Results 1 to 4 of 4

Thread: Cant update S&D,Maleware bytes and other issues

  1. #1
    Junior Member
    Join Date
    Feb 2010
    Posts
    3

    Default Cant update S&D,Maleware bytes and other issues

    i got a virus and have been trying to remove it for awhile.
    I got AVG to work but i still have issues from the virus.

    Issues:
    I can not update Spybot or visit safer-networking website.
    i can not update maleware bytes or website.
    right click programs opens windows installer every time.

    most annoying for me is the windows installer trying to install symantec anti virus every right click.

    Hijackthis log:
    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 10:44:21 AM, on 2/24/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\windows\System32\smss.exe
    C:\windows\system32\winlogon.exe
    C:\windows\system32\services.exe
    C:\windows\system32\lsass.exe
    C:\windows\system32\svchost.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\windows\system32\spoolsv.exe
    C:\windows\Explorer.EXE
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\windows\system32\ctfmon.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\windows\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\windows\System32\svchost.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\windows\system32\msiexec.exe
    C:\TrendMicro\HiJackThis\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.netmarble.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - (no file)
    O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
    O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\windows\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\windows\system32\shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {10060452-A92B-4427-8E06-46904B8A3678} (OMG Control) - http://neo.playomg.com/ActiveX/OMG3008.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/game...lugin11USA.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsof...?1187930582000
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab2.cab
    O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1187930559859
    O16 - DPF: {99CAAA27-FA0C-4FA4-B88A-4AB1CC7A17FE} (MGLaunch_v1004 Class) - http://www.netgame.com/mplugin/mglaunch_USAv1005.cab
    O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} (NeffyLauncherCtl Class) - http://dist.cdnetworks.co.kr/cdndist...fyLauncher.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{22C5CBE9-856E-4470-9D38-2C4C16AC215F}: NameServer = 93.188.162.103,93.188.166.85
    O17 - HKLM\System\CCS\Services\Tcpip\..\{8C4D0866-5AF1-4E84-8283-525A9F2F3746}: NameServer = 202.96.128.68,61.144.56.101
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 93.188.162.103,93.188.166.85
    O17 - HKLM\System\CS2\Services\Tcpip\..\{22C5CBE9-856E-4470-9D38-2C4C16AC215F}: NameServer = 93.188.162.103,93.188.166.85
    O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 93.188.162.103,93.188.166.85
    O17 - HKLM\System\CS5\Services\Tcpip\..\{22C5CBE9-856E-4470-9D38-2C4C16AC215F}: NameServer = 93.188.162.103,93.188.166.85
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.162.103,93.188.166.85
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\windows\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\windows\system32\browseui.dll
    O22 - SharedTaskScheduler: 7whfiudhf8s7f3oifhif7syfdhsof - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - (no file)
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 5996 bytes

  2. #2
    Junior Member
    Join Date
    Feb 2010
    Posts
    3

    Default

    i updated Spybot from another PC with a USB stick and did a boot scan.

    still have all the same issues. any suggestions on what i can do to fix them?

  3. #3
    Junior Member
    Join Date
    Feb 2010
    Posts
    3

    Default

    fixed the update/website issues by deleting IP entrys and ones i do not know.

    Still need to fix right click on shortcuts starting windows installer.

  4. #4
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,955

    Default

    Hello ZeroSpaceOne,

    Please see these FAQs, "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)

    Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. In addition helpers would think you are already being assisted because of the post count. For that reason we may merge such posts if there is time but please do not count on it.


    Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days

    If you have waited four days or longer for assistance, please start a topic in this sub-forum and post with a link back to your topic in the HJT forum, so that we know who you are and your topic is not archived.
    Best regards.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •