Oct 8 2007, 11:41 PM
Post
#1
|
|
|
Newbie ![]() Group: Members Posts: 7 Joined: 8-October 07 Member No.: 39,069 |
My wifes laptop and been infested with slowness and pop-ups. The pop-ups are all titled Internet Speed Monitor. I've searched online and there appears to be no easy fix and most of the fixes I've seen are specific to the individuals system. I have already uninstalled this program but all this does is lessen the random popups, they still happen every few minutes. Before I go trawling through the registry I'd thought I'd try help from experts. I've run adaware even in safe mode but again to no avail, it removes this stuff and then it pops right back up. Please help, this is driving my wife (and hence me) nuts!
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:38:34 PM, on 10/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\ISM2\ISMPack6.exe C:\PROGRA~1\SMANTE~1\chkdsk.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\Program Files\CreataCard\Plus\FMRemind.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\QUICKENW\QWDLLS.EXE C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\MSN Messenger\livecall.exe C:\Program Files\GameHouse\TextTwist\TextTwist.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\Denise McDonald\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {3B1C253D-320A-4EE4-9119-B5165780B481} - C:\WINDOWS\system32\geedd.dll (file missing) O2 - BHO: (no name) - {3C03A265-AF30-42AE-8A38-10F39E8663BE} - C:\WINDOWS\system32\jkhhf.dll (file missing) O2 - BHO: (no name) - {69F42D1C-B2F7-B527-A848-E72B2B9782C8} - C:\WINDOWS\system32\dbernfhc.dll (file missing) O2 - BHO: (no name) - {6E813A76-6300-4682-803F-906DE122D7D8} - C:\Program Files\Common Files\hoket83122.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: BndDrive2 BHO Class - {8FB5B012-E8CB-46cd-B6D2-ED428FAE9043} - C:\Program Files\ISM\BndDrive5.dll (file missing) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C66552A1-E3F0-4375-8DCA-D01DEBA6C818} - C:\Program Files\Common Files\hoket4444.dll (file missing) O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\rlubyclm.dll (file missing) O2 - BHO: (no name) - {E3CF3F94-D3C3-4822-8016-0C804AB22D3F} - \ O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\upneukhn.dll",sitypnow O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ISMPack6] "C:\Program Files\ISM2\ISMPack6.exe" O4 - HKCU\..\Run: [Htre] "C:\PROGRA~1\SMANTE~1\chkdsk.exe" -vt yazb O4 - HKCU\..\Run: [Lbj] "C:\Program Files\?racle\e?plorer.exe" O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE O4 - Global Startup: CreataCard Plus 3 Forget Me Not Reminders Tray Icon.lnk = C:\Program Files\CreataCard\Plus\FMRemind.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll O20 - Winlogon Notify: ddcdbby - ddcdbby.dll (file missing) O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O24 - Desktop Component 0: (no name) - C:\Program Files\ComPlus Applications\profsycyc.html -- End of file - 6665 bytes |
|
|
|
swcrusader Internet Speed Monitor - Help! Oct 8 2007, 11:41 PM
jurgenv 1. Download this file - [color=red]combofix.exe
2.... Oct 9 2007, 05:11 PM
swcrusader Thanks for the help! My wife is frantic about... Oct 9 2007, 06:50 PM
jurgenv * Please open hijackthis and put a check next to t... Oct 9 2007, 07:05 PM
swcrusader Here we go:
C:\WINDOWS\system32\dd... Oct 9 2007, 09:21 PM
jurgenv Looking good, how is everything working? Oct 9 2007, 10:09 PM
swcrusader Im going to give it 24 hours, let my wife have at ... Oct 10 2007, 06:10 AM
jurgenv Don't worry, it's fixable. :P Oct 10 2007, 02:56 PM
swcrusader Unbelievable. Its still popping up those D*mn pop... Oct 11 2007, 02:42 AM
jurgenv Post me a new log from combofix. Oct 11 2007, 02:33 PM
swcrusader Here you are, thanks for continuing to work with m... Oct 12 2007, 03:05 AM
jurgenv * Download Dr.Web CureIt to the desktop:
ftp://ftp... Oct 12 2007, 02:52 PM
swcrusader Well it looks like the problem is all fixed. Its ... Oct 14 2007, 12:24 AM
jurgenv Ok, can I see a new hijackthis log to be sure? Oct 14 2007, 10:34 AM
LS CalamityJane Due to lack of feedback, this topic has been close... Nov 6 2007, 01:08 AM![]() ![]() |
|
Lo-Fi Version | Time is now: 3rd September 2010 - 09:33 AM |