Hi legalsrl,
I will give thata tryand get back to you shortly.
Thanks for the prompt attention to this matter.
Chuck
Main Topics
Browse All TopicsI have a computer that has been infected with "HTML FRAMER" virus. I need help to clean the system.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
OK,
Can you go to http://www.hijackthis.de and download HiJackThis
Run it, then save a log file, post the log file results through the analyser and post a link to the results here
I'll have a look at them
Cheers
Si
OK,
http://www.hijackthis.de/#
Chuck
Your hijackthis log is showing entries belonging to a variant of wareout infection.
Try Fixwareout and show us the logfiles.
Please download FixWareout from one of these sites:
http://downloads.subratam.
http://download.bleepingco
Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.
At the end of the fix, you may need to restart your computer again.
Finally, please post a fresh HijackThis log, along with the contents of the logfile C:\fixwareout\report.txt
It seems you have Windows Defender, SUPERAntispyware, Spybot S&D, PrevX, AVG and Symantec all running with realtime protection there.
It is not a good idea to have more than one antivirus/antispyware with realtime protection. They will just conflict with each other and causes problems, you only need one antivirus and one antispyware with real time protection.
You also have a rogue program installed there. You might like to download and run RogueRemover, it will remove ESpywareRemoval.
http://www.malwarebytes.or
Please fix these entries in Hijackthis:
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-B
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-E
O16 - DPF: {C3D96A02-EEA7-4264-98D7-D
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CCS\Services\T
Did you run Fixwareout yet?
You need to delete this service --> SpywareRemovalSysGuardServ
Go to Start Menu > Run > type
cmd
Press OK then type or copy and paste these commands onto the cmd screen pressing Enter after each line:
sc stop SpywareRemovalSysGuardServ
sc delete SpywareRemovalSysGuardServ
Let us know how the pc is going, if problem persists we can run other tools.
Okay, alternative route;
Fix this below entry in Hijackthis, that will disable/stopped that service, Hijackthis can only delete a service once it's stopped.
O23 - Service: System Guard(SpywareRemoval) (SpywareRemovalSysGuardSer
then open the Misc Tools section in hijackthis, click on "Delete an NT Service" tab
and enter the service --> SpywareRemovalSysGuardServ
<<<I do nothave the line that you refferenced.>>>
The 023 line is no longer present in the Hijackthis log which means; the service "SpywareRemovalSysGuardSer
Hijackthis will only show enabled services(the 023 entries) so if a service is not showing it means it has been disabled or that the service no longer exists.
Is that log after you let hijackthis fix that entry? when hijackthis fix an 023 entry it disables that service and therefore will no longer show up in the log.
rpggamergirl:
OK,
Let me review my situation at this point since it seems that we are getting sidetracked. My AVG showes that I still have the Frammer virus.I am still getting random web pages poping up at odd intervals, and the performance on this box seems to be sluggish.
I attached the lattest hijack this Log just 2 posts ago. I does not seem to show any problems that woould account for this.
How do you suggest that we proceed?
Chuck
Chuck,
I need to know if you've run Fixwareout.
You did not answer my question when I asked if you've run Fixwareout.exe The fixwareout log that you posted was not a fixwareout log but a RogueRemover log.
Please run Fixwareout and we'll start from there, as the sign of fixwareout was showing in your original log.
rpggamergirl:,
Thanks for staying with me on this. I have included the text of the report here, which has just been run.
Username "Chuck" - 04/17/2008 7:29:35
[Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.
~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWA
Windows\CurrentVersion\Run
"KernelFaultCheck"=hex(2):
72,6f,6f,74,25,5c,73,79,73
65,6d,33,32,5c,64,75,6d,70
b,00
"AVG7_CC"="C:\\PROGRA~1\\G
cc.exe /STARTUP"
"Windows Defender"="\"C:\\Program
Files\\Windows Defender\\MSASCui.exe\" -hide"
[HKEY_LOCAL_MACHINE\SOFTWA
Windows\CurrentVersion\Run
"QuickTime Task"="\"C:\\Program
Files\\QuickTime\\qttask.e
"Verizon_McciTrayApp"="C:\
Files\\Verizon\\McciTrayAp
[HKEY_CURRENT_USER\SOFTWAR
indows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\
exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot
- Search & Destroy\\TeaTimer.exe"
"AdwareAlert"="C:\\Program
Files\\AdwareAlert\\Adware
"WMPNSCFG"="C:\\Program Files\\Windows
Media Player\\WMPNSCFG.exe"
"SUPERAntiSpyware"="C:\\Pr
Files\\SUPERAntiSpyware\\S
e"
[HKEY_CURRENT_USER\SOFTWAR
indows\CurrentVersion\Run\
"FreeRAM XP"="\"C:\\Program Files\\YourWare
Solutions\\FreeRAM XP Pro\\FreeRAM XP
Pro.exe\" -win"
....
Hosts file was reset, If you use a custom hosts
file please replace it...
~~~~~ End report ~~~~~
This is most likely a problem with some bad code on a specific website. I doubt that you have anything to worry about in regards to html/framer. You can report it to AVG to let them know you are getting it and maybe they'll fix thier freeware. Bite the bullet and buy Symantec's Internet security product or see if your ISP offers free threat protection and dump AVG.
Good luck and have a good day.
Maybe you can try Kaspersky's online scan, though it doesn't remove any viruses that it finds, you can then remove it manually if any.
Sorry, but I won't be able to access internet for a week so I won't be able to post for at least a week. You'll be in good hands with other experts helping you.
I'll check back after 8 days and hopefully you found the solution by then.
Good luck!
Hi Chuck,
Please check out these links and see if it helps to uninstall AVG and Symantec.
1. How to Uninstall Norton, AVG, McAfee and Kaspersky Antivirus Software
http://apps.carleton.ca/co
2. How to Remove AVG Free Antivirus.
http://www.pchell.com/viru
1) Click on the following link and download AVG to your desktop
http://free.grisoft.com/do
2) Double-click on the downloaded file to run it
3) AVG will present you with three options to choose from. Choose the Uninstall option to completely uninstall AVG
See also (the same), How to Install/Uninstall AVG Components:
If you want to install or uninstall AVG components (e-mail plug-in for example), you have to run AVG installation using SETUP.EXE from AVG7 directory (directory with installed AVG) or using a downloaded installation file (http://www.grisoft.com -> Download section).
http://free.grisoft.com/ww
Running the installation process recognises the existence of installed AVG7 and the Add/Remove Components option is offered.
Hi rpggamergirl:,
I have uninstalled both Norton and AVG. I installed Avast. Seems to have solved the problem.
The only problem that i have remaing is Outlook is still looking for and AVG dll,. But that is another problem altogether.
This has been a battle and I thank yiou for all your help. Your instructions were to the poiny and easy to follw, great job and thanks again.
Chuck.
Business Accounts
Answer for Membership
by: legalsrlPosted on 2008-04-06 at 06:09:37ID: 21291648
Hiya,
e.com
Firstly go to http://www.superantispywar
Download the free version, install it, update it and boot the pc in to Safe Mode
Once in Safe Mode, run the Scan and remove all the nasties
That will clear the problem up
Cheers
Si