There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Malware Removal & HijackThis Logs
Tag Cloud
adware audio bios blue screen boot bsod computer crash dell desktop driver email error excel firefox freeze google hard drive hardware hijackthis install internet itunes laptop linux malware network no sound outlook problem recovery router screen server slow sound speakers spyware startup trojan usb video virus vista webcam windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
Extremely Slow Computer (In Progress)

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
24-Jun-2009, 08:39 PM #16
Is Speeditup Free or Search Defender still listed in Add Or Remove Programs, and does it have a Speeditup Free of Search Defender folder inside the C:\Program Files folder?

According to your log, it's still installed and running in the background.

O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe

http://www.sysinfo.org/startuplist.p...chDefender.exe

If it's there and uninstallable, get rid of it and then delete its folder.

---------------------------------------------------------------

Get rid of Windows Defender and then delete its folder.

It does a poor job of antispyware protection and is another program that's dragging down performance.

Rambooster likely isn't doing anything to help performance either.

----------------------------------------------------------------

Last edited by flavallee : 24-Jun-2009 09:01 PM.
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
24-Jun-2009, 09:19 PM #17
Ok, uninstalling Search Defender and Windows defender. Could you recommend some good anti-virus, anti-spyware etc? Preferably free, but I wouldn't mind spending money on something like this.
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
24-Jun-2009, 09:36 PM #18
My recommendation is Grisoft AVG Anti-Virus Free Edition 8.5.374 for your antivirus program and Malwarebytes Anti-Malware 1.38 and SUPERAntiSpyware 4.26.0.1004 for your antispyware arsenal.

They're all free and very user-friendly.

--------------------------------------------------------------

Is PC Tools Spyware Doctor still in that computer?

---------------------------------------------------------------
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
24-Jun-2009, 09:50 PM #19
Quote:
Originally Posted by flavallee View Post
--------------------------------------------------------------

Is PC Tools Spyware Doctor still in that computer?

---------------------------------------------------------------
I'm not actually sure. In fact, I'm worried I didn't even uninstall Search Defender. All that was in the Add or Remove Program was SpeeditupFree. Uninstalled that and am installing all the software you recommended.
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
25-Jun-2009, 07:44 AM #20
You're saying that SpeedItUp Free and/or Search Defender is not in the Add Or Remove Programs list, correct?

Is there a folder with that name inside the C:\Program Files folder? I advised you to delete it(after uninstalling the program) if there was.

Is PC Tools Spyware Doctor in the Add Or Remove Programs list and/or inside the C:\Program Files folder? If it is, uninstall it and then delete its folder.

----------------------------------------------------------------

After you get AVG8, Malwarebytes and SUPERAntiSpyware installed and have restarted your computer, and after you have done the above and answered my questions, post a new HijackThis log here.

-----------------------------------------------------------------
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
25-Jun-2009, 05:50 PM #21
Only SpeeditupFree was in the Add or Remove Programs window. Spyware Doctor wasn't and I can't seem to find it anywhere.

here's the log.

=====================================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:37:23 PM, on 6/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\TEMP\SPD723.EXE
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\RamBooster 2.0\Rambooster.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--
End of file - 5755 bytes
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
25-Jun-2009, 08:32 PM #22
Run a HijackThis scan, put a checkmark in

R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')

O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll


then click "Fix checked".

Close HijackThis, then restart your computer.

Run a second scan, then post that log here.

----------------------------------------------------------------
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
05-Jul-2009, 02:39 PM #23
Sorry for taking so long but I think AVG has completely destroyed my computer. It kept on popping up threats so I removed them all. Next time I booted I was told that 2 system32 files were missing.
1. msvcldn
2. msbiyk
A lot of my programs aren't working now. And I can't open anything in the control panel cos rundll32.exe is missing. I have no idea what to do.

Here's the new log.

===============================================

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:15 PM, on 7/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\RoamMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Intel\Switching\User\RoamSvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\GOD52E.EXE
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
F3 - REG:win.ini: load=C:\WINDOWS\system32\msvcldn.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\msbiyk.exe
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.62 surety.microsoft.com
O1 - Hosts: 209.44.111.62 aware-protect.com
O1 - Hosts: 209.44.111.62 www.aware-protect.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\mskfszv.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Adapter Switching (IntelRoam) - Intel Corporation - C:\Program Files\Intel\Switching\User\RoamSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: RoamMgr - Intel Corporation - C:\WINDOWS\System32\RoamMgr.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe

--
End of file - 5336 bytes
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
05-Jul-2009, 05:20 PM #24
You definitely have a big problem with your computer.

These are 7 new log entries that weren't in your previous log.

F3 - REG:win.ini: load=C:\WINDOWS\system32\msvcldn.exe

F3 - REG:win.ini: run=C:\WINDOWS\system32\msbiyk.exe

O1 - Hosts: ::1 localhost

O1 - Hosts: 209.44.111.62 surety.microsoft.com

O1 - Hosts: 209.44.111.62 aware-protect.com

O1 - Hosts: 209.44.111.62 www.aware-protect.com

O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\mskfszv.exe


The C:\WINDOWS\TEMP folder is also showing suspicious files, such as:

GOD52E.EXE

SPD723.EXE


---------------------------------------------------------------

Follow the instructions in post #9 to empty out those 2 TEMP folders.

Empty the Recycle Bin afterwards and then restart your computer.

---------------------------------------------------------------

Are you willing to let a malware expert assist you this time?

Is anyone else using that computer besides you?

---------------------------------------------------------------

Last edited by flavallee : 05-Jul-2009 05:28 PM.
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
05-Jul-2009, 10:05 PM #25
I've been willing to accept help from a malware expert this whole time. t's just that they're supposed to be really busy so I didn't push too much.

And I can't see hidden files/folders. I said this before but everytime I change the option and click OK, nothing happens. If i go back to Folder Options, it's always back to "do not show".

Figured I'd explain my problems in more depth. Basically, every time I click on a program or a shortcut, it opens the whole "Windows doesn't know what program to open this with. Pick One". I can navigate to the folder and have it work but it's a pretty serious problem. I want to be clear that this doesn't apply only to shortcuts, clicking on the programs themselves does the same thing. Interestingly, if I try opening a file it works properly.

I think the bigger problem is that i can't open anything in the control panel coz of the missing rundll32.exe.

I'm also a little scared of AVG and don't know what to do with all the warnings it's giving me. There a lot of system files there and while I kow virues often masquerade as system files, some of them might be legit.

Should I fix those new entries you mentioned?
flavallee's Avatar
Computer Specs
Trusted Advisor with 23,237 posts.
 
Join Date: May 2002
Location: Hillsborough county, Florida
Experience: Advanced
06-Jul-2009, 06:08 AM #26
You have to click both "Apply" and "OK", not just "OK".

If you don't apply the change, your computer doesn't know you want to change the settings.

-----------------------------------------------------------------

No, don't fix those 7 entries in HijackThis at this time.

I've submitted a report to have a malware expert assist you this time.

-----------------------------------------------------------------

Last edited by flavallee : 06-Jul-2009 06:14 AM.
cybertech's Avatar
Computer Specs
Moderator with 68,036 posts.
 
Join Date: Apr 2002
Location: Washington State
06-Jul-2009, 09:30 AM #27
Does AVG give you the name of the virus the files are infected with?
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
06-Jul-2009, 10:27 AM #28
I know this sounds weird but right now, for whatever reason, I CANNOT view hidden files/folders. Let me give you a rundown of what happens:

1. My Computer>Tools>Folder Options>View tab
2. Check "Show Hidden Folders" And Uncheck "hide system files"
3. Click Apply and then OK
4. Look around for hidden files - none show up
5. Go back to Folder Options, "Do not show hidden files and folders" is checked.
6. Repeat

About the virus names, they're almost all labelled as Trojan Horses. The system files are all tagged with TrojanHorse.VB.ITS. Hope that helps.
cybertech's Avatar
Computer Specs
Moderator with 68,036 posts.
 
Join Date: Apr 2002
Location: Washington State
06-Jul-2009, 04:18 PM #29
Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

Select the download that's appropriate for your Operating System




Download the file & save it as it's originally named.


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

Please note once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall.



  • Drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.




  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.
__________________
Microsoft MVP/Windows - Consumer Security
Grayson24's Avatar
Junior Member with 19 posts.
 
Join Date: Jun 2009
06-Jul-2009, 05:08 PM #30
Just a quick question. Should I install service pack 3 before doing any of that? Or does it not matter?
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 06:46 PM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.