flip3084 said: Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\userinit.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll O3 - Toolbar: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-21-1202660629-436374069-839522115-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?') O4 - HKUS\S-1-5-18\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User '?') O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User '?') O4 - HKUS\.DEFAULT\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User 'Default user') O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - O18 - Filter hijack: text/html - {81505e9a-8359-4309-821b-4b440084af2c} - C:\WINDOWS\system32\mst120.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
first, i would go to start --> run then type in msconfig and press enter. Go to the startup tab and disable these from startup:
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe
They are all unnecessary, and will start up on demand anyways, so no need to be running with boot.
I would also remove this
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url=http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/]http://us.rd.yahoo.com
that is yahoo search bar, i hate toolbars, but if you like it, no harm in it, best to just uninstall from add/remove programs.
R3 - URLSearchHook: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll
is another toolbar, don't know if you use it or not, if not, its safe to remove, its still being reviewed if it has malicious code or not, but again, i hate toolbars, so this is personal choice.
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
this is quicktime updater, you can remove it here, just delete it through hijackThis, its useless, and runs whenever you use quicktime anyways...more apple crap.
O4 - HKUS\S-1-5-18\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User '?') O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User '?') O4 - HKUS\.DEFAULT\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User 'Default user')
These are some pretty nasty virus/malware downloaders...not the easiest to get rid of, but possible...What you need to do is download malwarebytes, schedule a boot up scan, reboot, let it scan, then delete everything it asks you to. Also install avast antivirus, and do a full scan with it as well, these two should clean up all remnants of this...i recently had to clean it off of a friends computer...it can be a bitch, and block certain spyware scanners from updating...good luck
O18 - Filter hijack: text/html - {81505e9a-8359-4309-821b-4b440084af2c} - C:\WINDOWS\system32\mst120.dll
this is also a piece of spyware, and should be deleted, if you can remove it through hijack this, then do so, but if you scan with malwarebytes, it will probably take care of it. it is disguising itself as a legit dll, but its part of netmeeting, which its location shoudl be C:\Program Files\netmeeting, not in your system32 folder. Again, do malwarebytes first, and avast, then run hijack this again, if its still there, then delete through hijack this.
That should be good. Oh, if your going to install avast, be sure to remove McAfee, its not as horrible as norton, but still not that great. Avast is free and better.
peace
|