| Live Chat & Podcast at 1:00PM Eastern on Sunday! |
| |
| | |
| Thread Tools |
|
19-Oct-2007, 02:59 PM
#1 |
| Hi guys: I am a 67 year old relatively new computer user who has a problem. I have 2 boxes that keep popping up in my computer. When I'm doing something I have to wait until they go away which is very annoying. One is a small green rcetangle that has a red circle with one side solid red, and an orange line with 100%. It will come up in conjunction with a blue square with a circle of symbols --one says exit. You can't move them or exit because they seem to be right up against the screen and the curser goes behind them. I am running windows XP I have Symantics antivirus, Ad-ware se and --spyblaster- I installed this after this after this showed up so it wouldn't have caught this if it is spyware. I have run Microsoft one care virus and spyware remover but it was still there after the scan. Does anyone know how to get rid of this--I prefer for free but I will pay if it is neccessary. |
| |
|
19-Oct-2007, 03:56 PM
#2 |
| I'm 60 so we can communicate Click here to download HJTInstall.exe
|
|
19-Oct-2007, 04:10 PM
#3 |
| here is the log file Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:08:12 PM, on 10/19/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\HP\KBD\KBD.EXE C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ctv.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?a19d18361fd64cee86d2e923f6bbca69 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?a19d18361fd64cee86d2e923f6bbca69 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase2895.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/a...pv2.0.0.9.cab? O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: SNDSrvc - Unknown owner - (no file) O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 8265 bytes |
|
19-Oct-2007, 05:13 PM
#4 |
| Did this start after you loaded the Adobe software - the log looks OK but lets run a couple of things NOTE: If you have downloaded ComboFix previously please delete that version and download it again! Download this file : http://download.bleepingcomputer.com...a/ComboFix.exe Double click combofix.exe & follow the prompts. When finished, it shall produce a log for you. Post that log Note: Do not mouseclick combofix's window while its running. That may cause it to stall ===================== Download Superantispyware (SAS) free home version http://www.superantispyware.com/supe...freevspro.html Install it and double-click the icon on your desktop to run it. · It will ask if you want to update the program definitions, click Yes. · Under Configuration and Preferences, click the Preferences button. · Click the Scanning Control tab. · Under Scanner Options make sure the following are checked: o Close browsers before scanning o Scan for tracking cookies o Terminate memory threats before quarantining. o Please leave the others as they were. o Click the Close button to leave the control center screen. · On the main screen, under Scan for Harmful Software click Scan your computer. · On the left check C:\Fixed Drive. · On the right, under Complete Scan, choose Perform Complete Scan. · Click Next to start the scan. Please be patient while it scans your computer. · After the scan is complete a summary box will appear. Click OK. · Make sure everything in the white box has a check next to it, then click Next. · It will quarantine what it found and if it asks if you want to reboot, click Yes. · To retrieve the removal information for me please do the following: o After reboot, double-click the SUPERAntispyware icon on your desktop. o Click Preferences. Click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o It will open in your default text editor (such as Notepad/Wordpad). o Please highlight everything in the notepad, then right-click and choose copy. · Click close and close again to exit the program. · Please paste that information here for me regardless of what it finds with a new HijackThis log. This will take some time!!!!!!!! |
|
19-Oct-2007, 08:34 PM
#5 |
| I tried the ComboFix.exe site. I typed 1 and nothing happened--finally after about 2 hours I typed 2 to stop what I think never started and xed it out. Do you really need this-- should I try again or go on to what you say to do next. Do I need the first step Keep in mind I'm a newbie and don't know all the ins and outs of things yet and if I sound stupid that's why |
|
19-Oct-2007, 10:04 PM
#7 |
| I did the second scan--superantispyware--it only came up with 151 adware cookies--I left them there because I didn't know if they were for my ad-ware se or other harmful ad-ware. I had done an ad ware scan with ad-ware se and quaranteed all harmful ad ware brfore I wrote. When I was downloading the antispyware I saw the combo folder so it did download but didn't make an icon. Should I bring it up and run it--I'd hate to have it not work again. I'll go back and post the logs if you want. |
|
19-Oct-2007, 10:09 PM
#8 |
| SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 10/19/2007 at 08:53 PM Application Version : 3.9.1008 Core Rules Database Version : 3328 Trace Rules Database Version: 1328 Scan type : Complete Scan Total Scan Time : 00:46:13 Memory items scanned : 406 Memory threats detected : 0 Registry items scanned : 6166 Registry threats detected : 0 File items scanned : 43699 File threats detected : 151 Adware.Tracking Cookie C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.traderonline[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.addesktop[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@xiti[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@46343922[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@mb[3].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.burstbeacon[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@41409448[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@nextag[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adv.webmd[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.allaboutvision[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@superstats[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@88287119[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[4].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@6425137[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@qnsr[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atwola[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@drivecleaner[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@revsci[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adopt.specificclick[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adcentriconline[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@a[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@countercentral[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@46877078[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@57386690[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@43836137[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@gostats[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ad.greenmarquee[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@35668663[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@v7.stats.load[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@dealtime.co[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@stats.drivecleaner[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.mediamayhemcorp[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cancerbacup[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@pt.crossmediaservices[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@vhost.oddcast[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@easy-hit-counters[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[8].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@homeclick[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@sub1[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@39481703[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@9551721[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@toplisted[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@sitestats.tiscali.co[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.pcmightymax[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.owen-media-store[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.clickmanage[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@S124390[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@sales.liveperson[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.blankdvdmedia[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@burstnet[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@go.drivecleaner[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@70062990[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@tacoda[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@73722690[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@68418892[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@70307935[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@tracker.toptensites[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@_[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@11906334[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ticketcity[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@sitestat.mayoclinic[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@yadro[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@gtmedia.us.intellitxt[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@48493158[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@link.vericlick[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@counter.surfcounters[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@shopwhizz.pe.tripod[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.dealtime[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adserver[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@supermediastore[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@15978193[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@74613876[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@nicolaa5.tripod[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@products[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@27889365[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@data3.perf.overture[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@helpinghearts0.tripod[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@forums.govteen[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@partner2profit[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@clicktracks.commercebox[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@m1.webstats.motigo[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@13178860[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.uncoverthenet[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.elitecarseats[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@h.starware[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@wharfside[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@publishers.clickbooth[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1068864387[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@163a0a0e60[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@members.tripod.com[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1060531853[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@bupa[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@richmedia.yahoo[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.techguy[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@74139060[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.ticketsnow2[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1072721489[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@57612115[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ad.yieldmanager[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@arbitrack[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ad.thewheelof[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@try.starware[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@bannerspace[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@75069416[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@anad.tacoda[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070162032[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@2.adbrite[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.homeclick[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1062814013[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@interclick[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[6].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.drgnetwork[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@banners.iop[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070943674[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@kanoodle[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ecnext.advertserve[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@itcg.1245.clickshield[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1072545379[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070602459[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070847646[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1071419379[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[10].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.associatedcontent[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@43517443[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1069526847[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.supermediastore[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@hypertracker[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070542637[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1072658227[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@azjmp[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@media.sensis.com[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@onewayfurniture[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1071607107[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1071492249[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@stats.canalblog[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@itxt.vibrantmedia[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@27391302[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@gailbable.tripod[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@anat.tacoda[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@efluxmedia[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1071868927[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@81375089[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1071042649[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@1070791529[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@2o7[2].txt C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@data4.perf.overture[1].txt C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@nextag[2].txt C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@qnsr[2].txt C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Cookies\compaq_owner@track.searchignite[1].txt |
|
19-Oct-2007, 10:11 PM
#10 |
| I see by this maybe I should have quaranteened them. Oh well I'll go back and run the scan again--What do you think |
|
19-Oct-2007, 10:12 PM
#11 |
| Ok will do |
|
19-Oct-2007, 10:16 PM
#12 |
| Tried to get a new Hijack scan--did it copied and pasted it and it wouldn't past I got a message that this was the same as one posted earlier |
|
19-Oct-2007, 11:09 PM
#14 |
| new log SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 10/19/2007 at 08:53 PM Application Version : 3.9.1008 Core Rules Database Version : 3328 Trace Rules Database Version: 1328 Scan type : Complete Scan Total Scan Time : 00:46:13 Memory items scanned : 406 Memory threats detected : 0 Registry items scanned : 6166 Registry threats detected : 0 File items scanned : 43699 File threats detected : 151 Adware.Tracking Cookie C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.traderonline[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.addesktop[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@xiti[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@46343922[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@mb[3].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@www.burstbeacon[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@41409448[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@nextag[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adv.webmd[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.allaboutvision[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@superstats[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@88287119[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[4].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@6425137[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@qnsr[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@atwola[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@drivecleaner[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@revsci[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adopt.specificclick[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@adcentriconline[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@a[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@countercentral[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@46877078[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@57386690[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@43836137[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@gostats[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ad.greenmarquee[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@35668663[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@v7.stats.load[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@dealtime.co[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@stats.drivecleaner[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@ads.mediamayhemcorp[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cancerbacup[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@pt.crossmediaservices[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@vhost.oddcast[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@easy-hit-counters[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@cgi-bin[8].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@homeclick[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@sub1[2].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@39481703[1].txt C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@9551721[1].txtcookies gone |
|
19-Oct-2007, 11:10 PM
#15 |
| Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 22:10, on 2007-10-19 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\HP\KBD\KBD.EXE C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\01\SUPERAntiSpyware.exe C:\01\SUPERAntiSpyware.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ctv.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\01\SUPERAntiSpyware.exe O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin/module.main/favorites\ie_add_to.html O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/229?a19d18361fd64cee86d2e923f6bbca69 O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ca\msntabres.dll.mui/230?a19d18361fd64cee86d2e923f6bbca69 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase2895.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/a...pv2.0.0.9.cab? O20 - Winlogon Notify: !SASWinLogon - C:\01\SASWINLO.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: SNDSrvc - Unknown owner - (no file) O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 8286 bytes |

|
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |

| Thread Tools | |
| |
| You Are Using: |
Advertisements do not imply our endorsement of that product or service. All times are GMT -4. The time now is 12:53 AM. Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved. | |

