panura
Newbie


Posts: 5
|
 |
RunOnce Entry Reloads and Runs Forever! 2nd
« on: Oct 17th, 2006, 9:31pm » |
Quote Modify
|
=Re-submiited= I must have several different spyware and trojan solutions installed and I always or frequently use them. For instance, SpyBot S&D, AVG, Ewido!, XoftSpySE, SE Adware SEPlus, TrojanHunter (just tried today) Still I'm having a Problem. There’s an item that appears and reappears that concerns me because I haven’t seen it before. No matter what I do to disable or remove this entry, it comes right back. Ad-Watch Monitoring shows it immediately resurfaces as soon as I try to disable or remove it, often followed by ctfmon.exe If I ignore these two for a while and follow up with XoftSpySE, as I always do, before signing off or hibernating, then any combination of Hi Risk stuff, often in large numbers show up (only with XoftSpySE). Most recently I removed : (7)-Real Spy, (2) MediaMotor and (1) New Dial. I’m now compelled to do this several times a day! Below I provide: 1. AutoRun Entries, 2. a recent Hijack log. (partial in reply to posted instructions). What . . . to do ?? Thanks Al F. 1. Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce InstallShieldSetup = C:\PROGRA~1\INSTAL~1\{C4F1A~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{C4F1A~1\reboot.ini -l0x9 2. Partial Logfile of HijackThis v1.99.1 Scan saved at 10:17:28 PM, on 10/14/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Owner R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll O3 - Toolbar: Temporary Inbox - {F05F3153-08B2-44A6-8A0B-132011E28F21} - C:\Program Files\Temporary Inbox\untitled.dll O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~1\INSTAL~1\{C4F1A~1\Setup.exe -rebootC:\PROGRA~1\INSTAL~1\{C4F1A~1\reboot.ini -l0x9 O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe" O4 - HKCU\..\Run: [Brother Control] C:\Program Files\Brother\ControlCenter2\brctrcen.exe O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe O4 - Startup: Start Mailloop 7.lnk = C:\Program Files\The Internet Marketing Center\Mailloop 7\ML7.exe O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe O4 - Global Startup: ePad995.lnk = C:\Program Files\ePad995\ePad995.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\A The TEXT flash was removed from this post because it was causing IE to want to download ActiveX.
|
| « Last Edit: Oct 18th, 2006, 4:16am by panura » |
IP Logged |
|
|
|