An annoying Virus I can't get rid of

Discussion in 'Windows - Virus and spyware problems' started by pepestre, Jul 5, 2006.

  1. pepestre

    pepestre Member

    Joined:
    Jul 5, 2006
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    11
    Ive tried everything -- and I can't get rid of this wierd virus. its a "Fake virus popup" it opens on the bottom right of the screen and says asks me to update and "click here" and when I do it directs me to a spyquake website with a referral id... http://www.spywarequake.com/?aff=247

    Here's my logs: RAPPORT

    SmitFraudFix v2.67

    Scan done at 21:51:47.09, Wed 07/05/2006
    Run from C:\Documents and Settings\mohamed\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "altmannsberger"="{210b4043-35ca-4aa0-8796-191f9663dfb3}"



    »»»»»»»»»»»»»»»»»»»»»»»» End
    ________________________________
    Ewindo

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 10:41:30 PM 7/5/2006

    + Scan result:



    :mozilla.10:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.11:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.12:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.13:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.14:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.15:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.166:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.167:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.16:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.17:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.18:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.268:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.279:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.6:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.7:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.8:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.9:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.399:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.72:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.79:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
    :mozilla.300:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
    :mozilla.80:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.53:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.54:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.55:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
    :mozilla.411:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.340:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.341:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.342:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
    :mozilla.345:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
    :mozilla.346:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
    :mozilla.176:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
    :mozilla.36:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.37:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.38:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.39:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.188:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.189:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.190:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.197:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.207:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.208:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.209:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.210:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.222:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
    :mozilla.223:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.224:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.225:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.226:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.227:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.228:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.229:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.230:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.231:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.232:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.233:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.234:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.235:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.242:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.243:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.244:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.327:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned.
    :mozilla.254:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    :mozilla.255:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.258:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.192:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.193:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.194:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.195:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.196:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
    :mozilla.287:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.288:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.297:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.298:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.299:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.292:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.293:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    :mozilla.294:C:\Documents and Settings\mohamed\Application Data\Mozilla\Firefox\Profiles\dxirkgyi.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


    ::Report end
    ___________________________
    HIJACK THIS

    Logfile of HijackThis v1.99.1
    Scan saved at 11:56:26 PM, on 7/5/2006
    Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\Program Files\Creative\Launcher\CTLauncher.exe
    C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
    C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\system32\rundll32.exe
    F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    F:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\TechniSat DVB\bin\Server4PC.exe
    C:\WINDOWS\system32\wuauclt.exe
    F:\Program Files\iPod\bin\iPodService.exe
    C:\tqrecv\tqrecv.exe
    C:\tqrecv\tqrecv.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Opera\Opera.exe
    C:\Program Files\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9202;https=127.0.0.1:9202;socks=127.0.0.1:9203
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
    O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Creative Launcher] C:\Program Files\Creative\Launcher\CTLauncher.exe
    O4 - HKLM\..\Run: [AudioHQ] C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
    O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [DAEMON Tools] "F:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [updateMgr] "F:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
    O4 - HKCU\..\Run: [SoonR] "F:\Program Files\SoonR\SoonR Desktop Client\SoonrClient.exe" -boot
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Startup: Registration Prince of Persia Warrior Within.LNK = D:\Program Files\Ubisoft\Prince of Persia Warrior Within\Support\Register\RegistrationReminder.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: HPAiODevice(hp psc 700 series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp psc 700 series\Bin\hpobrt07.exe
    O4 - Global Startup: palstart.exe
    O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{54856F5D-1FFD-439F-AA7B-2E328EB98B5F}: NameServer = 194.126.53.34 194.126.43.34
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O21 - SSODL: altmannsberger - {210b4043-35ca-4aa0-8796-191f9663dfb3} - C:\WINDOWS\system32\vpxnk.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kaspersky Anti-Virus Service (kavsvc) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
     
  2. obdo

    obdo Member

    Joined:
    Jan 8, 2006
    Messages:
    92
    Likes Received:
    0
    Trophy Points:
    16
    alright first of all, if a virus is putting pop ups that say "Uninstall" DO NOT TOUCH IT

    Try a program like Spyboy Search & Destroy and if that does not work, you may have to wipe the drive (meaning reinstalling your Operating System, this erases everything on your drive and reinstalling whatever your OS has on it, all viruses should be gone then
     

Share This Page