  1. Andy, No need to apologise man, you're doing me a big favour! I have spywareblaster, panda, etc installed and have always kept things up to date so I guess this infection has snuck in when one of the sprogs has been in Kazaa or the like. Everything seems fine now, thanks for all your help. Ian
  2. Andy, The two logs you wanted - nothing found on Blacklight ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Friday, April 13, 2007 1:48:53 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: Kaspersky Anti-Virus database last update: 13/04/2007 Kaspersky Anti-Virus database records: 296918 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: ext
  3. Andy, The two logs are below. The failure to find helper .exe is fine, I knew it had gone but maybe worded my reply badly - however I am sure I remember trying to find out about this file a long while ago as I had noticed it and didn't know what it was doing there. If I remember how far back I'll let you know! I checked the two files in Hijackthis, had already removed old java stuff and will probably keep Panda as I've paid for it! Thanks Ian Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\yjtcr
  4. Andy, All seems to have worked fine, thank you so much! The only issue that I can see is seagate-helper is still there but as .old - it can't be deleted though, access denied. Sorry that you have so much to look at now! Thanks again Ian Gromozon Log Removal tool loaded into memory ------------------------------------ Executing rootkit removal engine.... ------------------------------------ Disabling rootkit file: \\?\C:\WINDOWS\system32\aux.pzq \\?\C:\WINDOWS\system32\aux.pzq Resetting file permissions... Clearing attributes... Removing file... Rootkit removed! Cle
  5. Andy, What a man! Fix worked and below is the hijackthis log that was generated almost immediately - one question, how did that sucker get in there? Thanks for your help on this and hope that no gromozone is also lurking! Ian Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 22:57:22, on 11/04/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svc
  6. Andy, Sorry for the delay - been working today! This is the contents of result.txt Thanks Ian ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll CheckAppHelp REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll CheckAppHelp REG_DWORD 0x1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execu
  7. Hi, Downloaded the file OK and started running but at 12% a message flashed up on the screen - difficult to catch but I think it was something about never having run hijackthis. Comboscan closed and no logs in the folder. Shall I follow the instructions in the links in the replies to the mail below? Thanks Ian
  8. Sorry, can't even get to the forum - as soon as I click on the title page the browser shuts down! same happens if I enter hijacktjhis in a search engine - I don't have it loaded Ian
  9. Hi, I know that this is the wrong Forum but I can't access anything that has the words CCleaner in it! I have been using it for years but suddenly the screen goes immediately to all wallpaper and then the desktop icons re-appear whenever: 1) I try and open CCleaner from the desktop, from the start menu or from program manager. 2) I type CCleaner into a search engine and this closes the browser too! 3) After running ccsetup the language screen appears but then it all goes again 4) entering ccsetup or CCleaner into search on windows explorer. 5) right click on the desktop icon
