best virus scanner???

Joined
Apr 20, 2005
Messages
150
Reaction score
0
ok ive finished the scan and removed a worm and a few more trojans :(... n ive just done a scan with hijackthis, heres the log file info


Code:
Logfile of HijackThis v1.99.1
Scan saved at 15:06:17, on 07/05/2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Hotkey\Hotkey.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe
C:\Program Files\Common Files\AOL\1142824574\ee\aolsoftware.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Documents and Settings\Lee\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Trixie.Bho - {B0744341-96E0-4341-9ED2-8BC36CE0CCD0} - mscoree.dll (file missing)
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Hotkey] C:\Program Files\Hotkey\Hotkey.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [e3920af9.exe] C:\Documents and Settings\Lee\Local Settings\Application Data\e3920af9.exe
O4 - HKCU\..\Run: [686b3e5a.exe] C:\Documents and Settings\Lee\Local Settings\Application Data\686b3e5a.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
O4 - Global Startup: SpeedUpMyPC.lnk = C:\Program Files\LIUtilities\SpeedUpMyPC\speedupmypc.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZZ
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\System32\mscoree.DLL
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\System32\mscoree.DLL
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://d:\foo.mht!http://spc.biz/exp/chm//x.chm::/open.exe
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/177f0ce93b069f27a406/netzip/RdxIE601.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142589578459
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v55/cubis/cubis.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: dvb03a - C:\WINDOWS\SYSTEM32\dvb03a.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc)
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,735
Reaction score
1,204
'Fix' the following ...

O4 - HKCU\..\Run: [e3920af9.exe] C:\Documents and Settings\Lee\Local Settings\Application Data\e3920af9.exe
O4 - HKCU\..\Run: [686b3e5a.exe] C:\Documents and Settings\Lee\Local Settings\Application Data\686b3e5a.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZZ
O16 - DPF: {11111111-1111-1111-1111-222222222222} - ms-its:mhtml:file://d:\foo.mht!http://spc.biz/exp/chm//x.chm::/open.exe


'Other' posible nasties ...

O9 - Extra button: (no name) - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\System32\mscoree.DLL
O9 - Extra 'Tools' menuitem: Tri&xie Options... - {20CCCFEC-D26F-4ffe-996B-388B39C8CCCA} - C:\WINDOWS\System32\mscoree.DLL
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123


These should be 'fixed' or un-installed ... up to you

O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Program Files\CDPoker\casino.exe
O16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) - http://www.worldwinner.com/games/v48/pool/pool.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v55/cubis/cubis.cab


Not sure ???

O20 - Winlogon Notify: dvb03a - C:\WINDOWS\SYSTEM32\dvb03a.dl



You like playing with fire, don't you ... ;)
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
theres more than one person uses this computer so most stuff installed on here i have no idea what it is, but thanks, ill go through and fix what u said needs fixing n that, thanks.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
ok well ive fixed everything u mentioned there, but im still having problems browsing the net, still only gettin blank pages on most sites i go on, n the comp is runnin extra slow, currently running system mechanic 6 pro to see if that helps.
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,735
Reaction score
1,204
leey2ki said:
ok well ive fixed everything u mentioned there, but im still having problems browsing the net, still only gettin blank pages on most sites i go on, n the comp is runnin extra slow, currently running system mechanic 6 pro to see if that helps.
I wouldn't give you tuppence for System Mechanic ... but then I've never used it.

I'll hand you back to Ady ... he has more patients than I. ;)
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
As you mentioned in your first post - you may have to re-install Windows.

When you have that many infections and then trying to remove them basically leaves your system in a mess.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
im just trying system mechanic out, ive lost norton so im using this to see if it works as good as ive heard it does

and ady has more patients than you??? you two doctors or something??? lol jokes.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
ugh i hope i can resolve problems without re-installing windows, cos im due to do another back-up soon, just need some new discs seeing as ive got over 50gb of stuff on the hard drive, sum of which is backed-up allready, sum which has been updated since the last back-up and then some new stuff(i back-up once a month)
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,735
Reaction score
1,204
leey2ki said:
im just trying system mechanic out, ive lost norton so im using this to see if it works as good as ive heard it does

and ady has more patients than you??? you two doctors or something??? lol jokes.
Yup, but I am the surgeon, I just cut out all the crap ... Ady used a more methodical approach.


;)
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Although I do have patience - I'm at the end of the road with this one.

I know a Windows re-install is a pain - but it is often the only way to to resolve matters.

To save your work, you could always get a new HD and install Windows on that - then slave the old one and access the files you need and copy them, making sure you scan them all.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
hhmmm just looking at that spyware quake thread, one of the files that came up whilst being scanned was a .dll that was mentioned in that thread
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
I take it you have followed everything refered to in that Spywarequake thread and removed everything?
 
Joined
Apr 19, 2005
Messages
6,175
Reaction score
2
As you mentioned reinstall windows; I would re-install otherwise you PC will crash???

So save what you can and re-install;) do a full format first.:nod: :user:
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
i know theres a way of re-installing windows so that it only replaces the windows files still saving your saved data/files on the hard drive, ive scanned the computer with all the different progs i have and no infections are coming up and ive scanned individual folders that have been cropping up alot in the scans and all seems to be clean.

i do alot of graphics work for making money and i cant accesse the sites i use for stock photo's and for new brushes n fonts etc which i need to accesse to do a couple of jobs i have waiting to be completed, and they are due soon :(

if you could let me know how i can do that windows replacement thingy majiggy id really appreciate it, would save so much time cos it could be a few days before i can afford the dvd's to do the new backup, and te jobs are due before i can do the backup :(
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
Adywebb said:
I take it you have followed everything refered to in that Spywarequake thread and removed everything?

ive followed it as best i could, some stuff wouldnt work to allow me to do it properly though, but i never actually saw anything that mentioned spyware quake.
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
leey2ki said:
hhmmm just looking at that spyware quake thread, one of the files that came up whilst being scanned was a .dll that was mentioned in that thread
I take it you then removed the offending dll?

Are you still getting any symptoms of the virus/spyware - or are you now just suffering from slow down and the blank IE pages?

If thats the case, you may be OK to save your files to DVD (do not include system files etc), then do a full Windows format/install.
Then once you are back up and running with all the various AV's and Anti-Spyware programs loaded, scan the DVD's and load the files back on.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
yeh it seems im now just suffering from slow comp and blank ie pages, but i have nothing to save backup on to :(
 
Joined
Apr 19, 2005
Messages
6,175
Reaction score
2
leey2ki said:
yeh it seems im now just suffering from slow comp and blank ie pages, but i have nothing to save backup on to :(

As I have said your PC will crash by what you say it won`t be long:nod:
I have learnt the hard way Trust me;) Re-install.
 
Joined
Apr 20, 2005
Messages
150
Reaction score
0
oh my ******* lord, i have said i want to re-install, but i can not ******* afford to just wipe everything clean otherwise i am going to loose money, jesus christ mate, read next time before you try "repeating advice"
 

Adywebb

Growing old....
Moderator
Joined
Jan 1, 2005
Messages
5,459
Reaction score
21
Don't blow a fuse mate - I know your frustrated, but itsme is right - sometimes you just HAVE to re-install :(

You can try a Windows Repair Install if you wish - but it often does not work, and you can still loose your files.

Use the tutorial HERE and give it a go if you wish.

Good luck mate :) - we are trying to help, and I am spending alot of my personal time on these sort of things when I could be out enjoying myself :nod:
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top