i did uinstall one of the av programs as u said and here is my new log

Logfile of HijackThis v1.99.1
Scan saved at 12:00:01, on 27.08.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:


C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programfiler\McAfee.com\VSO\mcvsshld.exe
C:\Programfiler\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programfiler\MSN Messenger\MsnMsgr.Exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\programfiler\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Programfiler\Messenger\msmsgs.exe
C:\Programfiler\Internet Explorer\IEXPLORE.EXE
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Documents and Settings\sTyLe\Skrivebord\CHijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vg.no/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {60D3AAEB-AA39-4AE0-B2F9-E4AF0613A2A3} - C:\PROGRA~1\Cosmi\SPYWAR~1\pop\ABG_PL~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Programfiler\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Programfiler\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\RunServices: [Windowsz] rwnt.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programfiler\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Morpheus.lnk = C:\Programfiler\Morpheus\Morpheus.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\programfiler\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

Dani AI

Generated

correctly noted that a clean reinstall is often the fastest, most reliable fix when system integrity is uncertain. For , where important school work is involved, the priority is preserving personal files safely while returning the PC to a known-good state. The following is a concise, practical recovery and prevention plan that complements the thread discussion.

Reinstall (preferred when time allows)

  • Create offline backups of documents, pictures and email stores to external media. Do not image the whole system partition.
  • Export browser favorites and any product/license keys needed later. Keep a written inventory of installed apps and drivers.
  • Verify backups on a different, known-clean machine and scan those files before restoring. Avoid restoring executables or installers from the infected machine.
  • Perform a full OS reinstall to a reformatted partition, then apply all official updates before reconnecting to untrusted networks. After updates, install a modern AV and enable a host-based firewall.
  • Restore only scanned personal files and re-install applications from original installers.

Targeted cleanup (if reinstall is not possible)

  • Isolate the machine from networks. Use bootable rescue media or an offline scanner to remove threats before reconnecting.
  • Disable system restore before major cleanup to prevent reinfection via restore points, then re-enable it afterward.
  • Run layered scans: offline rescue scan, rootkit detector, then full antivirus/anti-malware scans from a clean environment. Carefully review and document any startup/service changes before removing them.
  • After cleanup, change all account passwords from a clean device and monitor for suspicious activity.

Prevention and follow-up

  • Keep the OS and applications fully patched, use least-privilege user accounts for daily work, enable a firewall, and maintain up-to-date antivirus. Create a disk image after a clean install to speed future recovery.

Recommended Answers

All 3 Replies

hope anybody can respawn

plz can anybody here help me?
i really need to fix my prob im doing much school work on it

Hi sTyLe,

what I (sorry) overlooked in your first log is that you are running XP apparently without any service packs. Connecting a PC to the internet without these (and all subsequent hoftfixes) is more than "not recommended". Your IE is outdated too. Whatever you will try to remove your malware, the same or other will come back sooner or later this way: Even old and known malware can exploit all the loop holes in your system and no antivirus software can really protect you this way. I can't see a firewall either (connected via a router?). All this messes up things pretty bad - updating this system may even fail now due to the infections. (Try anyway)

The antivirus guys here (and everywhere) need much more information on what happens on your computer, which malware your AV scanners possibly reported and how the infection manifests itself in detail. What exactly is on the popup window? Is there a clue (maybe in the title bar) which program sends the window? Is it an ad?

Apart from the reference to RWNT.EXE I can't see anything unusual on the log. Together with the popups, this points to an infection which can't be removed that easy - you will have to run several tools and maybe online scans to identify them and then several steps to remove them may follow. This usually takes some days, so if you need your computer for school work, wiping and reinstalling (this time with Service Packs + hotfixes) would be probably faster and you get rid of your nasties, too.
Read in this forums how to set up your system to avoid infections.

I wish I could help you better, but maybe somebody comes with a better suggestion for you. Good luck!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.