Author Topic: Trojan or virus suspected + svchost issue  (Read 600 times)

Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« on: January 01, 2007, 07:55:11 PM »
Greetings fellows.

Recently I came across an issue with y laptop (Toshiba satellite with XPSP2)
The first message I received today, while starting windows, was something about Svchost missing or some registry error, if is needed I'll take note of it during my next restart.

Next I wasn't happy with that, so I did a virus scan AVG didn't detected threads, however, avira detected this "DR/Messe.106.A" in windows/svchost.exe

The virus database has no info on this, after some research, the only place with info is some german site http://board.protecus.de/t27317.htm

other than that, everythng works fine so far, but I don't want this to grow, any help would be appreciated here, I assume you need the hijackthis log?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #1 on: January 01, 2007, 08:12:16 PM »
Yes please, post the hijackthis log

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #2 on: January 01, 2007, 08:47:41 PM »
Alright, there you go:
Logfile of HijackThis v1.99.1
Scan saved at 07:10:51 p.m., on 01/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe
C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe
C:\ARCHIV~1\Grisoft\AVG7\avgemc.exe
C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System320THotkey.exe
C:\Archivos de programa\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Archivos de programa\Java\jre1.5.0_09\bin\jusched.exe
C:\ARCHIV~1\Grisoft\AVG7\avgcc.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\ARCHIV~1\ARCHIV~1\PCSuite\Services\SERVIC~1.EXE
C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\1XConfig.exe
C:\ARCHIV~1\ARCHIV~1\Nokia\MPAPI\MPAPI3s.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\CapabilityManager.exe
C:\Archivos de programa\Opera\Opera.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\Generic.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\hjt\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
F2 - REG:system.ini: Shell=Explorer.exe scvhost.exe
F3 - REG:win.ini: run=C:\WINDOWS\scvhost.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\ARCHIV~1\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
O4 - HKLM\..\Run: [LtMoh] C:\Archivos de programa\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System320THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TouchED] C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\ARCHIV~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\Run: [DataLayer] C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [avgnt] "C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\RunServices: [Windows Update] C:\WINDOWS\scvhost.exe
O4 - HKLM\..\RunServices: [] C:\WINDOWS\scvhost.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [PcSync] C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All by FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibalatino.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1144880521697
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\ARCHIV~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Archivos de programa\TuneUp Utilities 2006\WinStylerThemeSvc.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #3 on: January 01, 2007, 08:58:14 PM »
Can you do the following please
Download [color=\"red\"]SDFix[/color] and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Afterwards, can you decide which AntiVirus software your happiest with
Either AVG or Avira
Having more than one running on the machine can cause system Instabilities and slowdowns
Remove one from add/remove programs

When that's done
Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Mod Ryan

  • Sr. Member
  • ****
  • Posts: 441
  • Karma: +0/-0
    • View Profile
    • http://runecore.com <--- there still fags.
Trojan or virus suspected + svchost issue
« Reply #4 on: January 02, 2007, 01:06:49 AM »
HMM, when i got hacked by RAT, there was a problem with my svchost, i am not assuming yet, but if you have a trojan in that it could potentially be bad, i had one in it, and it was leaking information to the sender, so be weary, take caution and follow questolos orders, soon you should hopefully be clean.
« Last Edit: January 03, 2007, 12:25:39 AM by guestolo »












[color=\"gold\"]CONTACT CARD[/color]



[color=\"gold\"]MSN Details:[/color] [color=\"blue\"] R9_Ronaldo_R10@hot mail.com [/color]





[color=\"gold\"]REPUTATION Details :[/color]



[color=\"blue\"]TTG Elite Anti-Scammer

Owner And Root Admin Of RuneCore

Admin Of RuneCore TS Chat

Admin Of RS2MM

Admin Of W/E

Admin Of Carbon-Gaming

Admin Of Ban Jagex

Admin Of RSAAA

Admin Of Rune-Plate

Admin And Owner Of RuneScape Supreme

Global Mod On RS-Elite

Global Mod On Projekt RS2

Global Mod On RsCheatNetwork

Global Mod On Hostile

[/color]



[color=\"gold\"]RYANS TRANSACTIONS[/color]



[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]SPIN [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]SHRIMPY[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Pure, 3.8M to[/color] [color=\"red\"]ISH[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Level 98, 20M to [/color][color=\"red\"]CASANOVA[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought An Ownage Pure From[/color] [color=\"red\"]I R MEXICAN[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought 15M From[/color] [color=\"red\"]FLAME7420[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LINPAPAZ[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold 12M To[/color] [color=\"red\"] SEAN1390 [/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold 23M to [/color][color=\"red\"]BURNSY[/color] [color=\"green\"]COMPLETE[/color]

[color=\"red\"]B O N 3 S[/color][color=\"gold\"] Leveling Up My Pure [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold A Level 59 Pure To [/color][color=\"red\"]B O N 3 S[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold[/color] [color=\"red\"]DREATH[/color][color=\"gold\"] 50M [/color][color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]THE CEREAL BOWL[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Level 98 Main 15M To [/color][color=\"red\"]TAMEDOG [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]YORGK[/color] [color=\"green\"]COMPLETE[/color]

[color=\"red\"]B 0 N 3 S[/color] [color=\"gold\"]Trained My Main [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought Level 89 From[/color] [color=\"red\"]I R MEXICAN[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought Level 96 From [/color][color=\"red\"]STENSILIW[/color] [color=\"green\"]COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"] SEAN1390 [/color] [color=\"green\"] COMPLETE [/color]

[color=\"red\"]DREATH[/color][color=\"gold\"] Trained My pure [/color][color=\"green\"] DIDN'T GET ANY XP AT ALL [/color]

[color=\"gold\"]Bought Empire Banner From[/color] [color=\"red\"]LEETSAUCE[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold 8M To [/color][color=\"red\"] D A M A G E [/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought 7M From [/color][color=\"red\"]FLAME7420[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Member Pin. To [/color][color=\"red\"]24 KABUTOPS[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Rune Pure To [/color][color=\"red\"]QUANNY[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]EKKE[/color] [color=\"green\"] COMPLETE[/color]

[color=\"gold\"]Sold Santa hat to[/color] [color=\"red\"]S P R O A T[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]MAHATMA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought Website Removed for Spamming Banner From [/color][color=\"red\"]LEETSAUCE[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]RS2 BUYER[/color] [color=\"green\"] COMPLETE MM = PRO EDGE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]DEVILMAN[/color] [color=\"green\"] COMPLETE I WENT FIRST [/color]

[color=\"gold\"]Bought 12.5M From[/color] [color=\"red\"]DEVILMAN[/color] [color=\"green\"] COMPLETE I WENT FIRST [/color]

[color=\"gold\"]Sold Level 104 RS Account for 20M to [/color][color=\"red\"]ALLDEMFATTIESGOHELL[/color] [color=\"green\"] COMPLETE MM = LITTEFLY1 [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"] WAQAS [/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]JAVINO194[/color] [color=\"green\"] COMPLETE NO MM[/color]

[color=\"gold\"]Sold 50M To [/color] [color=\"red\"]RS TRANSIT[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]DIGERNES [/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]USIIF[/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Lvl 63 Pure To [/color] [color=\"red\"]EXILESKIMMER[/color] [color=\"green\"] COMPLETE VERY FAST MM = MADHATTER [/color]

[color=\"gold\"]Sold 30M To [/color] [color=\"red\"]LIVESPARTAN[/color] [color=\"green\"] COMPLETE MM = MAGHREB [/color]

[color=\"gold\"]Sold Lvl 107 To [/color] [color=\"red\"]SKATE ORR DIE[/color] [color=\"green\"] COMPLETE MM = JB LEE/JASON[/color]

[color=\"gold\"]Bought Lvl 91 Rune Pure From[/color] [color=\"red\"]T3h P0wner[/color] [color=\"red\"] RECOVERED - Do Not Trade With Him (The Account Name Is X D34D M4N X) [/color]



[color=\"gold\"]RYANS MIDDLEMANS[/color]



[color=\"gold\"]MM' 3.5M And Steam Account[/color] [color=\"blue\"](Ekke-Skeptical)[/color]

[color=\"gold\"]MM' 3M and a lvl 64 Pure [/color][color=\"blue\"](Sean1390-DAMAGE)[/color]

[color=\"gold\"]MM' Member Pin and 900K [/color][color=\"blue\"](Mercer-Javino194)[/color]

[color=\"gold\"]MM' 1.6M And A Member Pin[/color] [color=\"blue\"](Skeptical-Ekke)[/color]

[color=\"gold\"]MM' Mem. Pin[/color] [color=\"blue\"](Ekke-Skeptical)[/color]

[color=\"gold\"]MM' 18M & Level 101[/color] [color=\"blue\"](Skatelife-Tgirl) [/color]

[color=\"gold\"]MM' 1.2M and Mem. Pin[/color] [color=\"blue\"] (Heapswer-TSniper) [/color]

[color=\"gold\"]Transfered 7M and a Mage Book For [/color][color=\"blue\"](I R MEXICAN)[/color]

[color=\"gold\"]MM' 10M & 70USD[/color] [color=\"blue\"](Casanova-Cash_Tyler) [/color]

[color=\"gold\"]MM' Easter Egg & 90USD[/color] [color=\"blue\"](XxAlexxX-Decklin)[/color]

[color=\"gold\"]MM' 3M[/color] [color=\"blue\"](Waqas-Xfer)[/color]

[color=\"gold\"]MM' 14M & Level 100 [/color] [color=\"blue\"](Silent-WBA)[/color]

[color=\"gold\"]MM' 7M & 50 USD[/color] [color=\"blue\"](Casanova-LinPapaz)[/color]

[color=\"gold\"]MM' 22M & 140 USD [/color] [color=\"blue\"] (Casanova-RS Transit)[/color]

[color=\"gold\"]MM' Around 4M [/color] [color=\"blue\"] (F123nzy-Xfer)[/color]

[color=\"gold\"]MM' 2.5M [/color] [color=\"blue\"] (Glower-Warlord Slayer) [/color]

[color=\"gold\"]MM' 50M & Lvl 118 [/color] [color=\"blue\"] (RS transit - Matt) [/color]

[color=\"gold\"]MM' 1M & Lvl 60 [/color] [color=\"blue\"] (Mynameownsall-Sproat) [/color]

[color=\"gold\"]MM' 1M & Account [/color] [color=\"blue\"] (Tsniper-Dannyboy) [/color]

[color=\"gold\"]MM' Mem. Pin & 1M[/color] [color=\"blue\"] (Madhatter-Eddy) [/color]

[color=\"gold\"]MM' Level 110 & 50M[/color] [color=\"blue\"] (SebBoe-Danny) [/color]

[color=\"gold\"]MM' 14M & Lvl 99 Account [/color] [color=\"blue\"] (Heapswer-Matt) [/color]

[color=\"gold\"]MM' 13M & RunePure Account [/color] [color=\"blue\"] (Shot Down-SomeGuy) [/color]

[color=\"gold\"]MM' 2M & $10 [/color] [color=\"blue\"] (J0sh4tran-Right Nad) [/color]

[color=\"gold\"]MM' 8M & $52 [/color] [color=\"blue\"] (J0sh4tran-I0 3) [/color]

[color=\"gold\"]MM' 25M & Level 98 With Amazing Stats [/color] [color=\"blue\"] (I Ho0s S0oH I-Duel King)[/color]

[color=\"gold\"]MM' Level 104 & 17M [/color] [color=\"blue\"] (Basi Homme-WatfordFc94) [/color]

[color=\"gold\"]MM' 5.5M & Lvl 90 [/color] [color=\"blue\"] (II Sift Heads II - X Trainer X) [/color]

[color=\"gold\"]MM 600K & Training Services [/color] [color=\"blue\"] (X Trainer X - Pleasenoscammer) [/color]



[color=\"gold\"] Total Money MM' = 454M ($4120USD) [/color]





[color=\"blue\"] Visit The Most Futuristic BlackMarket To Date! Rune Core JOIN NOW![/color][/u][/size]

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #5 on: January 02, 2007, 01:09:34 AM »
Remember Mod Ryan, it's not svchost.exe we're dealing with
It's scvhost.exe
Anyways, SDFix should help out

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Mod Ryan

  • Sr. Member
  • ****
  • Posts: 441
  • Karma: +0/-0
    • View Profile
    • http://runecore.com <--- there still fags.
Trojan or virus suspected + svchost issue
« Reply #6 on: January 02, 2007, 01:11:45 AM »
Yeah sorry about that lol, i hope that program helps you and questolo, "Ryan" is fine lol http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/tongue.gif\' class=\'bbc_emoticon\' alt=\':P\' />
« Last Edit: January 03, 2007, 12:25:49 AM by guestolo »












[color=\"gold\"]CONTACT CARD[/color]



[color=\"gold\"]MSN Details:[/color] [color=\"blue\"] R9_Ronaldo_R10@hot mail.com [/color]





[color=\"gold\"]REPUTATION Details :[/color]



[color=\"blue\"]TTG Elite Anti-Scammer

Owner And Root Admin Of RuneCore

Admin Of RuneCore TS Chat

Admin Of RS2MM

Admin Of W/E

Admin Of Carbon-Gaming

Admin Of Ban Jagex

Admin Of RSAAA

Admin Of Rune-Plate

Admin And Owner Of RuneScape Supreme

Global Mod On RS-Elite

Global Mod On Projekt RS2

Global Mod On RsCheatNetwork

Global Mod On Hostile

[/color]



[color=\"gold\"]RYANS TRANSACTIONS[/color]



[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]SPIN [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"]SHRIMPY[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Pure, 3.8M to[/color] [color=\"red\"]ISH[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Level 98, 20M to [/color][color=\"red\"]CASANOVA[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought An Ownage Pure From[/color] [color=\"red\"]I R MEXICAN[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought 15M From[/color] [color=\"red\"]FLAME7420[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LINPAPAZ[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold 12M To[/color] [color=\"red\"] SEAN1390 [/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold 23M to [/color][color=\"red\"]BURNSY[/color] [color=\"green\"]COMPLETE[/color]

[color=\"red\"]B O N 3 S[/color][color=\"gold\"] Leveling Up My Pure [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold A Level 59 Pure To [/color][color=\"red\"]B O N 3 S[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold[/color] [color=\"red\"]DREATH[/color][color=\"gold\"] 50M [/color][color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]THE CEREAL BOWL[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Level 98 Main 15M To [/color][color=\"red\"]TAMEDOG [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]LAKOTA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]YORGK[/color] [color=\"green\"]COMPLETE[/color]

[color=\"red\"]B 0 N 3 S[/color] [color=\"gold\"]Trained My Main [/color][color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought Level 89 From[/color] [color=\"red\"]I R MEXICAN[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Bought Level 96 From [/color][color=\"red\"]STENSILIW[/color] [color=\"green\"]COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin to [/color][color=\"red\"] SEAN1390 [/color] [color=\"green\"] COMPLETE [/color]

[color=\"red\"]DREATH[/color][color=\"gold\"] Trained My pure [/color][color=\"green\"] DIDN'T GET ANY XP AT ALL [/color]

[color=\"gold\"]Bought Empire Banner From[/color] [color=\"red\"]LEETSAUCE[/color] [color=\"green\"]COMPLETE[/color]

[color=\"gold\"]Sold 8M To [/color][color=\"red\"] D A M A G E [/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought 7M From [/color][color=\"red\"]FLAME7420[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Member Pin. To [/color][color=\"red\"]24 KABUTOPS[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Rune Pure To [/color][color=\"red\"]QUANNY[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]EKKE[/color] [color=\"green\"] COMPLETE[/color]

[color=\"gold\"]Sold Santa hat to[/color] [color=\"red\"]S P R O A T[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]MAHATMA[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Bought Website Removed for Spamming Banner From [/color][color=\"red\"]LEETSAUCE[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color][color=\"red\"]RS2 BUYER[/color] [color=\"green\"] COMPLETE MM = PRO EDGE [/color]

[color=\"gold\"]Sold Mem. Pin To[/color] [color=\"red\"]DEVILMAN[/color] [color=\"green\"] COMPLETE I WENT FIRST [/color]

[color=\"gold\"]Bought 12.5M From[/color] [color=\"red\"]DEVILMAN[/color] [color=\"green\"] COMPLETE I WENT FIRST [/color]

[color=\"gold\"]Sold Level 104 RS Account for 20M to [/color][color=\"red\"]ALLDEMFATTIESGOHELL[/color] [color=\"green\"] COMPLETE MM = LITTEFLY1 [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"] WAQAS [/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]JAVINO194[/color] [color=\"green\"] COMPLETE NO MM[/color]

[color=\"gold\"]Sold 50M To [/color] [color=\"red\"]RS TRANSIT[/color] [color=\"green\"] COMPLETE [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]DIGERNES [/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Mem. Pin To [/color] [color=\"red\"]USIIF[/color] [color=\"green\"] COMPLETE NO MM [/color]

[color=\"gold\"]Sold Lvl 63 Pure To [/color] [color=\"red\"]EXILESKIMMER[/color] [color=\"green\"] COMPLETE VERY FAST MM = MADHATTER [/color]

[color=\"gold\"]Sold 30M To [/color] [color=\"red\"]LIVESPARTAN[/color] [color=\"green\"] COMPLETE MM = MAGHREB [/color]

[color=\"gold\"]Sold Lvl 107 To [/color] [color=\"red\"]SKATE ORR DIE[/color] [color=\"green\"] COMPLETE MM = JB LEE/JASON[/color]

[color=\"gold\"]Bought Lvl 91 Rune Pure From[/color] [color=\"red\"]T3h P0wner[/color] [color=\"red\"] RECOVERED - Do Not Trade With Him (The Account Name Is X D34D M4N X) [/color]



[color=\"gold\"]RYANS MIDDLEMANS[/color]



[color=\"gold\"]MM' 3.5M And Steam Account[/color] [color=\"blue\"](Ekke-Skeptical)[/color]

[color=\"gold\"]MM' 3M and a lvl 64 Pure [/color][color=\"blue\"](Sean1390-DAMAGE)[/color]

[color=\"gold\"]MM' Member Pin and 900K [/color][color=\"blue\"](Mercer-Javino194)[/color]

[color=\"gold\"]MM' 1.6M And A Member Pin[/color] [color=\"blue\"](Skeptical-Ekke)[/color]

[color=\"gold\"]MM' Mem. Pin[/color] [color=\"blue\"](Ekke-Skeptical)[/color]

[color=\"gold\"]MM' 18M & Level 101[/color] [color=\"blue\"](Skatelife-Tgirl) [/color]

[color=\"gold\"]MM' 1.2M and Mem. Pin[/color] [color=\"blue\"] (Heapswer-TSniper) [/color]

[color=\"gold\"]Transfered 7M and a Mage Book For [/color][color=\"blue\"](I R MEXICAN)[/color]

[color=\"gold\"]MM' 10M & 70USD[/color] [color=\"blue\"](Casanova-Cash_Tyler) [/color]

[color=\"gold\"]MM' Easter Egg & 90USD[/color] [color=\"blue\"](XxAlexxX-Decklin)[/color]

[color=\"gold\"]MM' 3M[/color] [color=\"blue\"](Waqas-Xfer)[/color]

[color=\"gold\"]MM' 14M & Level 100 [/color] [color=\"blue\"](Silent-WBA)[/color]

[color=\"gold\"]MM' 7M & 50 USD[/color] [color=\"blue\"](Casanova-LinPapaz)[/color]

[color=\"gold\"]MM' 22M & 140 USD [/color] [color=\"blue\"] (Casanova-RS Transit)[/color]

[color=\"gold\"]MM' Around 4M [/color] [color=\"blue\"] (F123nzy-Xfer)[/color]

[color=\"gold\"]MM' 2.5M [/color] [color=\"blue\"] (Glower-Warlord Slayer) [/color]

[color=\"gold\"]MM' 50M & Lvl 118 [/color] [color=\"blue\"] (RS transit - Matt) [/color]

[color=\"gold\"]MM' 1M & Lvl 60 [/color] [color=\"blue\"] (Mynameownsall-Sproat) [/color]

[color=\"gold\"]MM' 1M & Account [/color] [color=\"blue\"] (Tsniper-Dannyboy) [/color]

[color=\"gold\"]MM' Mem. Pin & 1M[/color] [color=\"blue\"] (Madhatter-Eddy) [/color]

[color=\"gold\"]MM' Level 110 & 50M[/color] [color=\"blue\"] (SebBoe-Danny) [/color]

[color=\"gold\"]MM' 14M & Lvl 99 Account [/color] [color=\"blue\"] (Heapswer-Matt) [/color]

[color=\"gold\"]MM' 13M & RunePure Account [/color] [color=\"blue\"] (Shot Down-SomeGuy) [/color]

[color=\"gold\"]MM' 2M & $10 [/color] [color=\"blue\"] (J0sh4tran-Right Nad) [/color]

[color=\"gold\"]MM' 8M & $52 [/color] [color=\"blue\"] (J0sh4tran-I0 3) [/color]

[color=\"gold\"]MM' 25M & Level 98 With Amazing Stats [/color] [color=\"blue\"] (I Ho0s S0oH I-Duel King)[/color]

[color=\"gold\"]MM' Level 104 & 17M [/color] [color=\"blue\"] (Basi Homme-WatfordFc94) [/color]

[color=\"gold\"]MM' 5.5M & Lvl 90 [/color] [color=\"blue\"] (II Sift Heads II - X Trainer X) [/color]

[color=\"gold\"]MM 600K & Training Services [/color] [color=\"blue\"] (X Trainer X - Pleasenoscammer) [/color]



[color=\"gold\"] Total Money MM' = 454M ($4120USD) [/color]





[color=\"blue\"] Visit The Most Futuristic BlackMarket To Date! Rune Core JOIN NOW![/color][/u][/size]

Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #7 on: January 02, 2007, 03:26:50 PM »
Ok, upon restarting, Avira detected this
"BDS/Nuclear.AQ" in C:\WINDOWS\rootkit.exe

And just after that, I received the same messages I received before:

*Windows can\'t find the archive
 C:\windows\svchost.exe


*Windows can\'t load nor execute C:\windows\svchost.exe in the registry, make sure the archive exists or remove the entry from the registry.

SDFix log:

SDFix: Version 1.53
****************

01/01/2007 - 22:36:52.45

Microsoft Windows XP [Versi¢n 5.1.2600]

Running From: C:\SDFix

Stage One - Safe Mode

Checking Services...

Service Name:


File Path:



Starting Registry Repairs...
 Restoring Default Hosts File...
 Stage One Complete
 Rebooting...
 Stage Two - Normal Mode
 Checking For Malware:
--------------------
 C:\Documents and Settings\Otaru\Mis documentos\download-flvplayer_setup.exe.exe
C:\WINDOWS\offlog.txt
C:\WINDOWS\rootkit.exe
 Backing Up and Removing any Files Found...

Alternate Stream Check:

C:\WINDOWS\system32
No streams found.
                                 Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"="C:\\TOSHIBA\\ivp\\NetInt\\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine"
"C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"="C:\\TOSHIBA\\Ivp\\ISM\\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\Java\\jre1.5.0_06\\bin\\javaw.exe"="C:\\Archivos de programa\\Java\\jre1.5.0_06\\bin\\javaw.exe:*:Enabled:Java(tm) 2 Platform Standard Edition binary"
"C:\\Archivos de programa\\Azureus\\Azureus.exe"="C:\\Archivos de programa\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Archivos de programa\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"="C:\\Archivos de programa\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\\Archivos de programa\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD"="C:\\Archivos de programa\\Microsoft Games\\Age of Empires II\\age2_x1\\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"C:\\WINDOWS\\system32\\Firewall.exe"="C:\\WINDOWS\\system32\\Firewall.exe:*:Enabled:Firewall"
"C:\\WINDOWS\\system32\\wscntfyr.exe"="C:\\WINDOWS\\system32\\wscntfyr.exe:*:Enabled:wscntfyr"
"C:\\Archivos de programa\\GPotato\\SpaceCowboy\\Launcher.atm"="C:\\Archivos de programa\\GPotato\\SpaceCowboy\\Launcher.atm:*:Enabled:SCLauncher"
"C:\\Archivos de programa\\GPotato\\SpaceCowboy\\SpaceCowboy.exe"="C:\\Archivos de programa\\GPotato\\SpaceCowboy\\SpaceCowboy.exe:*:Enabled:SpaceCowboy"
"C:\\Archivos de programa\\Opera\\Opera.exe"="C:\\Archivos de programa\\Opera\\Opera.exe:*:Enabled:Opera Internet Browser"
"C:\\sysreset\\mirc.exe"="C:\\sysreset\\mirc.exe:*:Enabled:mIRC"
"C:\\Archivos de programa\\Starcraft\\starcraft.exe"="C:\\Archivos de programa\\Starcraft\\starcraft.exe:*:Enabled:Starcraft"
"C:\\Archivos de programa\\Hamachi\\hamachi.exe"="C:\\Archivos de programa\\Hamachi\\hamachi.exe:*:Enabled:Hamachi Client"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\\Archivos de programa\\Kali95\\Kali.exe"="C:\\Archivos de programa\\Kali95\\Kali.exe:*:Enabled:Kali II (Ver 2.613)"
"C:\\Archivos de programa\\GIT\\Git.exe"="C:\\Archivos de programa\\GIT\\Git.exe:*:Enabled:Gamer\'s Internet Tunnel"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Archivos de programa\\MSN Messenger\\msncall.exe"="C:\\Archivos de programa\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\scvhost.exe"="C:\\WINDOWS\\scvhost.exe:*:Enabled:Microsoft Windows"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe"="C:\\Archivos de programa\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Archivos de programa\\MSN Messenger\\msncall.exe"="C:\\Archivos de programa\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip

Checking for files with Hidden Attributes:

C:\Archivos de programa\Outlook Express\msimn.exe
C:\WINDOWS\system32\cdplayer.exe.manifest
C:\WINDOWS\system32\logonui.exe.manifest
C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\Documents and Settings\Otaru\Mis documentos\UVM\~WRL0001.tmp

                                 FINISHED!

Here\'s the hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:52:41 p.m., on 01/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Archivos de programa\MSN Messenger\msnmsgr.exe
C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System320THotkey.exe
C:\Archivos de programa\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Archivos de programa\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\ARCHIV~1\ARCHIV~1\PCSuite\Services\SERVIC~1.EXE
C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\ARCHIV~1\ARCHIV~1\Nokia\MPAPI\MPAPI3s.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\CapabilityManager.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\Generic.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Archivos de programa\Opera\Opera.exe
C:\hjt\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
F3 - REG:win.ini: run=C:\WINDOWS\scvhost.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\ARCHIV~1\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
O4 - HKLM\..\Run: [LtMoh] C:\Archivos de programa\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System320THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TouchED] C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [DataLayer] C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [avgnt] "C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [TOSCDSPD] C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [PcSync] C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All by FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra \'Tools\' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra \'Tools\' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra \'Tools\' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra \'Tools\' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibalatino.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1144880521697
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Archivos de programa\TuneUp Utilities 2006\WinStylerThemeSvc.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #8 on: January 03, 2007, 01:25:11 AM »
Do a "System scan only" with Hijackthis and put a check next to these entries:

F3 - REG:win.ini: run=C:\WINDOWS\scvhost.exe


After you have ticked the above entry, close All other open windows
Including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Reboot the computer

Back in Windows
Can you do the following

Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Manually look for the next files and delete if found, they should be gone, but take a look
C:\WINDOWS\rootkit.exe <-file
C:\WINDOWS\system32\Firewall.exe <-file

Can you rename on the next file if found
C:\WINDOWS\system32\wscntfyr.exe <-file, RIGHT CLICK on the file and select RENAME
Name it wscntfyr.old
DON'T rename wscntfy.exe which is also in the system32 folder, notice the spelling

Afterwards
Go to either of these links
http://virusscan.jotti.org/
OR
http://www.virustotal.com/flash/index_en.html

Use the browse button and navigate to the file on your harddrive

C:\WINDOWS\system32\wscntfyr.old
Right click on the file and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please

In addition, can you please do the following
Download and save too your root directory
In your case, This will be the C:\ directory
 F-Secure Blacklight(blbeta.exe)
So you will now have C:\blbeta.exe
* Open a command window. (Start>Run and type: cmd)
* Copy paste or type the following in the command window:

C:\blbeta.exe /expert
   
    * Accept the user agreement.
    * Click Scan.
    * After the scan finishes, click on Next, then Exit.
Do not rename any files if found by blacklight, I need to see the log
The log will be created here>>C:\fsbl-xxxxxxx.log
« Last Edit: January 03, 2007, 01:28:00 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #9 on: January 03, 2007, 02:48:21 AM »
Done, I didn't found firewall.exe, rootkit.exe nor wscntfyr.exe, that's good, I guess.
Also, after fixing the file with hijack this, seems like the svchost issue was fixed.

This is the log from blbeta.exe

01/03/07 01:30:16 [Info]: BlackLight Engine 1.0.55 initialized
01/03/07 01:30:16 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/03/07 01:30:16 [Note]: 7019 4
01/03/07 01:30:16 [Note]: 7005 0
01/03/07 01:30:19 [Note]: 7006 0
01/03/07 01:30:19 [Note]: 7022 0
01/03/07 01:30:19 [Note]: 7011 344
01/03/07 01:30:19 [Note]: 7026 0
01/03/07 01:30:20 [Note]: 7026 0
01/03/07 01:30:31 [Note]: FSRAW library version 1.7.1021
01/03/07 01:42:30 [Note]: 7007 0
Aditionally, after checking avira's log I noticed this:

Virus or unwanted program 'DR/Messe.106.A'
detected in file 'C:\System Volume Information\_restore{2440E67B-4CEC-409C-BEAB-EDE997C06B9B}\RP306\A0043530.exe' [DR/Messe.106.A].

I'm not sure..should I delete the file? since it's in a restore "volume" I don't know if it's safe.

Just to be safe, I'll be running another full scan with avira.

Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #10 on: January 03, 2007, 04:20:54 AM »
After the scan it detected the following:
Trojan horse TR/Drop.Ardamax.K.4 in C.\WINDOWS\system32\WinSecure.003

Moving to quarantine and waiting for further directions.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #11 on: January 04, 2007, 01:37:12 PM »
I'm concerned about this entry
C.\WINDOWS\system32\WinSecure.003

Can you manually navigate to the System32 folder
Do you see any other files with the same name, but different no.
eg.. WinSecure.004 and so on

It belongs to a keylogger program from Ardamax
Usually unknowingly installed

Can I also have you do the following

Go to START>>RUN>>copy and paste the next command below in bold to the open field
regedit /e c:\registrybackup.reg
Hit OK
Let this finish, this will make a backup of the registry to the C: folder

Go to START>>RUN>>type in regedit
Hit OK
We're looking for this registry key in bold below
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
Expand(+) on the following
+HKEY_LOCAL_MACHINE
+SYSTEM
+CurrentControlSet
+Services
SharedAccess
+Parameters
+FirewallPolicy
+StandardProfile+
+AuthorizedApplications
Highlight List

Look on the right hand side for the following entries
C:\WINDOWS\system32\Firewall.exe
C:\WINDOWS\system32\wscntfyr.exe
C:\WINDOWS\scvhost.exe


RIGHT CLICK on each of the following above and select DELETE
Exit the registry

If this keylogger was unknowing installed
Immediately change passwords to online activities
As eg..Change passwords to email, online banking, gaming, etc....

Come back here and post one last hijackthis log and let me know how things are running please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #12 on: January 05, 2007, 04:21:53 AM »
Ah yes, there it is:
in System32 folder: WinSecure.001, 2, 3...up to 007
I assume it's safe to delete those files?

Changes in registry done, everything seems smooth so far.

Here's the hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 03:13:27 a.m., on 05/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System320THotkey.exe
C:\Archivos de programa\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Archivos de programa\Java\jre1.5.0_10\bin\jusched.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe
C:\Archivos de programa\Winamp\winampa.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\CapabilityManager.exe
C:\ARCHIV~1\ARCHIV~1\PCSuite\Services\SERVIC~1.EXE
C:\ARCHIV~1\ARCHIV~1\Nokia\MPAPI\MPAPI3s.exe
C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Archivos de programa\Archivos comunes\Teleca Shared\Generic.exe
C:\Archivos de programa\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\hjt\HijackThis.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Archivos de programa\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\ARCHIV~1\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Archivos de programa\SigmaTel\Controladores de sonido SigmaTel AC97\stacmon.exe
O4 - HKLM\..\Run: [LtMoh] C:\Archivos de programa\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Archivos de programa\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Archivos de programa\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System320THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TouchED] C:\Archivos de programa\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Archivos de programa\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [DataLayer] C:\Archivos de programa\Archivos comunes\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Archivos de programa\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [avgnt] "C:\Archivos de programa\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinampAgent] C:\Archivos de programa\Winamp\winampa.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Archivos de programa\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKCU\..\Run: [TOSCDSPD] C:\Archivos de programa\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [PcSync] C:\Archivos de programa\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Archivos de programa\Archivos comunes\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Download All by FlashGet - C:\Archivos de programa\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Archivos de programa\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Referencia - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\ARCHIV~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Archivos de programa\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibalatino.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1144880521697
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\ARCHIV~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Archivos de programa\Archivos comunes\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Archivos de programa\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Archivos de programa\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Archivos de programa\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Archivos de programa\Archivos comunes\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Archivos de programa\TuneUp Utilities 2006\WinStylerThemeSvc.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #13 on: January 05, 2007, 11:00:51 AM »
Yes, delete those files
I don't see any third party firewall software installed
If you don't have one installed
Can you ensure that your XP Firewall is running properly in the Windows control panel
If it is, carry on with the following

You can then ReSet Windows To Hide hidden Files and Folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Do Not Show hidden files and folders.
* Check the Hide protected operating system files (recommended) option.
* Click Apply>> OK.

If everything is running better, we should do the following
Go to START>>All Programs>>Accessories>>System Tools>>System Restore
Create a New restore point
Give it a name and click Create
When that's done

Go to START>>RUN>>type the following
cleanmgr
Hit OK
Let if finish calculating

Select the More Options tab
and click Cleanup.. under 'System Restore'
This will clear all later restore points except for the one you just made

Ok the prompts, it may take a few seconds to remove old restore points
Ok again after it's ready and let it finish cleaning

You should give your computer a bit more protection
Install
SpywareBlaster 3.5.1 by JavaCool  
    *Will block bad ActiveX Controls
    *Block Malevolent cookies in Internet Explorer and Firefox
    *Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates
After updating, select "Protection" on the Left
Then select "Enable all Protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"

Also, include a good Hosts file
http://www.mvps.org/winhelp2002/hosts.htm

Here's more info on how to download and extract it
http://www.mvps.org/winhelp2002/hosts2.htm
You will want to do this once a month

Stay safe  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

NOTE: You can delete that backup of the registry we did earlier
c:\registrybackup.reg>>Simply right click on the file and select DELETE
« Last Edit: January 05, 2007, 12:35:14 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline artie

  • Newbie
  • *
  • Posts: 7
  • Karma: +0/-0
    • View Profile
Trojan or virus suspected + svchost issue
« Reply #14 on: January 05, 2007, 07:11:20 PM »
Yeah, I have Windows default firewall active.
Everything is up and running, thanks a lot for everything http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Trojan or virus suspected + svchost issue
« Reply #15 on: January 06, 2007, 01:00:19 AM »
Glad to help, I'll lock this topic as your problems appear resolved
Take Care  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here