I have tried this guide to remove but it did not work
http://www.bleepingcomputer.com/forums/topic111715.htmlThe reason I know it did not work is some sites I go into get this error saying "blocked - activate xp antivirus for secure internet surfing" Because of this I could not complete the last step on the guide which was to run the panda scan.
I'm hoping somebody can tell what exactly what's going on here as I cannot get to the bottom of this and have tried spybot and ad-aware.... Look forward to your reply.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:16:43, on 14/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe
C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_S
4I0T1.EXE
C:\Program Files\MarkAny\ContentSafer
\MAAgent.e
xe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\PocketCam 3Mega\ICON.EXE
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
C:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
C:\WINDOWS\system32\lxddco
ms.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.ex
e
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.google.ie/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-C
C05FCB5032
8} - C:\WINDOWS\system32\winsrc
.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-E
DD6AC9525F
0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C
6B60AAEBA6
D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgcc.e
xe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [LXDDCATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\LXD
Dtime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [EPSON Stylus C46 Series] C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\E_S
4I0T1.EXE /P23 "EPSON Stylus C46 Series" /O6 "USB003" /M "Stylus C46"
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer
\MAAgent.e
xe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\ieupd
ates.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgw.ex
e /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE
~1\avgw.ex
e /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - Global Startup: PocketCam 3Mega Monitor.lnk = ?
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {138E6DC9-722B-4F4B-B09D-9
5D19186969
6} (Bebo Uploader Control) -
http://www.bebo.com/files/BeboUploader.5.1.4.cabO21 - SSODL: gimmicks - {40dcff6e-af8d-4183-8ebe-a
82270ac449
e} - (no file)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgamsv
r.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgupsv
c.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE
~1\avgemc.
exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddco
ms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
--
End of file - 4663 bytes
Start Free Trial