We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
The MSE Forum Team would like to wish you all a Merry Christmas. However, we know this time of year can be difficult for some. If you're struggling during the festive period, here's a list of organisations that might be able to help
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Has MSE helped you to save or reclaim money this year? Share your 2025 MoneySaving success stories!
HELP!!! Trojan and backdoor virus on my pc
Comments
-
You are right in your interpretation of what you saw; it was a website pretending to show you infected files etc. It wasn't a cruel joke, though - the aim is to get you to download their "antivirus" software which, quite often, is malware itself.
My wife encounters these regularly when she's looking for crafting materials - they are quite carefully targeted at users who will panic and take whatever advice appears on the screen.
As long as you didn't download anything (and it looks like you didn't, judging by the MWB scan) you've had a lesson, but no harm done.
I don't have as much experience of Hijack This as some other users, so hang on for a more expert assessment, but don't panic; I don't think there's any need for system wipes or returning to PCWorld.
You might want to think about changing from AVG to Avast which is better at intercepting websites like this when you try to connect to them.
Oh, and don't do any more banking until someone's given you the OK on the HT log!I'm dreaming of a white Christmas.
But, if the white runs out, I'll drink the red.0 -
OP i have had the exact same problem as you - with the website saying you have a virus that looks like the message is coming from your computer.
As soon as it came up i knew it was very iffy and immediately shut down my computer and reset the system to a earlier date and it appeared to have gone.
Ive been following the advice on here (in my own post) and the guys have been brilliant. But unfortanetly mine is still showing massive problems. So im still trying to sort it out : (
Dont have any advice as am needing it myself lol, but just thought i'd let you know that the same thing has happened to others!0 -
Hi all! Thank you all for your advice and support. Rik you have been brilliant.
I've scan my comp with SUPERAntiSpyware (full scan) and it found over 1200 Adware. Tracking Cookie and 1 Trojan. Quarantined and destroyed files and then ran a full scan again. 104 Adware. Tracking Cookies.
Next I tried DrWeb - found nothing.
Ran SuperAntiSpyware for a 3rd time - found 16.
Next tried CCleaner. Clicked scan for issues - no issues were found. Not 100% sure how to use CCleaner.
WhiteChristmas - have you had backdoor viruses on your comp? If so, are you safe now to continue using online banking or anything else? Will have a look at Avast.
LouLou - I've been following your progress. I hope your pc gets well soon. Unfortunately, I panicked and did click things but didn't download (pressed x in corner of iffy looking pop up box).0 -
interlcore wrote: »Hi all! Thank you all for your advice and support. Rik you have been brilliant.
I've scan my comp with SUPERAntiSpyware (full scan) and it found over 1200 Adware. Tracking Cookie and 1 Trojan. Quarantined and destroyed files and then ran a full scan again. 104 Adware. Tracking Cookies.
Next I tried DrWeb - found nothing.
Ran SuperAntiSpyware for a 3rd time - found 16.
Next tried CCleaner. Clicked scan for issues - no issues were found. Not 100% sure how to use CCleaner.
WhiteChristmas - have you had backdoor viruses on your comp? If so, are you safe now to continue using online banking or anything else? Will have a look at Avast.
LouLou - I've been following your progress. I hope your pc gets well soon. Unfortunately, I panicked and did click things but didn't download (pressed x in corner of iffy looking pop up box).
CCleaner will just remove your web browsing and such like unless you do a registry scan - do one of these and select fix issues. But back up a copy of what it shows you and if possible post a log of that.
did you update Mbam? Because your version is a few out of date still. Do that after you have done the ccleaner bit then run a scan on mbam again."If you no longer go for a gap, you are no longer a racing driver" - Ayrton Senna0 -
Hi! I gave up on CCleaner because I couldn't understand how to get it to work.
The MalwareBytes I have is the 1.50.1 version.0 -
interlcore wrote: »Hi! I gave up on CCleaner because I couldn't understand how to get it to work.
The MalwareBytes I have is the 1.50.1 version.
Open up ccleaner and it will go to the first thing which is to scan for your crap(it was called carp cleaner at first) then once done click on registry and scan for issues.. then once done Id say delete but make sure you say yes to back up.
then update Malwarebytes as im on 5566 and your a few behind that.. then run Mbam again to a full scan..
Im not too !!!! hot on what you get via personal PCs as mine is linked to a secure server but do that and see how much it cleans.. your registry will be loaded with crap"If you no longer go for a gap, you are no longer a racing driver" - Ayrton Senna0 -
Please run COMBOFIX
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Shut down your anti virus
Follow the simple instructions it gives
Post the COMPLETE log it creates here (Split into sections if need be) ~ if there are loads of 'SNAPSHOT' pages then leave them out
If it comes up with a RENAMING error then RIGHT click the exe file and RENAME and call it QWERTY (Making the complete file name 'QWERTY.exe') Or SAVE as 'QWERTY' on download
(If no log comes up or you lose it, COMBOFIX.TXT can be found in C drive)
After posting the log rerun and post a fresh hijack this log:idea:0 -
ComboFix 11-01-21.03 - Jones 22/01/2011 11:29:00.1.4 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2815.1932 [GMT 0:00]
Running from: c:\users\Jones\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-12-22 to 2011-01-22 )))))))))))))))))))))))))))))))
.
2011-01-22 11:33 . 2011-01-22 11:33
d
w- c:\users\Default\AppData\Local\temp
2011-01-22 08:00 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{109D2D94-D862-4589-9179-638135002BFD}\mpengine.dll
2011-01-21 15:55 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
2011-01-21 15:49 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
2011-01-21 15:48 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2011-01-21 15:20 . 2011-01-21 15:20
d
w- c:\program files\CCleaner
2011-01-21 10:21 . 2011-01-21 10:21
d
w- c:\programdata\SUPERAntiSpyware.com
2011-01-21 10:21 . 2011-01-21 10:21
d
w- c:\program files\SUPERAntiSpyware
2011-01-21 09:38 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-01-21 09:38 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-01-21 09:38 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-01-21 09:36 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
2011-01-21 09:10 . 2011-01-21 02:00
d
w- c:\windows\Panther
2011-01-21 09:03 . 2011-01-21 01:41
d
w- C:\$WINDOWS.~Q
2011-01-21 08:57 . 2011-01-21 09:00
d
w- C:\$INPLACE.~TR
2011-01-21 02:05 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
2011-01-21 02:05 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
2011-01-21 02:04 . 2011-01-22 11:22
d
w- c:\windows\system32\wbem\Performance
2011-01-21 02:04 . 2009-11-25 12:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-21 02:04 . 2009-11-25 12:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-21 02:04 . 2009-11-25 12:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-21 02:04 . 2009-11-25 12:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-21 02:04 . 2009-11-25 12:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-21 01:32 . 2011-01-21 01:32
d
w- c:\users\Default\AppData\Local\Microsoft Help
2011-01-21 01:14 . 2011-01-21 02:01
d
w- c:\users\Jones
2011-01-21 01:14 . 2011-01-21 16:44
d
w- c:\users\Jordan
2011-01-21 01:14 . 2011-01-21 12:21
d
w- c:\users\Wayne
2011-01-21 01:13 . 2009-08-08 16:46 485920 ----a-w- c:\windows\system32\nvuninst.exe
2011-01-21 01:12 . 2011-01-21 01:12
d
w- c:\windows\system32\RTCOM
2011-01-21 01:12 . 2011-01-21 01:12
d
w- c:\program files\Realtek
2011-01-21 01:12 . 2011-01-21 01:19
d
w- c:\programdata\HP
2011-01-21 01:12 . 2009-04-16 13:08 312832 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70v.dll
2011-01-20 22:20 . 2011-01-21 01:18
d
w- c:\program files\hi
2011-01-20 20:06 . 2011-01-21 01:19
d
w- c:\programdata\Malwarebytes
2011-01-20 20:06 . 2010-12-20 18:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-20 20:06 . 2011-01-21 18:06
d
w- c:\program files\Malwarebytes' Anti-Malware
2011-01-20 20:06 . 2010-12-20 18:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-20 19:58 . 2011-01-21 01:18
d
w- c:\program files\FileHippo.com
2011-01-20 19:07 . 2011-01-20 19:07
d
w- C:\$AVG
2011-01-13 10:46 . 2011-01-13 10:46
d
w- C:\5a1d244efcba45b7071193
2011-01-07 10:05 . 2011-01-07 10:09 57344 ----a-w- c:\temp\clipstreamsa.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-11 17:03 . 2010-12-11 17:03 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-12-10 11:05 . 2010-12-10 11:05 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2010-12-10 11:04 . 2010-12-10 11:04 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2010-11-29 17:38 . 2010-11-29 17:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 17:38 . 2010-11-29 17:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-19 13:32 . 2010-11-19 13:32 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2010-11-19 13:32 . 2010-11-19 13:32 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2010-11-19 13:32 . 2010-11-19 13:32 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2010-11-12 18:53 . 2010-04-20 15:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2004-11-11 16:36 . 2004-11-11 16:36 1020416 ----a-w- c:\program files\PSCore3.dll
2004-11-11 16:36 . 2004-11-11 16:36 92160 ----a-w- c:\program files\PSSourceFilter3.dll
2004-11-11 16:36 . 2004-11-11 16:36 901120 ----a-w- c:\program files\MSRAAutoFix.dll
2004-11-11 16:36 . 2004-11-11 16:36 77312 ----a-w- c:\program files\PSPublish.dll
2004-11-11 16:36 . 2004-11-11 16:36 78848 ----a-w- c:\program files\CabinetDll3.dll
2004-11-11 16:36 . 2004-11-11 16:36 76800 ----a-w- c:\program files\bandexpander.dll
2004-11-11 16:36 . 2004-11-11 16:36 71680 ----a-w- c:\program files\PSTransitionFilter.dll
2004-11-11 16:36 . 2004-11-11 16:36 49664 ----a-w- c:\program files\PSDMusicDMO.dll
2004-11-11 16:36 . 2004-11-11 16:36 41984 ----a-w- c:\program files\WavDest3.dll
2004-11-11 16:36 . 2004-11-11 16:36 102912 ----a-w- c:\program files\PhotoStory3.exe
2004-09-17 19:00 . 2004-09-17 19:00 31440 ----a-w- c:\program files\PSLegitCheck.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-01-13 2424560]
"BrowserChoice"="c:\windows\System32\browserchoice.exe" [2010-02-11 293376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2010-06-26 167936]
"HostManager"="c:\program files\Common Files\AOL\1269802939\ee\AOLSoftware.exe" [2008-06-24 41824]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 136176]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-21 1343400]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S4 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
S4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
S4 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
S4 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [x]
S4 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S4 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
--- Other Services/Drivers In Memory ---
*Deregistered* - Avgldx86
*Deregistered* - MBAMSwissArmy
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2011-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
2011-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
.
.
Supplementary Scan
.
uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-661756199.sherlockholmes.openmediagateway.com - c:\program files\Microsoft Silverlight\4.0.50401.0\Silverlight.Configuration.exe
.
LOCKED REGISTRY KEYS
[HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
[HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
DLLs Loaded Under Running Processes
- - - - - - - > 'Explorer.exe'(3620)
c:\users\Jones\AppData\Local\FLVService\lib\FLVSrvLib.dll
.
Completion time: 2011-01-22 11:34:34
ComboFix-quarantined-files.txt 2011-01-22 11:34
Pre-Run: 235,750,735,872 bytes free
Post-Run: 235,321,696,256 bytes free
- - End Of File - - 4E509F6ADF604BBEFFAEAE809088358C0 -
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:50:49, on 22/01/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Freecorder\FLVSrvc.exe
C:\Program Files\Common Files\AOL\1269802939\ee\aolsoftware.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Program Files\hi\Trend Micro\HiJackThis\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://medion.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Trellian &Toolbar - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
O3 - Toolbar: AOL Broadband Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1269802939\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing)
O9 - Extra 'Tools' menuitem: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing)
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
--
End of file - 8470 bytes0 -
Jeff_Bridges_hair wrote: »Open up ccleaner and it will go to the first thing which is to scan for your crap(it was called carp cleaner at first) then once done click on registry and scan for issues.. then once done Id say delete but make sure you say yes to back up.
then update Malwarebytes as im on 5566 and your a few behind that.. then run Mbam again to a full scan..
Im not too !!!! hot on what you get via personal PCs as mine is linked to a secure server but do that and see how much it cleans.. your registry will be loaded with crap
I can't seem to find the 5566 version or MalwareBytes. Have you a direct link?
Either I have no nasties found or I can't get CCleaner to scan. Nothing comes up. I clicked on Registry and Scan for Issues but I no idea what it all means. It's come back with a mixture of Missing Shared DLLs, Unused file extenstions, Invalid Default Icon, Open with application Issue, ActiveX Com issue, Missing TypeLib Reference, Installer Reference Issue (lots of these) and Obsolete software key. I clicked Fix selected issues and said yes to backup.0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 352.9K Banking & Borrowing
- 253.9K Reduce Debt & Boost Income
- 454.7K Spending & Discounts
- 246K Work, Benefits & Business
- 602.1K Mortgages, Homes & Bills
- 177.8K Life & Family
- 259.9K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards