vegasgal 0 Newbie Poster

I posted for help 2 days ago and I'm still waiting for someone to respond? I went online to chat with Nortons and I think we got it fixed, but still someone could've got back to me on your end.

Linda

vegasgal 0 Newbie Poster

Here is the HiJack This Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:27:23 PM, on 11/14/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\wanmpsvc.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINNT\System32\wbem\wmiprvse.exe
C:\WINNT\system32\msiexec.exe
C:\WINNT\System32\alg.exe
C:\WINNT\system32\wuauclt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\GWMDMMSG.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINNT\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.net
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

vegasgal 0 Newbie Poster

Hi,
Last night I get this little window called ccCommon and it says Windows Configures. I immediately x'd it out and then ran my Nortons, nothing showed up. I then ran Spyware Doctor and it picked up: HeurEngine.Packed.FSG - Trojan-Downloader.Zlob.GEN - HeurEngine.Packed.MoleBox - Application.NirCmd. I thought I had gotten rid of all this, but this morning when I turned on the pc I get this little window with the Windows Installer again, I took a screenshot of the it.
I'll go an run a report from hijack this. I did run Malmare last night and it says I'm clean.

Thanks,
Linda

vegasgal 0 Newbie Poster

Judy,
I will let you know when I've installed the new RAM.
I was able to find out about my video card, its a Intel 82845G - they don't make them anymore. I can remember when I purchased this pc the guy told me it only had 64MB and that I would need to bump it up. I do not have a clue on this one, I'll go poking around when I have the case open.
Thanks Again,
Vegasgal

vegasgal 0 Newbie Poster

I've got the problem solved.

Thank you for your help,
Vegasgal

vegasgal 0 Newbie Poster

Hi Judy,
I was able to do that just fine. I guess this problem is solved and I want to thank you so much for all your help.

Thank You,
Vegasgal

vegasgal 0 Newbie Poster

Judy,
I need help with the CodeStuff Starter. I was able to to all the ones on the Start Up Tab, but not sure how to do the ones on the Services Tab?

Thanks,
Vegasgal

vegasgal 0 Newbie Poster

Hi Judy,
I ordered 2-1GB of RAM, we'll see how that works out. Just finished downloading the CodeStuff Starter and will proceed with that. How can I find out what size my video card is? I did go in and change my vitual memory to 1152MB but I still get the popup.
Thanks,
Vegasgal

vegasgal 0 Newbie Poster

As I stated before I am double posting in this forum and was wondering how I can remove my original thread in: Windows NT/2000/XP/2003 ?

How can I change all the programs on the list from auto start? I'm clueless.

On the list of items you wanted me to put a checkmark on and then Fix Checked button on HJT, I could only find 08. I did find both folders on C Drive and removed them.

My Computer:
Size: 76.3 GB
Free Space: 53.8 GB
RAM: 768
Virtual Memory Set At: 600-768

Attaching the new HJT log

Thanks,
Vegasgal

vegasgal 0 Newbie Poster

Pc is 3 to 4 yrs old, not sure and I have 768 MB of Ram.

Thanks,
Vegasgal

vegasgal 0 Newbie Poster

Sorry but I went to My Computer and ran my mouse across the C: and it says: 53.6 GB and Total Size: 76.3 GB
I had Malwarebytes already and attaching the file.

Thanks,
Vegasgal

vegasgal 0 Newbie Poster

I posted the log in "Virus and Spyware".
I'll try and attach here. It wouldn't attach the first time cause I didn't have the right file extension.

vegasgal 0 Newbie Poster

I posted in the wrong area, so here I am again and hope this time the HiJack Log will be attached.
I keep getting a popup saying Windows virtual memory is low and that it will be fixed. So I go and check it out and nothing has changed, so I changed it to the recommended amount.
I use Firefox and it keeps crashing, it was crashing before I changed the memory. So now I thought I'd use IE and it closes on me.
I have no idea what is going on and thought maybe you could help me?

Thanks,
Vegasgal

vegasgal 0 Newbie Poster

I keep getting a popup saying that windows virtual memory is low. I go in and check it and it seems fine, although I did bump it up to the recommended size, not sure if I should've or not, will leave it alone until I find out whats going on.
I have the latest version of Firefox for my browser and it keeps crashing, so I go and use IE and get a popup saying that it had to close.
I ran Nortons and Spyware Doctor and its not picking up anything, infact, all of a sudden since yesterday spyware cannot complete its daily scans so I have to download them at least 4 times a day.
I ran HiJack This and have a log and hope someone here can help this old lady out?

Thank You,
Vegasgal

vegasgal 0 Newbie Poster

I did not remove Adobe Acrobat 5.0 and will take a look at Adobe Reader though.

Found that hidden file and ran a scan see attachment.

I want you to know that I truly appreciate all your help with this problem, it means alot to me that there are people like you who take precious time away from yourself to help others. Thank You

Until Next Time (NOT),
Vegasgal

vegasgal 0 Newbie Poster

I removed all the old Java's and left the current one. Deleted Pando, Urge and Viewpoint Media Player. I also deleted C:\WINNT\hvrqkcro <---had no idea what was in this folder. Adobe Acrobat 5.0 I couldn't find anywhere to check for updates, will I have to purchase the v8.0?

I looked 2 X in the C:\WINNT\system32 Folder for: 953BEBAFA6.sys - then looked 2 X in the C:\WINNT Folder and still couldn't find it.

I ran analysis on both QTFont.qfn and QTFont.for see attachments below.

pc is running much better now Thank You:icon_smile:

vegasgal 0 Newbie Poster

This afternoon when I logged on Nortons found and fixed 3 trojans. I ran SpyWare Doctor and came clean. Here are the 3 reports you wanted and from what I can read we still have a nasty little booger around. I hope that we can remove it soon.

XP Defender was not on the Add/Remove List nor is it listed in All Programs. I do remember seeing it the other day and with all this happening not sure if I deleted or not.

vegasgal 0 Newbie Poster

My Internet Explorer browser is not stable, I'm getting not responding more than I should. I also have Firefox, but switch between the 2 of them.

When I clicked on the first link for ComboFix, it did not give me an option as to where to install it. I've searched for it and I think this is it: Its in a folder called: C:\QooBox and inside the folder there are a few other items, one of the items has the ComboFix Quarantine txt so I am sure this is the one. I won't delete it until I hear back from you.

We do not bank online, but I do love shopping online. Yesterday I did purchase Spyware Doctor so I will keep an eye out on my credit card account.

Its late out west and will check here first thing!

Thanks Again

vegasgal 0 Newbie Poster

Everything seems to be normal once again. Thank You So Much for all your help in getting rid of this nasty booger. Here are the 3 logs you've requested and I hope you can come back here and give me the thumbs up!

http://www.vegasgal.net/logs/mbam-log-3-3-2008%20(20-19-17).txt

http://www.vegasgal.net/logs/combofix.txt

http://www.vegasgal.net/logs/hijackthis_2.txt

Many Thank Yous!
p.s. When I ran CombFix it did not disconnect me from the internet

vegasgal 0 Newbie Poster

It seems that somehow some kind of spyware got put on my pc and now it keeps saying that I need to buy a certain program in order to get rid of it. When I run my SpyWare Doctor, it keeps saying:
Malicious Action Blocked
mgmrwmrv.exe is attempting to access registry
HKLM\SOFTWARE\microsoft\windows\currentversion\explorer\BrowserHelperObjects\{bunchof numbers here}\

It also pops up with a message saying a TROJAN DOWNLOADER is on my PC and then it leads me to the page where I can buy the program to get rid of it.

I tried running SpyWare Doctor, but the problems persist. Today it must have affected my Nortons, my Auto Protect will not turn on. Here is the Hijack Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:51:33 PM, on 3/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINNT\system32\mgmrwmrv.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\GWMDMMSG.exe
C:\WINNT\System32\hkcmd.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Logitech\QCDriver\LVCOMS.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe