There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Malware Removal & HijackThis Logs
Tag Cloud
audio bios blue screen boot bsod computer connection crash dell desktop driver drivers email error excel firefox freeze google hard drive hardware hijackthis install internet laptop linux malware network no sound outlook problem reboot redirect router screen slow sound speakers spyware startup trojan usb video virus vista webcam windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Malware Removal & HijackThis Logs >
Solved: DSSAGENT.EXE Panicking Beginner (In Progress)

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
13-Jun-2009, 02:54 PM #1
Solved: DSSAGENT.EXE Panicking Beginner
Could I have the benefit of someone's experience to help deal with this problem which has just arisen on my laptop.

I have a Toshiba Equium M70, with Windows XP and IE 7. I use Free Avast and Spybot Search and Destroy.

I have just done a thorough scan using Free Avast, I always get about 30 'lines' that are 'unable to scan, Archive is password protected'. I usually ignore them (out of ignorance) as they seem to be something to do with Spybot Search and Destroy. This is what they say.

C:\documents and settings\all users\application data\...\sbRecovery.ini (some say .reg at the end)

I noticed today however one line which says

C:\documents and settings\all users\application data\...\DSSAGENT.EXE

I googled it and it is obviously not a good thing......

When I went to 'put it in the chest' in Avast or to delete it - I get 'error occured moving file to chest - Archive is password protected'

I did a search of my files and cannot find anything called DSSAGENT - does this mean that Spybot has dealt with it or is something horrible lurking in my laptop.

Any help would be much appreciated.

Fujairah
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
13-Jun-2009, 03:05 PM #2
You don't give the full path, what is between "application date" and DSSAGENT.EXE (the part where the little dots are)?
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
13-Jun-2009, 03:11 PM #3
If it's in the Spybot - Search & Destroy\Recovery folder, as I suspect it is, that is a backup created by Spybot S&D so that would mean it has dealt with it.
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
13-Jun-2009, 03:16 PM #4
Sorry - did not realise there was more to see - obvious now I have extended it - what a dimwit...

Here is the full thing.

C:\Documents and Settings\All Users\Application Data\Spybot - Search and Destroy\Recovery\DSSAgent.zip\sbRecovery.ini

also three others as above but

DSSAgent1.zip\sbRecovery.ini
DSSAgent1.zip\sbRecovery.reg
DSSAgent.zip\DSSAGENT.exe

(now I can see the others say Mywaywebsearch and Commondialogs - just for information)

Fujairah
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
13-Jun-2009, 03:18 PM #5
Thank you Cookiegal, that would be a relief.

Do you know where it would have come from?

Fujairah
Byteman's Avatar
Moderator with 14,939 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
13-Jun-2009, 10:52 PM #6
Hi,

I believe the security apps do not flag this these days, though they used to.

My grandson's Reader Rabbit games had it and SpyBot used to flag it but stopped, though you can elect it because it is still detected..... if removed, the games often did not work anymore.

info>>>
http://accs-net.com/smallfish/mattel.htm


http://www.cexx.org/dssagent.htm

This DSSAgent can be more than one thing. Kids games like Reader Rabbit came with it and installed it.

This list might indicate to you what installed it:


Mattel Interactive Software

Brodcast was created by Brøderbund which was bought by The Learning Tree which was then bought by Mattel. As a definitive list of software including Brodcast isn't available, all older software from Broderbund, The Learning Tree and Mattel are suspect. The following is a partial list of Mattel Interactive software from their main page www.mattelinteractive.com:

Education: Arthur®, Berlitz®, Carmen Sandiego, ClueFinders®, Dr. Seuss®, KidPix, Learn to Speak™, Madeline™, Oregon Trail®, Reader Rabbit®, Schoolhouse Rock!®, Sesame Street®
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
14-Jun-2009, 09:04 AM #7
Hi Byteman

Thank you for your reply. Broderbund rings a bell, I think through my family tree maker.

Those pages make interesting reading, and I am quite shocked by such a well known name having this in their software.

I had a look in Recovery in Spybot and sure enough it is there with some other items. I debated 'ticking the box' and deleting it but after reading the Help section I was not sure if I was deleting the last point of back up or DSSAgent itself so I have left alone for the time being. I admit I don't have a great understanding of the workings of Spybot - it just seems to work.

Just to clarify things for a novice - does this mean that it is still on my laptop but Spybot stops it working or has Spybot removed it. Should I follow the removal link in the information you gave me as I will just unistall family tree maker if it affects it.

Thank you

Fujairah


(just tried to use the link to the removal utility from that web site and it no longer exists)

Last edited by fujairah : 14-Jun-2009 11:02 AM.
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
14-Jun-2009, 11:17 AM #8
The one from Broderbund is still considered malware but they may not be using it anymore and the uninstall seems to no longer be available:

http://www.systemlookup.com/Startup/...agent_exe.html

There may be a couple of entries remaining in the registry but SpyBot has dealt with the file so you can just leave the back-up alone as it's neutralized.

Are you at all familiar with the registry?
__________________
Microsoft MVP - Consumer Security
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
14-Jun-2009, 11:52 AM #9
Hi Cookiegal

I am not familiar at all with Registry's. I read the manual removal instructions but decided it could be one step to far for me on my own.

I was going to have a look when I had someone more computer savvy with me.

Fujairah
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
14-Jun-2009, 12:18 PM #10
Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
__________________
Microsoft MVP - Consumer Security
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
14-Jun-2009, 02:51 PM #11
Hi Cookiegal

I have done as instructed, this is what is in the log.

It came up with 5 infections. (RogueWinAntiVirus, Adware180solution, Disabled Security Centre x 3)

The Log

Malwarebytes' Anti-Malware 1.37
Database version: 2277
Windows 5.1.2600 Service Pack 2
14/06/2009 19:37:35
mbam-log-2009-06-14 (19-37-35).txt
Scan type: Quick Scan
Objects scanned: 87584
Time elapsed: 7 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f 4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8fcd f9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)


This is unrelated but my laptop has not closed down on its own for the last couple of days - I go to Start, Shut down, - nothing happens. So I just press the on/off button till is shuts down.

Also for the first time it told me my Automatic Updates for Windows was disabled so I have enabled them - I used to use AVG but some time ago there was a problem with a Windows Update which clashed with AVG. It took me off the internet for over a week and in the end I had to have someone out to sort out my laptop. I remember he disabled Windows Updates saying I did not need them anyway. My laptop is very slow as it is downloading a large backlog of Windows Updates - I hope I have done the correct thing re-enabling them.

Thank you for helping me with this, I really do appreciate it. I obviously had some malware that needed rooting out.

Fujairah

Last edited by fujairah : 14-Jun-2009 03:00 PM.
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
14-Jun-2009, 04:21 PM #12
Yup, this means you have bigger problems than what you initally posted.

Click here to download HJTsetup.exe.
  • Save HJTsetup.exe to your desktop.
  • Double click on the HJTsetup.exe icon on your desktop.
  • By default it will install to C:\Program Files\Hijack This.
  • Continue to click Next in the setup dialogue boxes until you get to the Select Addition Tasks dialogue.
  • Put a check by Create a desktop icon then click Next again.
  • Continue to follow the rest of the prompts from there.
  • At the final dialogue box click Finish and it will launch Hijack This.
  • Click on the Do a system scan and save a log file button. It will scan and then ask you to save the log.
  • Click Save to save the log file and then the log will open in notepad.
  • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or even required.

Note: During this process, it would help a great deal and be very much appreciated if you would refrain from installing any new software or hardware on this machine, unless absolutely necessary, until the clean up process is finished as it makes our job more tedious, with additional new files that may have to be researched, which is very time consuming.

Also, please do not run any security programs or fixes on your own as doing so may compromise what we will be doing. It is important that you wait for instructions.
__________________
Microsoft MVP - Consumer Security
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
14-Jun-2009, 04:34 PM #13
Hi Cookiegal

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:32:41, on 14/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\system32\ZoomingHook.exe
C:\WINDOWS\system32\TCtrlIOHook.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe hwSetUP
O4 - HKLM\..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe SVPwUTIL
O4 - HKLM\..\Run: [Zooming] ZoomingHook.exe
O4 - HKLM\..\Run: [TCtryIOHook] TCtrlIOHook.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/f...trol_en_US.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1136577733953
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O16 - DPF: {EF6E7E56-9229-4C73-AAD0-15316405DB95} (Easy Photo Uploader) - http://preview.gfranklin4.photosite....adBox_live.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 9819 bytes



Prior to following these instructions, my laptop downloaded all the windows updates it has missed - took a while - when it finished it said 'Windows will restart your computer', it tried, but nothing happened. Then a small box came up in the bottom left hand corner which said 'restore default settings' (something about English Language?), I clicked on it and now my laptop is closing and starting normally. So I am not sure what that was about.

Thank you once again for looking at this.

Fujairah

Last edited by fujairah : 14-Jun-2009 05:14 PM. Reason: adding information after being interrupted midpost.
Cookiegal's Avatar
Administrator with 63,382 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
14-Jun-2009, 05:47 PM #14
Please visit Combofix Guide & Instructions for instructions for installing the recovery console and downloading and running ComboFix.

The only thing different from the instructions there is that when downloading and saving the ComboFix.exe I would like you to rename it to Combo-Fix.exe please.

Post the log from ComboFix when you've accomplished that along with a new HijackThis log.

Important notes regarding ComboFix:

ComboFix may reset a number of Internet Explorer's settings, including making it the default browser. This can easily be changed once we're finished.

ComboFix also prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you, please let me know. This can be undone manually when we're finished. Read HERE for an article written by dvk01 on why we disable autoruns.
__________________
Microsoft MVP - Consumer Security
fujairah's Avatar
Computer Specs
Member with 43 posts.
 
Join Date: Jun 2009
Location: England
Experience: Beginner
14-Jun-2009, 06:15 PM #15
Hi Cookiegal

That looks quite complicated and it will take me a while to read it all so I am going to go to bed now (its gone 11 o clock here - not sure what time it is in Quebec). I have downloaded it to the point where I have the icon on my desktop but as I am not even sure if I have tea-timer on Spybot I need to write down all the instructions and check these out.

I take it I need to disable Avast, Tea-Timer in Spybot, Windows Firewall? is Zone Alarm a Firewall?.

Thank you very much for all the time you have spent and all your help so far, I will work through the instructions and post the logs tomorrow.

Fujairah
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 02:39 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.