          What is your current antivirus program, because I can see AVG, and Norton running, and this is NO-NO.

                                          Derek Mc

                                            Topic Starter


                                            Rookie

                                            Re: Virus preventing me downloading
                                            « Reply #33 on: June 28, 2008, 02:29:45 AM »
                                            AVG I got the other pc running and got the remove tools and BuDump so un-installed all Norton products
                                            And,,,,,,ran another HJT log
                                            « Last Edit: June 28, 2008, 03:17:29 AM by Derek Mc »

                                            Derek Mc

                                              Topic Starter


                                              Rookie

                                              Re: Virus preventing me downloading
                                              « Reply #34 on: June 28, 2008, 03:16:26 AM »
                                              Logfile of Trend Micro HijackThis v2.0.2
                                              Scan saved at 13:20:29, on 21/06/2008
                                              Platform: Windows Vista  (WinNT 6.00.1904)
                                              MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                              Boot mode: Normal

                                              Running processes:
                                              C:\Windows\system32\Dwm.exe
                                              C:\Windows\Explorer.EXE
                                              C:\Windows\system32\taskeng.exe
                                              C:\Windows\system32\taskeng.exe
                                              C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                              C:\Program Files\Windows Defender\MSASCui.exe
                                              C:\Windows\System32\hkcmd.exe
                                              C:\Windows\System32\igfxpers.exe
                                              C:\Program Files\Apoint\Apoint.exe
                                              C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                              C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                              C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
                                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                                              C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                              C:\Program Files\Apoint\ApMsgFwd.exe
                                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                              C:\Program Files\Google\Google Talk\googletalk.exe
                                              C:\Program Files\Winamp\winampa.exe
                                              C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                              C:\Program Files\Sony\Network Utility\LANUtil.exe
                                              C:\Windows\ehome\ehtray.exe
                                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                              C:\EPC\Toolbar\EPSIBar.exe
                                              C:\Program Files\Apoint\Apntex.exe
                                              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                              C:\Windows\ehome\ehmsas.exe
                                              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                              C:\Windows\System32\GRVSA.exe
                                              C:\Windows\system32\igfxsrvc.exe
                                              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                              C:\Program Files\AVG\AVG8\avgtray.exe
                                              C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                              C:\Windows\system32\SearchFilterHost.exe

                                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                              R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                              O1 - Hosts: ::1 localhost
                                              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                              O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
                                              O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                              O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                              O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                              O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
                                              O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                              O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                              O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                              O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                              O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                              O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                              O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe"
                                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                                              O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                              O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                              O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
                                              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                              O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                              O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                              O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                              O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                              O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                                              O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                              O13 - Gopher Prefix:
                                              O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
                                              O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C} (AOL Pictures Uploader Class) - http://o.aolcdn.com/pictures/ap/Resources/v2.14/cab/aolpPlugins.10.6.0.8.cab
                                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                              O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                              O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                              O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                                              O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                              O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                              O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                              O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                              O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
                                              O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                              O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                              O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                              O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                              O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                              O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                              O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                              O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                              O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                              O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                              O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                              O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                              O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                              O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                              O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                              O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                              O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                              --
                                              End of file - 14914 bytes

                                              Derek Mc

                                                Topic Starter


                                                Rookie

                                                Re: Virus preventing me downloading
                                                « Reply #35 on: June 28, 2008, 05:22:07 AM »
                                                Malwarebytes' Anti-Malware 1.18
                                                Database version: 873

                                                12:20:19 28/06/2008
                                                mbam-log-6-28-2008 (12-20-19).txt

                                                Scan type: Full Scan (C:\|)
                                                Objects scanned: 124027
                                                Time elapsed: 43 minute(s), 55 second(s)

                                                Memory Processes Infected: 0
                                                Memory Modules Infected: 0
                                                Registry Keys Infected: 0
                                                Registry Values Infected: 0
                                                Registry Data Items Infected: 0
                                                Folders Infected: 0
                                                Files Infected: 0

                                                Memory Processes Infected:
                                                (No malicious items detected)

                                                Memory Modules Infected:
                                                (No malicious items detected)

                                                Registry Keys Infected:
                                                (No malicious items detected)

                                                Registry Values Infected:
                                                (No malicious items detected)

                                                Registry Data Items Infected:
                                                (No malicious items detected)

                                                Folders Infected:
                                                (No malicious items detected)

                                                Broni


                                                  Mastermind
                                                • Kraków my love :)
                                                • Thanked: 614
                                                  • Computer Help Forum
                                                • Computer: Specs
                                                • Experience: Experienced
                                                • OS: Windows 8
                                                Re: Virus preventing me downloading
                                                « Reply #36 on: June 28, 2008, 07:25:58 PM »
                                                You posted 7 days old HJT log. Please, run HJT one more time, and post fresh log.

                                                Derek Mc

                                                  Topic Starter


                                                  Rookie

                                                  Re: Virus preventing me downloading
                                                  « Reply #37 on: June 29, 2008, 01:26:02 AM »
                                                  I ran HJT yesterday and it gave me the old log file again. I ran it as administrator this morning to get this logfile.

                                                  Logfile of Trend Micro HijackThis v2.0.2
                                                  Scan saved at 08:21:53, on 29/06/2008
                                                  Platform: Windows Vista  (WinNT 6.00.1904)
                                                  MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                                  Boot mode: Normal

                                                  Running processes:
                                                  C:\Windows\system32\Dwm.exe
                                                  C:\Windows\Explorer.EXE
                                                  C:\Windows\system32\taskeng.exe
                                                  C:\Program Files\Windows Defender\MSASCui.exe
                                                  C:\Windows\System32\hkcmd.exe
                                                  C:\Windows\System32\igfxpers.exe
                                                  C:\Windows\system32\igfxsrvc.exe
                                                  C:\Program Files\Apoint\Apoint.exe
                                                  C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                  C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                  C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                                  C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                                  C:\Program Files\Winamp\winampa.exe
                                                  C:\Program Files\AVG\AVG8\avgtray.exe
                                                  C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                  C:\Program Files\Sony\Network Utility\LANUtil.exe
                                                  C:\Windows\ehome\ehtray.exe
                                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                  C:\EPC\Toolbar\EPSIBar.exe
                                                  C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                                  C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                                  C:\Windows\ehome\ehmsas.exe
                                                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                  C:\Windows\System32\GRVSA.exe
                                                  C:\Windows\system32\taskeng.exe
                                                  C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                                  C:\Program Files\Apoint\ApMsgFwd.exe
                                                  C:\Program Files\Apoint\Apntex.exe
                                                  C:\Program Files\AOL 9.0 VR\waol.exe
                                                  C:\Program Files\AOL 9.0 VR\shellmon.exe
                                                  C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
                                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                                                  C:\Windows\system32\SearchFilterHost.exe

                                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                  R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                  R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                  O1 - Hosts: ::1 localhost
                                                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                  O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                                  O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                  O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                                  O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                                  O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                  O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                                  O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                                  O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                                  O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
                                                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                                  O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                  O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                  O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                                  O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                  O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                                  O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                                  O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                                                  O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                                                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                  O13 - Gopher Prefix:
                                                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                  O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                  O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                                  O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                                  O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                                  O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                                  O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                                  O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                                  O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                                  O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                                  O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                                  O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                  O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                  O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                                  O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                                  O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                  O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                  O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                                  O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                                  O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                                  O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                                  O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                  --
                                                  End of file - 12704 bytes

                                                  Broni


                                                    Mastermind
                                                  • Kraków my love :)
                                                  • Thanked: 614
                                                    • Computer Help Forum
                                                  • Computer: Specs
                                                  • Experience: Experienced
                                                  • OS: Windows 8
                                                  Re: Virus preventing me downloading
                                                  « Reply #38 on: June 29, 2008, 11:16:49 AM »
                                                  *** Disable Windows Defender, as it'll interfere with cleaning process:
                                                     * Open Windows Defender
                                                      * Click Tools
                                                      * Click General Settings
                                                      * Scroll down to Real Time Protection Options
                                                      * Uncheck Turn on Real Time Protection
                                                      * After you uncheck this, click on the Save button
                                                      * Close Windows Defender

                                                  *** Disable TeaTimer, as it'll interfere with the cleaning process:
                                                  Right click Spybot's TeaTimer System Tray Icon.
                                                  Click Exit Spybot-S&D Resident.
                                                  TeaTimer closes.

                                                  1. Print this post out, since you won't have an access to it, at some point.

                                                  2. Close all windows, except for HijackThis.

                                                  3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

                                                  - *O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                                  - *O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                                  - *O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                                  - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                                  - *O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                  - O8 - Extra context menu item: &Search - ?p=ZJxdm025YYGB
                                                  - O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                                                  - *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                                  - O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)


                                                  4. Click on Fix checked button.

                                                  5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

                                                  6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

                                                  7. Delete following files/folders (if present):

                                                  - MyWebSearch folder from C:\Program Files

                                                  8. Restart in Normal Mode.

                                                  9. Post new HijackThis log.

                                                  Derek Mc

                                                    Topic Starter


                                                    Rookie

                                                    Re: Virus preventing me downloading
                                                    « Reply #39 on: June 29, 2008, 12:02:49 PM »
                                                    OK done all of that, not tried any downloads yet I await your instructions

                                                    Logfile of Trend Micro HijackThis v2.0.2
                                                    Scan saved at 19:01:35, on 29/06/2008
                                                    Platform: Windows Vista  (WinNT 6.00.1904)
                                                    MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                                    Boot mode: Normal

                                                    Running processes:
                                                    C:\Windows\system32\Dwm.exe
                                                    C:\Windows\Explorer.EXE
                                                    C:\Windows\system32\taskeng.exe
                                                    C:\Program Files\Windows Defender\MSASCui.exe
                                                    C:\Windows\System32\hkcmd.exe
                                                    C:\Windows\System32\igfxpers.exe
                                                    C:\Program Files\Apoint\Apoint.exe
                                                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                    C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                                    C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                                    C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\registration.exe
                                                    C:\Windows\system32\igfxsrvc.exe
                                                    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                                    C:\Program Files\AVG\AVG8\avgtray.exe
                                                    C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                    C:\Program Files\Sony\Network Utility\LANUtil.exe
                                                    C:\Windows\ehome\ehtray.exe
                                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                    C:\EPC\Toolbar\EPSIBar.exe
                                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                                    C:\Windows\ehome\ehmsas.exe
                                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                    C:\Windows\System32\GRVSA.exe
                                                    C:\Windows\system32\taskeng.exe
                                                    C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                                    C:\Program Files\Apoint\ApMsgFwd.exe
                                                    C:\Program Files\Apoint\Apntex.exe
                                                    C:\Windows\system32\NOTEPAD.EXE
                                                    C:\Program Files\AOL 9.0 VR\waol.exe
                                                    C:\Program Files\AOL 9.0 VR\shellmon.exe
                                                    C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
                                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                    R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                    O1 - Hosts: ::1 localhost
                                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                    O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                                    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                                    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                                    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                                    O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                                    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                                    O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                    O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                    O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                                    O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                    O13 - Gopher Prefix:
                                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                                    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                                    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                                    O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                                    O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                                    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                                    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                                    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                                    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                                    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                    --
                                                    End of file - 12063 bytes

                                                    Derek Mc

                                                      Topic Starter


                                                      Rookie

                                                      Re: Virus preventing me downloading
                                                      « Reply #40 on: June 29, 2008, 12:26:43 PM »
                                                      OK so far,
                                                      I am able to use AOL downloading with some success but not Firefox or i.e7 still, better than it was,,,,,

                                                      Broni


                                                        Mastermind
                                                      • Kraków my love :)
                                                      • Thanked: 614
                                                        • Computer Help Forum
                                                      • Computer: Specs
                                                      • Experience: Experienced
                                                      • OS: Windows 8
                                                      Re: Virus preventing me downloading
                                                      « Reply #41 on: June 29, 2008, 12:37:38 PM »
                                                      Hold your horses. We're not done, yet.

                                                      Go Start, and in "Start Search" type in:
                                                      cmd
                                                      Hit Enter.

                                                      At Command Prompt, type in:
                                                      sc stop MyWebSearchService
                                                      Hit Enter.

                                                      Type in:
                                                      sc delete MyWebSearchService
                                                      Hit Enter.

                                                      Restart computer. Post new HJT log.

                                                      Derek Mc

                                                        Topic Starter


                                                        Rookie

                                                        Re: Virus preventing me downloading
                                                        « Reply #42 on: June 30, 2008, 02:04:45 AM »

                                                        SC open service FAILED 5
                                                        Access denied

                                                        message?

                                                        Derek Mc

                                                          Topic Starter


                                                          Rookie

                                                          Re: Virus preventing me downloading
                                                          « Reply #43 on: June 30, 2008, 01:11:56 PM »
                                                          I have run a full search from the cmd box and cannot find Mywebsearch so it seems my last visit to the cmb bar was successful in deleting it.

                                                          Broni


                                                            Mastermind
                                                          • Kraków my love :)
                                                          • Thanked: 614
                                                            • Computer Help Forum
                                                          • Computer: Specs
                                                          • Experience: Experienced
                                                          • OS: Windows 8
                                                          Re: Virus preventing me downloading
                                                          « Reply #44 on: June 30, 2008, 09:55:07 PM »
                                                          Post fresh HJT log.

                                                          Derek Mc

                                                            Topic Starter


                                                            Rookie

                                                            Re: Virus preventing me downloading
                                                            « Reply #45 on: July 01, 2008, 01:40:50 AM »
                                                            Ran this this morning.

                                                            Logfile of Trend Micro HijackThis v2.0.2
                                                            Scan saved at 08:40:15, on 01/07/2008
                                                            Platform: Windows Vista  (WinNT 6.00.1904)
                                                            MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                                            Boot mode: Normal

                                                            Running processes:
                                                            C:\Windows\system32\Dwm.exe
                                                            C:\Windows\system32\taskeng.exe
                                                            C:\Windows\Explorer.EXE
                                                            C:\Program Files\Windows Defender\MSASCui.exe
                                                            C:\Windows\System32\hkcmd.exe
                                                            C:\Windows\System32\igfxpers.exe
                                                            C:\Windows\system32\igfxsrvc.exe
                                                            C:\Program Files\Apoint\Apoint.exe
                                                            C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                            C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                                            C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                                            C:\Program Files\AVG\AVG8\avgtray.exe
                                                            C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                            C:\Program Files\Sony\Network Utility\LANUtil.exe
                                                            C:\Windows\ehome\ehtray.exe
                                                            C:\Windows\ehome\ehmsas.exe
                                                            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                            C:\EPC\Toolbar\EPSIBar.exe
                                                            C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                                            C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                                            C:\Windows\system32\taskeng.exe
                                                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                            C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                                            C:\Program Files\Apoint\ApMsgFwd.exe
                                                            C:\Program Files\Apoint\Apntex.exe
                                                            C:\Windows\System32\GRVSA.exe
                                                            C:\Windows\System32\mobsync.exe
                                                            C:\Program Files\AOL 9.0 VR\waol.exe
                                                            C:\Program Files\AOL 9.0 VR\shellmon.exe
                                                            C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
                                                            C:\Program Files\Mozilla Firefox\firefox.exe
                                                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                            R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                            O1 - Hosts: ::1 localhost
                                                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                            O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                                            O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                            O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                                            O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                                            O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                            O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                            O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                            O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                            O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                                            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                            O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                                            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                                            O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                                            O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                                            O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                            O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                            O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                            O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                            O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                            O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                                            O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                                            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                            O13 - Gopher Prefix:
                                                            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                                            O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                                            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                                            O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                                            O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                                            O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                                            O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                                            O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
                                                            O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                                            O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                                            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                                            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                                            O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                                            O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                                            O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                                            O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                            O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                            O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                                            O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                                            O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                            O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                            O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                                            O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                                            O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                                            O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                                            O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                                            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                            --
                                                            End of file - 11972 bytes

                                                            Broni


                                                              Mastermind
                                                            • Kraków my love :)
                                                            • Thanked: 614
                                                              • Computer Help Forum
                                                            • Computer: Specs
                                                            • Experience: Experienced
                                                            • OS: Windows 8
                                                            Re: Virus preventing me downloading
                                                            « Reply #46 on: July 01, 2008, 10:30:38 PM »
                                                            It's still there.

                                                            Go back to my post #41, and run those commands one more time...
                                                            I'm not sure, if I understand your post #42:
                                                            Quote
                                                            SC open service FAILED 5
                                                            Access denied

                                                            message?

                                                            Derek Mc

                                                              Topic Starter


                                                              Rookie

                                                              Re: Virus preventing me downloading
                                                              « Reply #47 on: July 02, 2008, 02:07:29 AM »
                                                              I tried it again from the
                                                              c:\users\derek prompt. I then got

                                                              The specified service does not exist as an installed service

                                                              I then ran the delete my,,,,,,,etc
                                                              and got the same - the specified service does not exist as an installed service


                                                              Broni


                                                                Mastermind
                                                              • Kraków my love :)
                                                              • Thanked: 614
                                                                • Computer Help Forum
                                                              • Computer: Specs
                                                              • Experience: Experienced
                                                              • OS: Windows 8
                                                              Re: Virus preventing me downloading
                                                              « Reply #48 on: July 02, 2008, 07:27:08 PM »
                                                              Go Start>Run, type in:
                                                              services.msc
                                                              Click OK.

                                                              Services window will open. Check the list, and see, if there is MyWebSearchService, or something similar present. If something similar, post back its exact name.

                                                              Derek Mc

                                                                Topic Starter


                                                                Rookie

                                                                Re: Virus preventing me downloading
                                                                « Reply #49 on: July 03, 2008, 02:24:38 AM »
                                                                One or two come up all listed as inside the

                                                                Microsoft common console document

                                                                the folders are
                                                                1. x_86 microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en.us_e208...

                                                                2. x_86,,,same except after,,,,,,                                                                       6000.16386_none_cd2d20a848c...

                                                                The other two look "normal" and are
                                                                system32 (c:\windows)
                                                                en.us (C:\windows\system32)

                                                                Broni


                                                                  Mastermind
                                                                • Kraków my love :)
                                                                • Thanked: 614
                                                                  • Computer Help Forum
                                                                • Computer: Specs
                                                                • Experience: Experienced
                                                                • OS: Windows 8
                                                                Re: Virus preventing me downloading
                                                                « Reply #50 on: July 03, 2008, 07:18:22 PM »
                                                                I'm not sure, if I understand your answer.
                                                                What are the names of services, you found in "services.msc" window?

                                                                Derek Mc

                                                                  Topic Starter


                                                                  Rookie

                                                                  Re: Virus preventing me downloading
                                                                  « Reply #51 on: July 04, 2008, 02:04:01 AM »
                                                                  I don't know what that list must have been? I ran it again now and did find a listing

                                                                  My Web Search Service. I opened the properties and attempted to disable it as I cannot seem to delete it?

                                                                  Broni


                                                                    Mastermind
                                                                  • Kraków my love :)
                                                                  • Thanked: 614
                                                                    • Computer Help Forum
                                                                  • Computer: Specs
                                                                  • Experience: Experienced
                                                                  • OS: Windows 8
                                                                  Re: Virus preventing me downloading
                                                                  « Reply #52 on: July 04, 2008, 06:42:16 PM »
                                                                  Quote
                                                                  I opened the properties and attempted to disable it
                                                                  ...and? Did it let you?
                                                                  If so, post new HJT log.

                                                                  Derek Mc

                                                                    Topic Starter


                                                                    Rookie

                                                                    Re: Virus preventing me downloading
                                                                    « Reply #53 on: July 05, 2008, 02:01:55 AM »
                                                                    It did appear to let me disable it, but not delete it i searched in the cmd box but it cannot be found.
                                                                    Here is the HJT log

                                                                    Logfile of Trend Micro HijackThis v2.0.2
                                                                    Scan saved at 09:00:06, on 05/07/2008
                                                                    Platform: Windows Vista  (WinNT 6.00.1904)
                                                                    MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                                                    Boot mode: Normal

                                                                    Running processes:
                                                                    C:\Windows\system32\taskeng.exe
                                                                    C:\Windows\system32\Dwm.exe
                                                                    C:\Windows\Explorer.EXE
                                                                    C:\Program Files\Windows Defender\MSASCui.exe
                                                                    C:\Windows\System32\hkcmd.exe
                                                                    C:\Windows\System32\igfxpers.exe
                                                                    C:\Program Files\Apoint\Apoint.exe
                                                                    C:\Windows\system32\igfxsrvc.exe
                                                                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                                    C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                                    C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                                                                    C:\Program Files\Common Files\aol\1206988110\ee\aolsoftware.exe
                                                                    C:\Program Files\AVG\AVG8\avgtray.exe
                                                                    C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                                    C:\Program Files\Sony\Network Utility\LANUtil.exe
                                                                    C:\Windows\ehome\ehtray.exe
                                                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                                    C:\EPC\Toolbar\EPSIBar.exe
                                                                    C:\Windows\ehome\ehmsas.exe
                                                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                                                                    C:\Windows\system32\taskeng.exe
                                                                    C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
                                                                    C:\Windows\System32\GRVSA.exe
                                                                    C:\Program Files\Apoint\ApMsgFwd.exe
                                                                    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                                    C:\Program Files\Apoint\Apntex.exe
                                                                    C:\Program Files\AOL 9.0 VR\waol.exe
                                                                    C:\Program Files\AOL 9.0 VR\shellmon.exe
                                                                    C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
                                                                    C:\Windows\system32\SearchFilterHost.exe
                                                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.easyspace.com/webmail_login.php
                                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com
                                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                                                    R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                                    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                                    O1 - Hosts: ::1 localhost
                                                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                                                    O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                                                    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                                    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                                                    O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                                                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                                                    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                                                                    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                                                    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                                                    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                                                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                                                    O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                                                                    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                                                    O4 - HKLM\..\Run: [MarketingTools] C:\Program Files\Sony\Marketing Tools\MarketingTools.exe
                                                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                                                                    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1206988110\ee\AOLSoftware.exe
                                                                    O4 - HKLM\..\Run: [CorelDRAW Graphics Suite 11b] C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe /title="CorelDRAW Graphics Suite 12" /date=041508 serial=DR12CEl-3361936-xty lang=EN
                                                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                                                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                                                    O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                                                    O4 - HKCU\..\Run: [NSUFloatingUI] "C:\Program Files\Sony\Network Utility\LANUtil.exe"
                                                                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                                                    O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
                                                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
                                                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
                                                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
                                                                    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                                                                    O4 - Global Startup: EPSI ToolBar.lnk = C:\EPC\Toolbar\EPSIBar.exe
                                                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                                                    O13 - Gopher Prefix:
                                                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                                                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                                                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                                                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll,
                                                                    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
                                                                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                                                    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                                                    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
                                                                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                                                                    O23 - Service: NSUService - Sony Corporation - C:\Program Files\Sony\Network Utility\NSUService.exe
                                                                    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                                                                    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                                                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                                                                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                                                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                                                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                                                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                                                    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                                                                    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                                                    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                                                    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                                                                    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                                                                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                                                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                                                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

                                                                    --
                                                                    End of file - 11847 bytes

                                                                    Broni


                                                                      Mastermind
                                                                    • Kraków my love :)
                                                                    • Thanked: 614
                                                                      • Computer Help Forum
                                                                    • Computer: Specs
                                                                    • Experience: Experienced
                                                                    • OS: Windows 8
                                                                    Re: Virus preventing me downloading
                                                                    « Reply #54 on: July 05, 2008, 05:32:16 PM »
                                                                    Well done :)

                                                                    Your computer is clean

                                                                    1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                                                                    Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                                                                    Run CCleaner.

                                                                    2. Turn off System Restore:

                                                                    - Windows XP:
                                                                       1. Click Start.
                                                                       2. Right-click the My Computer icon, and then click Properties.
                                                                       3. Click the System Restore tab.
                                                                       4. Check "Turn off System Restore".
                                                                       5. Click Apply.   
                                                                       6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                                                                       7. Click OK.
                                                                    - Windows Vista:
                                                                       1. Click Start.
                                                                       2. Right-click the Computer icon, and then click Properties.
                                                                       3. Click on System Protection under the Tasks column on the left side
                                                                       4. Click on Continue on the "User Account Control" window that pops up
                                                                       5. Under the System Protection tab, find Available Disks
                                                                       6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                                                                       7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                                                                       8. Click OK

                                                                    3. Restart computer.

                                                                    4. Turn System Restore on.

                                                                    5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                                                                    6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                                                                    7. Let me know, how your computer is doing.