We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

The MSE Forum Team would like to wish you all a Merry Christmas. However, we know this time of year can be difficult for some. If you're struggling during the festive period, here's a list of organisations that might be able to help
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Has MSE helped you to save or reclaim money this year? Share your 2025 MoneySaving success stories!

HELP!!! Trojan and backdoor virus on my pc

1356

Comments

  • You are right in your interpretation of what you saw; it was a website pretending to show you infected files etc. It wasn't a cruel joke, though - the aim is to get you to download their "antivirus" software which, quite often, is malware itself.

    My wife encounters these regularly when she's looking for crafting materials - they are quite carefully targeted at users who will panic and take whatever advice appears on the screen.

    As long as you didn't download anything (and it looks like you didn't, judging by the MWB scan) you've had a lesson, but no harm done.

    I don't have as much experience of Hijack This as some other users, so hang on for a more expert assessment, but don't panic; I don't think there's any need for system wipes or returning to PCWorld.

    You might want to think about changing from AVG to Avast which is better at intercepting websites like this when you try to connect to them.

    Oh, and don't do any more banking until someone's given you the OK on the HT log!
    I'm dreaming of a white Christmas.
    But, if the white runs out, I'll drink the red.

  • loulou123
    loulou123 Posts: 1,183 Forumite
    OP i have had the exact same problem as you - with the website saying you have a virus that looks like the message is coming from your computer.

    As soon as it came up i knew it was very iffy and immediately shut down my computer and reset the system to a earlier date and it appeared to have gone.

    Ive been following the advice on here (in my own post) and the guys have been brilliant. But unfortanetly mine is still showing massive problems. So im still trying to sort it out : (

    Dont have any advice as am needing it myself lol, but just thought i'd let you know that the same thing has happened to others!
  • interlcore
    interlcore Posts: 198 Forumite
    edited 21 January 2011 at 3:43PM
    Hi all! Thank you all for your advice and support. Rik you have been brilliant.
    I've scan my comp with SUPERAntiSpyware (full scan) and it found over 1200 Adware. Tracking Cookie and 1 Trojan. Quarantined and destroyed files and then ran a full scan again. 104 Adware. Tracking Cookies.
    Next I tried DrWeb - found nothing.
    Ran SuperAntiSpyware for a 3rd time - found 16.
    Next tried CCleaner. Clicked scan for issues - no issues were found. Not 100% sure how to use CCleaner.

    WhiteChristmas - have you had backdoor viruses on your comp? If so, are you safe now to continue using online banking or anything else? Will have a look at Avast.

    LouLou - I've been following your progress. I hope your pc gets well soon. Unfortunately, I panicked and did click things but didn't download (pressed x in corner of iffy looking pop up box).
  • Jeff_Bridges_hair
    Jeff_Bridges_hair Posts: 6,330 Forumite
    edited 21 January 2011 at 4:30PM
    interlcore wrote: »
    Hi all! Thank you all for your advice and support. Rik you have been brilliant.
    I've scan my comp with SUPERAntiSpyware (full scan) and it found over 1200 Adware. Tracking Cookie and 1 Trojan. Quarantined and destroyed files and then ran a full scan again. 104 Adware. Tracking Cookies.
    Next I tried DrWeb - found nothing.
    Ran SuperAntiSpyware for a 3rd time - found 16.
    Next tried CCleaner. Clicked scan for issues - no issues were found. Not 100% sure how to use CCleaner.

    WhiteChristmas - have you had backdoor viruses on your comp? If so, are you safe now to continue using online banking or anything else? Will have a look at Avast.

    LouLou - I've been following your progress. I hope your pc gets well soon. Unfortunately, I panicked and did click things but didn't download (pressed x in corner of iffy looking pop up box).

    CCleaner will just remove your web browsing and such like unless you do a registry scan - do one of these and select fix issues. But back up a copy of what it shows you and if possible post a log of that.

    did you update Mbam? Because your version is a few out of date still. Do that after you have done the ccleaner bit then run a scan on mbam again.
    "If you no longer go for a gap, you are no longer a racing driver" - Ayrton Senna
  • Hi! I gave up on CCleaner because I couldn't understand how to get it to work.
    The MalwareBytes I have is the 1.50.1 version.
  • interlcore wrote: »
    Hi! I gave up on CCleaner because I couldn't understand how to get it to work.
    The MalwareBytes I have is the 1.50.1 version.


    Open up ccleaner and it will go to the first thing which is to scan for your crap(it was called carp cleaner at first) then once done click on registry and scan for issues.. then once done Id say delete but make sure you say yes to back up.

    then update Malwarebytes as im on 5566 and your a few behind that.. then run Mbam again to a full scan..


    Im not too !!!! hot on what you get via personal PCs as mine is linked to a secure server but do that and see how much it cleans.. your registry will be loaded with crap
    "If you no longer go for a gap, you are no longer a racing driver" - Ayrton Senna
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Please run COMBOFIX
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Shut down your anti virus
    Follow the simple instructions it gives
    Post the COMPLETE log it creates here (Split into sections if need be) ~ if there are loads of 'SNAPSHOT' pages then leave them out
    If it comes up with a RENAMING error then RIGHT click the exe file and RENAME and call it QWERTY (Making the complete file name 'QWERTY.exe') Or SAVE as 'QWERTY' on download
    (If no log comes up or you lose it, COMBOFIX.TXT can be found in C drive)


    After posting the log rerun and post a fresh hijack this log
    :idea:
  • ComboFix 11-01-21.03 - Jones 22/01/2011 11:29:00.1.4 - x86
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2815.1932 [GMT 0:00]
    Running from: c:\users\Jones\Desktop\ComboFix.exe
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ((((((((((((((((((((((((( Files Created from 2010-12-22 to 2011-01-22 )))))))))))))))))))))))))))))))
    .
    2011-01-22 11:33 . 2011-01-22 11:33
    d
    w- c:\users\Default\AppData\Local\temp
    2011-01-22 08:00 . 2011-01-13 09:41 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{109D2D94-D862-4589-9179-638135002BFD}\mpengine.dll
    2011-01-21 15:55 . 2009-09-10 05:52 257024 ----a-w- c:\windows\system32\msv1_0.dll
    2011-01-21 15:49 . 2010-02-11 07:10 293376 ----a-w- c:\windows\system32\browserchoice.exe
    2011-01-21 15:48 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
    2011-01-21 15:20 . 2011-01-21 15:20
    d
    w- c:\program files\CCleaner
    2011-01-21 10:21 . 2011-01-21 10:21
    d
    w- c:\programdata\SUPERAntiSpyware.com
    2011-01-21 10:21 . 2011-01-21 10:21
    d
    w- c:\program files\SUPERAntiSpyware
    2011-01-21 09:38 . 2010-02-27 07:32 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
    2011-01-21 09:38 . 2010-02-27 07:32 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
    2011-01-21 09:38 . 2010-02-27 07:32 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-01-21 09:36 . 2010-10-20 03:00 2327552 ----a-w- c:\windows\system32\win32k.sys
    2011-01-21 09:10 . 2011-01-21 02:00
    d
    w- c:\windows\Panther
    2011-01-21 09:03 . 2011-01-21 01:41
    d
    w- C:\$WINDOWS.~Q
    2011-01-21 08:57 . 2011-01-21 09:00
    d
    w- C:\$INPLACE.~TR
    2011-01-21 02:05 . 2009-12-29 06:55 172032 ----a-w- c:\windows\system32\wintrust.dll
    2011-01-21 02:05 . 2010-01-09 06:52 132608 ----a-w- c:\windows\system32\cabview.dll
    2011-01-21 02:04 . 2011-01-22 11:22
    d
    w- c:\windows\system32\wbem\Performance
    2011-01-21 02:04 . 2009-11-25 12:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2011-01-21 02:04 . 2009-11-25 12:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
    2011-01-21 02:04 . 2009-11-25 12:47 297808 ----a-w- c:\windows\system32\mscoree.dll
    2011-01-21 02:04 . 2009-11-25 12:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
    2011-01-21 02:04 . 2009-11-25 12:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
    2011-01-21 01:32 . 2011-01-21 01:32
    d
    w- c:\users\Default\AppData\Local\Microsoft Help
    2011-01-21 01:14 . 2011-01-21 02:01
    d
    w- c:\users\Jones
    2011-01-21 01:14 . 2011-01-21 16:44
    d
    w- c:\users\Jordan
    2011-01-21 01:14 . 2011-01-21 12:21
    d
    w- c:\users\Wayne
    2011-01-21 01:13 . 2009-08-08 16:46 485920 ----a-w- c:\windows\system32\nvuninst.exe
    2011-01-21 01:12 . 2011-01-21 01:12
    d
    w- c:\windows\system32\RTCOM
    2011-01-21 01:12 . 2011-01-21 01:12
    d
    w- c:\program files\Realtek
    2011-01-21 01:12 . 2011-01-21 01:19
    d
    w- c:\programdata\HP
    2011-01-21 01:12 . 2009-04-16 13:08 312832 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70v.dll
    2011-01-20 22:20 . 2011-01-21 01:18
    d
    w- c:\program files\hi
    2011-01-20 20:06 . 2011-01-21 01:19
    d
    w- c:\programdata\Malwarebytes
    2011-01-20 20:06 . 2010-12-20 18:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-01-20 20:06 . 2011-01-21 18:06
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2011-01-20 20:06 . 2010-12-20 18:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-01-20 19:58 . 2011-01-21 01:18
    d
    w- c:\program files\FileHippo.com
    2011-01-20 19:07 . 2011-01-20 19:07
    d
    w- C:\$AVG
    2011-01-13 10:46 . 2011-01-13 10:46
    d
    w- C:\5a1d244efcba45b7071193
    2011-01-07 10:05 . 2011-01-07 10:09 57344 ----a-w- c:\temp\clipstreamsa.dll
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-12-11 17:03 . 2010-12-11 17:03 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
    2010-12-10 11:05 . 2010-12-10 11:05 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
    2010-12-10 11:04 . 2010-12-10 11:04 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
    2010-11-29 17:38 . 2010-11-29 17:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-11-29 17:38 . 2010-11-29 17:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-11-19 13:32 . 2010-11-19 13:32 2594584 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
    2010-11-19 13:32 . 2010-11-19 13:32 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
    2010-11-19 13:32 . 2010-11-19 13:32 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
    2010-11-12 18:53 . 2010-04-20 15:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2004-11-11 16:36 . 2004-11-11 16:36 1020416 ----a-w- c:\program files\PSCore3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 92160 ----a-w- c:\program files\PSSourceFilter3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 901120 ----a-w- c:\program files\MSRAAutoFix.dll
    2004-11-11 16:36 . 2004-11-11 16:36 77312 ----a-w- c:\program files\PSPublish.dll
    2004-11-11 16:36 . 2004-11-11 16:36 78848 ----a-w- c:\program files\CabinetDll3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 76800 ----a-w- c:\program files\bandexpander.dll
    2004-11-11 16:36 . 2004-11-11 16:36 71680 ----a-w- c:\program files\PSTransitionFilter.dll
    2004-11-11 16:36 . 2004-11-11 16:36 49664 ----a-w- c:\program files\PSDMusicDMO.dll
    2004-11-11 16:36 . 2004-11-11 16:36 41984 ----a-w- c:\program files\WavDest3.dll
    2004-11-11 16:36 . 2004-11-11 16:36 102912 ----a-w- c:\program files\PhotoStory3.exe
    2004-09-17 19:00 . 2004-09-17 19:00 31440 ----a-w- c:\program files\PSLegitCheck.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
    "FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2010-08-09 248832]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
    "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-01-13 2424560]
    "BrowserChoice"="c:\windows\System32\browserchoice.exe" [2010-02-11 293376]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-20 7625248]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
    "Freecorder FLV Service"="c:\program files\Freecorder\FLVSrvc.exe" [2010-06-26 167936]
    "HostManager"="c:\program files\Common Files\AOL\1269802939\ee\AOLSoftware.exe" [2008-06-24 41824]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "EnableUIADesktopToggle"= 0 (0x0)
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 136176]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-01-21 1343400]
    S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
    S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
    S4 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\AVGIDSDriver.Sys [x]
    S4 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [x]
    S4 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\DRIVERS\AVGIDSFilter.Sys [x]
    S4 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\AVGIDSShim.Sys [x]
    S4 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
    S4 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]

    --- Other Services/Drivers In Memory ---
    *Deregistered* - Avgldx86
    *Deregistered* - MBAMSwissArmy
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    .
    Contents of the 'Scheduled Tasks' folder
    2011-01-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
    2011-01-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-06-07 09:45]
    .
    .
    Supplementary Scan
    .
    uSearchURL,(Default) = hxxp://search.aol.co.uk/web?isinit=true&query=%s
    IE: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4
    .
    - - - - ORPHANS REMOVED - - - -
    Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    AddRemove-661756199.sherlockholmes.openmediagateway.com - c:\program files\Microsoft Silverlight\4.0.50401.0\Silverlight.Configuration.exe

    .
    LOCKED REGISTRY KEYS
    [HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    [HKEY_USERS\S-1-5-21-2391137309-2146828521-3579586563-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'Explorer.exe'(3620)
    c:\users\Jones\AppData\Local\FLVService\lib\FLVSrvLib.dll
    .
    Completion time: 2011-01-22 11:34:34
    ComboFix-quarantined-files.txt 2011-01-22 11:34
    Pre-Run: 235,750,735,872 bytes free
    Post-Run: 235,321,696,256 bytes free
    - - End Of File - - 4E509F6ADF604BBEFFAEAE809088358C
  • Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 11:50:49, on 22/01/2011
    Platform: Windows 7 (WinNT 6.00.3504)
    MSIE: Internet Explorer v8.00 (8.00.7600.16700)
    Boot mode: Normal
    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    C:\Program Files\Freecorder\FLVSrvc.exe
    C:\Program Files\Common Files\AOL\1269802939\ee\aolsoftware.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
    C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
    C:\Windows\system32\wuauclt.exe
    C:\Windows\Explorer.exe
    C:\Program Files\hi\Trend Micro\HiJackThis\HiJackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://medion.msn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Trellian BHO Impl - {24180B00-2EB6-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: Trellian &Toolbar - {71AAABE5-1F0F-11d7-BD6F-004854603DCE} - C:\Program Files\TRELLIAN\Toolbar\toolbar.dll
    O3 - Toolbar: AOL Broadband Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Broadband Toolbar 5.0\aoltb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Freecorder FLV Service] "C:\Program Files\Freecorder\FLVSrvc.exe" /run
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1269802939\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol broadband toolbar 5.0\resources\en-GB\local\search.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
    O9 - Extra button: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing)
    O9 - Extra 'Tools' menuitem: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing)
    O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    O9 - Extra button: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: eBay.co.uk - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/710-72741-17534-1/4 (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    --
    End of file - 8470 bytes
  • Open up ccleaner and it will go to the first thing which is to scan for your crap(it was called carp cleaner at first) then once done click on registry and scan for issues.. then once done Id say delete but make sure you say yes to back up.

    then update Malwarebytes as im on 5566 and your a few behind that.. then run Mbam again to a full scan..


    Im not too !!!! hot on what you get via personal PCs as mine is linked to a secure server but do that and see how much it cleans.. your registry will be loaded with crap

    I can't seem to find the 5566 version or MalwareBytes. Have you a direct link?

    Either I have no nasties found or I can't get CCleaner to scan. Nothing comes up. I clicked on Registry and Scan for Issues but I no idea what it all means. It's come back with a mixture of Missing Shared DLLs, Unused file extenstions, Invalid Default Icon, Open with application Issue, ActiveX Com issue, Missing TypeLib Reference, Installer Reference Issue (lots of these) and Obsolete software key. I clicked Fix selected issues and said yes to backup.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.9K Banking & Borrowing
  • 253.9K Reduce Debt & Boost Income
  • 454.7K Spending & Discounts
  • 246K Work, Benefits & Business
  • 602.1K Mortgages, Homes & Bills
  • 177.8K Life & Family
  • 259.9K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.