Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > Malware and Virus Removal

Malware and Virus Removal Problems removing malware/viruses? Get help from our Malware removal experts.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 19th September 2008   #1
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


[Resolved] please take a look at this hijackthis log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:43:27 AM, on 9/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\COMODO\SafeSurf\cssurf.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.wunderground.com/global/stations/02485.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

http://www.dell4me.com/myway
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NETSCAPE - {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} - C:\WINDOWS\DOWNLO~1

\netscape.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32

\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program

Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program

files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program

Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1

\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: NETSCAPE - {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} - C:\WINDOWS\DOWNLO~1

\netscape.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} -

C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} -

c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround

Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -

startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe

/autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support

Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0

\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update

Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support

Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3

\DLCCtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program

Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common

Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support

Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} -

(no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583}

- C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - file://C:\Program

Files\iGive_Shopping_Window\iGivesShoppingWindow\iGivetShoppingWindow\igivC 0.htm (file

missing) (HKCU)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -

http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} -

https://www.windowsonecare.com/insta...SSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program

Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) -

http://musicstore.connect.com/XSL/mb...LStreaming.cab
O16 - DPF: {4E7BD74F-2B8D-469E-D7EE-FE6FA781BF33} (NETSCAPE) -

http://downloads.netscape.com/search...r/netscape.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module)

- http://cdn.scan.onecare.live.com/res...scbase5036.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsof...uweb_site.cab?

1140842262609
O16 - DPF: {AC414988-E5BB-4C2C-873B-EA53D2F3D23A} (CCTVUpdateInstall) -

http://t.live.cctv.com/ieocx/CCTVUpdateInstall.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class)

- http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} -

http://cdn.digitalcity.com/radio/amp...1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -

http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

http://fpdownload2.macromedia.com/ge...nt/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) -

http://drmlicense.one.microsoft.com/.../en/crlocx.ocx
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -

http://download.games.yahoo.com/game...ploader_v6.cab
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} -

http://mvnet.xlontech.net/qm/fox/061...ie06101001.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1

\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll C:\WINDOWS\system32\cssdll32.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program

Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common

Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program

Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -

C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program

Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common

Files\Motive\McciCMService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program

Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter)

- SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

--
End of file - 12843 bytes

my computer is running at around 85 on up to 100% i really think someone is on here with me. sorry if i did the post backwards,first time i've ever done it.


Last edited by jan roberts; 19th September 2008 at 07:12. Reason: someone please tell me what to do with trend micro hijack and the log itself right now i've got them min.
jan roberts is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 20th September 2008   #2
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi jan
Please open Notepad click the format tab and uncheck WordWrap.

Now please do this.

Jotti File Submission:
  • Please go to Jotti's malware scan
  • Copy and paste the following file path into the "File to upload & scan"box on the top of the page: one at a time
    • C:\WINDOWS\system32\cssdll32.dll
  • Click on the submit button
  • Please post the results in your next reply.

Thanks
Geri

Geri is offline   Reply With Quote
Old 20th September 2008   #3
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


gerri thank you so much for answering this post. ran into a small problem with jotti and maybe my fault. you said copy and paste well i just typed it in was i supposed to go to c\windows\system32\cssdll32.dll and copy that and paste it! anything i gave it an hour and aborted when it wasnt moving(the upload part).
i also lost the hijackthis,so did another one and this time unchecked word wrap,and know where it is. so thats where i am now. i plead stupidity,dumbnes or just totally lost.
i do know how to copy and paste,do that on im and it isnt typing into the little box. im going to wait until i hear from on how i think im supposed do it. i was going to just to it but chicken out.i really dont want it blowing up or something equally horrible.
have patience please,im way over my head and i know it

jan roberts is offline   Reply With Quote
Old 20th September 2008   #4
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi jan
As long as you typed it correctly it should have worked.

Sometimes Jotti is very busy and it takes a while.

Enable the 'Show Hidden Files/Folders' option, like this:
Click Start.
Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.


Lets try this one.

Upload a File to Virustotal
Please visit Virustotal
  • Click the Browse... button
  • Navigate to the file C:\WINDOWS\system32\cssdll32.dll
  • Click the Open button
  • Click the Send button
  • Copy and paste the results back here please.

Thanks
Geri

Geri is offline   Reply With Quote
Old 20th September 2008   #5
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


gerri here is the file? | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Français | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...
File cscdll.dll received on 09.20.2008 23:02:28 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


Result: 0/36 (0%)
Loading server information...
Your file is queued in position: 1.
Estimated start time is between 39 and 56 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they're generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
Email:


Antivirus Version Last Update Result
AhnLab-V3 2008.9.19.2 2008.09.19 -
AntiVir 7.8.1.34 2008.09.19 -
Authentium 5.1.0.4 2008.09.20 -
Avast 4.8.1195.0 2008.09.20 -
AVG 8.0.0.161 2008.09.20 -
BitDefender 7.2 2008.09.20 -
CAT-QuickHeal 9.50 2008.09.20 -
ClamAV 0.93.1 2008.09.20 -
DrWeb 4.44.0.09170 2008.09.20 -
eSafe 7.0.17.0 2008.09.18 -
eTrust-Vet 31.6.6096 2008.09.20 -
Ewido 4.0 2008.09.20 -
F-Prot 4.4.4.56 2008.09.20 -
F-Secure 8.0.14332.0 2008.09.20 -
Fortinet 3.113.0.0 2008.09.20 -
GData 19 2008.09.20 -
Ikarus T3.1.1.34.0 2008.09.20 -
K7AntiVirus 7.10.466 2008.09.20 -
Kaspersky 7.0.0.125 2008.09.20 -
McAfee 5388 2008.09.19 -
Microsoft 1.3903 2008.09.20 -
NOD32v2 3457 2008.09.19 -
Norman 5.80.02 2008.09.19 -
Panda 9.0.0.4 2008.09.20 -
PCTools 4.4.2.0 2008.09.20 -
Prevx1 V2 2008.09.20 -
Rising 20.62.52.00 2008.09.20 -
Sophos 4.33.0 2008.09.20 -
Sunbelt 3.1.1653.1 2008.09.20 -
Symantec 10 2008.09.20 -
TheHacker 6.3.0.9.090 2008.09.20 -
TrendMicro 8.700.0.1004 2008.09.20 -
VBA32 3.12.8.5 2008.09.20 -
ViRobot 2008.9.20.1385 2008.09.20 -
VirusBuster 4.5.11.0 2008.09.20 -
Webwasher-Gateway 6.6.2 2008.07.21 -
Additional information
File size: 101888 bytes
MD5...: 515a7fae2070c2b0242b2353443e2f11
SHA1..: ef8c7dcf9a12b43bcd2c19a2ad366d65db16e2d5
SHA256: 6121c5613784831f584b50e8dc91bbd7ac58bdb602fe4cdb4b237670b6bb4537
SHA512: 0606e844bdfe3134bcc4c08931e34cded1e8478a2ff74fa66f6f1ace7f6ab9ec
65a06d9dd1aa160cdeca4e1c39d76c0d2e4b3dd217d9556b209693d83dd49331
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x76601270
timedatestamp.....: 0x4802a0de (Mon Apr 14 00:10:06 2008)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xe107 0xe200 6.44 25c5ee562f1bf0ed29afe388a8d7903f
PAGE 0x10000 0x2485 0x2600 6.38 85e85f7eb17c096c32c8eacb7845c45d
.data 0x13000 0x1d00 0x1400 0.56 038c3139f1438d1c5677da9b59c3bb69
.rsrc 0x15000 0x60a0 0x6200 3.76 6652e31dee2db01c7002d6e1bf6d9798
.reloc 0x1c000 0xb50 0xc00 6.59 03d193ca648a7f2ff237908f87a433f1

( 5 imports )
> ADVAPI32.dll: RegDeleteValueW, RegQueryValueExA, OpenThreadToken, RevertToSelf, SetThreadToken, OpenProcessToken, DuplicateToken, GetTokenInformation, RegCreateKeyExW, GetLengthSid, RegCloseKey, RegOpenKeyA, RegCreateKeyExA, GetFileSecurityW, GetUserNameA, RegOpenKeyExW, RegQueryValueExW, RegOpenKeyExA
> KERNEL32.dll: GetTempFileNameW, LoadLibraryA, MoveFileA, GetFileAttributesA, FileTimeToDosDateTime, WideCharToMultiByte, FreeLibrary, GetProcAddress, LoadLibraryW, lstrcpyW, CloseHandle, LocalFree, SetEvent, Sleep, InterlockedExchange, InterlockedCompareExchange, GetLastError, LocalAlloc, VerifyVersionInfoW, SetFileAttributesA, CreateEventW, WaitForSingleObject, ReleaseMutex, WaitForMultipleObjects, GetTickCount, SetThreadPriority, GetCurrentThread, CreateThread, GetCurrentThreadId, SetLastError, lstrlenW, SetFileAttributesW, CreateDirectoryW, GetFileAttributesW, CompareStringW, lstrcmpiW, lstrcatW, DeleteFileW, CreateFileW, WriteFile, ReadFile, SetFileTime, MoveFileW, SetEndOfFile, GetFileSize, SetFilePointer, GetVolumeInformationW, FindClose, FindFirstFileW, MultiByteToWideChar, RaiseException, GetDriveTypeW, GetEnvironmentVariableW, OutputDebugStringA, GetDiskFreeSpaceA, lstrcatA, GetWindowsDirectoryA, GlobalFree, OutputDebugStringW, CreateMutexW, GetCurrentProcess, ProcessIdToSessionId, GetCurrentProcessId, DuplicateHandle, QueryPerformanceCounter, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, InterlockedIncrement, CreateFileA, InterlockedDecrement, DeviceIoControl, DeleteFileA, lstrcpyA
> msvcrt.dll: _except_handler3, strncpy, sprintf, wcscpy, wcsncpy, memmove, wcschr, wcslen, free, malloc, _initterm, _adjust_fdiv
> ntdll.dll: DbgPrint, NtCreateEvent, RtlInitUnicodeString, VerSetConditionMask, RtlGetNtProductType, NtQueryInformationFile, RtlNtStatusToDosError, RtlFreeUnicodeString, RtlDosPathNameToNtPathName_U, NtClose, RtlFreeHeap, NtOpenFile, NtQueryDirectoryFile, NtFsControlFile, NtCreateFile
> USER32.dll: GetMenu, wvsprintfA, MessageBoxA, CloseDesktop, wsprintfA, wsprintfW, MsgWaitForMultipleObjects, SetThreadDesktop, UnregisterClassW, CheckMenuItem, DefWindowProcW, PostQuitMessage, DestroyWindow

( 68 exports )
BreakConnections, CSCBeginSynchronizationW, CSCCheckShareOnlineA, CSCCheckShareOnlineExW, CSCCheckShareOnlineW, CSCCopyReplicaA, CSCCopyReplicaW, CSCDeleteA, CSCDeleteW, CSCDoEnableDisable, CSCDoLocalRenameA, CSCDoLocalRenameExW, CSCDoLocalRenameW, CSCEncryptDecryptDatabase, CSCEndSynchronizationW, CSCEnumForStatsA, CSCEnumForStatsExA, CSCEnumForStatsExW, CSCEnumForStatsW, CSCFillSparseFilesA, CSCFillSparseFilesW, CSCFindClose, CSCFindFirstFileA, CSCFindFirstFileForSidA, CSCFindFirstFileForSidW, CSCFindFirstFileW, CSCFindNextFileA, CSCFindNextFileW, CSCFreeSpace, CSCGetSpaceUsageA, CSCGetSpaceUsageW, CSCIsCSCEnabled, CSCIsServerOfflineA, CSCIsServerOfflineW, CSCMergeShareA, CSCMergeShareW, CSCPinFileA, CSCPinFileW, CSCPurgeUnpinnedFiles, CSCQueryDatabaseStatus, CSCQueryFileStatusA, CSCQueryFileStatusExA, CSCQueryFileStatusExW, CSCQueryFileStatusW, CSCQueryShareStatusA, CSCQueryShareStatusW, CSCSetMaxSpace, CSCShareIdToShareName, CSCTransitionServerOnlineA, CSCTransitionServerOnlineW, CSCUnpinFileA, CSCUnpinFileW, CheckCSC, CheckCSCEx, LogoffHappened, LogonHappened, MprServiceProc, ReInt_WndProc, RefreshConnections, Update, WinlogonLockEvent, WinlogonLogoffEvent, WinlogonLogonEvent, WinlogonScreenSaverEvent, WinlogonShutdownEvent, WinlogonStartShellEvent, WinlogonStartupEvent, WinlogonUnlockEvent



ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.

VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy

jan roberts is offline   Reply With Quote
Old 20th September 2008   #6
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi
OK that came back OK. I'm not seeing anything else.

Can you open task manager and see what file is using all the CPU.

Geri

Geri is offline   Reply With Quote
Old 21st September 2008   #7
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


since last night the cpu usage is down way down. put password on router,(with belkins help) and finally got smart and shut down computer. did some things around the house turned her on and so far usage is like i said way down. knock on wood.

i did have a one time(so far) occurence with a redirect (mediacom but we discussed it).

i thank you for taking time to help me.

jan roberts is offline   Reply With Quote
Old 21st September 2008   #8
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi jan
OK that's good.

Your welcome.
If anything should come up lets us know.

Surf Safely
Geri

Geri is offline   Reply With Quote
Old 21st September 2008   #9
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


im back, still have lots of cpu usage,i go to task manager and check applications and nothing is running. am i checking the correct place? what makes the cpu run? i know its a strange question but its at 84% now and all im doing is typing this. i put the task manager in system tray so i could see it i could hear it. im totally confused. what makes it do this? sometimes it sounds like it is going flat out. could it be how i use the computer,icons on desktop,sites in folders,(neatly).but it never did this before. just since we got wireless router so my son in law could go on line. and he and his laptop are in sweden til next month. i really would like to go back to being the only computer on the internet. this is driving me nuts (besides i dont share well with others,especially when my computer is going nine hundred miles an hour)

any ideas

jan roberts is offline   Reply With Quote
Old 22nd September 2008   #10
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi
jan
Click on the "processes" tab and under CPU check to see what file(s) is using the most.

Geri

Geri is offline   Reply With Quote
Old 22nd September 2008   #11
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


its my antivirus! sometimes up over 200k! is it supposed to do that?
normally it around 14k. good grief! good thing ip doesnt charge by cpu. what do i do? keep it? get a different kind? wow!

jan roberts is offline   Reply With Quote
Old 22nd September 2008   #12
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi
Are you using Comodo's AV?

Geri is offline   Reply With Quote
Old 22nd September 2008   #13
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


i was using viruskeeper pro by axbx. it sort of went crazy. i tried to open it to take it off automatic run at start. it wouldnt let me,not the one in system tray so i used the one on desktop.opened it and it started running and it wouldnt shut down i had to push the button! started up went to add remove and that said i had last used it aug 07!

yes i am now using comodo av its slower,and please i hope thats okay. i figured firewall av and maybe they would get along. i dont understand any of this,i ran that thing everyday! weird!!!

jan roberts is offline   Reply With Quote
Old 22nd September 2008   #14
Staff
 
Geri's Avatar
 
Profile:
Join Date: Mar 2003
Location: Washington State
Posts: 4,496
Computer Experience:
Somedays it's like Taz
Geri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation LevelGeri Reputation Level

My System

Hi
Yes that is strange, your HJT log doesn't have it listed.

We should get a on line scan.

If you have ATF Cleaner please run it. if not download and run it.

Download ATF Cleaner by Atribune and save it to your Desktop.
This is a good tool to get rid of the temporary garbage you pick up while surfing the net.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:

Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
Recycle bin


The rest are optional - if you want it to remove everything check "Select All".
Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.


Now a scan.

Please do an online scan with Kaspersky WebScanner

Click on “Accept” If your pop –up blocker blocks any windows from opening.

Click Run on the window that opens.
Windows Vista users you must open the web browser using the Run as Administrator command.
  • The program will launch and then begin downloading the latest definition files:
  • Under Scan on the left side.Click on My Computer
  • This will start the program and scan your system.
  • Click the “Scan Report” On the left side.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Click the Save Report As button, and in the Browse dialog box, type a name for the scan report file that you want to create and select its type Text file. Click OK to save the file.:
  • Save the text file to your desktop.
  • Copy and paste that information in your next post.

Please post the Kaspersky results.

Thanks
Geri

Geri is offline   Reply With Quote
Old 22nd September 2008   #15
Senior Member
 
Profile:
Join Date: Jan 2005
Location: south ga
Posts: 285
Computer Experience:
senior means age y'll
jan roberts Reputation Level


gerri ran the af cleaner. tried three times to run kaspersky webscan router is knocking me off or something its showing orange light for modem and modem says everything is fine.

this wireless has been nothing but trouble,how do i get rid of it? can i unplug it and go modem i would like to get scan done sometime this year

jan roberts is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need some help with a Hijackthis log BillB Malware and Virus Removal 5 15th December 2006 15:30
Web Browser Hijacked - Hijackthis log Pepperoni Malware and Virus Removal 6 29th November 2006 15:15
Please evaluate HiJackThis log (Popuppers/Ceres/etc.) Wakeman Malware and Virus Removal 4 4th March 2005 18:55
My HijackThis log - Please advise ksteele General Security 16 18th June 2004 03:35


All times are GMT +1. The time now is 20:37.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]