Computer Effected With Trojans: Removing The Virus?

Feb 18, 2005

Please give advice on what to delete to clean up IE. Logfile of HijackThis v1.99.0 Scan saved at 8:16:49 PM, on 2/18/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Computer Effected By Viruses, Spyware & Trojans?

Sep 12, 2007

I am not sure where/when/how but I guess that is not important anyways. but I don't know where to start. What logs, information etc do you all wonderfully helpful people need to proceed. know some passwords were stolen... I have that under control but there are numerous little beasties creating havoc on my PC. How would you all like me to submit logs & which ones do you want?

System Effected By 3 Worm Virus W32 Spybot ,w32spybot KHC And Trojan Dropper?

Mar 31, 2005

i have a packard bell laptop which is about 2.5 years old and has windows XP home pre loaded i have got infected by 3 worm viruses w32 spybot worm ,w32spybot worm KHC and trojan dropper. in an attempt to remove i decided to use the pc restore disk to restore all setting to factory settings however i have now done this twice and still appear to have the viruses is this normal or am i doing something wrong.

153 Infected Files, 23 Virus, 15 Trojans & Counting ?

Aug 17, 2005

My laptop, a Toshiba, running XP Home, became infected and it had Norton's pre-installed [she never updated it].It barely booted and eventually I uninstalled it and have since ran a MULTITUDE of anti virus apps in an attempt to clean the poor thing: Panda, AVG, McAfee, they all did half a job and sometimes even gave up. Avast and Spybot seem to have done the trick... or... have they? The laptop is still snoozing and crashing everytime I open a browser. I don't know what to do.

On Removing The Virus - Xp Theme Is Gone

Jan 16, 2006

cant get the xp theme back on my system after removing a virus and using the restore feature on my xp cd. I did notice that my theme changed to the windows classic style while dealing with the virus. The virus changed my theme to classic and added a webpage as my background picture so I think that was the cause. What should I do to fix this problem of not being able to change my theme to xp.

Ps. The theme is available but when I choose it all it does is it changes my background picture and colors but my buttons and windows stay classic.

Removing PopCap.B Virus

Sep 23, 2005

I have Windows XP Home and I run IE. I have this stupid virus in the archives and I can't get rid of it. I've deleted the file called PopCap, but it still shows in the archives. I've included a HiJackThis log just in case that will help you figure this out.

Unable To Change Desktop Background After Removing Virus?

Jan 24, 2006

I'm being driven insane by this. An office laptop running XP Home was riddled with malware - spyfighter, pcadprotector, CSW.HomeSearch etc. I've managed to remove them all after a full day of hassle but I'm still left with a frustrating issue in that I cannot adjust the desktop background. The properties box is greyed out for backgrounds. We have a simple peer to peer network (workgroup in fact) and no internal security or policies. What can I do before I throw the thing out of the window?

Accidental Deleted Registry Keys While Removing Virus?

Apr 6, 2007

In an attempt to remove malware, I accidently deleted some registry keys and am unable to log back onto my user name. I had exported the entire registry (*.reg) prior to screwing with the registry. Can somebody help me figure out how to restore my registry to the previous condition. Doing an import doesn't work.

Multiple Trojans On My Computer - Reboot Cycle

Feb 17, 2005

there are multiple trojans on my computer.and i know it because ive run mcaffee virus scan and they find them...can i delete them? no....why? because before its done and i can click the delete, i get a stupid error pop up screen saying mcafee has encountered a problem and needs to shut gives me two options "close" and "debug" idno what debug is so i just close the way this happens with a ton of random programs that i have (be it I.E. or AIM).also my coer does this weird thing where the whole screen goes blue with white

System Full Of Trojans Want A Stable Computer?

Jan 21, 2005

I've had a lot of trojans and meltdowns and have reformatted 438545769 times (I have just finished reformatting again. I used to have ZoneAlarm and AVG until I sat and watched as they let a trojan just come on in and munch up all my files. Right now I just want a *stable* computer.

Computer Infected By Malaware And Trojans And Junk?

Jan 21, 2005

I've been in a on-going battle against spyware, trojans, and mean little things that won't leave me alone. Currently using Norton Antivirus

Computer Is Infected With A Large Number Of Trojans

Oct 3, 2006

My computer is seriously infected with a large number of trojans, and other nasties. But i dont know where to start on how to get rid of them. When i run any long term virus detection program, it shuts down after a set amount of time. My cpu usage is almost always 100 percent, causing everything to run insanely slow, and also causing it to crash and restart. Need soome help on this one.

Start Time Slower After Removing VUNDO VIRUS/SPYWARE

Feb 27, 2007

My startup time has increased by at least 8 mins

my HJT log is:

Logfile of HijackThis v1.99.1
Scan saved at 11:33:54 PM, on 27/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:Program FilesCommon FilesSymantec SharedccSvcHst.exe
C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe
C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:Program FilesNorton SystemWorksNorton GoBackGBPoll.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesSpyware Doctorsdhelp.exe
C:WINDOWSsystem32 cpsvcs.exe
C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
C:Program FilesJavajre1.5.0_11injusched.exe
C:Program FilesMSN MessengerMsnMsgr.Exe
C:Program FilesuTorrentutorrent.exe
C:Program FilesNorton SystemWorksNorton GoBackGBTray.exe
C:WINDOWSsystem32 askmgr.exe
C:Program FilesInternet Exploreriexplore.exe
C:Program FilesMSN Messengerusnsvc.exe
C:Documents and Settings
.chanDesktopVundo Remove ToolshijackthisTJH.exe.exe

R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0AcrobatActiveXAcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:PROGRA~1SPYWAR~1 oolsiesdsg.dll
O2 - BHO: (no name) - {61ACC408-B733-482E-BDF1-C020F10014FE} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.5.0_11inssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - (no file)
O2 - BHO: (no name) - {CF293022-3C24-4843-B47F-4F38D7334F4D} - (no file)
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [osCheck] "C:Program FilesNorton AntiVirusosCheck.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.5.0_11injusched.exe"
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Taskbar Hide] "C:PROGRA~1TASKBA~1TaskBar.exe" -Start
O4 - HKCU..Run: [�Torrent] "C:Program FilesuTorrentutorrent.exe"
O4 - HKCU..Run: [Spyware Doctor] "C:Program FilesSpyware Doctorswdoctor.exe" /Q
O4 - Global Startup: Norton GoBack.lnk = C:Program FilesNorton SystemWorksNorton GoBackGBTray.exe
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.5.0_11inssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:PROGRA~1SPYWAR~1 oolsiesdpb.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:PokerTitan Pokercasino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:PokerTitan Pokercasino.exe
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:Program FilesNorton SystemWorksNorton CleanupWCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:Program FilesNorton SystemWorksNorton CleanupWCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:Program FilesPartyPokerRunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:Program FilesPartyPokerRunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: mljjgda - mljjgda.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:Program FilesCommon FilesSymantec SharedccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:Program FilesNorton SystemWorksNorton GoBackGBPoll.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:Program FilesNorton AntiVirusisPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:Program FilesNeroNero 7Nero BackItUpNBService.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:PROGRA~1NORTON~1NORTON~1NPROTECT.EXE
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:Program FilesSpyware Doctorsdhelp.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:PROGRA~1NORTON~1NORTON~1SPEEDD~1NOPDB.EXE
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe

Removing Virus Infected Files: Slow System And Freezes?

Jan 4, 2005

I did remove virus efeected files and my PC is behaving badly, it responds very slow to commands and freezes. Here is the log. Can anybody help me to resore my computer

Website That Scans Computer For Viruses/worms/trojans ?

Apr 1, 2005

I mainly want to know if their is a site that can scan my computer to see if there are any trojans or worms. Any kind of stuff that a hacker could put onmy computer or anything that may have passed through my firewall.

Avg / Adware Fail In Removing Virus - Error Reboot In Safe Mode

Aug 11, 2009

I'll try to remember, to the best of my ability, the sequence of events...Suffice it to say that I downloaded and tried to install something I shouldn't have. I Immediately tried to get out of the errors from AVG (free version) and stop the install. All seems good, then IE keeps opening to bogus ad sites. I realize I've got something. AVG and AdAware both fail in removing this Win32Trojan.tdss (I think AVG gave me this description). AVG tells me to reboot to remove it properly. Reboot throws me into "can't verify this installation of Windows". Boot in safe mode work, then I get the same error on reboot...even in safe mode.

I don't have the original Windows CD (separated from husband and software at the same time; cannot find any software now), but it's a Dell and it came with Windows XP Home (product key on box), but I installed XP Pro instead. Don't know what product key was used or how to get it.....

Error Code 0F00:0244
Error Code 0F00:1A44
Msg: Block 6442285....

Ntosktnl.exe Effected By Viruses And Changed?

Mar 19, 2007

Woke up this morning to find that my AVG ati virus has detected 3 files that say they a infected and changed I have posted and image of problem below.How can I repair this problem? I haven't had any boot up problems or crashes at all, this problem appear after a Microsoft windows update.

Trojan Virus - Is Computer Cleaned After Virus Infection?

Aug 14, 2008

I had a trojan Virus in the computer. I think that I got rid of it, but I am not sure could anyone that can read a log please tell me if there is anything else left in the computer. The computer now doesn't stay on-line it disconnects itself. I called the company that provides me with my internet service, and they said that I need a filter for the phone line. The person told me that, that will take care of the problem of the internet disconnecting. I think that it could be the virus I had in the computer. I wasn't able to get on-line for at least a week, I had gone and checked the disk for errors and finally the anti-virus program was able to find the virus's.

Korgo-v Worm In Computer: Removing From The System?

Jan 22, 2005

I have the Korgo-v worm in my computer,and was wanting to know how to get it out?

Computer Restarts - Removing USB Cable From Phone

Jun 16, 2005

I have recently bought myself a Sony Ericsson K750i and after removing the USB cable from the phone or from the computer my computer just restarts for no apparent reason. I have tested my phone on other computers and they work perfectly fine. I was just wondering if anyone heard of this before and know what it could be. BTW: I have tried it in diagnostics mode and it still restarts. I have also tried it in SAFE MODE where it doesnt restart (but it doesnt find the device either :P)

Computer Running Very Slow: No Change After Removing Unwanted Things?

Sep 14, 2006

My computer (H.P. Pavilion ze 4900 laptop) is running ver-r-r-ry slow.I have: Defragged, Cleaned up my cookies, Uninstalled unneeded programs, Restored the system to a date prior to the occurrence of the slow running speed,Restarted the computer.I have not: Done a disc clean-up (because I have been given conflicting counsel [re: the safety of doing a disc clean-up] by folks who know more about computers than I do.)

Shut down programs running in the back ground(Although I have lots of programs running in the back ground,I have not shut any of those things down because 1)I dont know how to discriminate between what should and what should not be shut down and 2)I dont how to shut those programs down.)Done a virus sweep or a spy-ware sweep (because those operations take a long time even when the computer is running at normal speed

Get Off Trojans And Other Spyware?

Oct 23, 2006

The Trojan.Downloader.zlob.abt Trojan.Fake.alert.eb... Are both on my sys. but according to Bit Defender, "they're causing no harm to my sys." I presume that means they are quaranteed. I've run SpySweeper and a couple others and have been unable to turn either one up. Nor can I locate them in Google. My questions are, how can I get them off my sys.

Pop Up - Gets Trojans Not Online

Jan 23, 2006

I reformated a mans pc the other day here at home but i took it to his house to get port #'s to get online for updates.We got 3 updates restarted and went back to updates and got pop ups galore.reformatted again OFF-LINE and still got pop ups. I have the pc at home again. What am i dealing with here?I am now in the process of installing ONLY the XP CD and not the other 3.

Virus In My Computer And Computer Running Slow - Trojan

Jan 19, 2007

My computer has been running slow and I just did a quick virus scan and I seem to have a 8 trojan horses or something

Getting 2 Trojans: Checked The Log File?

Jan 5, 2005

i already did trend micro free scan and here my hijack this file Logfile of HijackThis v1.99.0Scan saved at 5:28:05 AM, on 1/5/2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Lots Of Spyware And Trojans Lately

Jul 31, 2007

I just finished cleaning my sisters' computer from various trojans, etc...atleast all of those I could find. I have scanned with Adaware, Spybot, AVG, and Bazooka, and installed Sygate firewall. I was wondering if there is anything that I should delete from my hijack log.

Trojans Pop-ups Ad Ware, Spyware

May 9, 2007

My PC is lousy with viruses etc. I scanned with HijackThis, but I don't understand the results. It does not automatically fix problem files, I must choose what to remove. I'm positive that I'm going to remove something vital.

Attacked Today 20+ Trojans

Jan 12, 2008

today i was attacked with more than 20 trojans i had windows virus crap up and that didnt do much. i had avg running thank god it was scanning and found 13 trojans already in my comp and intercepted another 8 i dont know what i did to bring that all down on me. a website was opening it self, poping up whenever it was called "internet speed moniter" or something like that i think thats the source tho im not sure. my comp shut down by it self then i came back to find it had installed its program on my comp without my permission and several other new folders were in my programs files folder. well i figured just whipe the hard drive and start over clean..i put my xp disk in and attempted to do so. but i was over my head.i dont know how and need some assistance.

Trojans - Cannot Access My Documents

Oct 4, 2008

my computer seems to be hacked by someone, I don't know who. This morning, I turned on the computer and saw that two fake virus protections "VirusResponse Lab 2009" and "Windows Antivirus 2008" have been invading my desktop. I keep exiting them all out, but they just keep coming back. There were approximately 50 Trojans, indeed, now I have used both XoftSpySE to delete WAV 2008 and used Malwarebytes' Anti-Malware to delete VirusResponse Lab 2008 (I THINK). Next thing: After they have not been popping up anymore (hopefully), on the bottom right corner where the time shows, it says "VIRUS ALERT!" I go to Start and notice I cannot access My Documents, Control Panel, Recent Documents, and "All Programs." They are gone, except some programs listed in the front and Shut Down only. I also see that when I open "My Computer", there is no "C" Drive showing. I can't access that drive even though I'm using it. Now, there is a window from "Windows Security Alert" popping up telling me to "Enable Protection", the option with "Keep Blocking" and "Unblock". I don't know if I should choose "Enable Protection" because IE keeps opening and it's making my computer slow.

System Is Infected With Trojans & Spywares?

Aug 10, 2005

my system says its infected with trojans and spyware what to do?

Pc Acting Wierd- I Found Around 260 Trojans

Oct 19, 2009

I found around 260 Trojans, and after disinfecting, Whenever I connect to the net, it only lasts for two minutes. Then I have to reboot to connect again. and continued again. So I decided to reformat my PC, and did so. Now I'm stuck with 2 OSes, one in my C drive, and one in My D drive.

