Posted: 3/21/2011 8:03:38 AM EDT
|
Im having some computer issues, and im not to great at fixing them.
I apparently have a program called gew.exe that is screwing things up. Also when i google something and click a link I am redirected to spam sites. I have run about a dozen spyware and anti-virus programs w/ no luck. |
|
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:22:08 PM, on 3/14/2011 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\WINDOWS\system32\STacSV.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Memeo\AutoBackup\InstantBackup.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://co103w.col103.mail.live.com/m...px?n=281850821 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USCON/1 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://g.msn.com/USCON/1 F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter O4 - HKLM\..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe /background O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe ––silent ––no_ui O4 - HKLM\..\Run: [Memeo AutoSync] C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe ––silent O4 - HKLM\..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ––silent ––no_ui O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://*.travelers.com O15 - Trusted Zone: http://*.travelerspc.com O15 - Trusted Zone: http://*.travelers.com (HKLM) O15 - Trusted Zone: http://*.travelerspc.com (HKLM) O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab O16 - DPF: {D6E0B119-DCF2-4CD6-8DFB-7CFF1B70F7FF} (TeamOn Import Object) - https://bis.na.blackberry.com/html/w...s/TOImport.cab O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://vertaforesupport.webex.com/c...rt/ieatgpc.cab O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Update Service (gupdate1c9a3ee23378a9a) (gupdate1c9a3ee23378a9a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE –– End of file - 12331 bytes This is what hijackthis came up with last week. |
|
typically if you're being redirected they've replaced or updated your host file
It's located here: c:\windows\system32\drivers\etc\hosts *or c:\winnt\system32\drivers\etc\hosts on some boxes* Look for a hosts file (may be hidden so you will have to go to tools, folder options, view and check (actually a radio button) show hidden and also check the hide protected files button) Open it with textpad or notepad. file should have 1 line in it that isn't rem'd out (# before it) it should be: 127.0.0.1 localhost.... (may be more i can't remember) Remove any of the other stuff below this and try your web redirecting. As for the process running i don't see it in your Hijackthis list. Where is running from? Can you end it? There other files in the directory? |
|
I would recommend rebooting your PC into Safe Mode and then running your anti spyware programs while in Safe Mode.
I also highly recommend downloading, updating , and then running Malwarebyte's Anti-Malware Its one of the best available, and its free for the home user. |
|
Quoted:
I would recommend rebooting your PC into Safe Mode and then running your anti spyware programs while in Safe Mode. I also highly recommend downloading, updating , and then running Malwarebyte's Anti-Malware Its one of the best available, and its free for the home user. Thats been done to no avail. Thanks though. |
|
Quoted:
Quoted:
I would recommend rebooting your PC into Safe Mode and then running your anti spyware programs while in Safe Mode. I also highly recommend downloading, updating , and then running Malwarebyte's Anti-Malware Its one of the best available, and its free for the home user. Thats been done to no avail. Thanks though. If the host file doesn't work check out avast. It's free and after the intstall select you want to do a boot scan. It will scan all your files on boot before windows starts up. Normally it catches the redirect viruses. www.avast.com |
|
I know others have suggested parts of this but here's what I'd do:
If you can download and install Malwarebyte's Anti-Malware then do that (download from another PC then USB key to the infested system if you have to). Update the malware definitions in the program. Reboot into safe mode and run a full scan on every drive. Delete anything that is found. Next go into Internet Explorer's properties and I believe on the Advanced tab there is a "Reset All" settings. I can't remember if it's in Advanced but it's in there in IE's settings. That'll reset IE to it's normal default settings. Also if you can after that try to go to the "Manage Add-Ons" within IE and disable ALL add-Ons. |
|
Quoted:
Quoted:
Quoted:
I would recommend rebooting your PC into Safe Mode and then running your anti spyware programs while in Safe Mode. I also highly recommend downloading, updating , and then running Malwarebyte's Anti-Malware Its one of the best available, and its free for the home user. Thats been done to no avail. Thanks though. If the host file doesn't work check out avast. It's free and after the intstall select you want to do a boot scan. It will scan all your files on boot before windows starts up. Normally it catches the redirect viruses. www.avast.com I ran this last night. It caught 3-4 "things" then went on to startup and looks fine until I try to click on an icon, start bar ect. Then it just locks up. Fffffff. Any good computer repairman in hot springs? Posted Via AR15.Com Mobile |
|
You may be better off to just remove the hard drive, connect it to another computer as a slave, save any crucial data you may have, and re-install the OS from scratch. Then you can scan your crucial data you backed up to make sure none of it is infected before you upload it back to your newly installed OS.
Any competent PC repair tech can do this, if memory serves, it will run you about $150 to have this done at a PC repair shop. Unless of course you know someone that can hook you up. I would be happy to do it for free. But I travel for work and am gone a lot of the time. As of now, it will be a minimum of a week before I could even start on it. Total process of backing up, re-installing OS & drivers, scanning backup, then uploading backup back to new OS would only take 2-4 hours if you don't have a huge amount of data. But the more data you have to back up, the longer it will take. |
|
Quoted:
You may be better off to just remove the hard drive, connect it to another computer as a slave, save any crucial data you may have, and re-install the OS from scratch. Then you can scan your crucial data you backed up to make sure none of it is infected before you upload it back to your newly installed OS. Any competent PC repair tech can do this, if memory serves, it will run you about $150 to have this done at a PC repair shop. Unless of course you know someone that can hook you up. I would be happy to do it for free. But I travel for work and am gone a lot of the time. As of now, it will be a minimum of a week before I could even start on it. Total process of backing up, re-installing OS & drivers, scanning backup, then uploading backup back to new OS would only take 2-4 hours if you don't have a huge amount of data. But the more data you have to back up, the longer it will take. I do have the entire HD backed up on a external drive. I've considered just re installing windows but I don't want to have to buy office again... Posted Via AR15.Com Mobile |
| Have you called ms? Im sure they can issue a new code or help you out after the three times. I mean after three mags do i have to quit using my rifle? Apples and oranges, but if you buy a product you should use it as much as you want within the user agreement of course. |
|
Quoted:
I do, but the little code you can only use 3 times has been used 3 times. Posted Via AR15.Com Mobile I think you mean the license for office, That should be for three systems instead of three installs, IIRC as long as you haven't made a substantial change to the system you should be able to reinstall with the same license. IIRC the components that Microsoft uses to determine how much of the original system still exists are CPU, motherboard, hard drive and optical drive. I think as long as you have at least two of the original components in the system you are good to go. At least on OEM copys of windows. |
|
Quoted:
Quoted:
I do, but the little code you can only use 3 times has been used 3 times. Posted Via AR15.Com Mobile I think you mean the license for office, That should be for three systems instead of three installs, IIRC as long as you haven't made a substantial change to the system you should be able to reinstall with the same license. IIRC the components that Microsoft uses to determine how much of the original system still exists are CPU, motherboard, hard drive and optical drive. I think as long as you have at least two of the original components in the system you are good to go. At least on OEM copys of windows. This should be correct. You own the license for office, so you can re-install it on a computer "legally" as long as you are still within your (3) license uses, which installing it back on a PC that it was originally on would count. If the license key fails to allow install of office, just ring up MS and let them know this. They will hook you up. I have done this more than once, with no issues. |
|
http://support.kaspersky.com/viruses/solutions?qid=208280684 Check this out and give it a try. It has worked well for me in the past. |
|
Has anyone suggested doing a system restore to an earlier date? This is the quickest and easiest and safest. May have to do this from safe mode.
Edit: I saw where you tried this, but if that didn't work do it again to an earlier date. Another thing you can do is to slave the drive in another computer and run your scans on it there. This is safer done if you plug it in as a usb after the other computer boots. There are adaptors for this. Sometimes you can do a repair install. Google this for details on how. Not hard, just a few details. |
|
Quoted:
One more easy thing you can try: Reinstall service pack 3. Other versions of windows wont let you do this but XP will. Sometimes that will fix things. Or do the repair install. Do i just find that on Microsoft site? (im fairly computer-dumb, if you cant tell) |
|
Service pack 3 should be on the M$ site. If not google it, shouldn't be hard to find.
Try here: http://www.microsoft.com/downloads/en/details.aspx?FamilyId=5B33B5A8-5E76-401F-BE08-1E1555D4F3D4&displaylang=en For a repair install try here: http://www.michaelstevenstech.com/XPrepairinstall.htm Scroll down a bit to "XP repair install" Neither is hard. Let us know how you do. CC |