Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

McAfee Active Shield error message

2390 Views 14 Replies 2 Participants Last post by  Byteman
Everytime I boot up my computer this box pops up over an over again:

Mcafee Active Shield has found a suspect file on your computer.Mcafee strongly recommends that you scan your computer now.

I have scanned and nothing has changed

I use Aol 9.0 security edition....

Below is my log from HijackThis

HELP!!!!! I can not take it any more. I have tried everything....

Logfile of HijackThis v1.99.1
Scan saved at 8:53:43 PM, on 1/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\America Online 9.0b\shellmon.exe
c:\program files\common files\aol\1136864626\ee\anotify.exe
c:\program files\common files\aol\1136864626\ee\aolsoftware.exe
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\AOL\1136864626\ee\SSCEvtHdlr.exe
C:\Program Files\HijackThis.exe

O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136864626\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1136864626\ee\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\GetFlash.exe
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/installers/cab/WinAntiVirusPro2006FreeInstall.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
See less See more
Status
Not open for further replies.
1 - 10 of 15 Posts
THANKS FOR THE HELP...HERE IS THE VUNDOFIX.TXT AND HIJACKTHIS LOG
VundoFix V6.2.13

Checking Java version...

Java version is 1.4.2.3

Logfile of HijackThis v1.99.1
Scan saved at 8:51:17 PM, on 1/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\Common Files\AOL\1136864626\ee\SSCEvtHdlr.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\HijackThis.exe

O2 - BHO: RawExecAction Object - {18898424-E3AB-4BA9-8E8D-5434B1CECA75} - C:\WINDOWS\system32\vtuts.dll (file missing)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136864626\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1136864626\ee\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/installers/cab/WinAntiVirusPro2006FreeInstall.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Scan started at 8:31:42 PM 1/9/2007

Listing files found while scanning....

C:\WINDOWS\system32\aieamdfd.dll
C:\WINDOWS\system32\bfierhnt.dll
C:\WINDOWS\system32\bhidpbqw.dll
C:\WINDOWS\system32\gpclkhiu.dll
C:\WINDOWS\system32\kbdcxasq.dll
C:\WINDOWS\system32\rigywyqf.dll
C:\WINDOWS\system32\rkylesik.dll
C:\WINDOWS\system32\totrsmtt.dll
C:\WINDOWS\system32\xggiikxp.dll
C:\WINDOWS\system32\vtuts.dll
C:\WINDOWS\system32\stutv.ini
C:\WINDOWS\system32\stutv.bak1
C:\WINDOWS\system32\stutv.bak2
C:\WINDOWS\system32\stutv.ini2
C:\WINDOWS\system32\stutv.tmp

Beginning removal...

Attempting to delete C:\WINDOWS\system32\aieamdfd.dll
C:\WINDOWS\system32\aieamdfd.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bfierhnt.dll
C:\WINDOWS\system32\bfierhnt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\bhidpbqw.dll
C:\WINDOWS\system32\bhidpbqw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gpclkhiu.dll
C:\WINDOWS\system32\gpclkhiu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\kbdcxasq.dll
C:\WINDOWS\system32\kbdcxasq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rigywyqf.dll
C:\WINDOWS\system32\rigywyqf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rkylesik.dll
C:\WINDOWS\system32\rkylesik.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\totrsmtt.dll
C:\WINDOWS\system32\totrsmtt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xggiikxp.dll
C:\WINDOWS\system32\xggiikxp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtuts.dll
C:\WINDOWS\system32\vtuts.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\stutv.ini
C:\WINDOWS\system32\stutv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\stutv.bak1
C:\WINDOWS\system32\stutv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\stutv.bak2
C:\WINDOWS\system32\stutv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\stutv.ini2
C:\WINDOWS\system32\stutv.ini2 Has been deleted!

Performing Repairs to the registry.
Done!
See less See more
here are avg anti-spyware and panda reports

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:56:01 PM 1/9/2007

+ Scan result:

C:\WINDOWS\system32\ctceyjyb.exe -> Adware.Searchcolor : Cleaned.
C:\WINDOWS\system32\lfrdhnvl.exe -> Adware.Searchcolor : Cleaned.
C:\WINDOWS\system32\auxuxskr.dll -> Adware.Winfixer : Cleaned.
C:\WINDOWS\system32\ciwplont.dll -> Logger.VBStat.c : Cleaned.
C:\VundoFix Backups\aieamdfd.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\bfierhnt.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\bhidpbqw.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\gpclkhiu.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\kbdcxasq.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\rigywyqf.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\rkylesik.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\totrsmtt.dll.bad -> Logger.VBStat.e : Cleaned.
C:\VundoFix Backups\xggiikxp.dll.bad -> Logger.VBStat.e : Cleaned.
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned.
C:\WINDOWS\system32\fomewhni.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt -> TrackingCookie.Zedo : Cleaned.

PANDA
::Report end

Incident Status Location

Spyware:spyware/virtumonde Not disinfected Windows Registry
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Brian Doherty\Cookies\brian [email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Lynette Doherty\Cookies\lynette [email protected][1].txt
See less See more
the spybot report is too long....this forum will not let me post it because of the length...do you have an email address i could send it to?
ok...a few things...when I did the hijackthis scan only and check the items you told me to, the only one not on the list was the 02-BHO etc... the other to were there....
i ran VundoFix again and it found no infected files....
what else do you want me to do after this...run hijackthis again and post the log?
Logfile of HijackThis v1.99.1
Scan saved at 5:35:56 PM, on 1/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\mcafee.com\antivirus\oasclnt.exe
C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
C:\Program Files\Common Files\AOL\1136864626\ee\SSCEvtHdlr.exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\Program Files\Common Files\AOL\1136864626\ee\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136864626\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1136864626\ee\SSCRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus\oasclnt.exe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus\mcvsescn.exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1136864626\ee\services\safetyCore\ver210_5_2_1\aolavupd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANTIVI~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
See less See more
--- Report generated: 2007-01-10 21:55 ---

Smitfraud-C.Toolbar888: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan

VirtuMonde: Class ID (Registry key, fixed)
HKEY_CLASSES_ROOT\CLSID\{18898424-E3AB-4BA9-8E8D-5434B1CECA75}

VirtuMonde: User settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-2457602204-2058530417-1820168162-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18898424-E3AB-4BA9-8E8D-5434B1CECA75}

VirtuMonde: Browser helper object (Registry key, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18898424-E3AB-4BA9-8E8D-5434B1CECA75}


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-01-10 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-01-05 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-01-05 Includes\DialerC.sbi (*)
2006-11-24 Includes\Hijackers.sbi (*)
2007-01-05 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-01-05 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-12-22 Includes\Malware.sbi (*)
2007-01-05 Includes\MalwareC.sbi (*)
2003-03-15 Includes\plugin-ignore.ini
2006-10-20 Includes\PUPS.sbi (*)
2007-01-05 Includes\PUPSC.sbi (*)
2007-01-05 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-01-05 Includes\SecurityC.sbi (*)
2006-10-13 Includes\Spybots.sbi (*)
2007-01-05 Includes\SpybotsC.sbi (*)
2003-03-15 Includes\Temporary.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-12-08 Includes\Trojans.sbi (*)
2007-01-05 Includes\TrojansC.sbi (*)
See less See more
the last post was from spybot not hijack this
i updated java....tell me what to do with the system restore
Hello...
I tried to do the System Restore, but no System Restore wizard came up...did I do something wrong...or do I not have this....
1 - 10 of 15 Posts
Status
Not open for further replies.
Top