Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs

Reply
 
Topic Tools
  #1  
Old October 22nd, 2004, 07:49 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
mslaugh.exe

Ah Great i let my dad use my pc and he deletes my firewall

i get on and go to processes and see mslaugh.exe so i think *** is this

i search is on google and it says

File name mslaugh - mslaugh.exe
File Process - BLASTER.E WORM


Security 0 - 5 ( 4 )

Spyware - No
Virus - Yes

What can i do to get rid of it safely?

delete it from processes, System32?

I Dont have Norton New Protection as its buggerd ( BTW Im On Holiday so this pc aint up to date 8) )

And good free virus protection to install?

sorry to ask for info everyday but as soon as this is done i wont be i hope

Any Help would be great

thx Samm
Reply With Quote
  #2  
Old October 22nd, 2004, 07:56 PM
Acrobaze Acrobaze is offline
Malware Removal Team
 
Join Date: Nov 2003
O/S: Windows 10 Home
Location: France
Posts: 11,994
Hi!

Download HijackThis from:
http://www.cybertechhelp.com/downlo...ackthis1977.zip

Create a new folder only for HijackThis (Example : C:\HijackThis).
Unzip it to this folder.
Click "Scan", after click "Save Log".
Save the log, and copy/paste it into your response to this thread.
Dont check or fix anything yet.

---------

There is a free antivirus here:
http://www.grisoft.com/us/us_dwnl_free.php

and a free firewall here:
http://www.zonelabs.com/store/conten...sp?lid=pdb_za1


Cheers.
Reply With Quote
  #3  
Old October 22nd, 2004, 08:05 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
Link Doesnt Work 8(
Reply With Quote
  #4  
Old October 22nd, 2004, 08:11 PM
Acrobaze Acrobaze is offline
Malware Removal Team
 
Join Date: Nov 2003
O/S: Windows 10 Home
Location: France
Posts: 11,994
Ho! Try one of these:

http://www.spywareinfo.com/~merijn/downloads.html
or
http://www.lurkhere.com/~nicefiles/index.html
Reply With Quote
  #5  
Old October 22nd, 2004, 08:45 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
The Effect Of The Virus Is Coming And Its Took me ages to get to this website and d/l hijackthis 8(

Log from HiJackThis

Logfile of HijackThis v1.98.2
Scan saved at 21:45:43, on 22/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\WINDOWS\System32\ndis.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\mslaugh.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\taskservices.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\user\Local Settings\Temp\Temporary Directory 1 for hijackthis1977.zip\HijackThis.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\Reader\ActiveX\AcroIEHelper.ocx (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\ectgxj.exe
O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
O4 - HKLM\..\Run: [NDIS Adapter] ndis.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [tasks service] taskservices.exe
O4 - HKLM\..\RunServices: [NDIS Adapter] ndis.exe
O4 - HKLM\..\RunServices: [tasks service] taskservices.exe
O4 - HKLM\..\RunOnce: [NDIS Adapter] ndis.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NDIS Adapter] ndis.exe
O4 - HKCU\..\RunOnce: [NDIS Adapter] ndis.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6076DE2B-5833-4109-86E0-3C66EEB441B5}: NameServer = 163.121.128.134 212.103.160.18
O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Oophjhff.dll
Reply With Quote
  #6  
Old October 22nd, 2004, 08:47 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
BTW i cant even load up windows task manager
Reply With Quote
  #7  
Old October 22nd, 2004, 09:01 PM
Acrobaze Acrobaze is offline
Malware Removal Team
 
Join Date: Nov 2003
O/S: Windows 10 Home
Location: France
Posts: 11,994
There is not only mslaugh! But worms also.

---------1

Don't let HijackThis in temp folder.
Create a new folder, example c:\HThis and move it there.

---------2

Close all browser windows, run only HijackThis and check:

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\Reader\ActiveX\AcroIEHelper.ocx (file missing)

O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\ectgxj.exe
O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
O4 - HKLM\..\Run: [NDIS Adapter] ndis.exe
O4 - HKLM\..\Run: [tasks service] taskservices.exe
O4 - HKLM\..\RunServices: [NDIS Adapter] ndis.exe
O4 - HKLM\..\RunServices: [tasks service] taskservices.exe
O4 - HKLM\..\RunOnce: [NDIS Adapter] ndis.exe
O4 - HKCU\..\Run: [NDIS Adapter] ndis.exe
O4 - HKCU\..\RunOnce: [NDIS Adapter] ndis.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Oophjhff.dll

Click "Fix checked".

------------------2

Reboot in safe mode, make sure you can see hidden files and folders and delete:

C:\WINDOWS\System32\mslaugh.exe
C:\WINDOWS\System32\ndis.exe
C:\WINDOWS\System32\ectgxj.exe

Empty the recycle bin.

-------------------3

Reboot in normal mode.

Ndis.exe is related to try to infect with the virus "Parite.B" (or "Pate.B" for others antivirus), then, scan online immediatly your computer:
http://www.pandasoftware.com/activescan/

--------------------4

After a reboot, post a new HijackThis log, please.
Reply With Quote
  #8  
Old October 23rd, 2004, 12:52 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
I Done All You said and realy appriciate your time 8)

Everytime i deleted 1 exe a new exe came in my documents so i deleted them i think one was called helper? not sure but it looked bad

oh aswell HiJackThis has made backups of things i deleted should i delete the backups?

Here Is The Log

Logfile of HijackThis v1.98.2
Scan saved at 13:52:29, on 23/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\nvsv32.exe
C:\WINDOWS\System32\taskservices.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\New Folder (2)\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir..._PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [norton updated] nvsv32.exe
O4 - HKLM\..\Run: [tasks service] taskservices.exe
O4 - HKLM\..\RunServices: [norton updated] nvsv32.exe
O4 - HKLM\..\RunServices: [tasks service] taskservices.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6076DE2B-5833-4109-86E0-3C66EEB441B5}: NameServer = 163.121.128.134 212.103.160.18
Reply With Quote
  #9  
Old October 23rd, 2004, 01:15 PM
Acrobaze Acrobaze is offline
Malware Removal Team
 
Join Date: Nov 2003
O/S: Windows 10 Home
Location: France
Posts: 11,994
Ok! Good job, Samm!

Still two malwares to delete.

Control Alt Del
End these processes: nvsv32.exe and taskservices.exe

Close all browser windows, run only HijackThis and check:

O4 - HKLM\..\Run: [norton updated] nvsv32.exe
O4 - HKLM\..\Run: [tasks service] taskservices.exe
O4 - HKLM\..\RunServices: [norton updated] nvsv32.exe
O4 - HKLM\..\RunServices: [tasks service] taskservices.exe

Click "Fix checked.

Reboot in safe mode and delete these two files:
C:\WINDOWS\System32\nvsv32.exe
C:\WINDOWS\System32\taskservices.exe

Empty the recycle bin.

Have you re-install the firewall?

Please, post a new log.
Reply With Quote
  #10  
Old October 23rd, 2004, 01:21 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
Ok My Norton Is Busted And It Wont Even Load Up Cause my dad deleted the firewall and its curropted it 8(

is there any free good firewalls?
Reply With Quote
  #11  
Old October 23rd, 2004, 01:23 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
I Dunno What Wrong WIth The PC But Now I Got tres32.exe and google says its a worm any ideas? i think i need to install this firewall before doing anything else?
Reply With Quote
  #12  
Old October 23rd, 2004, 02:18 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
Ok I Deleted Some Stuff That You Diddent Metion On The New Logfile I Done As Dodge On Another Thread Said So http://www.cybertechhelp.com/forums/...ad.php?t=53969

So Here Is The New Logfile

Logfile of HijackThis v1.98.2
Scan saved at 15:18:25, on 23/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\New Folder (2)\HijackThis.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6076DE2B-5833-4109-86E0-3C66EEB441B5}: NameServer = 163.121.128.134 212.103.160.18

It Looks Alot Smaller And PC Is Running Faster 8)

Any Problems On There?

Im Gonna Restart And Put In Safemode then delete the files and send the new logfile 8)

Hope i aint anoying you mate with all this info

Last edited by Samm; October 23rd, 2004 at 02:21 PM.
Reply With Quote
  #13  
Old October 23rd, 2004, 03:14 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
Last Logfile

Logfile of HijackThis v1.98.2
Scan saved at 16:15:50, on 23/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Messenger Plus! 2\MsgPlus.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Macromedia\Flash Communication Server MX\FlashComAdmin.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\Macromedia\Flash Communication Server MX\FlashCom.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\New Folder (2)\HijackThis.exe
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6076DE2B-5833-4109-86E0-3C66EEB441B5}: NameServer = 163.121.128.134 212.103.160.18
Reply With Quote
  #14  
Old October 23rd, 2004, 04:51 PM
Acrobaze Acrobaze is offline
Malware Removal Team
 
Join Date: Nov 2003
O/S: Windows 10 Home
Location: France
Posts: 11,994
Yes, check and fix this line with HijackThis:

O4 - HKLM\..\Run: [NT Logging Service] syslog32.exe

Then, make sure you can see the hidden files and delete this file if present:

syslog32.exe

--------

Yes, in my first post in this thread, I gave you a link to a free firewall:

http://www.zonelabs.com/store/conten...sp?lid=pdb_za1

---------

Post a new log, please.
Reply With Quote
  #15  
Old October 23rd, 2004, 05:59 PM
Samm's Avatar
Samm Samm is offline
Member
 
Join Date: Oct 2004
Location: Currently In Egypt For Holiday Until Christmas
Posts: 39
I Cant Install The Firewall 8(

Message Saying " DOCUMENT/~user/LOCALS~1/Temp/vsutil.dll [VSSETProtection]

Message Saying "DOCUMENT/~user/LOCALS~1/Temp/vsutil.dll [WSEDbgPrint]

PC Is Realy Cheesing Me Off 8(
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 09:55 PM.