Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Hi Im trying to learn as much as I can.  (Read 39771 times)

0 Members and 1 Guest are viewing this topic.

tony440

    Topic Starter


    Beginner

    Hi Im trying to learn as much as I can.
    « on: June 29, 2008, 12:30:09 PM »
    HI again, my problem is simple and I want to learn from it. But trying to get info is more difficult cause to enter anywhere I have to be register. I do want to be register but it takes me more time. I will be patient and register so I can learn more.
    Here goes : Ive downloaded a movie and it was major infected. I go crazy and start removing stuff from my computer. Little by little I LOST ALL MY DRIVES, including drives from my mainboard. I have a big mess. I know cause Ive scan my PC. And they all say the same you have a lots of trojans,virus,malware, you name anything and Ill have it. also I have driver detective and tells me all the problems. I have Uniblue registrybooster and tells me what a bunch off errors dude!
    QUESTION? CAN I JUST LEARN STEP BY STEP HOW TO REMOVE AND FIX ALL MY ERRORS AND GET BACK MY LOST INFO MANUALLY WITHOUT ALL THIS PROGRAMS?
    I willing to be patient and learn everything I need to do it. so I can fight and help others with any kind of problem with their computers thanks to a person who they will never meet. If I even had the idea of how to get back to the person that is attacking me. Ill chop off his fingers so he or she has to use the computer with his *censored*.

    Broni


      Mastermind
    • Kraków my love :)
    • Thanked: 614
      • Computer Help Forum
    • Computer: Specs
    • Experience: Experienced
    • OS: Windows 8
    Re: Hi Im trying to learn as much as I can.
    « Reply #1 on: June 29, 2008, 12:43:51 PM »
    Print these instructions out.

    1. Download SUPERAntiSpyware Free for Home Users:
    http://www.superantispyware.com/

        * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
        * An icon will be created on your desktop. Double-click that icon to launch the program.
        * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
        * Close SUPERAntiSpyware.

    PHYSICALLY DISCONNECT  FROM THE INTERNET

    Restart computer in Safe Mode.
    To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

        * Open SUPERAntiSpyware.
        * Under "Configuration and Preferences", click the Preferences button.
        * Click the Scanning Control tab.
        * Under Scanner Options make sure the following are checked (leave all others unchecked):
              o Close browsers before scanning.
              o Scan for tracking cookies.
              o Terminate memory threats before quarantining.
        * Click the "Close" button to leave the control center screen.
        * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
        * On the left, make sure you check C:\Fixed Drive.
        * On the right, under "Complete Scan", choose Perform Complete Scan.
        * Click "Next" to start the scan. Please be patient while it scans your computer.
        * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
        * Make sure everything has a checkmark next to it and click "Next".
        * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
        * If asked if you want to reboot, click "Yes".
        * To retrieve the removal information after reboot, launch SUPERAntispyware again.
              o Click Preferences, then click the Statistics/Logs tab.
              o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
              o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
              o Please copy and paste the Scan Log results in your next reply.
        * Click Close to exit the program.
    Post SUPERAntiSpyware log.

    RECONNECT TO THE INTERNET

    RESTART COMPUTER!

    2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

        * Double-click mbam-setup.exe and follow the prompts to install the program.
        * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
        * If an update is found, it will download and install the latest version.
        * Once the program has loaded, select Perform full scan, then click Scan.
        * When the scan is complete, click OK, then Show Results to view the results.
        * Be sure that everything is checked, and click Remove Selected.
        * When completed, a log will open in Notepad.
        * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    RESTART COMPUTER!

    3. Download HijackThis:
    http://www.snapfiles.com/get/hijackthis.html
    Post HijackThis log.

    tony440

      Topic Starter


      Beginner

      Re: Hi Im trying to learn as much as I can.
      « Reply #2 on: June 29, 2008, 06:39:30 PM »
      here are the 3 logs in this order 1st from superantispyware 2nd malware and 3rd highjack this:
      SUPERAntiSpyware Scan Log
      http://www.superantispyware.com

      Generated 06/29/2008 at 07:04 PM

      Application Version : 4.15.1000

      Core Rules Database Version : 3469
      Trace Rules Database Version: 1460

      Scan type       : Complete Scan
      Total Scan Time : 00:39:28

      Memory items scanned      : 184
      Memory threats detected   : 0
      Registry items scanned    : 4429
      Registry threats detected : 0
      File items scanned        : 21705
      File threats detected     : 14

      Rootkit.RunTime3/WinCtrl32
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP106\A0104404.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP90\A0099332.SYS

      Trojan.Unknown Origin
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP106\A0104405.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP87\A0098254.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP87\A0099258.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP87\A0099272.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP90\A0099314.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP90\A0099345.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP90\A0099377.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP90\A0099390.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP92\A0099415.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP92\A0100431.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP92\A0100444.SYS
         C:\SYSTEM VOLUME INFORMATION\_RESTORE{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP93\A0100474.SYS

      2nd
      Malwarebytes' Anti-Malware 1.18
      Database version: 885

      8:02:16 PM 6/29/2008
      mbam-log-6-29-2008 (20-02-14).txt

      Scan type: Full Scan (C:\|E:\|)
      Objects scanned: 78255
      Time elapsed: 44 minute(s), 56 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\System Volume Information\_restore{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP106\A0104414.sys (Backdoor.Rustock) -> No action taken.

      3rd
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:38:26, on 6/29/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\cisvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\PC Tools AntiVirus\PCTAV.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\MSI\Live Update 3\LMonitor.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Ares\Ares.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe
      C:\Program Files\LimeWire\LimeWire.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
      O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {402b6f8f-75e3-4e28-ba63-126f48f66480} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
      O2 - BHO: (no name) - {9030d464-4c02-4abf-8ecc-5164760863c6} - (no file)
      O2 - BHO: (no name) - {f9112a18-3d55-4e21-8e5d-f589bd167154} - (no file)
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [liveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKLM\..\RunOnce: [MSIWU_1] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
      O4 - HKLM\..\RunOnce: [MSIWU_0] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
      O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
      O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
      O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [java_sun] Java (Sun)
      O15 - Trusted Zone: http://asia.msi.com.tw
      O15 - Trusted Zone: http://global.msi.com.tw
      O15 - Trusted Zone: http://www.msi.com.tw
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191246115781
      O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191246203109
      O16 - DPF: {8167c273-df59-4416-b647-c8bb2c7ee83e} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
      O20 - Winlogon Notify: coruscantsimpleactivitylogger - C:\WINDOWS\SYSTEM32\SimpleActivityLogger.dll
      O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
      O23 - Service: Ares Chatroom server (areschatserver) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Cryptographic Services CryptSvcRasMan (CryptSvcRasMan) - Unknown owner - C:\WINDOWS\system32\acctresp.exe
      O23 - Service: Intel(R) License Manager for FLEXlm (intel(r) license manager for flexlm) - Macrovision Corporation - C:\Program Files\Common Files\Intel\FLEXlm\lmgrd.intel.exe
      O23 - Service: Distributed Transaction Coordinator MSDTCLmHosts (msdtclmhosts) - Unknown owner - C:\WINDOWS\system32\advapi32m.exe (file missing)
      O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Telnet TlntSvrTermService (tlntsvrtermservice) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)f.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: Windows Management Instrumentation winmgmtAppMgmt (winmgmtappmgmt) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)y.exe (file missing)

      --
      End of file - 8628 bytes

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: Hi Im trying to learn as much as I can.
      « Reply #3 on: June 29, 2008, 09:06:46 PM »
      Your Malwarebytes log says "No action taken."
      Maybe, you posted its log from before fixing entries.
      Please, post correct log, or re-run Malwarebytes.
      If you re-run, I'll need fresh HJT log.

      tony440

        Topic Starter


        Beginner

        Re: Hi Im trying to learn as much as I can.
        « Reply #4 on: June 30, 2008, 01:03:06 PM »
        uh Im really stuck I follow your instr. here is the log I get

        Malwarebytes' Anti-Malware 1.18
        Database version: 885

        8:02:21 PM 6/29/2008
        mbam-log-6-29-2008 (20-02-21).txt

        Scan type: Full Scan (C:\|E:\|)
        Objects scanned: 78255
        Time elapsed: 44 minute(s), 56 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 1

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        C:\System Volume Information\_restore{5114BC6D-2B34-4E28-91B8-D6A61C5DAFF5}\RP106\A0104414.sys (Backdoor.Rustock) -> Quarantined and deleted successfully.

        Broni


          Mastermind
        • Kraków my love :)
        • Thanked: 614
          • Computer Help Forum
        • Computer: Specs
        • Experience: Experienced
        • OS: Windows 8
        Re: Hi Im trying to learn as much as I can.
        « Reply #5 on: June 30, 2008, 10:16:05 PM »
        Fresh HJT log, please.

        tony440

          Topic Starter


          Beginner

          Re: Hi Im trying to learn as much as I can.
          « Reply #6 on: July 02, 2008, 11:10:06 AM »
          is hjt stands for hijackthis? if it does. Ive made a scan and save the log here it is:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:48:23, on 7/2/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\cisvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\Userinit.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\PC Tools AntiVirus\PCTAV.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\Program Files\MSI\Live Update 3\LMonitor.exe
          C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Ares\Ares.exe
          C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          C:\Program Files\LimeWire\LimeWire.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
          O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {402b6f8f-75e3-4e28-ba63-126f48f66480} - (no file)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O2 - BHO: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
          O2 - BHO: (no name) - {9030d464-4c02-4abf-8ecc-5164760863c6} - (no file)
          O2 - BHO: (no name) - {f9112a18-3d55-4e21-8e5d-f589bd167154} - (no file)
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [liveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
          O4 - HKLM\..\RunOnce: [MSIWU_1] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
          O4 - HKLM\..\RunOnce: [MSIWU_0] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
          O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
          O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
          O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
          O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [java_sun] Java (Sun)
          O15 - Trusted Zone: http://asia.msi.com.tw
          O15 - Trusted Zone: http://global.msi.com.tw
          O15 - Trusted Zone: http://www.msi.com.tw
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191246115781
          O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191246203109
          O16 - DPF: {8167c273-df59-4416-b647-c8bb2c7ee83e} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
          O20 - Winlogon Notify: coruscantsimpleactivitylogger - C:\WINDOWS\SYSTEM32\SimpleActivityLogger.dll
          O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
          O23 - Service: Ares Chatroom server (areschatserver) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
          O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Cryptographic Services CryptSvcRasMan (CryptSvcRasMan) - Unknown owner - C:\WINDOWS\system32\acctresp.exe
          O23 - Service: Intel(R) License Manager for FLEXlm (intel(r) license manager for flexlm) - Macrovision Corporation - C:\Program Files\Common Files\Intel\FLEXlm\lmgrd.intel.exe
          O23 - Service: Distributed Transaction Coordinator MSDTCLmHosts (msdtclmhosts) - Unknown owner - C:\WINDOWS\system32\advapi32m.exe (file missing)
          O23 - Service: PC Tools AntiVirus Engine (PCTAVSvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
          O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
          O23 - Service: Telnet TlntSvrTermService (tlntsvrtermservice) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)f.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          O23 - Service: Windows Management Instrumentation winmgmtAppMgmt (winmgmtappmgmt) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)y.exe (file missing)

          --
          End of file - 8397 bytes
           

          Broni


            Mastermind
          • Kraków my love :)
          • Thanked: 614
            • Computer Help Forum
          • Computer: Specs
          • Experience: Experienced
          • OS: Windows 8
          Re: Hi Im trying to learn as much as I can.
          « Reply #7 on: July 02, 2008, 07:49:21 PM »
          You have two antivirus programs running: PC Tools AntiVirus, and Avast. You can't do this. One of them has to be uninstalled.
          I suggest, Avast is a keeper.
          When done post new HJT log.

          tony440

            Topic Starter


            Beginner

            Re: Hi Im trying to learn as much as I can.
            « Reply #8 on: July 02, 2008, 08:02:20 PM »
            hi thanks for the info heres again a log what is this log anyway? can I know or should I really know?

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:00:31, on 7/2/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16674)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\cisvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\slserv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\Explorer.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
            C:\Program Files\MSI\Live Update 3\LMonitor.exe
            C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Windows Media Player\WMPNSCFG.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Ares\Ares.exe
            C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            C:\Program Files\LimeWire\LimeWire.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
            O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {402b6f8f-75e3-4e28-ba63-126f48f66480} - (no file)
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O2 - BHO: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
            O2 - BHO: (no name) - {9030d464-4c02-4abf-8ecc-5164760863c6} - (no file)
            O2 - BHO: (no name) - {f9112a18-3d55-4e21-8e5d-f589bd167154} - (no file)
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [liveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKLM\..\RunOnce: [MSIWU_1] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
            O4 - HKLM\..\RunOnce: [MSIWU_0] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
            O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
            O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [java_sun] Java (Sun)
            O15 - Trusted Zone: http://asia.msi.com.tw
            O15 - Trusted Zone: http://global.msi.com.tw
            O15 - Trusted Zone: http://www.msi.com.tw
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191246115781
            O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191246203109
            O16 - DPF: {8167c273-df59-4416-b647-c8bb2c7ee83e} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O20 - Winlogon Notify: coruscantsimpleactivitylogger - C:\WINDOWS\SYSTEM32\SimpleActivityLogger.dll
            O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
            O23 - Service: Ares Chatroom server (areschatserver) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
            O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Cryptographic Services CryptSvcRasMan (CryptSvcRasMan) - Unknown owner - C:\WINDOWS\system32\acctresp.exe
            O23 - Service: Intel(R) License Manager for FLEXlm (intel(r) license manager for flexlm) - Macrovision Corporation - C:\Program Files\Common Files\Intel\FLEXlm\lmgrd.intel.exe
            O23 - Service: Distributed Transaction Coordinator MSDTCLmHosts (msdtclmhosts) - Unknown owner - C:\WINDOWS\system32\advapi32m.exe (file missing)
            O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
            O23 - Service: Telnet TlntSvrTermService (tlntsvrtermservice) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)f.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
            O23 - Service: Windows Management Instrumentation winmgmtAppMgmt (winmgmtappmgmt) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)y.exe

            --
            End of file - 8074 bytes

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: Hi Im trying to learn as much as I can.
            « Reply #9 on: July 02, 2008, 08:41:54 PM »
            HJT log allows me to see what is running on your computer, and determine, if your computer is in any danger.
            This is very powerful too. DO NOT play with it, unless you know what you're doing.
            I'll check the log, now.

            Broni


              Mastermind
            • Kraków my love :)
            • Thanked: 614
              • Computer Help Forum
            • Computer: Specs
            • Experience: Experienced
            • OS: Windows 8
            Re: Hi Im trying to learn as much as I can.
            « Reply #10 on: July 02, 2008, 09:02:21 PM »
            *** Disable TeaTimer, as it'll interfere with the cleaning process:
            Right click Spybot's TeaTimer System Tray Icon.
            Click Exit Spybot-S&D Resident.
            TeaTimer closes.

            *** Disable Windows Defender, as it'll interfere with cleaning process:
               * Open Windows Defender
                * Click Tools
                * Click General Settings
                * Scroll down to Real Time Protection Options
                * Uncheck Turn on Real Time Protection
                * After you uncheck this, click on the Save button
                * Close Windows Defender

            1. Print this post out, since you won't have an access to it, at some point.

            2. Close all windows, except for HijackThis.

            3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases (marked with *), no actual program will be removed):

            - R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            - O2 - BHO: (no name) - {402b6f8f-75e3-4e28-ba63-126f48f66480} - (no file)
            - O2 - BHO: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
            - O2 - BHO: (no name) - {9030d464-4c02-4abf-8ecc-5164760863c6} - (no file)
            - O2 - BHO: (no name) - {f9112a18-3d55-4e21-8e5d-f589bd167154} - (no file)
            - *O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            - *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            - *O4 - HKLM\..\Run: [liveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
            - *O4 - HKLM\..\RunOnce: [MSIWU_1] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
            - *O4 - HKLM\..\RunOnce: [MSIWU_0] "C:\PROGRA~1\MSI\LIVEUP~1\MSIWUPro.exe" -DEL:[C:\PROGRAM FILES\SETUP FILES\MS-6728 V3.A0\CACHE\MS-6728V3.A0.EXE]
            - *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            - *O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            - *O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
            - *O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            - *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            - *O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
            - if you're not familiar with any of O15 - Trusted Zone entries, checkmark unknown entries
            - *O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            - O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
            - O23 - Service: Cryptographic Services CryptSvcRasMan (CryptSvcRasMan) - Unknown owner - C:\WINDOWS\system32\acctresp.exe
            - O23 - Service: Distributed Transaction Coordinator MSDTCLmHosts (msdtclmhosts) - Unknown owner - C:\WINDOWS\system32\advapi32m.exe (file missing)
            - O23 - Service: Telnet TlntSvrTermService (tlntsvrtermservice) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)f.exe
            - O23 - Service: Windows Management Instrumentation winmgmtAppMgmt (winmgmtappmgmt) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)y.exe


            4. Click on Fix checked button.

            5. Restart computer in Safe Mode (keep tapping F8 key, when your computer starts, until menu appears)

            6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

            7. Delete following files/folders (if present):

            - actxprxy(4)y.exe, actxprxy(4)f.exe, acctresp.exe files from C:\WINDOWS\system32

            8. Restart in Normal Mode.

            9. Post new HijackThis log.

            tony440

              Topic Starter


              Beginner

              Re: Hi Im trying to learn as much as I can.
              « Reply #11 on: July 03, 2008, 11:43:51 PM »
              Ive noticed that in this new log still the 02-20-23 that I check and fix still came back. DO I have to disconnect the internet phoneline PC and check them and fix them again?I will if I have to. Also Why are so many running processes and what are they exactly?Thanks for so much info by the way!

              here goes the log :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 01:30:38, on 7/4/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Windows Defender\MsMpEng.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\cisvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\slserv.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\Explorer.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
              O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {402b6f8f-75e3-4e28-ba63-126f48f66480} - (no file)
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O2 - BHO: (no name) - {7e853d72-626a-48ec-a868-ba8d5e23e045} - (no file)
              O2 - BHO: (no name) - {9030d464-4c02-4abf-8ecc-5164760863c6} - (no file)
              O2 - BHO: (no name) - {f9112a18-3d55-4e21-8e5d-f589bd167154} - (no file)
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O11 - Options group: [java_sun] Java (Sun)
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191246115781
              O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191246203109
              O16 - DPF: {8167c273-df59-4416-b647-c8bb2c7ee83e} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O20 - Winlogon Notify: !saswinlogon - C:\WINDOWS\
              O20 - Winlogon Notify: coruscantsimpleactivitylogger - C:\WINDOWS\SYSTEM32\SimpleActivityLogger.dll
              O20 - Winlogon Notify: winrkp32 - C:\WINDOWS\
              O23 - Service: Ares Chatroom server (areschatserver) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
              O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Cryptographic Services CryptSvcRasMan (CryptSvcRasMan) - Unknown owner - C:\WINDOWS\system32\acctresp.exe
              O23 - Service: Intel(R) License Manager for FLEXlm (intel(r) license manager for flexlm) - Macrovision Corporation - C:\Program Files\Common Files\Intel\FLEXlm\lmgrd.intel.exe
              O23 - Service: Distributed Transaction Coordinator MSDTCLmHosts (msdtclmhosts) - Unknown owner - C:\WINDOWS\system32\advapi32m.exe (file missing)
              O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
              O23 - Service: Telnet TlntSvrTermService (tlntsvrtermservice) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)f.exe
              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
              O23 - Service: Windows Management Instrumentation winmgmtAppMgmt (winmgmtappmgmt) - Unknown owner - C:\WINDOWS\system32\actxprxy(4)y.exe

              --
              End of file - 6371 bytes

              Broni


                Mastermind
              • Kraków my love :)
              • Thanked: 614
                • Computer Help Forum
              • Computer: Specs
              • Experience: Experienced
              • OS: Windows 8
              Re: Hi Im trying to learn as much as I can.
              « Reply #12 on: July 04, 2008, 12:14:42 AM »
              1. Did you disable TeaTimer, and Windows Defender, while performing cleaning?
              2. What happened with deleting actxprxy(4)y.exe, actxprxy(4)f.exe, acctresp.exe files? You were not able to delete them?
              3. Go Start>Run, type in:
              cmd
              Click OK.

              At Command Prompt, type in:
              sc stop CryptSvcRasMan
              Hit Enter.
              Type in:
              sc delete CryptSvcRasMan
              Hit Enter.

              Repeat same "sc stop", and "sc delete" set of command substituting CryptSvcRasMan with:
              msdtclmhosts
              tlntsvrtermservice
              winmgmtappmgmt


              Report on progress, and post new HJT log.

              tony440

                Topic Starter


                Beginner

                Re: Hi Im trying to learn as much as I can.
                « Reply #13 on: July 04, 2008, 08:07:32 PM »
                I look again for the actxprxy(4)y.exe , actxprxy(4)f.exe and acctresp.exe there were no results I did manually and also use the search browser and there are no files with those lettrs or names??? I guess they were deleted successfully.
                Here is the new log from HJT:

                 Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 21:59:48, on 7/4/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Defender\MsMpEng.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\cisvc.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\slserv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\Explorer.EXE
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\WINDOWS\system32\cidaemon.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
                O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                O4 - HKCU\..\Run: [NBJ] "C:\PROGRA~1\Ahead\NEROBA~1\NBJ.exe"
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O9 - Extra button: (no name) - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Sun Java Console - {08b0e5c0-4fcb-11cf-aaa5-00401c608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O11 - Options group: [java_sun] Java (Sun)
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1191246115781
                O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191246203109
                O16 - DPF: {8167c273-df59-4416-b647-c8bb2c7ee83e} (WebSDev Control) - http://liveupdate.msi.com.tw/autobios/LOnline/install.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O20 - Winlogon Notify: coruscantsimpleactivitylogger - C:\WINDOWS\SYSTEM32\SimpleActivityLogger.dll
                O23 - Service: Ares Chatroom server (areschatserver) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                O23 - Service: avast! iAVS4 Control Service (aswupdsv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus (avast! antivirus) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner (avast! mail scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner (avast! web scanner) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Intel(R) License Manager for FLEXlm (intel(r) license manager for flexlm) - Macrovision Corporation - C:\Program Files\Common Files\Intel\FLEXlm\lmgrd.intel.exe
                O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

                --
                End of file - 5454 bytes
                 ;D

                Broni


                  Mastermind
                • Kraków my love :)
                • Thanked: 614
                  • Computer Help Forum
                • Computer: Specs
                • Experience: Experienced
                • OS: Windows 8
                Re: Hi Im trying to learn as much as I can.
                « Reply #14 on: July 04, 2008, 08:45:16 PM »
                Good job :)

                Your computer is clean

                1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
                Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
                Run CCleaner.

                2. Turn off System Restore:

                - Windows XP:
                   1. Click Start.
                   2. Right-click the My Computer icon, and then click Properties.
                   3. Click the System Restore tab.
                   4. Check "Turn off System Restore".
                   5. Click Apply.   
                   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
                   7. Click OK.
                - Windows Vista:
                   1. Click Start.
                   2. Right-click the Computer icon, and then click Properties.
                   3. Click on System Protection under the Tasks column on the left side
                   4. Click on Continue on the "User Account Control" window that pops up
                   5. Under the System Protection tab, find Available Disks
                   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
                   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
                   8. Click OK

                3. Restart computer.

                4. Turn System Restore on.

                5. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

                6. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

                7. Let me know, how your computer is doing.