We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Combo-fix/ Hijack this conflict?

245

Comments

  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 12 November 2010 at 10:52PM
    H. knarf44, 'G' drive is one of my partitions. The only external drive that is plugged in is the Canon printer Card reader which doesn't have a card installed.

    Zentimo is a recent install that frees any external card without having to go thru the usual 'Unplug device' icon on the Toolbar. Iobit360 is a registry cleaner. Both are on drive 'G'.

    here is the latest Malwarebytes log.


    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org
    Database version: 4550
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702
    12/11/2010 22:19:31
    mbam-log-2010-11-12 (22-19-31).txt
    Scan type: Full scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|M:\|N:\|)
    Objects scanned: 396540
    Time elapsed: 1 hour(s), 3 minute(s), 57 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    (No malicious items detected)
    Registry Data Items Infected:
    (No malicious items detected)
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    (No malicious items detected)
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 12 November 2010 at 11:07PM
    Here also is the latest Hijack log.


    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 22:57:35, on 12/11/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    G:\Online Armor\OAcat.exe
    C:\WINDOWS\system32\devldr32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Documents and Settings\Terry\Desktop\Trend Micro\HiJackThis\HiJackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://by150w.bay150.mail.live.com/default.aspx?rru=home&livecom=1&wa=wsignin1.0
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/clipextractor/{A9E3981F-6A11-4EF1-A702-3819AB03CE4F}
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Roboform\roboform.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Roboform\roboform.dll
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [@OnlineArmor GUI] "G:\Online Armor\oaui.exe"
    O4 - HKLM\..\Run: [IObit Security 360] "G:\IObit Security 360\IS360tray.exe" /autostart
    O4 - HKCU\..\Run: [Zentimo xStorage Manager] G:\Zentimo\Zentimo.exe /startup
    O4 - S-1-5-18 Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (User 'SYSTEM')
    O4 - S-1-5-18 Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'SYSTEM')
    O4 - S-1-5-18 Startup: Rightmove Desktop.lnk = L:\rightmove\Rightmove Desktop\Rightmove Desktop.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe (User 'Default user')
    O4 - .DEFAULT Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'Default user')
    O4 - .DEFAULT Startup: Rightmove Desktop.lnk = L:\rightmove\Rightmove Desktop\Rightmove Desktop.exe (User 'Default user')
    O4 - Startup: Alienware Dock.lnk = F:\Program Files\AlienGUIse\AlienwareDock\ObjectDock.exe
    O4 - Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe
    O4 - Startup: Rightmove Desktop.lnk = L:\rightmove\Rightmove Desktop\Rightmove Desktop.exe
    O8 - Extra context menu item: Customize Menu - [URL]file://D:\Roboform\RoboFormComCustomizeIEMenu.html[/URL]
    O8 - Extra context menu item: Fill Forms - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O8 - Extra context menu item: Identities Editor - [URL]file://D:\Roboform\RoboFormComEditIdent.html[/URL]
    O8 - Extra context menu item: Locate Spot on Map by GPS - F:\IExif 2.3\IExifMap.htm
    O8 - Extra context menu item: Password Generator - [URL]file://D:\Roboform\RoboFormComPasswordGenerator.html[/URL]
    O8 - Extra context menu item: RoboForm Toolbar - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O8 - Extra context menu item: Save Forms - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - F:\IExif 2.3\IExifCom.htm
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - [URL]file://D:\Roboform\RoboFormComFillForms.html[/URL]
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - [URL]file://D:\Roboform\RoboFormComSavePass.html[/URL]
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - [URL]file://D:\Roboform\RoboFormComShowToolbar.html[/URL]
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} (first direct internet banking plus digital safe) - https://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab
    O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218797834562
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-31-0.cab
    O20 - Winlogon Notify: !SASWinLogon - G:\SUPERAntiSpyware\SASWINLO.DLL
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - G:\Online Armor\OAcat.exe
    O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - G:\Online Armor\oasrv.exe
    O23 - Service: Zentimo Assistant (ZentimoService) - Unknown owner - G:\Zentimo\ZentimoService.exe
    --
    End of file - 7014 bytes

    Yet Combofix (now properly installed on the desktop) STILL says that A squared anti virus AND Avira anti virus, are still running?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Anyone.........?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • GunJack
    GunJack Posts: 11,896 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    edited 13 November 2010 at 9:51AM
    you still have elements of online armour running.....would be worth looking on their website for a removal tool, similar to those produced for mcafee, norton, avg, etc. Uninstalling av progs never does it completely cleanly, so removing all traces would be the starting point, even if you have to do it manually :(

    p.s. also, eset's online scanner, panda scanner, IOBit are still lurking, same goes for that...
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • Knarf44
    Knarf44 Posts: 557 Forumite
    I assume you use Avira as your anti virus protection or do you use Eset as that appears later in the log, or did you use the online scan facilities for it and Panda.

    What are these? Are they something you use? If not, use Hijack This to fix them or if they appear in add/remove programs uninstall them.

    O4 - S-1-5-18 Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'SYSTEM')
    O4 - Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe


    If you have uninstalled Spybot get HJT to fix this entry too:

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll

    The rest seems ok.
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 13 November 2010 at 11:25AM
    GunJack wrote: »
    you still have elements of online armour running.....would be worth looking on their website for a removal tool, similar to those produced for mcafee, norton, avg, etc. Uninstalling av progs never does it completely cleanly, so removing all traces would be the starting point, even if you have to do it manually :(

    p.s. also, eset's online scanner, panda scanner, IOBit are still lurking, same goes for that...


    But Online armour is my Firewall. Surely I want to KEEP that.

    Shouldn't I be able to turn off Armour, Avira Etc so that when I run Hijack or Combo, they don't appear?

    Uninstalling doesn't make a lot of difference here as a couple of the progs that i uninstalled are still showing up as 'Running'.

    Knarf44 wrote: »
    I assume you use Avira as your anti virus protection or do you use Eset as that appears later in the log, or did you use the online scan facilities for it and Panda.

    What are these? Are they something you use? If not, use Hijack This to fix them or if they appear in add/remove programs uninstall them.

    O4 - S-1-5-18 Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe (User 'SYSTEM')
    O4 - Startup: Moo0 Magnifier 1.09.lnk = C:\Magnifier 1.09\Magnifier.exe


    If you have uninstalled Spybot get HJT to fix this entry too:

    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - I:\SPYBOT~1\SPYBOT~1\SDHelper.dll

    The rest seems ok.

    I haven't uninstalled Spybot as I keep that as part of my arsenal.

    Never heard of ESET (AFAIR). That must have installed when I ran Panda (which went through Cloud, BTW). Would I be wise to remove these as I have done with the online scan now?

    I frequently make use of Mooo Magnifier.

    Surely it can't be OK for Combo-fix to show progs as running when clearly they are not.

    Is there somewhere in the registry that they can be detected and removed?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • GunJack
    GunJack Posts: 11,896 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    eset is an online scanner - even they are online, they often leave hangover traces on your system. If you use a router, windows firewall is adequate. As for turning them off to scan, not all progs are that friendly :(
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Ok. Now that I have scanned then I take it that i would be wise to remove these traces (Eset Etc)

    would just removing them using Hijack be OK?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • spud17
    spud17 Posts: 4,441 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    eset is an online scanner - even they are online, they often leave hangover traces on your system.

    From what I remember, it only runs on IE and installs ActiveX, hence the O16 entry.
    Move along, nothing to see.
  • If you have malwarebytes, I wouldn't bother with spybot.
    Too much armour and you can't move!
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.3K Work, Benefits & Business
  • 601K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.