PDA

View Full Version : Browser Hijacked; VirusBursters; Critical System Errors; Windows Security Alerts



tuckerville
2006-11-02, 14:53
Hi,
I'm new here, but spent all last night trying to fix my computer! I have done everything that you guys required before posting. However, after completing the PandaScan for All My Computer and saving the results, I cannot find them on my computer ANYWHERE. The results found one virus that it disinfected, 2 "Hacking tools and potentially unwanted tools" and about 80+ spyware/adware results that it could not fix. At the moment I am re-running the scan, but since it will probably take a few more hourse, I wanted to go ahead and post in case something happens to my saved version of Hijackthis. Below please find the results for that scan.

Basically, IE has turned my Google homepage into a System Security Alert that won't go away even with changing the internet options and rebooting. I am getting aggressive advertising from all kinds of "suspect" spyware products, and my internet is randomly freezing. I am also getting random pornography sites that pop-up when I am not even on the internet - each site is an ad for locating people "in my city" which they have correctly defined (these are not sites that I have visited before.) There is a button on each page that says "if abuse, click here" and when I click it, it tells me to uninstall a codec program. When I do, it is back after I reboot. Thanks so much for your help! I will re-post when the Panda Virus Scan finishes again.

Logfile of HijackThis v1.99.1
Scan saved at 7:59:45 AM, on 11/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TrueCodec\isamonitor.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\Qctray.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\SYMANT~3\VPTray.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\TrueCodec\isamini.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Documents and Settings\eoconnor\Local Settings\Temporary Internet Files\Content.IE5\O5UFS5Q3\HijackThis[1].exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.netscape.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.unc.edu/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://surfix.w-lan.whu.edu/proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.unc.edu"); (C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {8bf5b8fc-11cb-409f-8c91-4d4ca04a1b6d} - C:\Program Files\TrueCodec\isaddon.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\TrueCodec\iesplugin.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [QCTRAY] C:\PROGRA~1\ThinkPad\CONNEC~1\Qctray.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [Tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe /server"
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TPTRAY] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98TRAY.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~3\VPTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {10E0E75E-6701-4134-9D95-C0942ED1F1C8} (Snapfish Outlook Import ActiveX Control) - http://www.snapfish.com/SnapfishOutlookImport.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: clamoring - {0d9eb558-0666-479e-868a-21b1d1a53bd1} - C:\WINDOWS\system32\veklo.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

tuckerville
2006-11-02, 16:09
Incident Status Location

Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\iesplugin.dll
Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\pmmon.exe
Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\veklo.dll
Adware:adware/tvmedia Not disinfected C:\Documents and Settings\eoconnor\Application Data\tvmcwrd.dll
Adware:adware/transponder Not disinfected c:\windows\dlmax.dll
Adware:adware/ieplugin Not disinfected c:\windows\kwv2.dat
Adware:adware/exact.bargainbuddy Not disinfected c:\windows\launcher.exe
Adware:adware/ncase Not disinfected c:\windows\msbbi.exe
Adware:adware/windowenhancer Not disinfected c:\windows\system32\SBUtils
Adware:adware/sidesearch Not disinfected c:\program files\Lycos
Adware:adware/btgrab Not disinfected Windows Registry
Adware:adware/mbkwbar Not disinfected Windows Registry
Adware:adware/topmoxie Not disinfected Windows Registry
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@atwola[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@go[2].txt
Spyware:Cookie/Paypopup Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@paypopup[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.myaffiliateprogram[1].txt
Spyware:Cookie/MyWay Not disinfected C:\Documents and Settings\Administrator\Cookies\administrator@www.xzoomy[1].txt
Virus:Trj/Downloader.FK Disinfected C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\GLOXWXAB\stc[1].html
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.2o7.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.adtech.de/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.com.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.go.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.maxserving.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.qksrv.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.realmedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.revenue.net/]
Spyware:Cookie/Santa Monica networks inc Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.smni.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\eoconnor\Application Data\Mozilla\Profiles\default\5trg2sly.slt\cookies.txt[www.myaffiliateprogram.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@2o7[1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@adultfriendfinder[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@atwola[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@drivecleaner[1].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@malwarewipe[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@stats.drivecleaner[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@stats1.reliablestats[2].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@statse.webtrendslive[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.drivecleaner[1].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.systemdoctor[1].txt
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\eoconnor\Cookies\eoconnor@www.virusburst[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@247realmedia[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ad.yieldmanager[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ads.pointroll[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@bluestreak[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@burstnet[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@casalemedia[2].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@cs.sexcounter[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@ehg-dig.hitbox[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@go[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@hitbox[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@mediaplex[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@realmedia[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@server.iad.liveperson[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@statcounter[1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@statse.webtrendslive[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@trafficmp[1].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@webpower[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@www.burstbeacon[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@www.myaffiliateprogram[2].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Cookies\eoconnor@z1.adserver[1].txt
Adware:Adware/SecurityError Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\laf2D8.tmp
Spyware:Spyware/ClearSearch Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Loader.EX_[C:\Documents and Settings\eoconnor\Local Settings\Temp\Loader.EXe]
Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.cab[mbkwnst.exe][MBKWBar.exe]
Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.cab[mbkwnst.exe][MBKWBar.exe][IEToolBar.dll]
Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.exe[MBKWBar.exe]
Adware:Adware/MBKWBar Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mbkwnst.exe[MBKWBar.exe][IEToolBar.dll]
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\mm_reco.exe
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\randreco.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\Tvm.exe
Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\TvmBho.dll
Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\temp.fr4CA5\TvmCore.dll
Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\Tvm.upd
Adware:Adware/TVMedia Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\tvmupdater.exe
Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temp\vb2D9.exe[VirusBursters.exe]
Potentially unwanted tool:Application/DriveCleaner Not disinfected C:\Documents and Settings\eoconnor\Local Settings\Temporary Internet Files\Content.IE5\ZYOF7LCX\installdrivecleanerstart[1].cab[UDC6_0001_D19M1908NetInstaller.exe]
Spyware:Spyware/Support Not disinfected C:\Program Files\Support.com\bin\tgcmd.exe
Adware:Adware/VideoKeyCodec Not disinfected C:\Program Files\TrueCodec\iesuninst.exe
Potentially unwanted tool:Application/VirusBurst Not disinfected C:\Program Files\VirusBursters\VirusBursters.exe
Adware:Adware/MBKWBar Not disinfected C:\WINDOWS\mbkwnst.exe[MBKWBar.exe]
Adware:Adware/MBKWBar Not disinfected C:\WINDOWS\mbkwnst.exe[MBKWBar.exe][IEToolBar.dll]

Mr_JAk3
2006-11-02, 20:40
Hi tuckerville and welcome to Safer Networking Forums :)

You got some infections there...

Please download HijackThis to your desktop from here -> HijackThis 1.99.1 (http://downloads.malwareremoval.com/HijackThis.exe)
Create a new folder named HijackThis to your desktop. Move Hijackthis.exe into that folder.

Please download SmitfraudFix (http://siri.urz.free.fr/Fix/SmitfraudFix.zip) (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply along with a fresh Hijackhis log.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm (http://www.beyondlogic.org/consulting/processutil/processutil.htm)

NOTE: Do not run any other options from SmitfraudFix until I tell you to do so!

Mr_JAk3
2006-11-07, 10:05
This topic is closed due to lack of a response.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread.

Applies only to the original topic starter.