Help! I have a trojan
Moderator: Thanas
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Help! I have a trojan
I can't use my computer. I'm typing on some hand-held contraption, and could not use search functions. Sorry.
Anyway, mcaffee ain't done shit buy freeze and it says I have a Trojan. It won't do anything. Is there a better program ? What is your advice?
I have a pc with xp on it. Help me. Hel
Anyway, mcaffee ain't done shit buy freeze and it says I have a Trojan. It won't do anything. Is there a better program ? What is your advice?
I have a pc with xp on it. Help me. Hel
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
- General Zod
- Never Shuts Up
- Posts: 29211
- Joined: 2003-11-18 03:08pm
- Location: The Clearance Rack
- Contact:
Re: Help! I have a trojan
A Hijack This! log might be helpful. But without specifics like the name of the virus it's hard to say.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
FakeAlert.JU. Also error loading fiwozero.ddl
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
Re: Help! I have a trojan
I've googled fiwozero.dll and what I got is that it is an infected file. Some sort of Trojan\backdoor. Delete it.Bob the Gunslinger wrote:FakeAlert.JU. Also error loading fiwozero.ddl
ASVS('97)/SDN('03)
"Whilst human alchemists refer to the combustion triangle, some of their orcish counterparts see it as more of a hexagon: heat, fuel, air, laughter, screaming, fun." Dawn of the Dragons
ASSCRAVATS!
"Whilst human alchemists refer to the combustion triangle, some of their orcish counterparts see it as more of a hexagon: heat, fuel, air, laughter, screaming, fun." Dawn of the Dragons
ASSCRAVATS!
- ArmorPierce
- Rabid Monkey
- Posts: 5904
- Joined: 2002-07-04 09:54pm
- Location: Born and raised in Brooklyn, unfornately presently in Jersey
Re: Help! I have a trojan
Try running the computer in safe mode and run a bunch of anti spyware programs like superantispyware, spybot search and destroy. I just went through a few hours today because I got a bunch of shit loaded into my computer plus antivirus system pro which was giving me the biggest problems getting rid of since it kept stopping my from running programs.
Brotherhood of the Monkey @( !.! )@
To give anything less than your best is to sacrifice the gift. ~Steve Prefontaine
Aoccdrnig to rscheearch at an Elingsh uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht frist and lsat ltteer are in the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae we do not raed ervey lteter by it slef but the wrod as a wlohe.
To give anything less than your best is to sacrifice the gift. ~Steve Prefontaine
Aoccdrnig to rscheearch at an Elingsh uinervtisy, it deosn't mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht frist and lsat ltteer are in the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit a porbelm. Tihs is bcuseae we do not raed ervey lteter by it slef but the wrod as a wlohe.
Re: Help! I have a trojan
SuperAntiSpyware is good. So is Malwarebytes Anti-Malware. Last I tried Spybot (almost a year ago), though, it was only much good for cookies, but not the real nasties that hijack your desktop. Maybe it was overhauled?
If The Infinity Program were not a forum, it would be a pie-in-the-sky project.
“Faith is both the prison and the open hand.”— Vienna Teng, "Augustine."
“Faith is both the prison and the open hand.”— Vienna Teng, "Augustine."
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
I have Spybot S&D. I am trying to use it.ArmorPierce wrote:Try running the computer in safe mode and run a bunch of anti spyware programs like superantispyware, spybot search and destroy. I just went through a few hours today because I got a bunch of shit loaded into my computer plus antivirus system pro which was giving me the biggest problems getting rid of since it kept stopping my from running programs.
Forgive my totally stupid question here, but how do I start the computer in safe mode?
PS: I am using it right now while attempting to get Spybot to work, but it ended up "Not Responding." The computer is slow as hell and doesn't like to run programs right now.
Also, how do I delete the fiwo file?
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
Also, should I consider all of my passwords, personal information and even credit card numbers stolen? Should I start working to protect my identity? I thought I'd been pretty safe with the computer, but I just found out that we might have been storing some sensitive info on it somewhere.
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
- Archaic`
- Jedi Council Member
- Posts: 1647
- Joined: 2002-10-01 01:19am
- Location: Brisbane, Australia
- Contact:
Re: Help! I have a trojan
Before you start panicking, I'd suggest running the BitDefender online scanner. Normally, I'd suggest Kaspersky, but their one is down currently.
Run it from a Google Chrome window if you've got that installed, Firefox or Opera for preference if you don't. I expect you'll probably turn up quite a lot there. I'd suggest not turning off the computer at all from this point on until we're able to stop you getting reinfected on boot, though you can remove yourself from the internet when not around. After BitDefender has found and removed what it can, get HijackThis and give us all a log to check. We might be able to identify a few nasties and prevent them from reinfecting you when you do restart the computer.
You've already noted you use McAfee (yuck) for Anti-Virus. What do you use for a Firewall? Just the inbuilt? If you're having issues with things like this (and from the sounds of it, you've got multiple users for this computer as well), I'd suggest going with one of the free firewalls which scored an Excellent rating here.
Run it from a Google Chrome window if you've got that installed, Firefox or Opera for preference if you don't. I expect you'll probably turn up quite a lot there. I'd suggest not turning off the computer at all from this point on until we're able to stop you getting reinfected on boot, though you can remove yourself from the internet when not around. After BitDefender has found and removed what it can, get HijackThis and give us all a log to check. We might be able to identify a few nasties and prevent them from reinfecting you when you do restart the computer.
You've already noted you use McAfee (yuck) for Anti-Virus. What do you use for a Firewall? Just the inbuilt? If you're having issues with things like this (and from the sounds of it, you've got multiple users for this computer as well), I'd suggest going with one of the free firewalls which scored an Excellent rating here.
Veni Vidi Castravi Illegitimos
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
Okay, so I used safe start to run spybot, which found a bunch of trojans, mostly virtumonde (Spybot thought we would need help to get rid of this, and it still isn't gone, apparently). We uninstalled McAffe since it wasn't fucking working, but it was slowing the computer down so much that we couldn't even use the internet.
Then we restarted the computer so that we could go to bit defender, and after Spybot's scan (which found virtumonde again) we immediately experienced some random pop-ups. Bit Defender's online scan found one item, litunude.dll - Gen:Trojan.Heur.TDSS.cu4@haXEXRmi. Archaic, you mentioned that Bit defender would "do what it could", but it only scanned. So we downloaded their antivirus but we haven't restarted because you told us not to. The anti-virus says it won't work unless we restart.
We did download HijackThis, though, and in the next post I will post our log. It's long.
PS our firewall was whatever McAffee provided...Now it's gone. We'll replace it as soon as we can.
Then we restarted the computer so that we could go to bit defender, and after Spybot's scan (which found virtumonde again) we immediately experienced some random pop-ups. Bit Defender's online scan found one item, litunude.dll - Gen:Trojan.Heur.TDSS.cu4@haXEXRmi. Archaic, you mentioned that Bit defender would "do what it could", but it only scanned. So we downloaded their antivirus but we haven't restarted because you told us not to. The anti-virus says it won't work unless we restart.
We did download HijackThis, though, and in the next post I will post our log. It's long.
PS our firewall was whatever McAffee provided...Now it's gone. We'll replace it as soon as we can.
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:21:27 AM, on 11/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BDWizReg] "C:\Program Files\BitDefender\BitDefender 2010\bdwizreg.exe" /complete
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O20 - AppInit_DLLs: windows\system32\fiwozero.dll niwaluyu.dll c:\windows\system32\weziroze.dll
O21 - SSODL: dewufeseh - {363a07a8-8891-491d-8f07-586d815482a6} - c:\windows\system32\fiwozero.dll (file missing)
O21 - SSODL: ruzuhopew - {fc513b95-f004-4a42-934f-68eb081547ae} - c:\windows\system32\weziroze.dll
O22 - SharedTaskScheduler: mujuzedij - {363a07a8-8891-491d-8f07-586d815482a6} - c:\windows\system32\fiwozero.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {fc513b95-f004-4a42-934f-68eb081547ae} - c:\windows\system32\weziroze.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\rthlpsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
--
End of file - 11632 bytes
Scan saved at 3:21:27 AM, on 11/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE= ... pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [eFax 4.2] "C:\Program Files\eFax Messenger 4.2\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [BDWizReg] "C:\Program Files\BitDefender\BitDefender 2010\bdwizreg.exe" /complete
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMe ... loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O20 - AppInit_DLLs: windows\system32\fiwozero.dll niwaluyu.dll c:\windows\system32\weziroze.dll
O21 - SSODL: dewufeseh - {363a07a8-8891-491d-8f07-586d815482a6} - c:\windows\system32\fiwozero.dll (file missing)
O21 - SSODL: ruzuhopew - {fc513b95-f004-4a42-934f-68eb081547ae} - c:\windows\system32\weziroze.dll
O22 - SharedTaskScheduler: mujuzedij - {363a07a8-8891-491d-8f07-586d815482a6} - c:\windows\system32\fiwozero.dll (file missing)
O22 - SharedTaskScheduler: kupuhivus - {fc513b95-f004-4a42-934f-68eb081547ae} - c:\windows\system32\weziroze.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.6\rthlpsvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe
--
End of file - 11632 bytes
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
- Bob the Gunslinger
- Has not forgotten the face of his father
- Posts: 4760
- Joined: 2004-01-08 06:21pm
- Location: Somewhere out west
Re: Help! I have a trojan
Oh, and it turns out we had Norton Personal Firewall. Not any more.
"Gunslinger indeed. Quick draw, Bob. Quick draw." --Count Chocula
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett
"Unquestionably, Dr. Who is MUCH lighter in tone than WH40K. But then, I could argue the entirety of WWII was much lighter in tone than WH40K." --Broomstick
"This is ridiculous. I look like the Games Workshop version of a Jedi Knight." --Harry Dresden, Changes
"Like...are we canonical?" --Aaron Dembski-Bowden to Dan Abnett