We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
Problem with new laptop
Comments
-
Yes that's the right website, let malwarebytes finish first, and ideally you should uninstall mcafee before installing avira!!
> . !!!! ----> .0 -
So once the malwarebytes scan is complete (so far it's found 8 infected objects) and I've downloaded avira and done another scan will this hopefully fix the problem?
Oh and I've gone for the full system scan so I imagine this may take a while....Future Mrs Gerard Butler
[STRIKE]
Team Wagner
[/STRIKE] I meant Team Matt......obviously :cool:0 -
You'll have to wait and see, it's not always virus/malware related. Post what it finds, and let malwarebytes and avira fix it.!!
> . !!!! ----> .0 -
The things that its found are
Adware.MyWebSearch Registry Key
Backdoor.Bot Registry Key
Backdoor.Bot Registry Key
Backdoor.Bot Registry Key
Backdoor.Bot Registry Key
Trojan.Downloader File
Spyware.Zbot File
Spyware.Zbot File
The registry Key and File part is listed under Items
The backdoorbot, Trojan and Spyware are listed udner VendorFuture Mrs Gerard Butler
[STRIKE]
Team Wagner
[/STRIKE] I meant Team Matt......obviously :cool:0 -
To do a complete McAfee uninstall follow these instructions - http://service.mcafee.com/FAQDocument.aspx?lc=2057&id=TS100507
Before installing another antivirus.0 -
Did you tell MalwareBytes to fix what it found.
You then uninstall McAfee as above, install and update Avira and run a scan, and lastly download and run HijackThis, but don't fix anything - just post the log here.0 -
Yeah I uninstalled McAfee ad then installed Avira
I've just run the hijackthis scan
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:25:51, on 07/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Elantech\ETDCtrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\PersistenceThread.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Battery Meter\BTMeter.exe
C:\Program Files\WSED\WSED.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Video Chat\DellVideoChat.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Microsoft Works\WkCalRem.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.uk.msn.com/USCON/2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.uk.msn.com/USCON/2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.uk.msn.com/USCON/2
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://g.uk.msn.com/USCON/2
O1 - Hosts: 87.67.35.128 freemaill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 freemaill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 frimill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 share.ru
O1 - Hosts: 87.67.35.128 frimill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 share.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 87.67.35.128 frimilk.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.181 sexxx.com
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.181 xxx.com
O1 - Hosts: 210.51.10.184 www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandexx.ru
O1 - Hosts: 87.67.35.128 offshare.ru
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [PersistenceThread] C:\WINDOWS\system32\PersistenceThread.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe
O4 - HKLM\..\Run: [WSED] C:\Program Files\WSED\WSED.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [JavaIDE] C:\Program Files\Java\jre1.6.2\java.exe
O4 - HKLM\..\Run: [JavaBin] C:\Program Files\Java\jre1.6.3\java.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SightSpeed] "C:\Program Files\Dell Video Chat\DellVideoChat.exe" -bootmode
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; MDDC; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www.miniclip.com/games/bow-master/en/"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: wkcalrem.LNK = C:\Program Files\Microsoft Works\WkCalRem.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D} (PhotoboxPhotowaysUploader5 Control) - http://assets.photobox.com/assets/aurigma/ImageUploader5.cab?20091001020847
O16 - DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} (DellSystemLite.Scanner) - http://support.euro.dell.com/systemprofiler/DellSystemLite.CAB
O20 - Winlogon Notify: igdlogin - C:\WINDOWS\SYSTEM32\igdlogin.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 11824 bytesFuture Mrs Gerard Butler
[STRIKE]
Team Wagner
[/STRIKE] I meant Team Matt......obviously :cool:0 -
Looks like you have a few hosts file redirects. I would remove (tick and fix) the following:
O1 - Hosts: 87.67.35.128 freemaill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 freemaill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 frimill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 share.ru
O1 - Hosts: 87.67.35.128 frimill.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandex.ru
O1 - Hosts: 87.67.35.128 share.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 87.67.35.128 frimilk.ru
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.184 microsof.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.184 vkontakte.ru
O1 - Hosts: 210.51.10.181 sexxx.com
O1 - Hosts: 210.51.10.184 odnoklassniki.ru
O1 - Hosts: 210.51.10.182 microsoff.com
O1 - Hosts: 210.51.10.181 xxx.com
O1 - Hosts: 210.51.10.184 https://www.vkontakte.ru
O1 - Hosts: 210.51.10.182 hyandexx.ru
O1 - Hosts: 87.67.35.128 offshare.ru
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - c:\PROGRA~1\mcafee\SITEAD~1\mcsacore.exe (file missing)0 -
My god I could just kiss you all :T
Thank you soooooooooo much for your helpFuture Mrs Gerard Butler
[STRIKE]
Team Wagner
[/STRIKE] I meant Team Matt......obviously :cool:0 -
With all those dodgy host entries, I would let malwarebytes, and avira (did you install avast instead) do their scans to clean it up the best they can, and then backup your data to usb stick or external drive, and then put it back to the state it was in when it left the factory by using the restore partition - instructions should be in the manual.!!
> . !!!! ----> .0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 353.5K Banking & Borrowing
- 254.1K Reduce Debt & Boost Income
- 455K Spending & Discounts
- 246.6K Work, Benefits & Business
- 602.9K Mortgages, Homes & Bills
- 178.1K Life & Family
- 260.6K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards