Author Topic: referred by GR@ph<"S"  (Read 12581 times)

0 Members and 2 Guests are viewing this topic.

Offline irishsupplyguy

  • Newbie
  • *
  • Posts: 28
Re: referred by GR@ph<"S"
« Reply #45 on: November 04, 2005, 02:27:14 PM »
Good morning SpyDie:

When I paste the file name E:\WINDOWS\Temporary Internet Files\Content.IE5\H376PBO\ , directory in blue does not appear. If I delete H376PBO\ the blue directory does appear. What is my next move?

Offline Rawe

  • Malware Experts
  • Full Member
  • *****
  • Posts: 107
    • Log'N'Rock
Re: referred by GR@ph<"S"
« Reply #46 on: November 04, 2005, 02:35:52 PM »
Navigate to this folder: E:\WINDOWS\Temporary Internet Files\Content.IE5\

And delete all it's content.. Empty recycle bin.. And reboot.  :thumbsup:
Hi there, stranger!


Offline irishsupplyguy

  • Newbie
  • *
  • Posts: 28
Re: referred by GR@ph<"S"
« Reply #47 on: November 04, 2005, 04:44:43 PM »
Good morning Rawe, SpyDie, and Corrine:

Looks like I am totally clean!! Rawe thank you for all you efforts on my behalf. SpyDie you are an incredible bright human being. Corrine for effort and dedication you are undoubtly without peer. I thank you all!!

Attached is a fresh HJT log and a KAV scan.
Again, thanks a million!!


Logfile of HijackThis v1.99.1
Scan saved at 10:31:11 AM, on 11/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Trend Micro\Tmas\Tmas.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&mem=irishsupplyguy&login=ff7dd50d38554aacc7f54e2f02101075/irishsupplyguy:netzero.net/1128621779/30/sss.1.51174/&ts=434566d3&A=0&B=1120892400000&C=1120892400000&D=1125471600000&I=7.NH3&N=PLHS&O=I&UT=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1130265368093
O20 - Winlogon Notify: igfxcui - igfxsrvc.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe




-------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Friday, November 04, 2005 11:09:28
 Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.67.0
 Kaspersky Anti-Virus database last update:  4/11/2005
 Kaspersky Anti-Virus database records: 148563
-------------------------------------------------------------------------------

Scan Settings:
   Scan using the following antivirus database: standard
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - My Computer:
   A:\
   C:\
   D:\
   E:\

Scan Statistics:
   Total number of scanned objects: 42142
   Number of viruses found: 0
   Number of infected objects: 0
   Number of suspicious objects: 0
   Duration of the scan process: 1686 sec
No malware has been detected. The sections that have been scanned are CLEAN.

Scan process completed.

Offline SpyDie

  • The Spyware Cooker
  • Administrator
  • Hero Member
  • *****
  • Posts: 2045
    • The LandzDown Forum
Re: referred by GR@ph<"S"
« Reply #48 on: November 04, 2005, 06:08:37 PM »
Log is perfectly clean :) Glad to help and good to see you're computer is now fine :) I'd go and look at that post Corrine linked to.
Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: referred by GR@ph<"S"
« Reply #49 on: November 04, 2005, 06:26:44 PM »
After checking out Tony Klein's post, come back for some cake!  You have earned a celebration!   :breakkie:

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline irishsupplyguy

  • Newbie
  • *
  • Posts: 28
Re: referred by GR@ph<"S"
« Reply #50 on: November 04, 2005, 07:11:34 PM »
Hi Folks:

Read Tony's suggestions and applied all that I was not previously running. Ran Jason's tool box and made adjustments there, ran it again and got an A. You people are great and the only real defense we have out there against the predators. I'm sure you get on their nerves a great deal. Thank you all for an excellent job.

Best regards,
Mark

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5123
  • Half a bubble off plumb
Re: referred by GR@ph<"S"
« Reply #51 on: November 04, 2005, 07:15:00 PM »
Good job all ...  :D
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: referred by GR@ph<"S"
« Reply #52 on: November 04, 2005, 07:29:54 PM »
Mark, I hope having all that good security doesn't mean that you won't be back to LzD to visit. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline irishsupplyguy

  • Newbie
  • *
  • Posts: 28
Re: referred by GR@ph<"S"
« Reply #53 on: November 04, 2005, 09:15:40 PM »
Hi Corrine:

Where do visitors post just to say Hi? With the help from you and all the good people there hopefully I won't be back with any more security issues. If you will marry me I promise we can adopt SpyDie and Rawe!  :lol:

Thank you all!!!

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: referred by GR@ph<"S"
« Reply #54 on: November 04, 2005, 10:21:31 PM »
Quote from: irishsupplyguy
If you will marry me I promise we can adopt SpyDie and Rawe!
Family gatherings would be a bit difficult with Rawe in Finland and SpyDie in the U.K. 

Mark, after 27 posts and all the time you've spent here, you are not a "visitor" but a member of LzD!  Apart from the serious stuff, LandzDown Forum has Another great part of LandzDown is the Updates.  We have very special Update Moderators at LzD who make sure that all our members know when their favorite security software has been updated.  In fact, with the new software on your computer, you might be interested in staying current.

I hope you do stop by on occasion.  Perhaps play "word association", one of the other games, or just say "Hi". 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline irishsupplyguy

  • Newbie
  • *
  • Posts: 28
Re: referred by GR@ph<"S"
« Reply #55 on: November 05, 2005, 01:51:29 PM »
Thank you all for your good work! I will visit.

Mark