Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » Anything left to remove?

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

Anything left to remove?

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 14-11-2007, 04:11 AM
Full Member
New Recruit
 
Join Date: Oct 2006
Posts: 50
imported_Fathom Is a beginner here at D-A-L
Anything left to remove?

Here's my logfile. Had BZub many copies and 100+ redirects that Adaware picked up but regenerated. Spybot got some changed registry keys and I now have Control Panel back.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\utilman.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=25040
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6557BC7D-87E0-4A98-B597-68F541D25BF3} - C:\WINDOWS\system32\duse.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{77F629B7-C519-4061-904D-FB07F9CBB70A}: NameServer = 203.194.27.57 203.194.56.150
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


I still have things turned off in the startup and I'm not sure if there's any bad from it.

Here's the original thread -
http://www.techhelpforum.com/showpos...65&postcount=1
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 15-11-2007, 10:43 AM
Full Member
New Recruit
 
Join Date: Oct 2006
Posts: 50
imported_Fathom Is a beginner here at D-A-L
Hello...hello ... anyone home? What an unresponsive forum.

A simple Q to those in the know. English language.


I run a forum serviced 3 times a day 24/7!

???
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 15-11-2007, 10:44 AM
Full Member
New Recruit
 
Join Date: Oct 2006
Posts: 50
imported_Fathom Is a beginner here at D-A-L
Ffs
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 16-11-2007, 05:04 AM
Full Member
New Recruit
 
Join Date: Oct 2006
Posts: 50
imported_Fathom Is a beginner here at D-A-L
OK,

Spybot finds and removes an Antivirus Override and 85 redirects.

Trojan Remover identifies -

O2 - BHO: (no name) - {6557BC7D-87E0-4A98-B597-68F541D25BF3} - C:\WINDOWS\system32\duse.dll

and another at C:\WINDOWS\system32\drivers\vnafudcc.dat controlled by
HKEY\SYSTEM\CurrentControlSet\Services\mglpewgn\"I mage Path"

none of which it can remove and nor can Hijack This. Trojan Remover won't work in safe mode despite it recommending to.

They're locked and immovable apparently. Trying to move forward here - any suggestions?

Where to from here?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hello 999? I've left my coat on the bus! D-A-L Chat Room 1 09-09-2009 04:01 PM
Left 4 Dead 2 jephree PC Games 3 07-06-2009 06:45 PM
Left 4 Dead Kaistar Chat Room 26 08-01-2009 04:11 PM
programs closing left and right help?!?! braden198 Windows XP Help 1 07-09-2008 08:47 AM
Add Remove Programs Won't Remove Program mr_film Windows XP Help 1 28-04-2005 10:24 PM


All times are GMT +1. The time now is 07:39 AM.

Bottom Corner