HJT Log - Possible Virus 2

No valid ip address error,... Just a few more things to do.Please download JavaRa to your desktop and unzip it to its own folderRun JavaRa.exe, pick the language of your choice and click Select. HiJackThis log « Reply #3 on: October 18, 2010, 10:03:01 PM » SUPERAntiSpyware Scan Loghttp://www.superantispyware.comGenerated 10/18/2010 at 07:27 PMApplication Version : 4.44.1000Core Rules Database Version : 5707Trace Rules Database Version: 3519Scan

Please download MsnCleaner.zip and Save it to your Desktop. Please be patient while it scans your computer. · After the scan is complete a summary box will appear.

Click OK. · Make sure everything in the white box has a check next to it, then click Next. · It will quarantine what it found and if it asks if Click here it's easy and free. The next day, the internet for that machine did not work while the other two laptops in the house could use the internet.

Local Service Temp folder emptied.

C:\Program Files\MorpheusBar\bar\2.bin\NPMORPBR.DLL moved successfully. I will be working on your Malware issues. Each program has its strengths and weakness's. http://www.help2go.com/forum/spyware-help/95830-hjt-log-help-removing-spyware-possible-virus.html Then click Remove Older Versions.Accept any prompts.Open JavaRa.exe again and select Search For Updates.Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.

I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs. 1. That may cause it to stall** Cheeseball81, Apr 15, 2008 #7 p51 Thread Starter Joined: Mar 21, 2002 Messages: 926 Cheeseball, I ran Combofix and another HJT. Explorer started successfully OTMoveIt3 by OldTimer - Version log created on 11022008_194825 Files moved on Reboot... C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

Egads, this is a mess too. check it out You can do this by restarting your computer and continually tapping the F8 key until a menu appears. IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} Click 'Show Results' to display all objects found".Click OK to close the message box and continue with the removal process.Back at the main Scanner screen:Click on the Show Results button to

I'll proceed with your advice. have a peek at these guys C:\Program Files\MorpheusBar\bar\2.bin\M0PLUGIN.DLL moved successfully. The only thing that I've found unsettling about this whole affair is the fact that an AV that requires payment to use misses things that freeware is catching. Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dllO2 - BHO: &Yahoo!

MOST IMPORTANT : Windows and IE, and whatever other software that you have that connects to the net, needs to be kept updated. If you are asked to reboot the machine choose Yes.

Generated Fri, 10 Feb 2017 15:15:48 GMT by s_wx1219 (squid/3.5.23) There are several different products that you can use for this. Now, please reboot back to normal mode.

crjdriver replied Feb 10, 2017 at 6:05 PM What's for Dinner...... Due to a few misunderstandings, I just want to make it clear that this site provides only an online analysis, and not HijackThis the program. DllUnregisterServer procedure not found in C:\Program Files\Windows Live\Messenger\riched20.dll C:\Program Files\Windows Live\Messenger\riched20.dll NOT unregistered. HiJackThis log « Reply #5 on: October 18, 2010, 10:04:32 PM » Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:47:45 PM, on 10/18/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer

Always use an UPDATED anti-virus program Make sure you update this at least weekly, if not more often.

Thank you so much in advance!Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:59:06 PM, on 10/16/2010Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\ACS.exeC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\Program Files\Alwil Several functions may not work. C:\Program Files\MorpheusBar\bar\1.bin\M0PLUGIN.DLL moved successfully. Several functions may not work.

It is important that you reply to this thread. The reason for this is simple.

Check out the forums and get free advice from the experts. Hopefully quick easy Q.. The system returned: (22) Invalid argument The remote host or network may be down. Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\Toshiba\Power Management\CeEPwrSvc.exeO23 -

Please try the request again. Completion time: 2008-04-16 7:44:56 ComboFix-quarantined-files.txt 2008-04-16 11:43:49 Pre-Run: 20,842,991,616 bytes free Post-Run: 20,819,984,384 bytes free . 2008-04-10 18:26:42 --- E O F --- Logfile of Trend Micro HijackThis v2.0.2 Scan saved Show Ignored Content As Seen On Welcome to Tech Support Guy! Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates,

Be assured, any links I give are safe.7. The desktop (the infected machine) has not been able to connect to the internet for the past two days. By default, most P2P file sharing programs are configured to automatically launch at startup. We are very busy.You have Viewpoint installed.Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".More information:

Antivirus;avast! UPDATES are important.