Author Topic: slow comp  (Read 1914 times)

Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« on: September 30, 2006, 05:07:03 PM »
ok my comp is really slow when it starts takes like 5mins to start and it freezes alot comp is slow and it freezes i was working well for days but suddenly the next time i opend it it got like this i have scaned my comp no virus detected and i deleted some files i dont need i think that was slowing it down but it still dosnt work and i dont have the recovery disk it got broken http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/sad.gif\' class=\'bbc_emoticon\' alt=\':(\' /> so what do?? plz help
« Last Edit: October 03, 2006, 11:47:55 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #1 on: September 30, 2006, 05:24:06 PM »
Quote
and i deleted some files i dont need i think that was slowing it down but it still dosnt work
What files did you delete?
Are you sure none were critical for the stability of your operating system?

Can you do the following
From my signature below, download and save too a permanent folder of it's own onto your harddrive
Hijackthis 1.99.1
Open Hijackthis.exe

Do a "SCAN and Save a Log file"
A log will open in Notepad
Copy and paste the WHOLE contents of the log  here... Don't try and fix anything yet----It is all important

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #2 on: September 30, 2006, 05:43:31 PM »
Logfile of HijackThis v1.99.1
Scan saved at 0:41:34, on 01.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hgiork\Kinqxja.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\PROGRA~1\COMMON~1\AOL\115783~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\115783~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mshome\Desktop\hijackthis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe  "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WIND
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:"C:\WINDOWS\svchost.exe",
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Akwyxmon] C:\Program Files\Hgiork\Kinqxja.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1157832268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: svchost.exe
O4 - Global User Startup: svchost.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://H:\games\WebDriverFullInstall.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CBB55E7-1303-4237-AB62-6804124674DD}: NameServer = 213.131.66.138 213.131.66.246
O17 - HKLM\System\CS2\Services\Tcpip\..\{3CBB55E7-1303-4237-AB62-6804124674DD}: NameServer = 213.131.66.138 213.131.66.246
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe





















ok thats all it said
« Last Edit: October 03, 2006, 11:48:16 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #3 on: October 01, 2006, 09:25:34 AM »
Can you do the following please
Go to either of these links
http://virusscan.jotti.org/
OR
http://www.virustotal.com/flash/index_en.html

Use the browse button and navigate to the file on your harddrive
C:\Program Files\Hgiork\Kinqxja.exe <- this file
Right click on the file and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please
Are there any other files in the Hgiork folder?

Also
==Download this file - Combofix.exe and save it too desktop
Double click combofix.exe & follow the prompts.
When finished, it shall produce a log for you.
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Post back this log please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #4 on: October 01, 2006, 12:26:44 PM »
AntiVir     
Found Trojan/DelProx.A
ArcaVir    
Found Trojan.Small.Cy
Avast    
Found Win32:Trojano-1035
AVG Antivirus    
Found Small.P
BitDefender    
Found Trojan.Small.CY
ClamAV    
Found Trojan.Small-158
Dr.Web    
Found Trojan.DownLoader.1389
F-Prot Antivirus    
Found W32/Downloader.AAW
Fortinet    
Found W32/Small.SN!tr.dldr
Kaspersky Anti-Virus    
Found Trojan.Win32.Small.cy
NOD32    
Found Win32/Small.CY
Norman Virus Control    
Found nothing
UNA    
Found Trojan.Win32.Rog
VirusBuster    
Found Trojan.Small.ADM
VBA32    
Found Trojan.Win32.Small.cy


thats all it said when i scanned C:\Program Files\Hgiork\Kinqxja.exe



and the combo fix my comp coulnt let me open it if its recommended ill try again



i havent played Runescape in 3 months about this problem and i really need runescape
« Last Edit: October 03, 2006, 11:48:33 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #5 on: October 01, 2006, 02:32:43 PM »
Quote
and the combo fix my comp coulnt let me open it if its recommended ill try again
Yes, try it again

Why won't it run, are you getting any error messages, let me know exactly please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #6 on: October 01, 2006, 03:47:00 PM »
it says press y or no i press y it wont do anything
« Last Edit: October 03, 2006, 11:48:47 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #7 on: October 01, 2006, 03:56:05 PM »
Press Y
Then hit Enter on your keyboard

Wait for the log to open, it will take a few minutes
« Last Edit: October 01, 2006, 03:56:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #8 on: October 01, 2006, 04:34:12 PM »
mshome - 06-10-01 22:51:22.59    Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\mshome\Desktop"

(((((((((((((((((((((((((((((((   Files Created from 2006-09-01 to 2006-10-01  ))))))))))))))))))))))))))))))))))
 

2006-09-29   12:52   3,952   -ra------   C:\WINDOWS\system32\drivers\DMICall.sys
2006-09-09   22:31   65,536   --a------   C:\WINDOWS\system32\MFC71DEU.DLL
2006-09-09   22:31   61,440   --a------   C:\WINDOWS\system32\MFC71ITA.DLL
2006-09-09   22:31   61,440   --a------   C:\WINDOWS\system32\MFC71ESP.DLL
2006-09-09   22:31   57,344   --a------   C:\WINDOWS\system32\MFC71ENU.DLL
2006-09-09   22:31   49,152   --a------   C:\WINDOWS\system32\MFC71KOR.DLL
2006-09-09   22:31   49,152   --a------   C:\WINDOWS\system32\MFC71JPN.DLL
2006-09-09   22:31   45,056   --a------   C:\WINDOWS\system32\MFC71CHT.DLL
2006-09-09   22:31   40,960   --a------   C:\WINDOWS\system32\MFC71CHS.DLL
2006-09-09   22:31   1,060,864   --a------   C:\WINDOWS\system32\MFC71.dll
2006-09-09   22:31   1,047,552   --a------   C:\WINDOWS\system32\MFC71u.dll
2006-09-09   22:07   173,184   --a------   C:\WINDOWS\system32\ygpss.scr
2006-09-09   22:06   86,016   --a------   C:\WINDOWS\unvise32qt.exe
2006-09-09   22:06   8,552   --a------   C:\WINDOWS\system32\drivers\asctrm.sys
2006-09-09   22:05   102,400   --a------   C:\WINDOWS\system32\SimpleRegistry.dll
2006-09-09   22:05   10,752   --a------   C:\WINDOWS\system32\aamd532.dll
 

((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-29 12:51   --------   d--------   C:\Program Files\Common Files\Sony Shared
2006-09-20 22:35   --------   d--------   C:\Program Files\SwiftSwitch
2006-09-19 02:47   --------   d--------   C:\Program Files\TalkGeek.org Autofighter
2006-09-18 01:12   --------   d--------   C:\Program Files\HyCam2
2006-09-16 16:22   --------   d--------   C:\Program Files\MSN Messenger
2006-09-15 21:50   --------   d--------   C:\Program Files\USB Game Controller
2006-09-15 21:27   --------   d--------   C:\Program Files\Metal Gear Solid
2006-09-09 23:54   --------   d--------   C:\Program Files\GameHouse
2006-09-09 23:52   --------   d--------   C:\Program Files\AWS
2006-09-09 23:52   --------   d--------   C:\Documents and Settings\mshome\Application Data\Aim
2006-09-09 23:51   --------   d--------   C:\Program Files\AIM Toolbar
2006-09-09 22:07   --------   d--------   C:\Program Files\Common Files\Nullsoft
2006-09-09 22:06   --------   d--------   C:\Program Files\Real
2006-09-09 22:06   --------   d--------   C:\Program Files\QuickTime
2006-09-09 22:05   --------   d--------   C:\Program Files\Pure Networks
2006-09-09 22:04   --------   d--------   C:\Program Files\America Online 9.0
2006-09-09 21:47   --------   d--------   C:\Program Files\Eidos Interactive
2006-08-21 14:21   16896   --a------   C:\WINDOWS\system32\fltlib.dll
2006-08-21 11:14   23040   --a------   C:\WINDOWS\system32\fltMc.exe
2006-08-21 11:14   128896   --a------   C:\WINDOWS\system32\drivers\fltMgr.sys
2006-07-27 15:24   679424   --a------   C:\WINDOWS\system32\inetcomm.dll
2006-07-21 10:24   72704   --a------   C:\WINDOWS\system32\hlink.dll
 

((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
 
*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Registry Cleaner"="\"C:\\Program Files\\TPT Registry_Cleaner (Trial)\\regclean.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"
"ccRegVfy"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"Akwyxmon"="C:\\Program Files\\Hgiork\\Kinqxja.exe"
"BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1157832268\\EE\\AOLHostManager.exe"
"AOLDialer"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"
"AOL Spyware Protection"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"wcmdmgr"="C:\\WINDOWS\\wt\\updater\\wcmdmgrl.exe -launch"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,02,00,00,00,\
  00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
  ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
  00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"ALUAlert"="C:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000000

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ  msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll

 
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton SystemWorks One Button Checkup.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
C:\WINDOWS\tasks\A89D17DF918A8E37.job
 
Completion time: 01.10.2006 22:59:07.23
ComboFix2.txt
ComboFix.txt



i think thats it
« Last Edit: October 03, 2006, 11:49:02 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #9 on: October 01, 2006, 05:40:34 PM »
Can you do the following
Make sure you do them in the exact order please

I need you too make 2 text files on your desktop
First: RIGHT CLICK an empty spot on the desktop and select NEW>>Text Document
Name the new text document
follow.txt
Left click anywhere on your desktop to set the new name
Open follow.txt and copy>>Paste All the below instructions to it
After you paste it>>X out and save the changes

Make another text document on desktop
Call it emy.txt

Copy>>Paste ONLY the [color=\"#FF0000\"]Red[/color] text below to it and save the changes
Ensure you copy from Files to delete: and below in the RED
=======================================

[color=\"#FF0000\"]Files to delete:
C:\WINDOWS\svchost.exe
C:\Program Files\Hgiork\Kinqxja.exe
C:\WINDOWS\tasks\A89D17DF918A8E37.job
C:\Documents and Settings\mshome\Start Menu\Programs\Startup\svchost.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe

Folders to delete:
C:\Program Files\Hgiork[/color]


=========================================================
Download The Avenger.zip by Swandog46 to your Desktop.

    * Click on Avenger.zip to open the file
    * Extract avenger.exe to your desktop

Close down all Browser windows and any other unnecessary windows that are open
Including this one
Use follow.txt to follow along with all instructions below
You should now have ONLY 'follow.txt' open

Can you now
Open Hijackthis.exe
Open Misc tools section>>Under 'System Tools'
Click the button>>Open Process Manager

Left click to Highlight ONLY  the one process that looks like the following
C:\WINDOWS\svchost.exe
After you have highlighted the above process
Click the Kill Process button
Click Yes to the prompt

Don't confuse it with others that look similiar to this C:\WINDOWS\System32\svchost.exe <-this is legit

In Hijackthis click Back Under 'Other Stuff'
Then click Scan button on the bottom left
When the scan has finished
Put a tick next to the following entries
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WIND
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:"C:\WINDOWS\svchost.exe",

O4 - HKLM\..\Run: [Akwyxmon] C:\Program Files\Hgiork\Kinqxja.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - Global Startup: svchost.exe
O4 - Global User Startup: svchost.exe


After you have checked the above entries
click FIX CHECKED
OK the prompt and exit Hijackthis

Now, start The Avenger program by clicking on its icon on your desktop>>Ok the prompt

    * Beside "Load Script from File:" click the folder icon
    * Next to Look in: box use the Drop down menu and left click to Highlight Desktop
    * Find emy.txt and double click on it to Select it
    * Now click on the Green Light to begin execution of the script
    * Answer "Yes" twice when prompted.

Avenger should now Reboot your computer

Back in Windows

Post back the following please
1. Post the log created by Avenger>>C:\Avenger.txt
2. Post a fresh hijackthis log
3. After you paste back the log from Hijackthis
Close Hijackthis>>After you close, ReOpen it
supply an uninstall list from Hijackthis
Open MISC TOOLS SECTION>>Open UNINSTALL MANAGER
Click the SAVE LIST... button
Save the list to your desktop then copy>>Paste back here the Whole contents
« Last Edit: October 01, 2006, 05:43:39 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #10 on: October 02, 2006, 12:27:19 AM »
id idnt understand what u said here

Left click to Highlight ONLY the one process that looks like the following
C:\WINDOWS\svchost.exe
After you have highlighted the above process
Click the Kill Process button
Click Yes to the prompt
« Last Edit: October 03, 2006, 11:49:15 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #11 on: October 02, 2006, 12:29:51 AM »
Open Hijackthis>>Open Misc tools section
Open the Process Manager
Under running Processes
Do you see this Exact process name

C:\WINDOWS\svchost.exe

If you do, Left click on it to Highlight it and then use the Kill process button in hijackthis to end process on it

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #12 on: October 02, 2006, 12:32:21 AM »
wait nvm i got it im almost done i think
« Last Edit: October 03, 2006, 11:49:29 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #13 on: October 02, 2006, 09:39:34 AM »
its says unable to delete O4 - Global Startup: svchost.exe
 and O4 - Global User Startup: svchost.exe cause its alredy in use use task maganer to close this program i dont have it open and it says that
« Last Edit: October 03, 2006, 11:49:46 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #14 on: October 02, 2006, 12:57:08 PM »
acually it says this file maybe in use task manager to shutdown the program and run hijackthis again to delete the file  when i delete O4 - Global Startup: svchost.exe and
O4 - Global User Startup: svchost.exe


only those 2 wont get deleted but all the resy did.
« Last Edit: October 03, 2006, 11:50:11 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #15 on: October 02, 2006, 06:21:15 PM »
Where are all the logs I asked for???

Quote
1. Post the log created by Avenger>>C:\Avenger.txt
2. Post a fresh hijackthis log
3. After you paste back the log from Hijackthis
Close Hijackthis>>After you close, ReOpen it
supply an uninstall list from Hijackthis
Open MISC TOOLS SECTION>>Open UNINSTALL MANAGER
Click the SAVE LIST... button
Save the list to your desktop then copy>>Paste back here the Whole contents

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #16 on: October 03, 2006, 08:35:22 AM »
i still didnt get to that part it wont let me delete global and the otehr one
« Last Edit: October 03, 2006, 11:50:24 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
slow comp
« Reply #17 on: October 03, 2006, 08:36:24 AM »
Carry on with ALL the instructions I posted earlier than post back all the logs
If you get stuck at one point
continue, let me know about it later
« Last Edit: October 03, 2006, 08:36:55 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #18 on: October 03, 2006, 12:47:19 PM »
Post back the following please
1. Post the log created by Avenger>>C:\Avenger.txt


here it is:


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\saqdppdy

*******************

Script file located at: \??\C:\WINDOWS\system32\ognkpltl.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\svchost.exe deleted successfully.
File C:\Program Files\Hgiork\Kinqxja.exe deleted successfully.
File C:\WINDOWS\tasks\A89D17DF918A8E37.job deleted successfully.


File C:\Documents and Settings\mshome\Start Menu\Programs\Startup\svchost.exe not found!
Deletion of file C:\Documents and Settings\mshome\Start Menu\Programs\Startup\svchost.exe failed!

Could not process line:
C:\Documents and Settings\mshome\Start Menu\Programs\Startup\svchost.exe
Status: 0xc0000034



File C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe not found!
Deletion of file C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe failed!

Could not process line:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
Status: 0xc0000034

Folder C:\Program Files\Hgiork deleted successfully.

Completed script processing.

*******************

Finished!  Terminate.











2. Post a fresh hijackthis log
3. After you paste back the log from Hijackthis



i didnt understand that part plz explain it easly tell me what im suppose to do weres the fresh hijackthis log?
« Last Edit: October 03, 2006, 11:50:38 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
slow comp
« Reply #19 on: October 03, 2006, 01:41:16 PM »
ok now here is the freash hijackthis log i think:



Logfile of HijackThis v1.99.1
Scan saved at 0:41:34, on 01.10.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hgiork\Kinqxja.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\PROGRA~1\COMMON~1\AOL\115783~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\115783~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\mshome\Desktop\hijackthis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe  "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WINDOWS\svchost.exe" "C:\WIND
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:\WINDOWS\svchost.exe","C:"C:\WINDOWS\svchost.exe",
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Akwyxmon] C:\Program Files\Hgiork\Kinqxja.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1157832268\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\TPT Registry_Cleaner (Trial)\regclean.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: svchost.exe
O4 - Global User Startup: svchost.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...html?p=ZNfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - file://H:\games\WebDriverFullInstall.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CBB55E7-1303-4237-AB62-6804124674DD}: NameServer = 213.131.66.138 213.131.66.246
O17 - HKLM\System\CS2\Services\Tcpip\..\{3CBB55E7-1303-4237-AB62-6804124674DD}: NameServer = 213.131.66.138 213.131.66.246
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe





that is how it gave it to me.





here is the uninstall list thing:





America Online (Choose which version to remove)
AOL Coach Version 2.0(Build:20041026.5 en)
AOL Connectivity Services
AOL Spyware Protection
AOL You've Got Pictures Screensaver
Autofighter
GhostMouse 2.0
HijackThis 1.99.1
Hitman 2: Silent Assassin
HyperCam 2
J2SE Runtime Environment 5.0 Update 6
LiveReg (Symantec Corporation)
Metal Gear Solid
Mozilla Firefox (1.5)
MSN Messenger 7.5
Norton SystemWorks 2003
Norton WMI Update
RealPlayer Basic
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
SwiftSwitch
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
USB Game Controller
WildTangent Updater
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781





ok now i think i gave u all the logs u asked for
« Last Edit: October 03, 2006, 11:50:58 PM by guestolo »
I'm a scammer right? Ban me



OK