Believe the hijacked destop is fixed. Thanks! However...when I start up, I bet it took three minutes for the destop to load. The wheels just kept spinning. Any reason for this?
New logs to follow.
Thanks and let me know about the slowdown, please.
Microsoft Windows XP [Version 5.1.2600]
The current date is: Wed 12/14/2005
The current time is: 21:34:26.34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
spyaxe uninstaller NOT present
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003
Killing PID 636 'explorer.exe'
Killing PID 636 'explorer.exe'
Starting registry repairs
Deleting files
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
~~~ Upon reboot ~~~
wininet.old not present!
oleadm.dll not present!
oleext.dll not present!
~~~ Upon completion ~~~
wininet.old not present!
oleadm.dll not present!
oleext.dll not present!
~~~~ Rechecking C:\WINDOWS\system32\wininet.dll for infection ~~~~
Logfile of HijackThis v1.99.1
Scan saved at 11:02:26 PM, on 12/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:31:03 PM, 12/14/2005
+ Report-Checksum: 3F98F605
+ Scan result:
HKU\S-1-5-21-3055202376-2734875014-2811016977-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33} -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-3055202376-2734875014-2811016977-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36A59337-6EEF-40AE-94B1-ED443A0C4740} -> Spyware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@e-2dj6wfk4uhcpceo.stats.esomniture[2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@image.masterstats[1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@maxim.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@rotator.adjuggler[1].txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
go get preferably two free onlines and post the results
Kaspersky Lab - Free Online scan: http://www.kaspersky.com/virusscanner
Click scan settings and place a check next to use [x]extended this database etc etc. Click ok.
Then choose: my computer: scan all your hard drives and mapped disks.
when finished click save as text and post that in your reply.
Panda ActiveScan-Free online scanner, http://www.pandasoftware.com/products/activescan.htm
Save the report and post it back here please if there are any that it is unable to deal with.
Winhound appears to be gone...but I time it this AM and it took over five minutes to boot up and sign on to IE (cable modem). It's never taken this long before... What's up?
Thanks
what do you mean sign i with IE ? comcast hiompage perhaps ?
have hijackthis fix those two (file missing) items
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
And in addremove programs uninstall comcast's extra tools, they are not needed, I use comcast myself and have uninstalled it.
Have you reset the modem lately ?
Turn the pc off, unplug the modem and firewall if you have one. wait 60 seconds plug the modem and firewall back in wait about two minutes and turn the pc back on
Update suns java manualy
Sun Java V1.5.0_06 is Available: http://java.com/en/index.jsp
Afterwards Turn off it's auto-updater,(Its buggy) , in control panel java >
update tab uncheck its option to update automatically.
After you install the newer version its important to uninstall the old versions, via addremove programs.
Scan Statistics:
Total number of scanned objects: 20056
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 791 sec
No malware has been detected. The sections that have been scanned are CLEAN.
Scan process completed.
MY COMPUTER SCAN:
KASPERSKY ON-LINE SCANNER REPORT
Thursday, December 15, 2005 22:09:58
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 16/12/2005
Kaspersky Anti-Virus database records: 155474
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Statistics:
Total number of scanned objects: 53249
Number of viruses found: 11
Number of infected objects: 25
Number of suspicious objects: 0
Duration of the scan process: 2511 sec
Infected Object Name - Virus Name
C:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfg.class-352f55f0-223ab046.class Infected: Trojan-Downloader.Java.OpenStream.y
C:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfg.class-40baf3a5-5c6e7951.class Infected: Trojan-Downloader.Java.OpenStream.y
C:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfg.class-486c9904-1d0eb084.class Infected: Trojan-Downloader.Java.OpenStream.y
C:\Documents and Settings\Compaq_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfg.class-4ee51477-5dbbfd9b.class Infected: Trojan-Downloader.Java.OpenStream.y
C:\Program Files\Norton AntiVirus\Quarantine\498856CB.zip/Jvb.class Infected: Exploit.Java.Bytverify
C:\Program Files\Norton AntiVirus\Quarantine\498856CB.zip/MyFunction.class Infected: Trojan-Dropper.Java.Small.c
C:\Program Files\Norton AntiVirus\Quarantine\498856CB.zip/MainApp.class Infected: Trojan.Java.ClassLoader.f
C:\Program Files\Norton AntiVirus\Quarantine\498856CB.zip Infected: Trojan.Java.ClassLoader.f
C:\Program Files\Norton AntiVirus\Quarantine\50C454D6/MyFunction.class Infected: Trojan-Dropper.Java.Small.c
C:\Program Files\Norton AntiVirus\Quarantine\50C454D6 Infected: Trojan-Dropper.Java.Small.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0164201C.htm Infected: Trojan-Clicker.JS.Linker.h
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\397917C3.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\397917C3.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\397917C3.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\397917C3.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\397917C3.zip Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\678E2F19.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\678E2F19.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\678E2F19.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\678E2F19.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\678E2F19.zip Infected: Trojan-Downloader.Java.OpenConnection.v
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CFE04BE.zip/Matrix.class Infected: Trojan-Downloader.Java.OpenStream.c
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CFE04BE.zip/Counter.class Infected: Trojan.Java.ClassLoader.h
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CFE04BE.zip/Parser.class Infected: Trojan.Java.ClassLoader.d
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6CFE04BE.zip Infected: Trojan.Java.ClassLoader.d