PLease somebody HELP!!. I'm trying to clean a PC up of viruses and spyware
1- I'm getting the following error message on a windows label "16 bit Windows Subsystem" when trying to install the antivirus AVG 6.0:
"C: Windows\system32\AUTOEXEC.
NT. The System file is not suitable for running MS-DOS and MIcrosoft Windows applications. Choose close to terminate the application"
What's happening here?
2- I have SpyBot installed I have ran it several times and it seems that the spyware-adware keeps recereating itself. Following is a "Hijack this" log, please review and let me know what I need to fix(a lot for sure!):
Logfile of HijackThis v1.98.2
Scan saved at 9:30:06 AM, on 8/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\cvss.e
xe
C:\windows\system\hpsysdrv
.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\Unload\hpqcmon.exe
C:\Program Files\WindUpdates\WinUpdt.
exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpobnz08.exe
C:\Program Files\WindUpdates\WinKA.ex
e
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hposol08.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digi
tal Imaging\Bin\hpoSTS08.exe
C:\hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://us7.hpwis.com/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://srch-us7.hpwis.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://us7.hpwis.com/R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://default-homepage-network.com/start.cgi?hklmR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) = websearch.drsnsrch.com/q.c
gi?q=
R1 - HKCU\Software\Microsoft\In
ternet Connection Wizard,ShellNext =
http://us7.hpwis.com/R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-
C2D500688D
A2} - (no file)
R3 - URLSearchHook: URLSearch Class - {965A592F-8EFA-4250-8630-7
960230792F
1} - C:\WINDOWS\System32\cdsm32
.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-
00C04FD644
97 - (no file)
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-
C2D500688D
A2 - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
32\userini
t.exe,C:\W
indows\Sys
tem32\wsau
pdater.exe
,
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-2
16055BF991
8} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {0982868C-47F0-4EFB-A664-C
7B0B101580
8} - C:\WINDOWS\System32\mskhhe
.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - (no file)
O2 - BHO: SDWin32 Class - {579F76BF-02FF-462C-8D08-A
48DEBE8790
4} - C:\WINDOWS\System32\gpxti.
dll
O2 - BHO: (no name) - {6AD84276-B417-59BA-8256-6
75578A3786
F} - C:\WINDOWS\System32\kdtc.d
ll
O2 - BHO: CUrlCliObj Object - {94927A13-4AAA-476A-989D-3
9245642768
8} - C:\WINDOWS\System32\msjfbl
.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - C:\HP\EXPLOREBAR\HPTOOLKT.
DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\system32\msdxm.
ocx
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digi
tal Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [WindUpdates] C:\Program Files\WindUpdates\WinUpdt.
exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digi
tal Imaging\bin\hpobnz08.exe
O4 - Global Startup: officejet 6100.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmse
arch.html
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZPxdm182O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmba
cklinks.ht
ml
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmca
che.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmsi
milar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar
1.dll/cmtr
ans.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\T
p1150\scri
1150a.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates
\System\Te
mp\ebatesw
ebsavings_
script0.ht
m
O9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-0
05004D0F1F
A} - C:\Program Files\MarketBrowser\lmt\Ma
rketBrowse
r_Launch.x
py
O9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-0
05004D0F1F
A} - C:\Program Files\MarketBrowser\lmt\Ma
rketBrowse
r_Launch.x
py
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {62475759-9E84-458E-A1AB-5
D2C442ADFD
E} -
http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/abarth/us/win/QuickTimeInstaller.exeO18 - Filter: text/html - {CC905FF6-B553-496C-9DFA-C
FF65ADCD0F
C} - C:\WINDOWS\System32\mshpeb
.dll
Thanks a lot in advance
Johnny