Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop dns driver drivers error ethernet excel freeze gaming graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard network printer problem ram registry repair router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
spyware trouble =( (New)

Reply  
Thread Tools
SySo's Avatar
Computer Specs
Account Disabled with 5 posts.
 
Join Date: Dec 2008
Experience: Computer Illiterate
30-Dec-2008, 08:26 PM #1
Thumbs down spyware trouble =(
ive been having issues with my computer and ive figured out it's spyware. so i googled possible antiviruses that could possibly get rid of the trojans and spyware on my computer. i tried spybot, spware doctor, norton, mostly everything. i had to uninstall it all when i realized it wasnt really working =(

then i was reading this thread that said combo fix...so i followed the instructions, and because i dont have any antiviruses i didnt need to disable any, then i got this "log".

the "log" stayed there for a while before i relaized that the scan was done and that was it...so now what...??? help would be nice, thank you! =]

oh, here is the log info:




.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\6nJ1Y0I2.exe.a_a
----- BITS: Possible infected sites -----
hxxp://aj+|Cv+@J:NGD_DQ{zcxLJS@Y3I7K3fWU Client DownloadS-1-5-18`HT4?? 6VwoQZCDHM6VwoQZCDHMXuPaPaPaPaP?#cxLJS@GD_DQ{zGD_DQ{zGD_DQ{z+@J:Nj+|Cvwsupd ate.com
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.
2008-12-29 15:58 . 2008-12-29 17:37 2,932 --a------ c:\windows\system32\d3d9caps.dat
2008-12-29 02:35 . 2008-12-29 02:38 <DIR> d-------- c:\program files\Common Files\PC Tools
2008-12-29 02:35 . 2008-12-30 18:55 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-12-29 02:35 . 2008-07-28 12:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2008-12-29 02:35 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2008-12-29 02:35 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2008-12-29 02:35 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2008-12-29 02:35 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2008-12-29 02:34 . 2008-12-30 02:24 <DIR> d-------- c:\program files\Spyware Doctor
2008-12-29 02:34 . 2008-12-29 02:34 <DIR> d-------- c:\documents and settings\pc user\Application Data\PC Tools
2008-12-29 02:34 . 2008-12-29 02:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-12-25 20:36 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-12-25 20:36 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-12-25 20:36 . 2008-04-13 13:45 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2008-12-25 20:36 . 2008-04-13 13:45 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-12-23 20:30 . 2008-12-23 20:31 <DIR> d-------- c:\program files\Winamp
2008-12-23 20:30 . 2008-12-24 18:22 <DIR> d-------- c:\documents and settings\pc user\Application Data\Winamp
2008-12-21 22:22 . 2008-12-21 22:40 73,728 --a------ c:\windows\system32\6nJ1Y0I2.exe
2008-12-15 15:41 . 2008-12-15 15:41 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-15 15:34 . 2008-04-13 19:12 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-14 19:24 . 2006-10-18 18:32 11,648 --a------ c:\windows\system32\lknucmp.sys
2008-12-14 19:24 . 2006-10-18 18:32 11,648 --a------ c:\windows\system32\drivers\lknucmp.sys
2008-12-14 19:24 . 2006-10-18 18:35 1,393 --a------ c:\windows\system32\lknucmp.inf
2008-12-14 19:23 . 2008-12-14 19:24 <DIR> d-------- c:\program files\Linksys Wireless-G Print Server
2008-12-14 19:23 . 2006-10-18 18:32 37,248 --a------ c:\windows\system32\lknuhub.sys
2008-12-14 19:23 . 2006-10-18 18:32 37,248 --a------ c:\windows\system32\drivers\lknuhub.sys
2008-12-14 19:23 . 2006-10-18 18:32 11,136 --a------ c:\windows\system32\drivers\lknuhst.sys
2008-12-14 19:23 . 2006-10-18 18:36 1,371 --a------ c:\windows\system32\lknuhub.inf
2008-12-14 19:23 . 2007-01-25 11:10 813 --a------ C:\setup.iss
2008-12-14 14:21 . 2008-12-14 14:21 <DIR> d--h----- c:\windows\system32\CanonMF Uninstaller Information
2008-12-14 14:20 . 2008-12-14 14:20 <DIR> d--h----- C:\CanonMF
2008-12-14 14:19 . 2008-12-14 19:01 <DIR> d-------- c:\documents and settings\pc user\Contacts
2008-12-14 14:12 . 2008-12-14 14:12 <DIR> d-------- c:\program files\Print Server
2008-12-14 14:11 . 1998-10-29 16:45 306,688 --a------ c:\windows\IsUninst.exe
2008-12-14 13:43 . 2008-12-14 13:43 244 --ah----- C:\sqmnoopt01.sqm
2008-12-14 13:43 . 2008-12-14 13:43 232 --ah----- C:\sqmdata01.sqm
2008-12-14 12:43 . 2008-12-14 12:43 268 --ah----- C:\sqmdata00.sqm
2008-12-14 12:43 . 2008-12-14 12:43 244 --ah----- C:\sqmnoopt00.sqm
2008-12-14 03:20 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-14 03:20 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-12-14 03:20 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-14 00:54 . 2008-12-14 01:04 <DIR> d-------- c:\program files\Windows Live
2008-12-14 00:54 . 2008-12-14 00:55 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-12-14 00:53 . 2008-12-14 00:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-12-13 13:22 . 2008-12-13 21:37 <DIR> d-------- c:\documents and settings\pc user\Application Data\FrostWire
2008-12-13 13:20 . 2008-06-10 02:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-13 13:19 . 2008-12-13 13:20 <DIR> d-------- c:\program files\Java
2008-12-13 13:19 . 2008-12-13 13:19 <DIR> d-------- c:\program files\Common Files\Java
2008-12-09 22:26 . 2008-12-27 20:35 1,510 --a------ c:\windows\Sketchpad Preferences.dat
2008-12-09 22:25 . 2008-12-09 22:25 <DIR> d-------- c:\program files\Sketchpad
2008-12-09 16:26 . 2008-12-09 16:27 <DIR> d-------- c:\program files\Google
2008-12-07 21:37 . 2008-12-07 21:37 <DIR> d-------- c:\program files\Common Files\Vbox
2008-12-07 21:36 . 2008-12-07 21:36 <DIR> d-------- c:\program files\Macromedia
2008-12-07 14:51 . 2008-04-13 13:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-07 14:36 . 2008-12-27 20:00 <DIR> d-------- c:\documents and settings\pc user\Application Data\Apple Computer
2008-12-07 14:35 . 2008-12-07 14:35 <DIR> d-------- c:\program files\iTunes
2008-12-07 14:35 . 2008-12-07 14:35 <DIR> d-------- c:\program files\iPod
2008-12-07 14:35 . 2008-12-07 14:35 <DIR> d-------- c:\program files\Bonjour
2008-12-07 14:35 . 2008-12-07 14:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-07 14:35 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-12-07 14:35 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-12-07 14:34 . 2008-12-07 14:34 <DIR> d-------- c:\program files\QuickTime
2008-12-07 14:34 . 2008-12-07 14:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-07 14:33 . 2008-12-14 00:57 <DIR> d----c--- c:\windows\system32\DRVSTORE
2008-12-07 14:33 . 2008-12-07 14:35 <DIR> d-------- c:\program files\Common Files\Apple
2008-12-07 14:33 . 2008-12-07 14:33 <DIR> d-------- c:\program files\Apple Software Update
2008-12-07 14:33 . 2008-12-07 14:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-12-07 14:24 . 2008-12-07 14:25 68,756,776 --a------ c:\temp\iTunes.exe
2008-12-06 20:39 . 2008-12-06 20:39 162 --a------ c:\windows\ODBC.INI
2008-12-06 20:16 . 2008-12-06 20:16 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-12-06 20:16 . 2006-10-26 19:58 30,512 --a------ c:\windows\system32\mdimon.dll
2008-12-06 20:15 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-12-06 20:13 . 2008-12-06 20:13 <DIR> d-------- c:\windows\system32\LogFiles
2008-12-06 20:13 . 2008-12-06 20:14 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-12-06 20:12 . 2008-12-06 20:12 <DIR> d-------- c:\program files\Microsoft Works
2008-12-06 20:11 . 2008-12-06 20:11 <DIR> d-------- c:\program files\MSBuild
2008-12-06 20:02 . 2008-12-06 20:10 <DIR> d-------- c:\windows\SHELLNEW
2008-12-06 20:01 . 2008-12-20 03:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-06 20:00 . 2008-12-06 20:00 <DIR> dr-h----- C:\MSOCache
2008-12-06 19:58 . 2003-10-17 19:28 351,840 -ra------ c:\windows\system32\drivers\ar5211.sys
2008-12-06 19:51 . 2008-12-06 19:51 11,861 --a------ c:\windows\system32\drivers\mdc8021x.sys
2008-12-06 19:50 . 2008-12-06 19:50 <DIR> d-------- c:\program files\AirPremier Tri-Mode Dualband G
2008-12-06 19:50 . 2003-05-31 20:10 651,264 --a------ c:\windows\system32\libeay32.dll
2008-12-06 19:50 . 2003-05-31 20:10 450,560 --a------ c:\windows\system32\AegisE5.dll
2008-12-06 19:50 . 2003-05-31 20:10 327,680 --a------ c:\windows\system32\AegisE2.dll
2008-12-06 19:50 . 2003-05-31 20:10 147,456 --a------ c:\windows\system32\ssleay32.dll
2008-12-06 19:50 . 2003-10-28 10:34 114,688 --a------ c:\windows\system32\athcfg10.dll
2008-12-04 22:52 . 2008-12-07 00:40 <DIR> d-------- c:\documents and settings\pc user\Application Data\MSN6
2008-12-04 22:52 . 2008-12-04 22:52 <DIR> d-------- c:\documents and settings\All Users\Application Data\MSN6
2008-12-04 11:03 . 2008-12-04 11:04 <DIR> d-------- c:\documents and settings\Administrator
2008-12-03 16:06 . 2008-10-16 15:38 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-12-03 16:06 . 2007-04-17 04:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-12-03 16:06 . 2007-03-08 00:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-03 16:06 . 2008-10-16 15:38 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-12-03 16:06 . 2008-10-16 15:38 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-12-03 16:06 . 2008-10-16 15:38 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-12-03 16:06 . 2008-10-16 15:38 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-12-03 16:06 . 2008-10-16 15:38 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-03 16:06 . 2008-10-16 08:11 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-12-03 15:42 . 2008-12-03 15:42 <DIR> d-------- c:\windows\system32\scripting
2008-12-03 15:42 . 2008-12-03 15:42 <DIR> d-------- c:\windows\system32\en
2008-12-03 15:42 . 2008-12-03 15:42 <DIR> d-------- c:\windows\l2schemas
2008-12-03 15:17 . 2006-11-01 18:31 1,669,120 -----c--- c:\windows\system32\dllcache\setup_wm.exe
2008-12-03 15:16 . 2006-10-18 21:47 991,744 -----c--- c:\windows\system32\dllcache\drmv2clt.dll
2008-12-03 14:44 . 2008-06-13 06:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-03 14:44 . 2008-08-14 05:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-12-03 14:43 . 2008-08-14 05:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-03 14:43 . 2008-08-14 05:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-03 14:43 . 2008-08-14 04:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-03 14:43 . 2008-08-14 04:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-03 14:43 . 2008-09-15 07:12 1,846,400 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-12-03 14:43 . 2008-09-04 12:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-03 14:43 . 2008-04-11 14:04 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-12-03 14:43 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-03 14:43 . 2008-10-15 11:34 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-03 14:43 . 2008-09-08 05:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-12-03 14:43 . 2008-05-01 09:33 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2008-12-03 14:43 . 2008-05-08 09:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-12-03 14:35 . 2008-12-18 15:33 <DIR> d--h----- c:\windows\$hf_mig$
2008-12-03 14:07 . 2008-12-03 14:07 0 --a------ c:\windows\vpc32.INI
2008-12-03 14:03 . 2008-12-30 17:37 <DIR> d-------- c:\program files\Symantec AntiVirus
2008-12-03 14:03 . 2008-12-03 14:03 <DIR> d-------- c:\program files\Symantec
2008-12-03 14:03 . 2008-12-04 11:08 <DIR> d-------- c:\program files\Common Files\Symantec Shared
2008-12-03 14:03 . 2008-12-03 14:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec
2008-12-03 14:03 . 2006-01-31 13:29 107,696 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 15:24 --------- d-----w c:\program files\microsoft frontpage
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-12 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 335872]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 53408]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-03-17 124656]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AirPremier Configuration Utility.lnk - c:\program files\AirPremier Tri-Mode Dualband G\AirPro.exe [2008-12-06 835666]
D-Link REG Utility.lnk - c:\program files\AirPremier Tri-Mode Dualband G\Reg.exe [2008-12-06 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Linksys Wireless-G Print Server\\PSDiagnosticM.exe"=
R1 pctfw2;pctfw2;\??\c:\windows\system32\drivers\pctfw2.sys [2008-12-29 160792]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-12-29 356920]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\DRIVERS\A3AB.sys [2007-05-23 547744]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-12-03 99376]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\DRIVERS\lknuhst.sys [2008-12-14 11136]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\DRIVERS\lknuhub.sys [2008-12-14 37248]
S3 LKNUCMP;Linksys Network USB Composite Device;c:\windows\system32\DRIVERS\lknucmp.sys [2008-12-14 11648]
S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" [2006-03-17 115952]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountp oints2\{15c71ad6-c701-11dd-8115-000802ba34db}]
\Shell\AutoRun\command - E:\launch.bat
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-12-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-12-29 c:\windows\Tasks\At1.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At10.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At11.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At12.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-23 c:\windows\Tasks\At13.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-26 c:\windows\Tasks\At14.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-28 c:\windows\Tasks\At15.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-28 c:\windows\Tasks\At16.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At17.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At18.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At19.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At2.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-31 c:\windows\Tasks\At20.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At21.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At22.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-26 c:\windows\Tasks\At23.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At24.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At25.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At26.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At27.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At28.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At29.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At3.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At30.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At31.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At32.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At33.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At34.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At35.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At36.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-23 c:\windows\Tasks\At37.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-25 c:\windows\Tasks\At38.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-28 c:\windows\Tasks\At39.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At4.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-28 c:\windows\Tasks\At40.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At41.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At42.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At43.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-31 c:\windows\Tasks\At44.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At45.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At46.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-26 c:\windows\Tasks\At47.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At48.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-30 c:\windows\Tasks\At5.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-29 c:\windows\Tasks\At6.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At7.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At8.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
2008-12-22 c:\windows\Tasks\At9.job
- c:\windows\system32\6nJ1Y0I2.exe [2008-12-21 22:40]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PrintServer Diagnostic - c:\program files\Print Server\PTP\PSDiagnostic.exe
MSConfigStartUp-MSFox - c:\docume~1\PCUSER~1\LOCALS~1\Temp\a.exe

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-30 19:06:27
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(888)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
Completion time: 2008-12-30 19:07:46
ComboFix-quarantined-files.txt 2008-12-31 00:07:42
Pre-Run: 30,913,712,128 bytes free
Post-Run: 31,043,788,800 bytes free
341 --- E O F --- 2008-12-20 08:19:43




....i hate to sound like an idiot....but what does that mean??? what is it telling me??? now what do i do????
tomdkat's Avatar
Computer Specs
Distinguished Member with 7,127 posts.
 
Join Date: May 2006
Location: S.F. Bay Area, CA
Experience: Intermediate
30-Dec-2008, 08:34 PM #2
I think you should read this post and then post accordingly in the malware removal forum.

Peace...
SySo's Avatar
Computer Specs
Account Disabled with 5 posts.
 
Join Date: Dec 2008
Experience: Computer Illiterate
30-Dec-2008, 09:51 PM #3
will do.

thanks =)
EAFiedler's Avatar
Moderator with 13,549 posts.
 
Join Date: Apr 2000
Location: Indiana
30-Dec-2008, 09:53 PM #4
Hi SySo

Welcome to Tech Support Forums

I will move your thread to the appropriate forum.
No need to create duplicate threads.
Thank you.

tomdkat please advise members to Report their thread and request a move to the appropriate forum, instead of creating duplicate threads.
Thank you.
EAFiedler's Avatar
Moderator with 13,549 posts.
 
Join Date: Apr 2000
Location: Indiana
30-Dec-2008, 10:00 PM #5
SySo I have moved your thread and deleted your duplicate thread.
We posted at the same time, so you most likely did not see my reply to this thread concerning duplicate threads.

Continue replies for this issue in this thread.
Thank you.
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,286 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
30-Dec-2008, 11:24 PM #6
Since you created a second account and that is against the rules, please tell me which one you want to keep, this one, or Hagrid?
SySo's Avatar
Computer Specs
Account Disabled with 5 posts.
 
Join Date: Dec 2008
Experience: Computer Illiterate
01-Jan-2009, 03:57 PM #7
erm...hope you dont mind me like asking but...who the HELL is Hagrid..? my name is Syana and this account is linked with my sister, Solana....and i dont even like hp =p
SySo's Avatar
Computer Specs
Account Disabled with 5 posts.
 
Join Date: Dec 2008
Experience: Computer Illiterate
01-Jan-2009, 03:58 PM #8
la di dah...will anyone pleeeese reply!!!! i need to install SOME sort of antivirus soon so i need replies ppppplz!!!! =]
~Candy~'s Avatar
Former Administrator with 104,742 posts.
 
Join Date: Jan 2001
Experience: Advanced
01-Jan-2009, 04:07 PM #9
How about giving a correct answer to the question. We know who you are, and we know you are both user screen names. We aren't stupid here It's against the forum rules to have multiple identities. You're wearing on our last nerve around here.
SySo's Avatar
Computer Specs
Account Disabled with 5 posts.
 
Join Date: Dec 2008
Experience: Computer Illiterate
01-Jan-2009, 04:31 PM #10
Oh really, you're not? i read hagrids thread and from what i got there, you need to get paid to be decent with people.

and im getting the side effects of that. im not hagird but i sure as hell agree with him. look, im not trying to be rude but i need to get rid of this problem before the break is over im getting back to work next week monday and i need the computer clean so i can do my work.

and acacandy, im prob gonna be deleted as a user for this but go screw yourself. ur social skills are non existent and you waltz around likes it ok to act this way around people. i dont want ur help. dont bother replying, really dont. cuz im not coming back and wasting my time. you think im hagrid, great. im not. i can guarantee we have the same problem (spyware ) but were not the same poeple. its conclusive to say your help is worth ****.

seeing as u live in vegas, go win some money and go to etiquette class. it might help.

yours truly,=)
syanna~~~~
~Candy~'s Avatar
Former Administrator with 104,742 posts.
 
Join Date: Jan 2001
Experience: Advanced
01-Jan-2009, 04:35 PM #11
And you just HAPPEN to be using the same computer Goodbye.
Reply

Tags
antivirus, malware, spyware, trojan

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 09:31 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.