mrbreezeet1
New member
I'm pretty sure I am OK now, And again pretty sure I have the latest Java from sun.
Some Background
I was having this issue, where music will play,and there doing some
kind of interview about a tattoo shop, then something I think about a ford
truck, and I don't know what all else.
There was no web page open other than my home page yahoo mail.
I ran AVG and it said it found 4 and removed 4 threats, also ran ad
aware,and it removed some cookies.
I also saw this " Viewpoint something or other in ask manager,(processes)
and removed it in add remove programs.
I wrote the XP group, One of the MPV's thought it sounded like "a Zlob infection with Vundo and SDBot along for the ride"
AVG had reported a ZlobWM, and also a AdloadEZ, and said it fixed them.
But I still had the issue.
Also my tried to bring up task manager, it said it was
disabled,
I ran The Vundo fix, and it found nothing,
Ran spy bot search and destroy, and it DID find the Zlob, and removed it.
So it "seems" OK now, but one of the MPV's said to post the HJT log file here.
I am getting a reference to "windows live one care," but I am not using Live one care anymore, so I tried to remove it with HJT, but it keeps coming back.
I am hoping it is not some other file or Trojan trying to "fool me" using the Windows Live One Care name.
Thank You, here is the Log file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:52 AM, on 4/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\jszituxm\jihidyha.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Grisoft\AVG7\avgw.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\A Diodati\My Documents\Downloads\Programs\HiJackThis.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
--
End of file - 1776 bytes
Some Background
I was having this issue, where music will play,and there doing some
kind of interview about a tattoo shop, then something I think about a ford
truck, and I don't know what all else.
There was no web page open other than my home page yahoo mail.
I ran AVG and it said it found 4 and removed 4 threats, also ran ad
aware,and it removed some cookies.
I also saw this " Viewpoint something or other in ask manager,(processes)
and removed it in add remove programs.
I wrote the XP group, One of the MPV's thought it sounded like "a Zlob infection with Vundo and SDBot along for the ride"
AVG had reported a ZlobWM, and also a AdloadEZ, and said it fixed them.
But I still had the issue.
Also my tried to bring up task manager, it said it was
disabled,
I ran The Vundo fix, and it found nothing,
Ran spy bot search and destroy, and it DID find the Zlob, and removed it.
So it "seems" OK now, but one of the MPV's said to post the HJT log file here.
I am getting a reference to "windows live one care," but I am not using Live one care anymore, so I tried to remove it with HJT, but it keeps coming back.
I am hoping it is not some other file or Trojan trying to "fool me" using the Windows Live One Care name.
Thank You, here is the Log file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:32:52 AM, on 4/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\All Users\Application Data\jszituxm\jihidyha.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Grisoft\AVG7\avgw.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\A Diodati\My Documents\Downloads\Programs\HiJackThis.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
--
End of file - 1776 bytes