Attached Files: cflog3.txt File size: 11.8 KB Views: 2 MGlogs.zip File size: 39.6 KB Views: 3 staywhereyouare, Jun 27, 2008 #11 chaslang MajorGeeks Admin - Master Malware Expert Staff Member I'm C:\WINDOWS\system32\sstqq.dll C:\WINDOWS\system32\qqtss.ini C:\WINDOWS\system32\qqtss.bak1 C:\WINDOWS\system32\qqtss.bak2 C:\WINDOWS\system32\qqtss.bak1 C:\WINDOWS\system32\qqtss.bak2 C:\WINDOWS\system32\qqtss.ini C:\WINDOWS\system32\sstqq.dll Attempting to delete C:\WINDOWS\system32\sstqq.dll C:\WINDOWS\system32\sstqq.dll Has been deleted! Unfortunately, I do not know the name of the software as it was written in Chinese characters and my Chinese is not very good. HJT log was clear after. http://realink.org/solved-why/solved-why-does-lsass-exe-r-w-hdd-each-second.html

Do you have any more question? All rights reserved. Users are normally targeted by false positives, fake alerts, and warning of infections on their computer. Advertisement Al Rocksalot Thread Starter Joined: Apr 3, 2006 Messages: 6 I think my laptop has a virus, I keep getting the Sysprotect pop up asking me to download from their read review

I have pasted a HJT log. or it could be something else... Also, I can't promise you we can repair all the damage it caused...

It seems I am unable to upload it again. I have made backups, and for the record, the replacement motherboard is a pcchips m285g v 9.2a I believe! Thanks again, Mike Logfile of HijackThis v1.99.1 Scan saved at 10:43:32 AM, on 5/16/2007 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe Go to Startup tab and disable the programs that you do not need to start when Windows start.

Go to add/remove programs and uninstall HijackThis. I just know that it comes up AFTER bios loads the hardware and before the winxp splash screen... I have noticed that BEFORE the splash screen, there is a white segmented load bar that goes across. https://h30434.www3.hp.com/t5/Desktop-Software-and-How-To-Questions/HP-Product-Registration-Pop-Up-How-do-I-get-rid-of-it/td-p/336637 When everything is done and your log is clean again, you can enable it again.

C:\WINDOWS\SYSTEM32\hjwvdnfq.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).

I need that log afterwards. -------------------------- * Please download the following file to your desktop: http://noahdfear.gee...com/FindAWF.exe Run the file. Discussion in 'Windows XP' started by Al Rocksalot, Apr 3, 2006. System doctor constantly coming up CD-RW won't all of a sudden work, nor will the DVD drive. Welcome to the Malware Forum!

Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): navigate to this website Are they reporting that they have found something? 0 Message Author Comment by:mlusharks ID: 175171692006-09-13 It's a generic popup that says I should protect my computer from viruses (although I Terms of Use Privacy Policy Licensing Advertise International Editions: US / UK India Jump to content Build Theme! This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

In the box that opens, find the following entries and put a checkmark next to them (if you need some of them to be in the trusted zone, leave them). There is nothing to really install since all HJT does is put an entry into your registry that shows it is installed. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. More about the author Please follow the instructions in Running GMER to detect rootkits and SysProt AntiRootkit Attach the logs when you finish.

Privacy Policy Support Terms of Use ZoneAlarm Forums - Your ZoneAlarm Information Source > ZoneAlarm Forums > ZoneAlarm Anti-virus & Anti-spyware > ZoneAlarm can't remove trojan.win32.pakes.mag Virus PDA View Full Version Thanks! You can delete the C:\MGtools folder and the C:\MGtools.exe file.

C:\Documents and Settings\Joel\Local Settings\Temp\xpre.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

Back to top #8 miekiemoes miekiemoes MalwareBytes Visiting Fellow 514 posts Posted 16 May 2007 - 01:39 PM I'm about 75% through with the AVG scan. If you are not having any other malware problems, it is time to do our final steps: You can uninstall SUPERAntiSpyware now. Solved: Why do I keep getting the Sysprotect Popup? i would deduce that the maker of the drive knows it best....

When you use the Manage Attachments button, you'll find it directly under C. Attached Files: SUPERAntiSpyware Scan Log - 06-20-2008 - 23-11-15.log File size: 611 bytes Views: 5 mbam-log-6-21-2008 (01-12-15).txt File size: 798 bytes Views: 5 cflog.txt File size: 10.5 KB Views: 2 staywhereyouare, C:\WINDOWS\SYSTEM32\hgupawvm.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. http://realink.org/solved-why/solved-why-don-t-these-work.html If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.

I've actually had this problem for so long now, I'm getting used to no sound...It's bad, I know. C:\WINDOWS\SYSTEM32\tvkamxuf.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : Cleaned with backup (quarantined). Thanks again for your help. It is.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [Reminder] C:\Windows\Creator\Remind_XP.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - Nothing was uninstalled.Click to expand... Join us in honoring this amazing group of Experts. HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Don't click on the window while the fix is running, because that will cause your system to hang. So unfortunately, you have to accept that. just so we make sure that you are 100% clean May 1, 2006 #8 Rin TS Rookie Topic Starter Yea, I did all of that down to the t! C:\Documents and Settings\Joel\Local Settings\Temp\snapsnet.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

Doubleclick combofix.exe Follow the prompts. Since trying to adjust settings to make them visible doesn't work (can only make the windows reappear with task manager) I wasn't sure. I hit cancel to debug and got a message that it could not debug. Let me know how things are running now?