# Infected with atlsystemXXXXXX.exe

Q: Infected with atlsystemXXXXXX.exe

Windows XP Professional system is infected with a virus or malware that makes files that start with atlsystem and end with .exe. In between atlsystem and .exe there are random numbers. MalwareBytes detects and says it removes them, but there is some underlying component that isn't removed. The files come back after reboot.

DDS Log Contents:

DDS (Ver_09-02-01.01) - NTFSx86
Run by nreitter at 18:39:59.64 on 2009-02-23
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1439 [GMT -5:00]

AV: eTrust ITM *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = <local>
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Realtime Monitor] "c:\program files\ca\etrustitm\realmon.exe" -s
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{14fcfe7c-ab86-428a-9d2e-bfb6f5a7aa6e}\Icon3E5562ED7.ico
uPolicies-explorer: DisablePersonalDirChange = 1 (0x1)
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1235403139892
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1235403130658
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
LSA: Notification Packages = scecli s t e m 3 2 \ i n o b u . d l

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\nreitter\applic~1\mozilla\firefox\profiles\xw51chwf.default\

============= SERVICES / DRIVERS ===============

R2 eq2soft;Service Eset;c:\windows\system32\svchost.exe -k netsvcs [2004-8-11 14336]
R2 netmantow;Network Connections.;c:\windows\system32\svchost.exe -k netsvcs [2004-8-11 14336]
S2 softyinforwow1;.Freame Micer;c:\windows\system32\svchost.exe -k netsvcs [2004-8-11 14336]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]

============== File Associations ===============

=============== Created Last 30 ================

2009-02-23 17:18 59,904 a------- c:\windows\system32\atlsystem429956.exe
2009-02-23 17:18 59,904 a------- c:\windows\system32\atlsystem663724.exe
2009-02-23 17:18 59,904 a------- c:\windows\system32\atlsystem882754.exe
2009-02-23 17:18 59,904 a------- c:\windows\system32\atlsystem568713.exe
2009-02-23 17:18 131,072 a------- c:\windows\system32\atlsystem66447.exe
2009-02-23 17:18 122,880 a------- c:\windows\system32\atlsystem34844.exe
2009-02-23 17:18 97,792 a------- c:\windows\system32\atlsystem918628.exe
2009-02-23 15:40 59,904 a------- c:\windows\system32\atlsystem461558.exe
2009-02-23 15:40 59,904 a------- c:\windows\system32\atlsystem896885.exe
2009-02-23 15:40 59,904 a------- c:\windows\system32\atlsystem232131.exe
2009-02-23 15:40 59,904 a------- c:\windows\system32\atlsystem9850.exe
2009-02-23 15:40 131,072 a------- c:\windows\system32\atlsystem653661.exe
2009-02-23 15:40 122,880 a------- c:\windows\system32\atlsystem945467.exe
2009-02-23 15:40 97,792 a------- c:\windows\system32\atlsystem805520.exe
2009-02-23 15:36 86,016 a------- c:\windows\system32\u152395931.dll
2009-02-23 15:36 77,824 a------- c:\windows\system32\u1523630.dll
2009-02-23 15:36 59,904 a------- c:\windows\system32\atlsystem488833.exe
2009-02-23 15:36 59,904 a------- c:\windows\system32\atlsystem407560.exe
2009-02-23 14:54 86,016 a------- c:\windows\system32\u142345755.dll
2009-02-23 14:54 77,824 a------- c:\windows\system32\u142395749.dll
2009-02-23 14:12 86,016 a------- c:\windows\system32\u142370424.dll
2009-02-23 14:12 77,824 a------- c:\windows\system32\u142329818.dll
2009-02-23 14:07 <DIR> a-dshr-- C:\cmdcons
2009-02-23 14:06 161,792 a------- c:\windows\SWREG.exe
2009-02-23 14:06 98,816 a------- c:\windows\sed.exe
2009-02-23 13:39 <DIR> --d----- C:\hjt
2009-02-23 12:40 131,072 a------- c:\windows\system32\atlsystem85617.exe
2009-02-23 12:40 122,880 a------- c:\windows\system32\atlsystem71669.exe
2009-02-23 10:33 <DIR> --d----- c:\windows\pss
2009-02-23 10:32 23,576 a------- c:\windows\system32\wuapi.dll.mui
2009-02-23 10:19 86,016 a------- c:\windows\system32\u10233874.dll
2009-02-23 10:18 77,824 a------- c:\windows\system32\u10237459.dll
2009-02-23 08:21 <DIR> --d----- c:\docume~1\nreitter\applic~1\Malwarebytes
2009-02-23 08:21 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-23 08:21 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-23 08:20 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-23 08:20 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-23 08:15 86,016 a------- c:\windows\system32\u82357832.dll
2009-02-23 08:15 77,824 a------- c:\windows\system32\u82312528.dll
2009-02-23 06:57 135,168 a------- c:\windows\system32\atlsystem5738.exe
2009-02-22 17:21 86,016 a------- c:\windows\system32\u172275047.dll
2009-02-22 17:21 77,824 a------- c:\windows\system32\u172265645.dll
2009-02-22 17:15 86,016 a------- c:\windows\system32\u172295311.dll
2009-02-22 17:15 77,824 a------- c:\windows\system32\u17229067.dll
2009-02-22 16:48 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-02-22 16:48 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-02-22 16:48 <DIR> --d----- c:\docume~1\nreitter\applic~1\SUPERAntiSpyware.com
2009-02-22 16:28 86,016 a------- c:\windows\system32\u16221541.dll
2009-02-22 16:28 77,824 a------- c:\windows\system32\u1622040.dll
2009-02-22 15:41 86,016 a------- c:\windows\system32\u152235944.dll
2009-02-22 15:41 77,824 a------- c:\windows\system32\u152248443.dll
2009-02-21 19:06 86,016 a------- c:\windows\system32\u192185922.dll
2009-02-21 19:06 77,824 a------- c:\windows\system32\u192114019.dll
2009-02-21 12:35 65,536 a------- c:\windows\system32\der5609488.dll
2009-02-21 12:35 65,536 a------- c:\windows\system32\der7119346.dll
2009-02-21 12:33 86,016 a------- c:\windows\system32\u122131225.dll
2009-02-21 12:33 77,824 a------- c:\windows\system32\u122135920.dll
2009-02-21 12:32 65,536 a------- c:\windows\system32\der4559674.dll
2009-02-12 15:56 <DIR> --d----- c:\program files\Citrix
2009-02-12 15:56 60,744 a------- c:\documents and settings\nreitter\g2mdlhlpx.exe
2009-02-05 20:41 <DIR> --d----- c:\program files\MJ4120 SERIES
2009-02-05 20:40 <DIR> --d----- c:\program files\CdrPlayBack_MJPEG
2009-02-05 20:39 548,864 a------- c:\windows\system32\J2K_Decode.dll
2009-02-05 20:39 352,256 a------- c:\windows\system32\ijl15.dll
2009-02-05 20:39 327,680 a------- c:\windows\system32\kdu_v45R.dll
2009-02-04 17:08 <DIR> --d----- C:\fc018016df1fe2817d17cc58ff
2009-02-04 17:08 <DIR> --d----- c:\windows\SxsCaPendDel
2009-01-29 15:03 132 a------- c:\windows\ODBC.INI
2009-01-29 10:10 <DIR> --d----- C:\crystalreportviewers12
2009-01-29 10:09 42,847 a------t c:\windows\system32\ISUSMsg.rtf

==================== Find3M ====================

2009-02-23 08:18 81,556 a------- c:\windows\system32\nvModes.dat
2009-01-21 16:53 249,856 -------- c:\windows\Setup1.exe
2009-01-21 16:53 73,216 a------- c:\windows\ST6UNST.EXE
2009-01-16 21:35 3,594,752 -------- c:\windows\system32\dllcache\mshtml.dll
2009-01-06 08:38 35,328 a------- c:\windows\system32\drivers\ax88772.sys
2008-12-26 12:25 123,127 a------- c:\windows\HPHins12.dat
2008-12-25 08:13 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-19 04:10 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 04:10 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 00:25 634,024 -------- c:\windows\system32\dllcache\iexplore.exe
2008-12-19 00:23 161,792 -------- c:\windows\system32\dllcache\ieakui.dll
2008-12-11 05:57 333,952 -------- c:\windows\system32\dllcache\srv.sys

============= FINISH: 18:40:17.27 ===============

KillAll::

NetSvc::
softyinforwow1
eq2soft
netmantow

Driver::
softyinforwow1
eq2soft
netmantow

Collect::
c:\windows\system32\atlsystem429956.exe
c:\windows\system32\atlsystem663724.exe
c:\windows\system32\atlsystem882754.exe
c:\windows\system32\atlsystem568713.exe
c:\windows\system32\atlsystem66447.exe
c:\windows\system32\atlsystem34844.exe
c:\windows\system32\atlsystem918628.exe
c:\windows\system32\atlsystem461558.exe
c:\windows\system32\atlsystem896885.exe
c:\windows\system32\atlsystem232131.exe
c:\windows\system32\atlsystem9850.exe
c:\windows\system32\atlsystem653661.exe
c:\windows\system32\atlsystem945467.exe
c:\windows\system32\atlsystem805520.exe
c:\windows\system32\u152395931.dll
c:\windows\system32\u1523630.dll
c:\windows\system32\atlsystem488833.exe
c:\windows\system32\atlsystem407560.exe
c:\windows\system32\u142345755.dll
c:\windows\system32\u142395749.dll
c:\windows\system32\u142370424.dll
c:\windows\system32\u142329818.dll
c:\windows\system32\atlsystem85617.exe
c:\windows\system32\atlsystem71669.exe
c:\windows\system32\u10233874.dll
c:\windows\system32\u10237459.dll
c:\windows\system32\u82357832.dll
c:\windows\system32\u82312528.dll
c:\windows\system32\atlsystem5738.exe
c:\windows\system32\u172275047.dll
c:\windows\system32\u172265645.dll
c:\windows\system32\u172295311.dll
c:\windows\system32\u17229067.dll
c:\windows\system32\u16221541.dll
c:\windows\system32\u1622040.dll
c:\windows\system32\u152235944.dll
c:\windows\system32\u152248443.dll
c:\windows\system32\u192185922.dll
c:\windows\system32\u192114019.dll
c:\windows\system32\der5609488.dll
c:\windows\system32\der7119346.dll
c:\windows\system32\u122131225.dll
c:\windows\system32\u122135920.dll
c:\windows\system32\der4559674.dll

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
**Note** When ComboFix finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.Ensure you are connected to the internet and click OK on the message box.Simply follow the instructions to copy/paste/send the requested file.

Already did some scans with tdsskiller and hitmanpro and they detected Trojan-Spy.Win32.Zbot, Rootkit.Win32.PMax.gen, and rootkit boot.cidox.b, I'm not sure how this machine got so badly infected. The user may have opened a link or some file by accident.

The infected svchost.exe is causing the most problems, creating multiple various connections and slowing down the internet connection. Explorer.exe would also crash and would create connections as well. Internet explorer would pop up to back-linking websites.

No restore cd for this computer. Although I do have a copy of xp meant for dell machines and this is a dell.

Just need to know how i can stop the svchost.exe from creating connections.

dds attached

dds1.txt   9.67KB

DDS (Ver_09-05-14.01) - NTFSx86
Run by Bogdan at 0:21:16,39 on 30.07.2004
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1251.380.1049.18.223.55 [GMT 3:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
H:\FIX\dds.scr

============== Pseudo HJT Report ===============

A:Infected by the same flash drive as this http://preview.tinyurl.com/o3l47t one was infected

I have a mild adware infection that is affecting every computer that goes through my network. Superantispyware can find and remove ONE file(no active, no registry) that is associated with this attack and the problem is resolved (ie. it does not come back unless i log into this particular network, it's still gone when I restart the computer, etc). The adware does not affect any of my cleaned computers unless I am logged into MY network. A clean load of windows XP with service packs loaded will immediately be infected on my network without so much as going anywhere aside from google.com.

As best I can tell my hijack this log is clean, but here it is for those of you who are far superior at this than I am. This is from the machine I am using which is currently infected.

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 10:43:09 AM, on 12/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\msiexec.exe

Remember to re-enable them afterwards.

Hello, I have a gateway desktop computer with Winidows XP SP3, Internet Explorer 8, 2GB RAM, and 600GB Hard Drive.Avira Free Antivirus detected TR/Drop.daws.juu in my recovery partition (D:\) yesterday. MBAM detected PUM.Hijack.StartMenu on my regular partition. I removed these infections and proceeded to backup some files to my eternal hard drive. While doing so, Avira detected TR/Keygen.AQ.19 and TR/Tool.Keygen.517 in the "system volume information" folder on my eternal hard drive. I removed these as well.Lately I've noticed that my computer would behave strangely but more of the behavior is so subtle that it's hard describe it properly. Every now and then a process named mme.exe would show up in the task manager. I did a little bit of digging and everything I found suggested that it is maliciious.I am usually able to resolve stuff like this on my own, but this time I'm getting nowhere. I have never had an infection on anything other than the partitiion that my operating system is installed on. I am need of your help badly. Thank you for your time, here are the logs. -----------------------------------------------------------------------------------------------------------------.DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702Run by Owner at 5:50:25 on 2012-02-10Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2022.1348 [GMT -6:00].AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}.===... Read more

A:Multiple Infections - Regular Partition infected with "PUM.Hijack.StartMenu" - Recovery Partitiion infected with...

Hi there,

It appears that you are receiving help at another forum: http://forums.majorgeeks.com/showthread.php?t=253464

Having multiple topics open at different forums only serves to confuse matters and waste the volunteers' time. In addition, it seems that you have since reformatted your drive. As such, I will close your topic here.

Regards.

Casey

I was contacted by some friends last Sunday who said they received lots of wierd emails from my email account. The emails contained nothing but a link. I did not send any emails over the weekend so I don't know how this happened. This must be a virus, right? I noticed my antivirus (avast!) began (a few days back) blocking a couple of malwares when downloading emails to Outlook 2007 on my laptop. It identified a infection called "Win32-Malware-gen". It now does this everytime I try to download emails and I now have duplicate emails in my Inbox. My antivirus identified the infected emails having subject "DHL Express Delivery" or "FedEx Service Notification" and a document.zip attachment which I think contained document.exe if I'm reading the Avast! log correctly. I did not open any of these emails. The antivirus moved them to chest but it seems the problem wasn't resolved. I then get a microsoft message saying Outlook encountered a problem and cannot exit. It offers me an "End Now" button, but it seems to get into a loop and the whole scenario happens again whereby Outlook reloads and I get the malware messages again.

Another problem I noticed which might be connected is that in IE8, whenever I attempt to login to any site it blocks and reloads webpage with "This tab has been recovered - A problem with this website caused Internet Explorer to close and reopen tab" message. Then it asks me t... Read more

13 more replies

Hi, Our computer has been infected since yesterday with the SMART HDD virus, which has been hiding all programs. I also believe our computer is infected with a TDSS type of rootkit virus in reading thru you website, as we've been having redirects happening in the search results of Google and BING for quite a number of weeks now.

We have a WINDOWS XP Service Pack 3 computer.

The SMART HDD virus had (at first) completely hidden all the programs from me and made them in-accessible. (see below) I was able to "un-hide" the programs, which allowed me access to Internet Explorer, Outlook Express and a few other programs, but not access to the important virus programs such as Malwarebytes and it wouldn't allow me to run the TDSSkiller program (even with re-naming it.), DDS froze up my system twice so I've not tried it again.

What I've done so far:

From a work computer on a whole different network, I was able to read up on your site, good information on what is going on and the steps I needed to take. However, the system is not allowing me to take the necessary steps, so I'll definitely need your help in getting around these roadblocks. I have been running my computer in SAFE MODE and doing that - I was (at first) able to un-hide the programs that are non-accessible, by going to My Computer and following the steps your site says to do. That temporarly enabled me to un-hide the programs, but now, the programs are hidden again. Before the progra... Read more

A:Infected with SMART HDD and also appear to be infected with a rootkit (TDSS type of issue)

Hello and Welcome to Bleeping Computer!!My name is Gringo and I'll be glad to help you with your computer problems. I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of usPlease do not run any tools unless instructed to do so.
We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.Please do not attach logs or use code boxes, just copy and paste the text.
Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.
Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.Please provide feedback about your experience as we go.
A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.NOTE:... Read more

Here is my log using HijackThis. My contacts in Windows Live Messenger are receiving pop-up message notifications with infected links. Norton is not picking anything up, and computer is running really slow. Malware Bytes did not pick anything up either. Any help would be appreciated ... thanks!-------------------------------------------------------------------------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:42:41 PM, on 05/07/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16850)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Rogers Online Protection\Rogers Online Protection\rps.exeC:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Prog... Read more

A:Spyware infected, MSN Live Messenger sending out IM with infected links

1 more replies

So at first I had the "Internet Security 2010" bug, but I think I fixed that with rkill. But now I got the green desktop with the "system is infected" message. I have heard of people who have this problem trying to restart only to find their system totally screwed, so I'm scared to turn off/restart. I have run DDS and Root Repeal. I know its Christmas, but please help!!!
DDS (Ver_09-12-01.01) - NTFSx86
Run by Michael at 3:25:14.42 on Fri 12/25/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.44 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe

A:Infected, Big Time... Green Desktop with "Your System is Infected" Message

Visit below website. Understand on how to use ComboFix >> download and run the program >> post the log here http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Yesterday while on the computer I suddenly got the Positive Finds popups. I had malwarebytes premium running and it wasn't able to prevent it I guess.

Ran a scan with MBAM and it detected it, I restarted thought it would be fine but Positive Finds is still all over my browser

This is the first virus/spyware/adware I've gotten in years so I would like some assistance from you guys

Thanks

We want all our members to perform the steps outlined in the link given below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:

Having problems with spyware and pop-ups? First Steps

link at the top of each page.

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post them in a new topic, as this one shall be closed.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

Directrdr has infected my computer. I run Firefox 3.5.3 and I cannot search with Google, Bing, or any other search engine that keep logs of my search history. Each time I use one of these search engines new tabs and/or new windows will open up to pages that I did not open myself. I can see the hxxp://www.directrdr.com . . . in the address bar and then it redirects to some other website that I did not authorize. I can use IXquick with few problems, it does not redirect to other pages, but sometimes new tabs will open anyway. When I run IE and try to navigate away from my homepage-MSN it redirects too. I have run Spybot, AVG, Malwarebytes, SDFix, and various others, tried cleaning in Safe Mode and I cannot get rid of this thing. Please help. Thank you for your time.I do not have a GMER file to attach because it keeps crashing. I tried to run it twice and each time it keeps stopping before it can complete its task, it will scan a few files and then stop. Error Message:gmer.exe has encountered a problem and needs to close. We are sorry for the inconvenience. DDS (Ver_10-03-17.01) - NTFSx86 Run by at 18:04:11.65 on Thu 07/01/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.68 [GMT -5:00]AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-5... Read more

A:Infected with directrdr browser hijacker?! Firefox & IE infected.

42 more replies

computer started out with avg detecting several resident shield viruses. noticed ping.exe was using my entire system resources. Firefox was hijacked and started opening random pages. Shut computer down and rebooted into safe mode. Cannot do system restore, tried several restore points with no sucess. Ran AVG in safe mode, backdoor generic14.cbjj found and supposedly white listed as necessary. Ran spybot s&d couple of harmful intrys found. Ran Malewarebytes in safemode trojan horse c:\windows\sytem32\Drivers\netbt.sys. virus fsquirt.exe found and supposedly deleted. Now are booted into safe mode with no connectivity and still obvious that my computer is sick. Need help with how to get back online and get the tools to help me correct this virus. Got help from BC Advisor Broni as to tools to help get this started. Computer is now booted to regular mode and I have ran the requested tools and am posting results as follows

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_26
Run by Cara Leigh at 15:40:52 on 2011-12-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1547 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG2012\avgrsx.exe
C:\Program Files\AVG\AVG2012\avgcsrvx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs

Examples of older versions in Add or Remove Programs:
Java 2 Runtime Environment, SE v1.4.2
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 6 Check any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.

59 more replies

Hi there!I'm infected with some very annoying trojan, ive previously ran adaware, spybot search and destroy, avg free antivirus, avast. Some of these picked up the problem, but im still getting the "yourieprotect" homepage when i go on internet explorer.I have ran everything as per this link: http://www.bleepingcomputer.com/forums/t/63896/how-to-remove-virusburst-removal-instructions/This is my smit file: smitRem ? log file version 3.2 by noahdfearMicrosoft Windows XP [Version 5.1.2600]"IE"="6.0000"The current date is: Wed 11/29/2006 The current time is: 14:26:06.57Running fromC:\Documents and Settings\Mourad\Desktop\smitRem~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Pre-run SharedTask Export(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)Copyright? 2006 BleepingComputer.comRegistry Pseudo-Format Mode (Not a valid reg file):[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader""{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]@="%SystemRoot%\system32\browseui.dll"[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]@="%SystemRoot%\system32\browseui.dll"~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Appinitdll check ........ Thank you Grinler!dumphive.exe ?2000-2004 Markus StephanyREG... Read more

A:I Am Also Infected With: Infected With W32/[email protected] A/k/a Zlob Trojan

1 more replies

Looking for help to remove this dasterdly thing / Been several days on it.

I.E. icon shows alot of activity in system tray

DDS Log below and Attach.txt, Attach.zip and Ark.txt attached also

DDS (Ver_10-10-21.02) - NTFSx86
Run by Mike at 16:05:53.54 on Sat 10/30/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.434 [GMT -4:00]

AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Worm Protection *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\GEARSec.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe

A:Infected with TDL4 Rootkit - MBR Possibly Infected

Hi all, sent here by Broni for elevated help.  Basically, to summarize, I got a worm possibly through a vulnerability in Flash and from an infected ad (I've only browsed legit websites and I have McAfee SiteAdvisor) and as is typical of people who have the worm, I can't remove it.  Apparently, it's infected my MBR and I was told to run DDS.

Here's DDS.txt

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16483  BrowserJavaVersion: 10.21.2
Run by Daniel at 18:10:34 on 2013-05-25
Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.4093.1324 [GMT -4:00]
.
AV: Norton Security Suite *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Security Suite *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Security Suite *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe

A:Infected MBR; Infected with MSIL/Necast.D worm

12 more replies

Hello! I am posting because I have offered to clean up a computer for a coworker, and want to make sure I do a thorough job. So far, I have seen indications of at least 4 separate malware programs. The first was Antivirus 360, which I believe I deleted for the most part via manually removing the files and registry values. I have also seen VirusProtect 3.8 and 3.9, though I had no luck locating the files I was told to delete...so I am not sure if the infection is there or not. His computer already has "Verizon Internet Security" installed, and I used that for an initial scan to see what it found. I deleted what it found, though that was done in safe mode, before I deleted all the files manually for AV360. When I enable Verizon Internet Security, it pops up two warnings, which mention a file by the name of Trojan.Win32.Monderb.xgy, in the C:\WINDOWS\system32\ljJCvSiI.dll. I looked up that file, and saw it was connected with the "Vundo" virus...or something along those lines. His computer is not connected to the internet at the moment. I am using my laptop to access the net, and transferring files via a flash drive to his computer. I have scanned with DDS, and will provide the log. I also have HJT ready to run on his desktop, as well as ComboFix. Here is the DDS log: DDS (Ver_09-01-19.01) - NTFSx86 Run by HP_Administrator at 16:34:39.23 on Mon 01/26/2009Internet Explorer: 7.0.5730.13Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033... Read more

A:Computer Infected/Possibly Infected With Various Malware

7 more replies

Here is my DDS log. Right now my desktop is pure white and I can't set a background image. Also I have a red X showing up in the tray saying "Your Computer is Infected - Click Here to Remove"

DDS (Ver_09-02-01.01) - NTFSx86
Run by Compaq_Administrator at 14:46:59.31 on Tue 02/10/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.606 [GMT -5:00]

AV: avast! antivirus 4.8.1296 [VPS 090210-0] *On-access scanning enabled* (Updated)
FW: Norton Internet Worm Protection *disabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe

Forgot to mention when I use google in Firefox, I have to open the link 6 or 7 times before it actually brings me to the link, other times it is redirected to a number of sites.

12 more replies

Posted about my main box and my vista spare part box.. this is to figure out whats up with one of three laptops that were all on a router together... This laptop crashed after getting the infection I recovered via the harddrive acer setup. No optical drive onstalled this is one of two acer netbooks we use in our family. Thoiught i reinstalled everything i believe a rootkit of some sort has ahold of this laptop...settings change on there own cpu usage is about 50% when just sitting idle from user stand point.

Please let me know what logs to provide.. Thanks again to all that have helped thus far and continue to be a great support.

btw: this laptop is an acer aspire one with win xp..

A:My laptop is infected... part of a group of pc's infected

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===
Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Close all open programs and internet browsers.Double click on AdwCleaner.exe to run the tool.Click on Delete tab follow the prompts.A log file will automatically open after the scan has finished.Please post the content of that log file with your next answer.You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).

32 more replies

Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:36:36 μμ, on 26/5/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16827)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Creative\Shared Files\CTAudSvc.exeC:\Program Files\Unlocker\UnlockerAssistant.exeC:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exeC:\Program Files\Motorola\SMSERIAL\sm56hlpr.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exeC:\Program Files\Creative\Sound Blaster X-Fi Surround 5.1\Console Launcher\CTAPR2.exeC:\Program Files\Creative\Shared Files\Module Loader\DLLML.exeC:\WINDOWS\system32\RunDll32.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Pr... Read more

A:Infected with a virus that causes NOD32 to remove any .exe that is not infected

1 more replies

Hi!

I seem to have been infected with some particularly vicious malware..

I get a red bubble with a white 'x' on my taksbar. The message 'your computer is infected! WIndows has detected a spyware infection! Click here to protect your computer with spyware!'

Anti - Vir is going nuts over it (It keeps on picking up trojans and worms) Malwarebytes' Anti-Malware can't get rid of it, and neither can spybot. It has turned off Windows firewall and won't let me turn it back on.

I use Windows XP, have automatic updates turned on, am running SP2 and update Antivir, Spybot and Malwarebytes' Anti-Malware regularly.

It won't let me run ad-aware or spybot.

If you require any further information, let me know!

Rob

DDS (Ver_09-07-30.01) - NTFSx86
Run by admin at 11:14:16.37 on 02/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.1023.453 [GMT 1:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe

13 more replies

I am finding increasingly more machines where antivirus can't seem to disinfect a machine, even with the latest definitions.

Is there a solution for this?

What is everyone else doing to cope with this problem?

I used to be able to disinfect an infected machine and really get it out. Now, after disinfection, I frequently see new alerts within just a few minutes for viruses that I know are included in the virus definition file.

Case in Point: I went on a service call today and found a dozen different viruses in over a hundred different files spread over an eight-computer LAN. After two and a quarter hours of defeat after defeat, I loaded up the entire network, router and all, and brought it back to my shop. This is a drastic step; but, I gotta' know for sure that they are clean when they go back and this is the only way I know to do it with certainty.

I have always been told that one should not run two antivirus programs at once. I'm now doubting one program can do it. Maybe two can't either; but, I am seeing situations where I believe two is better than one.

NTFS has only made it more difficult. I frequently have to remove an NTFS drive and connect it to a known-clean machine to remove viruses. But, that leaves all the virus-related lines in the registry of the non-active but suposedly disinfected drive.

Anyone have any suggestions how one can do a sure-clean on an infected NTFS machine without going to such drastic steps?

There's got to be a ... Read more

I believe I have an infection. When I open my Internet Explorer and browse the internet, after a bit of time a new IE browser window pops up with various ads, virus protection offers, google things etc. It happens every so often. I have tried Malwarebytes, and it did not find the virus. Other virus removal tools have indicated the following is infected:fsvga.sysThe anti virus tools do say they fix it, but it gets infected again afterwards.I have seen the following message:Infected copy of c:\windows\system32\drivers\fsvga.sys was found and disinfected Restored copy from - Kitty had a snack And it continues to be infected.According to GMER, as im sure you will notice, it does show the following:C:\WINDOWS\system32\DRIVERS\fsvga.sys suspicious modificationC:\WINDOWS\system32\drivers\atapi.sys suspicious modificationI have followed you instructions on posting virus removal help request, and the requested files have been attached. Here is also the DDS as follows. Thank you for your help in advance on this matter:DDS (Ver_10-03-17.01) - NTFSx86 Run by Joel at 14:48:26.03 on Wed 06/09/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1482 [GMT -5:00]============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcssvchost.exeC:\W... Read more

A:Infected With Unknown - Infected fsvga.sys

11 more replies

Let the ol' lady use my PC and ends up getting a 'HTML/Infected.WebPage.Gen notification from AVIRA. Everytime she hits her blogs on IE it ends in bad news. Here is the DDS log. Not sure if I require the Kasperesky scan. I don't have it but will see what you guys say first. Hope this helps. Please advise. Your assistance in this matter is greatly appreciated.DDS (Version 1.1.0) - NTFSx86 Run by ALAN WONG at 21:12:00.89 on Tue 12/23/2008Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_11Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.958.438 [GMT -8:00]AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)FW: Sygate Personal Firewall *enabled*============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\Program Files\Sygate\SPF\smc.exesvchost.exesvchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\AntiVir PersonalEdition Classic\avguard.exeC:\WINDOWS\Explorer.EXEC:\Program Files\AntiVir PersonalEdition Classic\avgnt.exeC:\WINDOWS\system32\VTTimer.exeC:\WINDOWS\system32\S3trayp.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\CyberLink\PowerDVD\PDVDServ.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Pr... Read more

A:Infected with HTML/Infected.WebPage.Gen

1 more replies

Hi,
My friend brought me her HP laptop a few weeks ago because it had a virus. I saw Security Suite stuff pop up all over, and you couldn't run ANYTHNG, so I used the instructions on this site to get rid of it. I thought it was gone but she brought her computer back to me a couple of weeks ago because she was getting popups again. Btw, she actually paid the security suite site thingy 80$. I'm having her go through the steps to get her money back for that now. So I rescanned with AVG and malwarebytes and it didn't come up with anything. I kept the computer for a few days and used it like normal but got no popups so I gave it back to her. So about a week ago she gave me back the computer as the IE would not work. So I scanned it again and both malwarebytes and AVG came up with a couple of things and got rid of them. So now I'd like to see if the computer really is clean. Also, I'd like to know what she needs on here to keep the computer clean?? She scans with both AVG and malwarebytes but I'm not sure that is enough if she keeps thinking she's getting infected. I know she does a lot of facebook apps. Also, this computer absolutely refuses to scan gmer. The first time I downloaded and ran it it scanned for about an hour then spontaneiously the computer shut down. I didn't see any messages because I wasn't paying attention to it when it shut down. So the next day (today) I tried to scan again and it stopped very close to the ... Read more A:Was infected with security suite, re infected? Hello and welcome to the forums!My secret agent name on the forums is SweetTech (you can call me ST for short), it's a pleasure to meet you. A:Can a USB Cd/rom be infected plugging into a infected system Hello dannyboy950: If your computer is badly infected, then backing up the system will just copy the infections to any backup DVDs, which you obviously know. I don't think you need to worry too much about your external DVD drive being infected, per se. That would only happen if one or more of the infections could compromise the DVD firmware or the USB driver(s). You should be aware though that many variants of viruses and malware will disable the Windows Volume Snapshot Service (VSS) which will prevent the creation of backups and system restore points. My advice would be to follow the directions here and submit an Farbar Recovery and Scan Tool (FRST) log to the trained Bleeping Computer Malware Response Team members in the Virus/Trojan/Spyware and Malware Removal Logs Forum. You should be aware that the anti-malware response community shares their information with other anti-malware/virus vendors and experts. First I used Malwarebytes' anti-malware and that didn't find any infections, then I scanned it with avg and that found over 500 infections, not all of them were serious ones but some of them were trojans with itunes files. This morning I tried uninstalling and then reinstalling itunes thinking that might solve the problem, but it didn't work and itunes still won't start. I hope someone can help me solve this problem as I am not the best when it comes to computers. If you need anymore info please just ask. DDS (Ver_09-06-26.01) - NTFSx86 Run by Zac at 7:40:37.82 on Sat 07/25/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.388 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe... Read more A:Trojan infected itunes may have infected more Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more 2 more replies Answer Match 24.36% heyy guys, okayy so about a month ago a trojan managed to get onto my netbook and i scanned with malwarebyte antimalware and super antispyware in safe mode which seemed to fix is for the most part, but im still getting some problems and avast, mbam and superantispyware are all coming up clean. the worst thing is my internet just cutting out after about 40 minutes of use, wireless zero configuration turns itself off and will not turn on and one of the svchosts using way too much memory and cpu, but i cant turn it off because that just messes up my netbook. soo yeah some help would be great cuz this is really getting on my nerves. More replies Answer Match 24.36% Today, I used a pendrive of a friend on my computer, I had auto folder open on. the folder opened and later to find nothing on the pendrive but only a E:\ folder inside the pendrive, then when i clicked hidden items viewable, i saw the pendrive logo I went inside transferred my important document since it needed an immediate printing. My computer has turned very slow following that and there are various hidden documents now on my desktop like$w_microsoft.docx which are of names of files i had deleted long ago and several other files which i had created and used long back but never used in the near history.

Please help me fix this , remove the virus and get back to my old computer speed.

Thanks alot for help in advance

----FRST LOG-------

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:06-05-2016
Ran by ASRLAPTOP (administrator) on DEEPAK (05-05-2016 18:57:15)
Platform: Windows 10 Home Single Language Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

A:I think i have been infected by a worm from using an infected pendrive, need hel

9 more replies

I too was recently infected with XP Security Tool 2010 and I used the fix described on BC. I installed Malwarebytes and FixExe.reg. This seemed to get rid of the problem. But very soon after each time I clicked on any link on Google on Firefox or Internet Explorer I am redirected to seemingly random advertisement websites. I also use Avira Antivirus protection and it pops up saying: HTML/Infected.WebPage.Gen in file C:\Documents and Settings\Network Service\...\2[1].php. If I catch the Avira popup and click remove it will Quarantine. However within 2 to 6 hours it returns.Have copied and pasted DDS.txt log, gmer.txt log, OTL,txt log, Systemlook.txt log and TDSKiller.txt log. Also attached the attach.txt file and gmer(ark) txt file. Sorry, did not untick the IAT/EAT box in gmer. Those are the logs myrti requested from toomuchpoison.Hope I didn't overdue it.Thanks,MajazzleDDS.txt log DDS (Ver_10-03-17.01) - NTFSx86 Run by Matt at 16:47:53.63 on Thu 04/29/2010Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_18Microsoft? Windows Vista? Home Basic 6.0.6002.2.1252.1.1033.18.1915.1050 [GMT -4:00]SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\Microsoft.Net\Framework\v3.0\WPF\... Read more

A:Infected with HTML/Infected.WebPage.Gen

26 more replies

When Windows loads, the "performance monitor" component for the optimizer pro virus calims that 375 items need to be cleaned and potimized. closing it out does not reactivate it. Mcafee also frequently pops up, preventing unwanted software from running. below is a copy paste of frst.txt and atached is the addition.txt file. Thank you.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-08-2015
Ran by teacher (administrator) on RM305-PC (28-08-2015 01:27:23)
Running from E:\
Loaded Profiles: teacher (Available Profiles: Rm305 & teacher)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Nalpeiron Ltd.) C:\Windows\SysWOW64\ASTSRV.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelpe... Read more

A:Infected with Optimizer Pro and pop says I am infected with viruses

0 more replies

Hello computer gods,I'm hoping you can fix my problem I've been infected with drsmartload, and I ran smitfraudfix. It said that it cleaned it up but it's still popping up as infected and I'm getting ridiculas adware and project 1 boxes. I will post my "hijack log" and hopefully this is the right forum if not please redirect me. Im looking foward to getting rid of this "Freakin" thing. CheersMSmitFraudFix v2.109Scan done at 20:14:36.00, Tue 10/10/2006Run from C:\Documents and Settings\Magg\Desktop\SmitfraudFix\SmitfraudFixOS: Microsoft Windows XP [Version 5.1.2600] - Windows_NTFix run in safe mode???????????????????????? Before SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll???????????????????????? Killing process???????????????????????? Generic Renos FixGenericRenosFix by S!Ri???????????????????????? Deleting infected filesC:\drsmartload?.exe DeletedC:\WINDOWS\keyboard1.dat DeletedC:\WINDOWS\newname.dat DeletedC:\WINDOWS\teller2.chk Deleted???????????????????????? Deleting Temp Files???????????????????????? Registry Cleaning Registry Cleaning done. ???????????????????????? After SmitFraudFix!!!Attention, following keys are not inevitably infected!!!SrchSTS.exe by S!RiSearch SharedTaskScheduler's .dll???????????????????????? End

A:Infected With Drsmartload Used Smitfraudfix Still Infected

2 more replies

Bit of a wierd 1.

Turned on my machine today, went to the toilet and came back and Avast was asking to restart my computer and do a full scan from boot up. I said yes but cancelled it because it was taking too long.

I go look in virus chest and I noticed that tier0_s.dll from my steam folder is sitting in there, and that it was transfered in there today. But where it says "Virus description", it says "--no virus--"

What does this mean? Is it some kind of false positive? Did I screw things up by cancelling the scan?

A:Avast says I have an infected file...which isn't infected

2 more replies

Hi I've had a few viruses named HTML/Infected.WebPage.Gen recently and I would normally be able to remove them myself using hijack this. But unfortunately hijack this isn't working for me and is coming up with an error. My anti virus is finding the viruses and I am removing them with the anti virus but they keep coming back.As soon as I click hijack this this message appears:For some reason your system denied write access to the Hosts file.If any hijacked domains are in this file, HijackThis may NOT be able to fix this.If that happens, you need to edit the file yourself. To do this, click Start, Run and type: Notepad ?C:\Windows\System32\drivers\etc\hosts?And press Enter. Find the line(s) HijackThis reports and delete them.Save the file as ?hosts.? (with quotes), and reboot.I have tried to do as it says above but another error message tells me that i am unable to save the file.I then clcik "OK" and then this error message appears:An unexpected error has occurred at procedure:ModMain_CheckOther1Item()Error#75 ? Path/File access errorPlease email me at [email protected], reporting the following:*What you were trying to fix when the error occurred, if applicable*How you can reproduce the error*A complete HijackThis scan log, if possibleIt then produces the Hijack scan, so then I proceeded to fix the files that I think may need fixing which are these files:BHO: thesuperads search enhancer: {b2fe5f61-3eb4-4e22-7c84-f52993635f52} - c:\wi... Read more

A:Infected with HTML/Infected.WebPage.Gen

Ok after reviewing the DDS log I now have removed the virus lol but I still haven't worked out what's wrong with my hijackThis?===========Hello While we understand your frustration at having to wait, please note that Bleeping Computer deals with several hundred requests for assistance such as yours on a daily basis. As a result, our backlog is quite large as are other comparable sites that help others with malware issues. Although our HJT Team members work on hundreds of requests each day, they are all volunteers who work logs when they can and are able to do so. No one is paid by Bleeping Computer for their assistance to our members.Further, our malware removal staff is comprised of team members with various levels of skill and expertise to deal with thousands of malware variants, some more complex than others. Although we try to take DDS/HJT logs in order (starting with the oldest), it is often the skill level of the particular helper and sometimes the operating system that dictates which logs get selected first. Some infections are more complicated than others and require a higher skill level to remove. Without that skill level attempted removal could result in disastrous results. In other instances, the helper may not be familiar with the operating system that you are using, since they use another. In either case, neither of us want someone to assist you who is not familiar with your issue and attempt to fix it.We ask that once you have posted your log and are waiting, pl... Read more

3 more replies

Every 10 minutes or so, a red pop up box appears saying my computer is infected and asks if I would like to remove - it is called PC Security Guardian. Then a minimized window opens and says "PC Guardian has detected suspicious software - click to remove."

There was no data from the GMER scan, so the ARK.txt log will not attach.
DDS.txt Log:

.
DDS (Ver_2011-06-03.01) - NTFSAMD64
Internet Explorer: 8.0.7600.16385
Run by Dunigan at 18:50:36 on 2011-06-08
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3839.2739 [GMT -5:00]
.
AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
FW: Norton Internet Security *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService

A:Infected with a pop ups saying computer is infected followed by a pig squeel

4 more replies

A:Was Or Is Infected Infected With Torpig.c.trojan (or The Like)

49 more replies

A:Infected Wih Html/infected.webpage.gen

Hello Braco and welcome to BleepingComputer!Apollogies for the delay. The forum has been very busy lately and. If you are still having problems, then please post a brand new HijackThis log as a reply to this topic. Before posting the log, please make sure you follow all the steps found in this topic: Preparation Guide For Use Before Posting A Hijackthis Log. Please also post the problems you are having.If we do not hear back from you within a couple of days we will need to close your topic.Thanks,Johannes

1 more replies

Hi,
I have tried a few different anti virus downloads to try and rid my computuer of the virus to no avial. Even purchased one which I know now was also a fake.

Rick
Rootrepeal_report_08_30_09__20_35_13_.txt   5.08KB

A:Infected with Fake virus infected pop ups

2 more replies

I'm at the end of my rope here. A "friend" gave me her computer to clean up. The thing was so full of malware it was unbeliveable. I've got most of it, but there is this one nasty bit of adware "Cool Web Search" that remains... I've tried running the latest versions of Ad aware, Spybot, and CWShredder. They seem to find and remove the cool web stuff, but when I shut down and start up again, it's back. I've gone to the trend micro site, but I keep getting a .dll error when I start downloading the definition files.

When I shut down, the machine hangs and tells me that it is waitng for a response from "Win Min".

It also occasionally freezes on startup, leaving me with a blue screen and a mouse pointer stuck in the middle. (This seems to be mitigated somewhat if I move the mouse around during startup!)

The log file from this machine is as follows.

Logfile of HijackThis v1.99.1
Scan saved at 10:03:03 PM, on 25/04/2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE

A:Infected Windows Me PC Hangs on Shutdown - "Win Min" infected with Cool Web Search

Please Keep your browser and all open programs closed (except firewalls and antivirus) when you are carrying out the fixes.

Download any of the required programs before attempting to start any of the fixes.

Turn off System Restore instructions (WinXP)
Rightclick My Computer | Properties | System Restore | check ?Turn off System Restore?, <Apply>, <OK>. Reboot. When we have confirmed that your log file is clean, you may renable System Restore and create a new restore point.

SHOW HIDDEN FILES AND FOLDERS.
To show hidden files instructions (WinXP)
Doubleclick My Computer | Tools | Folder Options | View tab
Select Show Hidden Files and Folders
Uncheck Hide extensions for known file types
Uncheck Hide protected operating system files (Recommended)
Select Apply to All Folders | Yes | Apply | OK
------------------------------------------------------------------

Download and run CWShredder (check for updates) for a preliminary cleanup first.Some files below may not be present after running the above programs.Full instructions below.

How to install and run CWShredder

Choose the stand alone version. This is free.
Save cwshredder.exe into its own directory, NOT in a TEMPorary folder or on the DESKTOP.

15 more replies

Hi
As my title suggests my bro's laptop has this annoying infection.
I use Firefox but my brother IE 8 (and so IE is default).
At random times and when connected to Internet, a popup appears with usually
the X button in corner and it will go for a variable amount of time.
Avira btw cannot get rid of it and in fact does not even find it after scanning with maximum options.
This also happens sometimes much rare tho: A message appears telling I have an infected computer and wants me to press OK and scan using IE. I click X and once it opened IE with scanning screen. I click X ASAP.

One more issue: Firefox sometimes will say "Firefox has stopped working.."
and that it will close. Right away a balloon pops up in tray telling me the browser was closed to protect me from Data Execution Prevention.

Avira sometimes at random times pops up saying Virus or unwanted program was found, right? It asks me what to do with this file.
Move to quarantine
Delete
Overwrite and delete
Rename
Deny access
Ignore

I usually picked delete or deny access
It found the virus in this file:
C:\Users\Piotrek\AppData\Local\Mozilla\Firefox\Profiles\jfyfitzg.default\Cache\34F11269d01

I understand I have Limewire. My brother uses it... Read more

A:[SOLVED] Infected with HTML/Infected.WebPage.Gen HTML script virus

16 more replies

Here are a few things that may be relevant to the problem:

1) Computer unable to access certain websites. (Ex: yahoo, facebook, etc.)
2) I did a scan and my computer is supposedly infected with "zlob" and "adware.IpWins"
3) My computer is running significantly slower then a few weeks ago.
4) Tons of random pop-ups that I did not have a few weeks ago.
5) Full system Scanned with Lavasoft's Ad-Aware but problem persists.

Here is my HJT log:
--------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:18 PM, on 9/8/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG... Read more

A:Computer infected with spyware. Infected with "Zlob"?

11 more replies

hello ,
i was infected by virusburst and i did lots of instructions to solve my problem, I used malwarebytes anti malware and it cleaned all infected files but now my problem is the internet explorer still not working and even starting any more,
and in mycomputer each folder opens in it's own window even in options it's marked to open in the same window
but i don't see any fake alert any more ,
I'm using windows vista and now opera browser,each browser that i marked as default browser stopped working(internet explorer and mozilla ) ,
i dont know which kind of log i should post here so i wait for your requests.
i just wanna know if i'm still infected and what should I do ???
thank you for helping me !!

A:I Was Infected By Virusburst.am I Still Infected ?

1 more replies

I think my computer is on a couple different botnets, and i wouldn't be surprised to see other viruses =/Any help your be greatly appreciated.Edit; sorry, i didn't see the rule of what virus i had was supposed to go into the title untill it was too late Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:58:11 PM, on 6/23/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\LEXBCES.EXEC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\LEXPPS.EXEC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Digital Media Reader\readericon45G.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\PROGRA~1\AVG\AVG8\avgtray.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\zHotkey.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\system32\acs.exeC:\Program Files\Common Files&#... Read more

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

A:"Your computer is infected!" Popup message. Computer infected with Trojan

16 more replies

Hi,
My daughter uses this computer and I have no idea what she may have gotten in to.
I am running Windows 7 Home Premium.
I have McAfee Total Protection.
McAfee has detected and quarantined or removed various threats.
I have also been using Malwarebytes over the years, but had not run recently.
I recently tried to run malwarebytes and it will not update and then windows gives me an error with a Problem signature:
Problem Event Name:    APPCRASH.
I went to malwarebytes forums to try to figure it out, but it led me back to BleepingComputers, so I figured I would continue here. You folks have helped me several times over the years and for that I am grateful.
Alan

A:Am I infected

17 more replies

Hi,
I'm having the same issue that I described in my other thread: http://www.bleepingcomputer.com/forums/t/540642/infected-rundll32-file/
While I'm not experiencing any problems with my computer right now, it still seems that there may be some sort of malware on it, and I would like to get rid of it.

Here is a link to my DDS log: http://pastebin.com/s0f8sFtX

A:Not sure if I'm still infected

My virus protection keeps finding a bgotrtu0.dll file on restart and removes it. Anyone help me with removing whatever is creating it? I have XP Pro with all service packs up to date. F-prot virus, malwarebites & superantispyware up to date as well.
Pearldiver57

A:Am i still infected?

1 more replies

My machine is suffering from a bug of some sort that won't allow my Zone Alarm Security Suite to run, won't allow regedit to run, won't allow hijackthis to run, etc, etc. The apps start but stop after a brief glimpse of their startup window

I have run Spybot and it revealed a number of potential issues. the ones that seemed to be important were Microsoft.WindowsSecurityCenter_disabled, Microsoft.Windows.RedirectedHosts. these are removed but come back. The internet explorer homepage was also changed

Can anyone help?

A:?? Infected

2 more replies

I'm not sure what happened but... today I downloaded from a P2P service. u_u Yeah, I know but I didn't think anything would happen as always. So the file itself was really big but I didn't install it at all, just extracted it. I was going to install it and block sites using my HOSTS File, etc but then I had to leave. So I turn off my computer for a few hours then come home to a message saying my hard drive has limited space. So I check it and I had about 2MB left on my 48.8GB hard drive which was weird since I'm sure I had upwards of 20 before I left? Don't quote me on it but I know there was a lot of room. So I delete the exe file that I downloaded to free up some space and managed to get 5GB of free space... but that's still not that much.

So I'm not sure if I'm infected with something that filled up my hard drive? Or... I'm not sure but I really just want to check and make sure nothing abnormal is going on.

A:Am I Infected?

Anyone to help? I'd really like to check to see what's going on...

2 more replies

A:Am I still infected?

26 more replies

Can someone analayze my logs

Mod Edit:  Sent "now that you have posted" content in PM - Hamluis.

A:Help i think my pc is infected

20 more replies

Highjack This Log, from the Administrator Account, in safe mode.

Logfile of HijackThis v1.99.1
Scan saved at 4:55:19 PM, on 6/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
G:\MISC\S&D-esque prograns\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
O2 - BHO: ViewSource Class - {85DDD882-701E-401B-8A7D-D51227048214} - C:\Program Files\Internet Spy\iewatcher.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CTFMon] C:\WINDOWS\system32\CTF\ctfmon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DVDTray] C:\Program Files\Ahead\ODD Toolkit\DVDTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Mes... Read more

A:Am I Infected?

Hello

I just formated my laptop and repartionned the hdd, I reinstalled Windows 7 Ultimate, but my pc take a several time too boot.

Below my Configuration and time to start windows

Config Speecy

tempsdemarrage.jpg   18.58KB

Thanks a lot

A:Maybe Infected, please can you help me

Plese find Bellow DDS Log and Attach.TXT

attach.txt   8.98KB

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17207  BrowserJavaVersion: 10.65.2
Run by Hicham at 22:27:33 on 2014-07-27
Microsoft Windows 7 Édition Intégrale   6.1.7601.1.1252.33.1036.18.8073.2314 [GMT 0:00]
.
AV: ESET Smart Security 7.0 *Enabled/Updated* {19259FAE-8396-A113-46DB-15B0E7DFA289}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: ESET Smart Security 7.0 *Enabled/Updated* {A2447E4A-A5AC-AE9D-7C6B-2EC29C58E834}
FW: Pare-feu personnel d'ESET *Enabled* {211E1E8B-C9F9-A04B-6D84-BC85190CE5F2}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\System32\WUDFHost.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe

Hi,I was infected with something that caused redirects of websites. I was able to (hopefully) removed it with Malwarebytes Anti-Malware (no more redirects). However, I still think I am infected with something because my system is really slow. Also, when I tried running Gmer in Safe Mode (I tried running it in Normal first but it just froze), a blue screen popped up with a message saying something like "ulpqdow.sys" is causing an error or something (it was really really fast) and then the system restarted. Am I infected with something and if so, how do I remove it? Also, did this "thing" came from Azureus ? The Azureus folder was modified this morning but I havent used it in months.Thank you very much for your help in advance. Here are the requested logs:DDS (Ver_10-03-17.01) - NTFSx86 Run by bin at 11:53:02.30 on Fri 08/06/2010Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_17Microsoft? Windows Vista? Home Premium 6.0.6002.2.1252.1.1033.18.2038.880 [GMT -7:00]SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exeC:\Windows ... Read more

A:Infected with something

Hello bintWelcome to BleepingComputer What are the symptoms that you are having?==========================Download OTL to your desktop.Double click on OTL to run it. When the window appears, underneath Output at the top change it to Minimal Output.Under the Standard Registry box change it to All.Under Custom scan's and fixes section paste in the below in boldnetsvcs%SYSTEMDRIVE%\*.*%systemroot%\*. /mp /sCREATERESTOREPOINT%systemroot%\system32\*.dll /lockedfiles%systemroot%\Tasks\*.job /lockedfiles%systemroot%\System32\config\*.sav %systemroot%\system32\drivers\*.sys /90%systemroot%\system32\Spool\prtprocs\w32x86\*.dllCheck the boxes beside LOP Check and Purity Check.Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.====================

23 more replies

Hi,I have used various anti viruses (ad aware, bit defender, house call and kaspersky) and now SuperAntiSpyware but I still get reoccurring root viruses when doing scans. I ran McAfee Avert Stinger as well. I also get detected: riskware Mass-mailer software Running process: C:\WINDOWS\Explorer.EXE when doing a scan with Kaspersky Anti Virus.PLEASE HELP. Here is my HiJackThis Log.Logfile of HijackThis v1.99.1Scan saved at 23:11, on 2007-07-04Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16473)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Ahead\InCD\InCDsrv.exeC:\Program Files\Sygate\SPF\smc.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exeC:\Program Files\Ahead\InCD\InCD.exeC:\WINDOWS\system32\SHVRTF.EXEC:\Program Files\Logitech\MediaLife\MediaLifeService.exeC:\Program Files\Iomega\DriveIcons\ImgIcon.exeC:\Program Files ... Read more

23 more replies

I been having issues with my computer slowing down terribly when ever i load and stream videos or games. I have done just about everything. I did whole computer scan including locked files and it showed that they were over 100 infected but low risk but AVG wouldn't dispose of the threats because of how low risk they were. I looked into the problem with AVG and they said to redo the scan without including the locked files and that showed that my computer was clean, but it still does not perform as it should. I have use malware programs jrt scannow pc boost software and nothing has helped. If there is anything I can do to help solve this issue is would be greatly appreciated.

A:I Think im infected

http://www.bleepingcomputer.com/forums/t/518596/multiple-com-surragate-slowing-down-computer/
This is where i started

19 more replies

Computer is acting very strange. NOD32 found something, I thought it quarantined it but it doesn't seem to be the case. Here is the log, thank you for checking it.Edit: Forgot to mention. Scans with some spyware software found Virtumonde and supposedly removed it, but doesnt act like it. Computer cant reboot normally, has to go to last good know a couple times before it finally boots.Logfile of HijackThis v1.99.1Scan saved at 9:12:46 AM, on 7/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16473)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\ehome\ehtray.exeC:\WINDOWS\Sonysys\VAIO Recovery\reminder.exeC:\Program Files\SONY\sHotKey\sHotKey.exeC:\WINDOWS\System32\ezSP_Px.exeC:\program files\support.com\client\bin\tgcmd.exeC:\WINDOWS\AGRSMMSG.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\Java\jre1.6.0_01\bin\jusched.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Windows Media Connect 2\WMCCFG.exeC:\Program Files\Ad... Read more

A:Am I Infected?

Sorry for the delay, it's been pretty busy here lately.
If you still need help, please post a new Hijackthis log, I'd be happy to take a look at it for you.

2 more replies

I left my computer open one night. When I woke up, someone was opening, closing the folder, pictures etc on my computer. I panicked and shut down the computer. Then, I scanned with a bunch of antivirus programs. Some of them found some malwares and some of them didn't. Of course, I couldn't trust it anymore. I formatted just disk C. By the way, I was purchasing online. Is my credit card in danger?
Anyway, I set up Avast and MBAM after recovery and I scan my computer regularly. However, they sometimes detect viruses(the last ones are svchost.exe and audiobg.exe) and deleting or moving to quarantine. I guess the virus cannot be defeated. What should I do? Are the virus located in disk D? If I format the whole computer(both disk C and D), can I trust it? Thanks.

A:Infected

MBAM still found something in svchost.exe. Isn't there anybody who can help?

24 more replies

here is the logs

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.17207
Run by jol at 12:22:42 on 2014-07-29
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.358.1033.18.8157.6498 [GMT 3:00]
.
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: Online Armor Firewall *Enabled* {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\Online Armor\OAcat.exe
C:\Program Files (x86)\Online Armor\oasrv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\windows\system32\nvvsvc.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\windows\System32\spoolsv.exe

hi i am not very technical thank you in advance for any help you can offer. this is what is coming up BV:AutoRun-J [Wrm]

i have the logs that u say to keep but it wont let me attach them, oh god i hope i have done this right, please dont shout at me if i havent

regards

PaintedRose

A:Help I am infected

2 more replies

Moderator Elvandil asked me to post my problem here to rule out the possibility of my computer being infected. Please follow the link below to read the XP crashing problems I've been having. I really appreciate your help.

http://forums.techguy.org/windows-nt-2000-xp/618003-progam-crash-windows-xp.html

A:Am I infected???

Hi all,A couple of days ago while on the net I had the following registry change request from Spybot, which I denied.27/05/2011 20:06:31 Denied (based on user decision) value "YI9B2F0F3H9GVYWVTSWQVMO" (new data: "C:\systemhost\systemhost.exe") added in System Startup user entry! This followed Kaspersky (not updated - I know I should have) quarantining x5 'unknownthreat UDS:DangerousObject.Multi.Generic on the 22nd and 23rd of this month.Further google searches on 'systemhost' took me to this site and some worrying reading. Aside from a couple of unsuccessful attempts for me to link with Firefox browser everything so far seems to be running smoothly.Spybot Search & Destroy found nothing untoward.Installed MalwareBytes - ran and nothing found.Installed and ran SUPERAntiSpyware - 5 tracking cookies found and deleted.I've also installed and ran DDS and GMER as recommended elsewhere and logs are saved if necessary.Oh yes I forgot I am using Windows Vista. Anything to worry about?Hope somebody can put my mind at rest,Jensen

A:Infected ?

Anything untoward happening at all?

not sure if i am infected or not but noticed over a 2 weeks ago that i am losing anywhere from 500mb to 2.5gb of free space on both my internal and external hd's. i have looked through the folders on the external (fewer folders/easier) and could not find anything with that days date on it.
travis.

A:i think i am infected?

5 more replies

I constantly keep having pop ups from mcafee regarding virus protection

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521
Run by VMarie at 8:33:39 on 2014-08-15
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3559.1023 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* signature-cached-Wed, 18 May 2016 20:30:52 +00008
SP: Windows Defender *Disabled/Updated* signature-cached-Wed, 18 May 2016 20:30:52 +00007
SP: Microsoft Security Essentials *Enabled/Updated* signature-cached-Wed, 18 May 2016 20:30:52 +00006
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe

A:infected but not sure with what

DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 11.0.9600.16521
Run by VMarie at 8:33:39 on 2014-08-15
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.3559.1023 [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* BOTTOM BUTTONS 2
SP: Windows Defender *Disabled/Updated* BOTTOM BUTTONS 1
SP: Microsoft Security Essentials *Enabled/Updated* BOTTOM BUTTONS 0
.
============== Running Processes ===============
.
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k GPSvcGroup
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\7B0A8368-1A6F-48A5-B236-8BD61816B3F9\axsmqwiahk64.exe
C:\Program Files (x86)\Coupons\CouponPrinterService.exe
C:\Program Files (x86)\Common Files\Nuance\dgnsvc.exe

http://www.bleepingcomputer.com/forums/topic400297.html/page__p__2267701__fromsearch__1#entry2267701

More replies

Hi , I keep getting this adobe update thing , I had clicked ok then I get a bynch of optimizer/speed up your computer etc stufff, I ran malware and it got rid of it then the adobe thing keeps coming back  screenshot

cant see the screenshot?  how to post it??

A:think I am infected

26 more replies

hey friends! i wonder what happen to my com. it change my destop pic to none. eventhough i've set my own destop pic, it change it back to black after awhile. what happen ? T.T

A:am i infected?

3 more replies

Logfile of HijackThis v1.99.1Scan saved at 10:14:35 AM, on 6/2/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Yahoo!\Antivirus\ISafe.exeC:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYSC:\WINDOWS\System32\snmp.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Yahoo!\Antivirus\VetMsg.exeC:\WINDOWS\Explorer.EXEC:\PROGRA~1\Grisoft\AVG7\avgcc.exeC:\Program Files\QuickTime\qttask.exeC:\WINDOWS\system32\rundll32.exeC:\PROGRA~1\Yahoo!\browser\ycommon.exeC:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXEC:\Program... Read more

Ok so my bitdefender went down and noone of my shields were active for some reason and i had to reboot to get them back up.. Then eventually i noticed a www.secure.exe running in the background, so im not sure exactly what to do or if anything else is on my maching, of course bd says nothing but ya..Here is my log any help is appreciated.!!

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:56:06 AM, on 9/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\WINDOWS\system32\RUNDLL32.EXE

A:Infected?

Logfile of HijackThis v1.99.1Scan saved at 04:47:11 p.m., on 06/06/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\ARCHIV~1\Grisoft\AVG7\avgamsvr.exeC:\ARCHIV~1\Grisoft\AVG7\avgupsvc.exeC:\ARCHIV~1\Grisoft\AVG7\avgemc.exeC:\WINDOWS\system32\slserv.exeC:\Archivos de programa\Analog Devices\SoundMAX\SMAgent.exeC:\WINDOWS\System32\svchost.exeC:\Archivos de programa\MSN Messenger\usnsvc.exeC:\WINDOWS\system32\svchost.exeC:\Archivos de programa\HJT\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ar.rd.yahoo.com/customize/ie/defaul...earch.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ar.rd.yahoo.com/customize/ie/defaul...earch.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = V?nculosR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-... Read more

A:Infected Pc! Help