Skip to main content

cant connect only to levelupgames sites( ragnarok.ph , levelupgames.ph,etc) and other level up games ( philippine Ragnarok Online )

Comments

54 comments

  • Customer

    have another problem... pc crashes and shows ati2dvag driver not working properly ? err something like that... whats up with that ?

    0
  • Customer

    Hi

     

     

    Download

    SDFix

    and save it to your desktop. (If you can't download with this computer try to get it downloaded on some other one.)

     

    Please then reboot your computer in Safe Mode by doing the

    following :


    • Restart your computer


    • After hearing your computer beep once during startup, but before the
      Windows icon appears, tap the F8 key continually;


    • Instead of Windows loading as normal, a menu with options should appear;


    • Select the first option, to run Windows in Safe Mode, then press
      Enter
      .


    • Choose your usual account.




    • In Safe Mode, double click the SDFix.exe file. Click Install in appearing window,


    • Open the extracted folder and double click RunThis.bat to
      start the script.


    • Type Y to begin the script.


    • It will remove the Trojan Services then make some repairs to the
      registry and prompt you to press any key to Reboot.


    • Press any Key and it will restart the PC.


    • Your system will take longer that normal to restart as the fixtool
      will be running and removing files.


    • When the desktop loads the Fixtool will complete the removal and
      display Finished, then press any key to end the script and load
      your desktop icons.


    • Finally open the SDFix folder on your desktop and copy and paste the
      contents of the results file Report.txt back onto the forum with
      a new HijackThis log



    0
  • Customer

    here's the new HJT log file

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 8:32:49 PM, on 6/16/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    C:\WINDOWS\System32\ezSP_Px.exe

    C:\program files\support.com\client\bin\tgcmd.exe

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe

    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\sony\usbsircs\usbsircs.exe

    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

    C:\Program Files\Sony\Giga Pocket\shwserv.exe

    C:\Program Files\NewDotNet\nnrun.exe

    C:\WINDOWS\System32\HPZipm12.exe

    C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    D:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    D:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    C:\Program Files\NewDotNet\nnrun.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    C:\WINDOWS\system32\wuauclt.exe

    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ragnarok.levelupgames.ph/events_detail.php?id=313

    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)

    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)

    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

    O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [VMConsole.exe] "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    O4 - HKLM\..\Run: [sDFix] D:\BERNHA~1\SDFix\RunThis.bat /second

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O4 - Global Startup: Remocon Driver.lnk = ?

    O8 - Extra context menu item: &Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm

    O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm

    O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe (file missing)

    O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NNServ - New.net, Inc. - C:\Program Files\NewDotNet\nnrun.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe

    O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    O23 - Service: VAIO Media DB Sync Service (VAIOMediaDBSyncService) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe

    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    O23 - Service: VideoAcceleratorService - Speedbit Ltd. - D:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

     

    --

    End of file - 11522 bytes

     

     

     

    uhhh and here's the report.txt uhhh im not sure if its really this... but that's the only content of the report.txt

     

     

    SDFix: Version 1.193

    Run by Bernhardt Ducante on Mon 06/16/2008 at 08:22 PM

     

    Microsoft Windows XP [Version 5.1.2600]

    Running From: D:\BERNHA~1\SDFix

     

    Checking Services :

     

     

    Restoring Windows Registry Values

    Restoring Windows Default Hosts File

     

    thanks ^^

    0
  • Customer

    Hi

     

    Did it do this:

    When the desktop loads the Fixtool will complete the removal and

    display Finished, then press any key to end the script and load

    your desktop icons.

    ?

     

    I just want to be sure running was finished before you posted the log.

    0
  • Customer

    uhh yeah... it displayed something like press anything to continue then it restarted....

    0
  • Customer

    Hi

     

    Yes, it did restart but did you wait after restart too as instructed?

     

    Uninstall NewDotNet (or New.Net) thru add/remove programs if found.

     

     

    Start hjt, do a system scan, check:

    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)

    O23 - Service: NNServ - New.net, Inc. - C:\Program Files\NewDotNet\nnrun.exe

    Close browsers and other windows. Click fix checked.

     

     

    Creating & executing batch file

    -------------------------------

     

    Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop. (If you are still unsure on how to do this there is a little tutorial with pictures here)

    @echo off

    sc stop NNServ

    sc delete NNServ

    Double-click on fixes.bat file to execute it.

     

     

    Delete C:\Program Files\NewDotNet folder if found.

     

     

     

    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

     

    Double-click ATF Cleaner.exe to open it

     

    Under Main choose:

    Windows Temp

    Current User Temp

    All Users Temp

    Cookies

    Temporary Internet Files

    Prefetch

    Java Cache

    *The other boxes are optional*

    Then click the Empty Selected button.

     

    If you use Firefox:

    Click Firefox at the top and choose: Select All

    Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

     

    If you use Opera:

    Click Opera at the top and choose: Select All

    Click the Empty Selected button.

    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

     

    Click Exit on the Main menu to close the program.

     

     

     

    Please download Malwarebytes' Anti-Malware to your desktop.


    • Double-click mbam-setup.exe and follow the prompts to install the program.


    • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.


    • If an update is found, it will download and install the latest version.


    • Once the program has loaded, select Perform full scan, then click Scan.


    • When the scan is complete, click OK, then Show Results to view the results.


    • Be sure that everything is checked, and click Remove Selected.


    • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt


    • Please post contents of that file & a fresh hjt log in your next reply.



    0
  • Customer

    currently scanning.... sorry for the long wait.... thanks

    err btw...

    Start hjt, do a system scan, check:

    O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)

    O23 - Service: NNServ - New.net, Inc. - C:\Program Files\NewDotNet\nnrun.exe


     

    i didnt find the O23 anymore after i removed it from the control panel - add/remove programs so i just continued to the next step.

    thanks

     

    ill post the log file and a new HJT log after the scan...

    0
  • Customer

    here's the logfile for malwarebytes

     

    Malwarebytes' Anti-Malware 1.17

    Database version: 860

     

    11:14:57 PM 6/16/2008

    mbam-log-6-16-2008 (23-14-57).txt

     

    Scan type: Full Scan (C:\|D:\|)

    Objects scanned: 112945

    Time elapsed: 39 minute(s), 50 second(s)

     

    Memory Processes Infected: 0

    Memory Modules Infected: 0

    Registry Keys Infected: 10

    Registry Values Infected: 0

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 0

     

    Memory Processes Infected:

    (No malicious items detected)

     

    Memory Modules Infected:

    (No malicious items detected)

     

    Registry Keys Infected:

    HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

     

    Registry Values Infected:

    (No malicious items detected)

     

    Registry Data Items Infected:

    (No malicious items detected)

     

    Folders Infected:

    (No malicious items detected)

     

    Files Infected:

    (No malicious items detected)

     

     

    ------------------------------------------------------------------------------------------------------

     

    here's the fresh HJT log.... thanks

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:21:43 PM, on 6/16/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    C:\WINDOWS\System32\ezSP_Px.exe

    C:\program files\support.com\client\bin\tgcmd.exe

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe

    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    C:\Program Files\sony\usbsircs\usbsircs.exe

    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

    C:\Program Files\Sony\Giga Pocket\shwserv.exe

    C:\WINDOWS\System32\HPZipm12.exe

    C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    D:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    D:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    C:\Program Files\Mozilla Firefox\firefox.exe

    D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    d:\Program Files\e-Games\CABAL Online (PH)\update.exe

    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ragnarok.levelupgames.ph/events_detail.php?id=313

    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)

    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

    O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [VMConsole.exe] "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    O4 - HKLM\..\Run: [sDFix] D:\BERNHA~1\SDFix\RunThis.bat /second

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O4 - Global Startup: Remocon Driver.lnk = ?

    O8 - Extra context menu item: &Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm

    O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm

    O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe (file missing)

    O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe

    O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    O23 - Service: VAIO Media DB Sync Service (VAIOMediaDBSyncService) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe

    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    O23 - Service: VideoAcceleratorService - Speedbit Ltd. - D:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

     

    --

    End of file - 11356 bytes

     

     

    thanks for the help

    0
  • Customer

    errrr about this...

     

    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes

    kill bits

    in the registry, so that certain activex controls can't install.

    If you don't know what activex controls are, see here


     

    activex.... i think i have one... errr uhmmm... adobe flash player activeX ? LOL ahahhaha no idea.. srry... oh and i have spyware blaster already...

     

    Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. See here to choose one

     

    hmmm have ad aware 2008 and the xoftspy.... uhmmm the malwarebytes that u said too....

     

    thanks a lot...

     

    ill wait for your reply regarding the activeX thingy before i do the prevention steps.... thanks thanks again

    0
  • Customer

    Hi

     

    Fix this one with hjt too:

    O4 - HKLM\..\Run: [sDFix] D:\BERNHA~1\SDFix\RunThis.bat /second

     

     

    Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.

     

     

    THESE STEPS ARE VERY IMPORTANT

     

    Let's reset system restore

    Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

     

    1. Turn off System Restore.

    On the Desktop, right-click My Computer.

    Click Properties.

    Click the System Restore tab.

    Check Turn off System Restore.

    Click Apply, and then click OK.

     

    2. Reboot.

     

    3. Turn ON System Restore.

    On the Desktop, right-click My Computer.

    Click Properties.

    Click the System Restore tab.

    UN-Check *Turn off System Restore*.

    Click Apply, and then click OK.

    NOTE: only do this ONCE,NOT on a regular basis

     

     

     

    Next we remove all used tools (in this case SDFix).

     

    Please download OTMoveIt2 and save it to desktop.


    • Double-click OTMoveIt2.exe.


    • Click the CleanUp! button.


    • Select Yes when the
      Begin cleanup Process?
      prompt appears.


    • If you are prompted to Reboot during the cleanup, select Yes.


    • The tool will delete itself once it finishes, if not delete it by yourself.



    Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so.

     

     

    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

     

    Updating Java:


    • Download the latest version of Java Runtime Environment (JRE) 6 Update 6.


    • Scroll down to where it says
      The J2SE Runtime Environment (JRE) allows end-users to run Java applications.
       


    • Click the
      Download
      button to the right.


    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
       


    • The page will refresh.


    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.


    • Close any programs you may have running - especially your web browser.


    • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.


    • Check any item with Java Runtime Environment (JRE or J2SE) in the name.


    • Click the Remove or Change/Remove button.


    • Repeat as many times as necessary to remove each Java versions.


    • Reboot your computer once all Java components are removed.


    • Then from your desktop double-click on jre-6u6-windows-i586-p.exe to install the newest version.



     

    UPDATING WINDOWS AND INTERNET EXPLORER

     

    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

     

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.

     

     

    Make your Internet Explorer more secure

     

    This can be done by following these simple instructions:

    From within Internet Explorer click on the Tools menu and then click on Options.

    Click once on the Security tab

    Click once on the Internet icon so it becomes highlighted.

    Click once on the Custom Level button.

    Change the Download signed ActiveX controls to Prompt

    Change the Download unsigned ActiveX controls to Disable

    Change the Initialize and script ActiveX controls not marked as safe to Disable

    Change the Installation of desktop items to Prompt

    Change the Launching programs and files in an IFRAME to Prompt

    Change the Navigate sub-frames across different domains to Prompt

    When all these settings have been made, click on the OK button.

    If it prompts you as to whether or not you want to save the settings, press the Yes button.

    Next press the Apply button and then the OK to exit the Internet Properties page.

     

     

     

    The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.



    • Download SpywareBlaster
      Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes
      kill bits
      in the registry, so that certain activex controls can't install.
      If you don't know what activex controls are, see here
      You can download SpywareBlaster here here
      SpywareBlaster tutorial



    • hosts file:

      • Every version of windows has a hosts file as part of them.


      • In a very basic sense, they are used to locate webpages.


      • We can customize a hosts file so that it blocks certain webpages.


      • However, it can slow down certain computers.


      • This is why using a hosts file is optional!!



      Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here

      If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:





      1. Click the start button (at the lower left hand corner of your screen)



      2. Click run



      3. In the dialog box, type services.msc



      4. hit enter, then locate dns client



      5. Highlight it, then double-click it.



      6. On the dropdown box, change the setting from automatic to manual.



      7. Click ok



      [*]Adblock Plus and NoScript are recommended addons for FireFox.

       

       

      [*]Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. See here to choose one

       

      [*]Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.

      See here to choose one if you use Windows own firewall or don't have a firewall at all.



     

    Just a final reminder for you. I am trying to stress these two points.

    UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.

    Make sure all of your security programs are up to date.

    Run the spybot and adaware regularly. (Once or twice a week minimum.)

    Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

     

     

     

    Once again, please post and tell me how things are going with your system... problems etc.

     

    Have a great day,

    Blade

    0
  • Customer

    Hi

     

    Of course you don't need to install Spywareblaster again. However, Ad-Aware, xoftspy and Malwarebytes' Anti-Malware aren't antivirus programs. You need antivirus program to have protection against viruses. Those three meantioned ones are meant to protect against spyware mainly.

    0
  • Customer

    uhhmmm i havent updated everything yet due to my very very very slow internet connection.... wonder if you could check my HJT log again.... i think i have something again.... its everytime i use my Yahoo Messenger.... my browser automatically opens and directs me to this link http://us.ard.yahoo.com/SIG=1505honea/M=58.../tc,c:clickTAG/

     

    here's the HJT log... thanks

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 10:08:58 PM, on 6/23/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\System32\ezSP_Px.exe

    C:\program files\support.com\client\bin\tgcmd.exe

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

    C:\Program Files\sony\usbsircs\usbsircs.exe

    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

    C:\Program Files\Sony\Giga Pocket\shwserv.exe

    C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ragnarok.levelupgames.ph/events_detail.php?id=313

    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)

    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

    O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [VMConsole.exe] "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O4 - Global Startup: Remocon Driver.lnk = ?

    O8 - Extra context menu item: &Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm

    O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm

    O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe (file missing)

    O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe

    O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    O23 - Service: VAIO Media DB Sync Service (VAIOMediaDBSyncService) - Sony Corporation - C:\Program Files\Sony\VAI

    0
  • Customer

    Hi

     

    Log is ok (remember to do the updates I advised above). You should try that Hosts file which link I posted a couple of posts earlier. That should help

    0
  • Customer

    cna u please check this again ?

    errr i think something is making my system slow again.... i accidentally clicked a 'strange' folder inside the memory stick of my psp.. then there it started to produce different wares... are there any ways to also clean my memory stick ? big thanks~

     

    here's the HJT log file

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 4:15:40 PM, on 6/28/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16674)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Sony\Giga Pocket\shwserv.exe

    C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    C:\WINDOWS\Explorer.exe

    C:\program files\support.com\client\bin\tgcmd.exe

    C:\WINDOWS\AGRSMMSG.exe

    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

    C:\Program Files\sony\usbsircs\usbsircs.exe

    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe

    D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

    D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

     

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.yahoo.com

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ragnarok.levelupgames.ph/events_detail.php?id=313

    R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\explorer.exe"

    O1 - Hosts: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"

    O1 - Hosts: "http://www.w3.org/TR/html4/loose.dtd">

    O1 - Hosts: <html>

    O1 - Hosts: <head>

    O1 - Hosts: <script LANGUAGE="JavaScript">

    O1 - Hosts: <!--

    O1 - Hosts: if (window != top)

    O1 - Hosts: top.location.href = location.href;

    O1 - Hosts: // -->

    O1 - Hosts: </script>

    O1 - Hosts: <title>Site Unavailable</title>

    O1 - Hosts: <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

    O1 - Hosts: <style type="text/css">

    O1 - Hosts: body{text-align:center;}

    O1 - Hosts: .geohead {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;width:750px;margin:10px 0 10px 0;height:35px;}

    O1 - Hosts: .geohead #geologo {width:270px;display:block; float:left; }

    O1 - Hosts: .geohead #rightside {width:480px;display:block; float:right;border-bottom:1px solid #999999; height:27px;}

    O1 - Hosts: .geohead #rightside #welcome {width:50%;display:block; float:left; text-align:left;}

    O1 - Hosts: .geohead #rightside #wlinks {width:50%;display:block; float:right; text-align:right;}

    O1 - Hosts: .ftr { margin:0px; color:#404040; font:x-small Arial,sans-serif; text-align:center; width:750px;}

    O1 - Hosts: .bodywrap{display:block;height:470px;}

    O1 - Hosts: .bodycnt{width:510px; display:block; float:left; background-color:#EEE9F5; height:auto; text-align:left; font-family:Arial, Helvetica, sans-serif;font-size:13px; color:#000000; padding:20px 20px 35px 20px;}

    O1 - Hosts: .title { font-family:Arial, Helvetica, sans-serif; font-weight:bold; font-size:24px; color:#7C56A9}

    O1 - Hosts: .adcnt{width:172px; display:block; float:right; text-align:left;cursor:pointer;cursor:hand;}

    O1 - Hosts: .adcnt td {text-align:left;}

    O1 - Hosts: .adsubt{font-size:10px; font-family:verdana; font-weight:bold; color:#b4b4b4; cursor:default;margin-top:5px;}

    O1 - Hosts: .ybadge { font-family: Verdana, Arial, Helvetica, sans-serif; font-size:10px; color: #666666; margin-top:10px;}

    O1 - Hosts: .ybadge img {margin-top:6px;}

    O1 - Hosts: .adtable {font-family:Verdana, Arial, Helvetica, sans-serif; font-size:10px;border: 1px solid #d6dbe7; background-color:#eff7ff; padding:3px; margin-bottom:10px; width:172px;}

    O1 - Hosts: .adttl{font-weight:bold;margin-bottom:3px;}

    O1 - Hosts: .addescr{color:#6b6b6b; margin-bottom:3px;}

    O1 - Hosts: .adlink a {color:#008200; text-decoration:none;}

    O1 - Hosts: </style>

    O1 - Hosts: </head>

    O1 - Hosts: <body>

    O1 - Hosts: <!-- following code added by server. PLEASE REMOVE -->

    O1 - Hosts: <!-- preceding code added by server. PLEASE REMOVE -->

    O1 - Hosts: <div id="maincnt">

    O1 - Hosts: <div class="geohead"><div id="geologo"><a href="http://geocities.yahoo.com"><img height=33 alt="Yahoo! GeoCities" src="http://us.i1.yimg.com/us.yimg.com/i/us/nt/ma/ma_geo_1.gif" width=259 border=0></a></div>

    O1 - Hosts: <div id="rightside"><div id="wlinks"><a href="http://geocities.yahoo.com">GeoCities Home</a> - <a href="http://www.yahoo.com">Yahoo!</a> - <a href="http://help.yahoo.com/help/us/geo/">Help</a></div>'>http://help.yahoo.com/help/us/geo/">Help</a></div>

    O1 - Hosts: </div></div>

    O1 - Hosts: <div class="bodywrap">

    O1 - Hosts: <div class="bodycnt">

    O1 - Hosts: <div class="title">Sorry, this GeoCities site is currently unavailable.</div>

    O1 - Hosts: <p>The GeoCities web site you were trying to view has temporarily exceeded its data transfer limit. Please try again later. </p>

    O1 - Hosts: <p>Are you the site owner?

    O1 - Hosts: Avoid service interruptions in the future by increasing your data transfer limit!

    O1 - Hosts: <a href="http://help.yahoo.com/help/us/geo/transfer/transfer-05.html" target="_blank">Find out how.</a> </p>

    O1 - Hosts: <p><a href="http://help.yahoo.com/help/us/geo/transfer/" target="_blank">Learn more about data transfer.</a></p>

    O1 - Hosts: </div>

    O1 - Hosts: <div class="adcnt">

    O1 - Hosts: <a target="_top" href="http://geocities.yahoo.com"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/smbiz/b/geo_mast_small2.gif" alt="Yahoo! GeoCities" border="0" height="15" hspace="0" vspace="0" width="141"></a>

    O1 - Hosts: <div class="adsubt">SPONSORED LINKS</div>

    O1 - Hosts: <!--<table width="172" border="0" bgcolor="#FFFFFF" class="adtable"><tr><td align=left>-->

    O1 - Hosts: <div class="adtable">

    O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27166/*http://smallbusiness.yahoo.com/webhosting" target="_blank">Yahoo! Web Hosting<br>

    O1 - Hosts: $25 Setup Waived</a></div>

    O1 - Hosts: <div class="addescr" title="Reliable plans include domain & 24x7 support.">Reliable plans include domain & 24x7 support.</div>

    O1 - Hosts: <div class="adlink" title="Reliable plans include domain & 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27166/*http://smallbusiness.yahoo.com/webhosting" target="_blank">webhosting.yahoo.com</a></div>

    O1 - Hosts: </div>

    O1 - Hosts: <div class="adtable">

    O1 - Hosts: <div class="adttl" title="Reliable plans include domain & 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27176/*http://smallbusiness.yahoo.com/domains/" target="_blank">Domain Names from Yahoo! only $9.95/yr</a></div>

    O1 - Hosts: <div class="addescr" title="Includes starter web page, email & domain forwarding, 24x7 support.">Includes starter web page, email & domain forwarding, 24x7 support.</div>

    O1 - Hosts: <div class="adlink" title="Includes starter web page, email & domain forwarding, 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27176/*http://smallbusiness.yahoo.com/domains/" target="_blank">domains.yahoo.com</a></div>

    O1 - Hosts: </div>

    O1 - Hosts: <div class="adtable">

    O1 - Hosts: <div class="adttl" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27184/*http://smallbusiness.yahoo.com/mail" target="_blank">Yahoo! Business Email<br> Domain Included</a></div>

    O1 - Hosts: <div class="addescr" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.">Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning.</div>

    O1 - Hosts: <div class="adlink" title="Setup fee waived. Up to 10 emails, SpamGuard, forwarding & virus scanning."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=27184/*http://smallbusiness.yahoo.com/mail" target="_blank">smallbusiness.yahoo.com</a></div>

    O1 - Hosts: </div>

    O1 - Hosts: <div class="adtable">

    O1 - Hosts: <div class="adttl" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=/27190/*http://smallbusiness.yahoo.com/merchant" target="_blank">Ecommerce from Yahoo!<br> 1 Month Free</a></div>

    O1 - Hosts: <div class="addescr" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support.">$50 setup fee waived. A reliable ecommerce plan, 24x7 support.</div>

    O1 - Hosts: <div class="adlink" title="$50 setup fee waived. A reliable ecommerce plan, 24x7 support."><a href="http://pa.yahoo.com/*http://us.rd.yahoo.com/evt=/27190/*http://smallbusiness.yahoo.com/merchant" target="_blank">smallbusiness.yahoo.com</a></div>

    O1 - Hosts: </div>

    O1 - Hosts: <div class="ybadge">

    O1 - Hosts: Get your own web site at <br><a target="_top" href="http://geocities.yahoo.com">Yahoo! GeoCities</a>

    O1 - Hosts: <a href="http://smallbusiness.yahoo.com/webhosting/" target="_top"><img src="http://us.i1.yimg.com/us.yimg.com/i/us/wh/gr/badge_hostedby_purp_2.gif" alt="Hosted by Yahoo! Web Hosting" align="middle" border="0" height="31" width="88"></a>

    O1 - Hosts: </div>

    O1 - Hosts: </div>

    O1 - Hosts: </div>

    O1 - Hosts: <div class=ftr>

    O1 - Hosts: <hr size=1 width=100%>

    O1 - Hosts: Copyright ©

    O1 - Hosts: 2005 Yahoo! Inc. All rights reserved<br>

    O1 - Hosts: <a href="http://privacy.yahoo.com/privacy/us/geo/">Privacy Policy</a>

    O1 - Hosts: - <a href="http://docs.yahoo.com/info/copyright/copyright.html">Copyright Policy</a>

    O1 - Hosts: - <a href="http://docs.yahoo.com/info/guidelines/community.html">Guidelines</a>

    O1 - Hosts: - <a href="http://docs.yahoo.com/info/terms/geoterms.html">Terms of Service</a>

    O1 - Hosts: - <a href="http://help.yahoo.com/help/us/geo/">Help</a>

    O1 - Hosts: </div>

    O1 - Hosts: </div>

    O1 - Hosts: </body>

    O1 - Hosts: </html>

    O1 - Hosts: <!-- text below generated by server. PLEASE REMOVE --></object></layer></div></span></style></noscript></table></script></applet>

    O1 - Hosts: <IMG SRC="http://geo.yahoo.com/serv?s=19190039&t=1196246175&f=us-w81" ALT=1 WIDTH=1 HEIGHT=1>

    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O2 - BHO: Ask Search Assistant BHO - {0A94B111-4504-4e26-AB05-E61E474AA38B} - C:\Program Files\AskPBar\SrchAstt\1.bin\A9SRCHAS.DLL

    O2 - BHO: Yahoo! IE Suggest - {5A263CF7-56A6-4D68-A8CF-345BE45BC911} - C:\Program Files\Yahoo!\Search\YSearchSuggest.dll (file missing)

    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll

    O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

    O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL

    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: [CreateCD_Reminder] C:\WINDOWS\Sonysys\VAIO Recovery\reminder.exe

    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe

    O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\System32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

    O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

    O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe

    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [VMConsole.exe] "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

    O4 - HKUS\S-1-5-21-841291386-1120501145-3778686463-1005\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User 'Ireneo Ducante')

    O4 - HKUS\S-1-5-21-841291386-1120501145-3778686463-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Ireneo Ducante')

    O4 - HKUS\S-1-5-21-841291386-1120501145-3778686463-1005\..\Run: [Tok-Cirrhatus] "C:\Documents and Settings\Ireneo Ducante\Local Settings\Application Data\smss.exe" (User 'Ireneo Ducante')

    O4 - S-1-5-21-841291386-1120501145-3778686463-1005 Startup: systemID.pif = ? (User 'Ireneo Ducante')

    O4 - S-1-5-21-841291386-1120501145-3778686463-1005 User Startup: systemID.pif = ? (User 'Ireneo Ducante')

    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    O4 - Global Startup: Remocon Driver.lnk = ?

    O8 - Extra context menu item: &Clean Traces - D:\Program Files\DAP\Privacy Package\dapcleanerie.htm

    O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm

    O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing)

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople

    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

    O23 - Service: GameConsoleService - Unknown owner - C:\Program Files\WildGames\Game Console - WildGames\GameConsoleService.exe (file missing)

    O23 - Service: Giga Pocket Hardware Detector - Sony Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

    O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe

    O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Giga Pocket\halsv.exe

    O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Giga Pocket\RM_SV.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    O23 - Service: VAIO Media DB Sync Service (VAIOMediaDBSyncService) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\GPDBWatcher.exe

    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe

    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    O23 - Service: VideoAcceleratorService - Speedbit Ltd. - D:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

     

    --

    End of file - 20209 bytes

    0
  • Customer

    srry i was just waiting for my system to be clean again... then that's when i'll start to do all the tips you said on how to prevent my system from viruses etc etc... uhmm is the windows firewall not enough or do i need another one ? for the anti virus... im still doing some checks what's best to get since some AVs detect some programs as viruses even if they're not.... thanks... and apologies

    0
  • Customer

    Why didn't you follow up my earlier advise to install antivirus and firewall? If you don't care for your security it's no use posting logs here. If you're given instructions how to keep system safer and you don't follow those instructions then who else you can blame than yourself? There're people who really care for their systems and follow up the advice to make the system safer.

     

    If you want me to help you clean that mess again you have to first install antivirus and firewall as instructed earlier. Then post a fresh hjt log back.

     

    And that memory stick must be formatted. instructions

    0
  • Customer

    Hi

     

    Windows XP own firewall isn't good enough. You will need 3rd party firewall unless you've got a router with hardware firewall enabled. Comodo Firewall Pro is good free firewall. However, remember not to choose Safesurfing toolbar during installation process. Comodo can be downloaded here. For antivirus I recommend Antivir.

    0
  • Customer

    currently downloading those 2... ill just give you the log tomorrow coz itz already 10pm here now.... thanks for the suggestions.... until tomorrow then...

    0
  • Customer

    blade81,

    its still me... forgot my password thats why i made a new account... uhmm...good news.... i have successfully installed both the comodo firewall and the avira antivirus.... bad news..... well uhmmm.... now my pc is not working.... why ? uhmm.... i scanned my pc and thee it detected some viuses/ worms... so i deleted them.... that's the only that i did.... then after sometime... i restarted my pc.... then when i log in my user account... its like asking me to activate my windows.... and to input the product key... i entered the product key that i found at the back of my cpu but it it said that its incorrect.... is that the onet am i supposed to enter? so right now...my pc is... well uhh... not working LOL

     

    ill be waiting fo your reply ... im using my uncle's laptop at a different house so just tell me what's next to do.... thanks

    0
  • Customer

    then when i log in my user account... its like asking me to activate my windows.... and to input the product key...

    Hi

     

    Could you provide a screenshot of that? It's a bit difficult to say what has happened without knowing what Antivir found.

    0
  • Customer

    1

     

    2

     

    3

     

    4

     

    here are the images.... ill be waiting for your rply.. thanks

    0
  • Customer

    errr ill try to give u one.... uhmmm ill just go home again....

    0
  • Customer

    Hi

     

    Yes, looks like activation screen. If you can't activate with the product key that came with your computer then I suggest you contact Microsoft as instructed in the activation message to sort things out.

    0
  • Customer

    still there? srry...

    i think i already need to go.. looks like youre not yet done on replying... thanks anyway... ill just try to look at your post tomorrow... thanks..

    0
  • Customer

    uhmmm are there any other ways i can make my computer work like reformatting it but only the dive c ? coz there are a lot of files in my drive d and i dont want to lose them..

    0
  • Customer

    Hi

     

    If you reformat you'll still have to deal with the activation issue.

    0
  • Customer

    Hi

     

    SP3 can be downloaded here. Before installing it system has to be malware free. Do you have now Antivir and Comodo firewall installed? If yes, post a fresh hjt log please.

    0
  • Customer

    uhmm now my pc is working... i used my recovery disc and now its back to windows xp home edition sp1.... im thinking of downloading the windows xp sp3 but since i have a very poor internet connection... ill just download it from another pc and just put it in the usb.... then put it in my pc.... is that possible ? and uhh can i download the windows xp sp3 from other sites aside from the microsoft windows site itself ? coz if i try to download it through the microsoft site, it automatically updates the pc and not as an .exe file ?

     

    is my idea possible ? or right ? LOL thanks

    0
  • Customer

    uhmmm i dont think the comodo firewall is compatible with xp home edition ? anyway, i dont think that my system has any malware or what since its still fresh from recovery but to be sure ill just scan my system after i install those 2 and then ill give u the log... thanks

    0
  • Customer

    Hi

     

    You're right. Comodo is not compatible with sp1. It needs sp2. Install Antivir and post a fresh hjt log then

    0

Please sign in to leave a comment.