VirusProtect Pro can't be removed from task bar!

Discussion in 'Windows - Virus and spyware problems' started by tcwh1971, Aug 5, 2007.

  1. tcwh1971

    tcwh1971 Member

    Joined:
    Feb 15, 2007
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Hi there,
    I've just joined so I hope I'm in the right section! I hope someone canhelp me out here so here goes. An application has somehow become embedded within my taskbar and won't go away! It's an icon in the shape of a small shield which flashes from a white 'X' on a red shield to a white question mark on a blue shield. The follwoing message appears every few minutes which reads as follows..."System has detected a number of active spyware applications that may impact the performance of your computer. Click hethe icon to get rid of the unwanted spyware by downloading an up-to-date antispyware solution." When I click on it it simply takes me to the site of 'VirusProtect Pro' and wants me to purchase the software. I'd like to know if this is worth doing or should I stay away from it? In any case, I want it removed from my task bar and PC totally and my question is... How can this be done? I already use 'Sybot, AVG and Ad-Aware SE Pro'. It obviously isn't picking up all the junk that's in my PC. But is there an Anti-virus software that actually can do this?

    Hope some one can help!

    Thanks in advance.
     
  2. Auttaja

    Auttaja Guest

    Download Hijackthis ver. 1.99.1 from HERE and save it to your Desktop.
    Double click on the HJTsetup.exe icon on your desktop.
    By default it will install to C:\Program Files\HijackThis.
    Continue to click Next in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
    Put a check by Create a desktop icon then click Next again.
    Continue to follow the rest of the prompts from there.
    At the final dialogue box click Finish and it will launch HijackThis.
    Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
    Copy and paste the log to this topic

    DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
     
  3. tcwh1971

    tcwh1971 Member

    Joined:
    Feb 15, 2007
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Hi as requested pleased find below the log file. Thanks for your help.

    Logfile of HijackThis v1.99.1
    Scan saved at 12:52:34, on 06/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    c:\APPS\HIDSERVICE\HIDSERVICE.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\WINDOWS\ALCWZRD.EXE
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\blueyonder IST\bin\mpbtn.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.adslguide.org/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by blueyonder
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {81A35F39-4850-474E-92C9-B4CF283207E0} - c:\windows\system32\iegfilt.dll (file missing)
    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Trust\3010A WIRELESS DESKSET\Keyboard\kbdap32a.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HdReg] C:\APPS\HDREG\HDREGAPP.EXE -r
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\3010A WIRELESS DESKSET\Mouse\mouse32a.exe
    O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB002" /M "Stylus Photo R300"
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [adiras] adiras.exe
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Office2K\Office\OSA9.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
    O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - http://w4s2.work4sure.com/c/ge/w4sgeen10.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - http://imlive.com/chatsource/ImlCID.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
     
  4. mstetson

    mstetson Member

    Joined:
    Aug 6, 2007
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    11
    I just had the same problem. I then downloaded spyhunter & it removed everything but the annoying popup shield in the task bar. I then went to the following link & downloaded smitfraudfix & followed the instructions & now everything is completely fixed & removed from my system. Wish I had done this yesterday as it was quite simple & quick. Here's the following link & be sure to print off the instructions as you will need to reboot the computer in the process:

    http://www.bleepingcomputer.com/forums/topic98219.html

    Good Luck. The people of Virusprotec Pro should be shut down for good.
     
  5. thegrunt

    thegrunt Regular member

    Joined:
    Jun 4, 2007
    Messages:
    637
    Likes Received:
    0
    Trophy Points:
    26
    I dont know if its a virus or something,but to get it off your taskbar go to start,run,type in msconfig and click ok.Now click the startup tab and look up the name of the program,uncheck it and select apply,then ok.You will need to restart your computer and thats it,hope this helps
     
  6. tcwh1971

    tcwh1971 Member

    Joined:
    Feb 15, 2007
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Thanks to everyone that replied to my problem regarding Virusprotec Pro in particular to mstetson who suuggestion worked a treat!

    Thanks again!
     
  7. Auttaja

    Auttaja Guest

    Nice to hear that u donĀ“t have problems anymore.. I am always litlle pessimistic so I would recommend little more research.

    ========

    Update Java
    Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

    *Download the latest version of Java(TM) SE Runtime Environment 6u2.
    *Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    *Click the "Download" button to the right.
    *Check the box that says: "Accept License Agreement".
    *The page will refresh.
    *Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    *Close any programs you may have running - especially your web browser.
    *Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    *Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    *Click the Remove or Change/Remove button.
    *Repeat as many times as necessary to remove each Java versions.
    *Reboot your computer once all Java components are removed.
    *Then from your desktop double-click on the download to install the newest version.

    =======

    Download and Run ComboFix
    *Download this file from either of the two below listed places :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

    *Then double click combofix.exe & follow the prompts.
    *When finished, it shall produce a log for you. Post that log in your next reply
    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
     
  8. mikerq

    mikerq Member

    Joined:
    Aug 17, 2007
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    11
    I have the same problem as tcwh1971,
    I ran http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    below is the log file, thanks Mikerq
    ComboFix 07-08-14.4 - "miker" 2007-08-17 15:41:10.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2995 [GMT -4:00]


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    D:\Autorun.inf


    ((((((((((((((((((((((((( Files Created from 2007-07-17 to 2007-08-17 )))))))))))))))))))))))))))))))


    2007-08-17 15:40 51,200 --a------ C:\WINDOWS\nircmd.exe
    2007-08-17 13:10 <DIR> d-------- C:\Program Files\Enigma Software Group
    2007-08-17 11:41 63 --a------ C:\WINDOWS\system\SysSD.dll
    2007-08-17 11:41 <DIR> d-------- C:\Program Files\SpywareDetector
    2007-08-11 10:30 <DIR> d-------- C:\Program Files\QuickTime
    2007-08-09 09:07 <DIR> d-------- C:\WorkNC18
    2007-08-09 08:53 <DIR> d-------- C:\Program Files\worknc18.21
    2007-07-27 12:11 <DIR> d-------- C:\UG-data
    2007-07-27 10:39 <DIR> d-------- C:\Program Files\GFI
    2007-07-27 10:39 <DIR> d-------- C:\Program Files\Common Files\GFI
    2007-07-27 10:36 21,504 --a------ C:\WINDOWS\system32\drivers\hidserv.dll
    2007-07-27 10:35 <DIR> d-------- C:\WINDOWS\system32\Data
    2007-07-27 10:34 3,072 --a------ C:\WINDOWS\CTXFIRES.DLL
    2007-07-27 10:34 11,776 --a------ C:\WINDOWS\INRES.DLL
    2007-07-27 09:59 <DIR> d-------- C:\WINDOWS\pss
    2007-07-27 09:46 <DIR> d--hs---- C:\System Recovery
    2007-07-27 09:29 9,715,200 --a------ C:\WINDOWS\RTLCPL.exe
    2007-07-27 09:29 86,016 --a------ C:\WINDOWS\SoundMan.exe
    2007-07-27 09:29 69,632 --a------ C:\WINDOWS\Alcmtr.exe
    2007-07-27 09:29 315,392 --a------ C:\WINDOWS\HideWin.exe
    2007-07-27 09:29 2,808,832 --a------ C:\WINDOWS\alcwzrd.exe
    2007-07-27 09:29 1,826,816 --a------ C:\WINDOWS\SkyTel.exe
    2007-07-26 17:55 2,812 --a------ C:\WINDOWS\system32\tmp.reg
    2007-07-26 17:49 <DIR> d-------- C:\WINDOWS\system32\appmgmt
    2007-07-26 17:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
    2007-07-26 17:25 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
    2007-07-26 13:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2007-07-26 12:14 208,248 --a------ C:\WINDOWS\system32\muweb.dll
    2007-07-26 10:39 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
    2007-07-26 10:22 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    2007-07-18 08:23 <DIR> d-------- C:\Program Files\DivX
    2007-07-18 08:22 80 -r-hs---- C:\WINDOWS\system32\B5C045142D.dll
    2007-07-18 08:22 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Protexis


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-08-17 15:02 --------- d-------- C:\Program Files\Symantec AntiVirus
    2007-08-15 13:13 12288 --a------ C:\WINDOWS\system32\zkpssqa.dll
    2007-07-27 14:38 --------- d-------- C:\Program Files\igstoig
    2007-07-27 10:36 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
    2007-07-27 10:36 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
    2007-07-27 10:33 --------- d-------- \\sbs2k3\profiles$\APPLIC~1\miker\APPLIC~1\Creative
    2007-07-27 10:19 --------- d--h----- C:\Program Files\WindowsUpdate
    2007-07-27 09:49 --------- d-------- C:\Program Files\Windows NT
    2007-07-27 09:49 --------- d-------- C:\Program Files\Visioneer OneTouch
    2007-07-27 09:47 --------- d--h----- C:\Program Files\InstallShield Installation Information
    2007-07-27 09:47 --------- d-------- C:\Program Files\UGS
    2007-07-27 09:47 --------- d-------- C:\Program Files\Symantec
    2007-07-27 09:47 --------- d-------- C:\Program Files\Sony
    2007-07-27 09:47 --------- d-------- C:\Program Files\Snapshot Viewer
    2007-07-27 09:47 --------- d-------- C:\Program Files\SMIRTware
    2007-07-27 09:47 --------- d-------- C:\Program Files\Roxio
    2007-07-27 09:47 --------- d-------- C:\Program Files\Realtek
    2007-07-27 09:47 --------- d-------- C:\Program Files\Rainbow Technologies
    2007-07-27 09:47 --------- d-------- C:\Program Files\Program Shortcuts
    2007-07-27 09:47 --------- d-------- C:\Program Files\PDF Complete
    2007-07-27 09:47 --------- d-------- C:\Program Files\Online Services
    2007-07-27 09:47 --------- d-------- C:\Program Files\MSXML 6.0
    2007-07-27 09:47 --------- d-------- C:\Program Files\MSXML 4.0
    2007-07-27 09:47 --------- d-------- C:\Program Files\MSN Gaming Zone
    2007-07-27 09:47 --------- d-------- C:\Program Files\Movie Maker
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft.NET
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft Works
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft Windows Small Business Server
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft Visual Studio .NET 2003
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft SQL Server
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft Outlook
    2007-07-27 09:47 --------- d-------- C:\Program Files\microsoft frontpage
    2007-07-27 09:47 --------- d-------- C:\Program Files\Microsoft ActiveSync
    2007-07-27 09:47 --------- d-------- C:\Program Files\Messenger
    2007-07-27 09:47 --------- d-------- C:\Program Files\Macrovision Corp
    2007-07-27 09:47 --------- d-------- C:\Program Files\InterVideo
    2007-07-27 09:47 --------- d-------- C:\Program Files\Intel
    2007-07-27 09:47 --------- d-------- C:\Program Files\igtostl
    2007-07-27 09:47 --------- d-------- C:\Program Files\HPQ
    2007-07-27 09:47 --------- d-------- C:\Program Files\HP
    2007-07-27 09:47 --------- d-------- C:\Program Files\Hewlett-Packard Company
    2007-07-27 09:47 --------- d-------- C:\Program Files\Hewlett-Packard
    2007-07-27 09:47 --------- d-------- C:\Program Files\Google
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\Symantec Shared
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\SureThing Shared
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\SpeechEngines
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\Sonic Shared
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\Roxio Shared
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\Privilege
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\ODBC
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\MSSoap
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\LightScribe
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\L&H
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\InterVideo
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\InstallShield
    2007-07-27 09:47 --------- d-------- C:\Program Files\Common Files\Crystal Decisions
    2007-07-27 09:47 --------- d-------- C:\Program Files\Cisco Systems
    2007-07-27 09:47 --------- d-------- C:\Program Files\Broadcom
    2007-07-27 09:47 --------- d-------- C:\Program Files\3Dconnexion
    2007-07-25 14:11 --------- d-------- \\sbs2k3\profiles$\APPLIC~1\miker\APPLIC~1\Sonic
    2007-07-09 15:07 129784 --------- C:\WINDOWS\system32\PxAFS.DLL
    2007-07-05 07:27 --------- d-------- \\sbs2k3\profiles$\APPLIC~1\miker\APPLIC~1\Roxio
    2007-07-03 17:10 --------- d-------- \\sbs2k3\profiles$\APPLIC~1\miker\APPLIC~1\Sony Corporation
    2007-06-20 01:16 --------- d-------- \\sbs2k3\profiles$\APPLIC~1\miker\APPLIC~1\AdobeUM
    2007-06-13 15:49 16377344 --a------ C:\WINDOWS\RTHDCPL.exe


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5DDE5591-A8AB-4897-93EF-1E4E943F85A7}]
    C:\Program Files\Video ActiveX Access\iesplg.dll

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{CC18AE76-7E65-4258-A193-9EA0C52DA6B8}"= C:\Program Files\Video ActiveX Access\iesbpl.dll [ ]

    [HKEY_CLASSES_ROOT\CLSID\{CC18AE76-7E65-4258-A193-9EA0C52DA6B8}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-09-27 20:33]
    "Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-07-10 14:53]
    "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 15:49 C:\WINDOWS\RTHDCPL.exe]
    "Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-03-31 17:44]
    "Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2006-05-12 15:50]
    "PDF Complete"="C:\Program Files\PDF Complete\pdfsty.exe" [2007-02-02 10:43]
    "nwiz"="nwiz.exe" [2006-10-31 10:35 C:\WINDOWS\system32\nwiz.exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-31 10:35]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 19:26]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
    "CTHelper"="CTHELPER.EXE" [2005-11-08 21:30 C:\WINDOWS\CTHELPER.EXE]
    "CTxfiHlp"="CTXFIHLP.EXE" [2005-11-08 21:30 C:\WINDOWS\system32\CTXFIHLP.EXE]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-11 10:30]
    "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2006-02-27 22:00]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-27 22:00]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24]
    "SetDefaultMIDI"="MIDIDef.exe" [2005-11-08 21:12 C:\WINDOWS\MIDIDEF.EXE]

    C:\Documents and Settings\miker\Start Menu\Programs\Startup\
    License Server.lnk - C:\WorkNC18\procdos\runwncbat.bat [2007-08-09 09:08:09]
    Picture Motion Browser Media Check Tool.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-07-03 15:16:48]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    ACT! Speed Loader.lnk - C:\Program Files\Symantec\ACT\ACTLDR.EXE [2007-04-24 13:06:01]
    SideACT!.lnk - C:\Program Files\Symantec\ACT\SideACT.exe [2007-04-24 13:06:07]
    Start 3DxWare.lnk - C:\Program Files\3Dconnexion\3Dconnexion 3DxWare\3dxsrv.exe [2006-07-21 18:54:40]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoWelcomeScreen"=1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "DisablePersonalDirChange"=1 (0x1)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "{d1e5ca97-235e-4ff0-9b92-7543c9d61ff4}"= C:\WINDOWS\system32\zkpssqa.dll [2007-08-15 13:13 12288]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-2405459268-3495583464-2812218850-1143\Scripts\Logon\0\0]
    "Script"=CadCamLogon.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "stllssvr"=3 (0x3)
    "SpywareBotSrv"=2 (0x2)
    "PCA"=2 (0x2)

    R2 pdfcDispatcher;PDF Document Manager;C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService
    S3 Blfp;Broadcom Advanced Server Program Driver;C:\WINDOWS\system32\DRIVERS\baspxp32.sys
    S3 SQLAgent$MICROSOFTBCM;SQLAgent$MICROSOFTBCM;C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE -i MICROSOFTBCM
    S3 VirtDisk;XSS Virtual Disk Driver;\??\C:\WINDOWS\SMINST\VirtDisk.sys


    Contents of the 'Scheduled Tasks' folder
    2007-08-17 07:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job - C:\Program Files\SpywareBot\SpywareBot.exe

    **************************************************************************

    catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-08-17 15:45:19
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\pdfcDispatcher]
    "ImagePath"="C:\Program Files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"

    Completion time: 2007-08-17 15:45:39
    C:\ComboFix-quarantined-files.txt ... 2007-08-17 15:45

    --- E O F ---
     
  9. sandisk

    sandisk Regular member

    Joined:
    Jun 27, 2005
    Messages:
    723
    Likes Received:
    0
    Trophy Points:
    26
    There seems to be lots of this malware going around at the minute. Two friends of mine had similar problems and just couldn't remove the icon from the task bar. The tried all types of anti-virus and spyware removers with no luck but eventually in the end they came across a software call "SuperAntiSpyware" and this removed everything from the pc. Best thing to do is google it and see if there is a free trial.

    Good luck
    Sandisk
     

Share This Page