When I turn on my computer, the background screen goes black with an ominous error message that I have "Dangerous Spyware" and with a link to a scan (which I have declined to accept). Â I have updated and run Spybot, but to no avail. Â It was recommended on here in answer to another question to download AVG, but again, the problem remains. Â I ran "Hiijack This" and the log i set forth below. Â Any suggestions? Â Many thanks!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:27:45 AM, on 3/2/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
C:\Program Files\Seagate\SeagateManag
er\Sync\Fr
eeAgentSer
vice.exe
C:\PROGRA~1\Iomega\System3
2\AppServi
ces.exe
C:\Program Files\Java\jre6\bin\jqs.ex
e
C:\Program Files\McAfee\SiteAdvisor\M
cSACore.ex
e
C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
C:\PROGRA~1\AVG\AVG8\avgam
.exe
c:\program files\common files\mcafee\mna\mcnasvc.e
xe
C:\PROGRA~1\AVG\AVG8\avgrs
x.exe
C:\PROGRA~1\AVG\AVG8\avgns
x.exe
c:\PROGRA~1\COMMON~1\mcafe
e\mcproxy\
mcproxy.ex
e
C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
C:\Program Files\McAfee\MPF\MPFSrv.ex
e
c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\WINDOWS\System32\nvsvc3
2.exe
C:\WINDOWS\system32\PSISer
vice.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Iomega\AutoDisk\ADSe
rvice.exe
C:\PROGRA~1\AVG\AVG8\avgem
c.exe
C:\Program Files\AVG\AVG8\avgcsrvx.ex
e
C:\WINDOWS\system32\wuaucl
t.exe
C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\Common Files\AOL\1172577490\ee\AO
LSoftware.
exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Seagate\SeagateManag
er\FreeAge
nt Status\StxMenuMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\frmwrk
32.exe
C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Spybot - Search &Â Destroy\TeaTimer.exe
c:\PROGRA~1\mcafee\VIRUSS~
1\mcvsshld
.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4
C09146192C
A} - C:\Program Files\Real\RealPlayer\rpbr
owserrecor
dplugin.dl
l
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4
E65E497C8C
0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-F
D60BB9AAE2
E} - C:\PROGRA~1\BLSTOO~1\BLSTO
O~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-0
0123456789
0} - C:\WINDOWS\system32\dla\tf
swshx.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre6\bin\ssv.dl
l
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
EA1C75885F
9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6
309F01C523
1} - C:\Program Files\McAfee\VirusScan\scr
iptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
F10577473F
7} - c:\program files\google\googletoolbar
5.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - C:\Program Files\Google\GoogleToolbar
Notifier\3
.1.807.174
6\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2
CD0E90A88F
F} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9
C25C1C588A
9} - C:\Program Files\Java\jre6\bin\jp2ssv
.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-E
ABFE594F69
C} - C:\Program Files\Java\jre6\lib\deploy
\jqs\ie\jq
s_plugin.d
ll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
5.dll
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-F
D60BB9AAE2
E} - C:\PROGRA~1\BLSTOO~1\BLSTO
O~1.DLL
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
A305ED9D92
2} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-5
16ABECAE06
4} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" Â -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1172577490\ee\AO
LSoftware.
exe
O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManag
er\FreeAge
nt Status\StxMenuMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search &Â Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBoos
ter\Regist
ryBooster.
exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &Â Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-2847186275-1
884707007-
79704905-5
00\..\Run:
[Sonic RecordNow!] Â (User 'Administrator')
O4 - HKUS\S-1-5-21-2847186275-1
884707007-
79704905-5
00\..\Run:
[DellSupport] "C:\Program Files\DellSupport\DSAgnt.e
xe" /startup (User 'Administrator')
O4 - HKUS\S-1-5-21-2847186275-1
884707007-
79704905-5
00\..\Run:
[ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User 'Administrator')
O4 - HKUS\S-1-5-21-2847186275-1
884707007-
79704905-5
00\..\Run:
[AOL Fast Start] "C:\Program Files\AOL 9.1\AOL.EXE" -b (User 'Administrator')
O4 - Startup: ChkDisk.lnk = ?
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\
search.htm
l
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
4C75499B57
8} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search &Â Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\docume~1\steven\locals~
1\temp\ntd
ll64.dll
O10 - Unknown file in Winsock LSP: c:\docume~1\steven\locals~
1\temp\ntd
ll64.dll
O12 - Plugin for .001: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n2.dll
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugi
n.dll
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-8
30A59E2353
3} (Microsoft Data Collection Control) -
https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {33415AC7-AFFA-4D55-B41C-C
64C0D07DFC
A} (Hewlett-Packard Printer Diagnostics) -
http://h50203.www5.hp.com/HPISWeb/Customer/cabs/HPISWebManager.CAB
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-F
BDDE494F8D
1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-0
67394E91CC
5} - c:\PROGRA~1\mcafee\SITEAD~
1\mcieplg.
dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrss
tx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgem
c.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.
exe
O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManag
er\Sync\Fr
eeAgentSer
vice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\1050\Inte
l 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System3
2\AppServi
ces.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.ex
e
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\M
cSACore.ex
e
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.e
xe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcods.ex
e
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafe
e\mcproxy\
mcproxy.ex
e
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.ex
e
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSv
c.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc3
2.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSISer
vice.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVI
CE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADSe
rvice.exe
--
End of file - 11146 bytes
after running the Malware bytes, if the problem still presists go to
http://www.hijackthis.de
and paste your log and remove the infected entries manually.
Best Regards,
Mohamed Allam
Senior Solution Developer