need help badly

  1. #1
    canadacatman is offline Newbie

    Angry need help badly

    hello to all.i have a bad problem with my pc.up til 3 days ago it was working fine.now slow as well hell.i ran my adware,noadware,avg free,xoftspy,disc defrag,and no viruses and only a few cookies.12 i think.i did all the delete temporary files and such but still nothing.now i read on here about jv16 registry cleaner.so i downloaded that and wow it found 430 errors or problems.nowwhen i try and delete the 430 erroes i get a message saying you are about toremove an item that is most likely not safe to remove,so what do i do with the 430 errors.i dont know very much about pc's.so any help would be greatly appreciated.i have windows xp.i also ran mlu blaster and that found 113.so any help again would be greatly appreciated especiallywith what to do with the 430 errors that jv16 found...thanks jessie williams
    Last edited by canadacatman; 25-02-2006 at 05:45 AM.


  2. #2
    canadacatman is offline Newbie
    oh ya sorry i forgot to ask are the spyware and antivirus im running good ones.and free anti virus,adware,noadware,xoft spy,jv16 power tools,and mlu blaster.thanks again jessie williams

  3. #3
    canadacatman is offline Newbie
    not sure what this means but i seen this is good to have.are there any problemsin here also

    Logfile of HijackThis v1.99.1
    Scan saved at 12:49:58 AM, on 2/25/2006
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\NoAdware4\NoAdware4.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\jessie\LOCALS~1\Temp\Rar$EX00.110\Hija ckThis.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafficswarm.com/cgi-bin/...5b52d63f63833e
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~1\IBBar.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~1\IBBar.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: MRU-Blaster Silent Clean.lnk = C:\Program Files\MRU-Blaster\mrublaster.exe
    O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~1\IBBar.dll
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DD6E6F1D-8C00-4067-8B27-BA100BEC38B3}: NameServer = 198.6.1.125 198.6.100.125
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: extfpu - C:\WINDOWS\SYSTEM32\extfpu.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  4. #4
    VopThis is offline Senior Member (Canada)
    Your lack of an evident Service Pack 1 (SP1) update for WinXP may also suggest you are way behind on critical updates which is your most crtical first line of defense for your PC. Are you on dialup or a high-speed connection?


    Neither noadware or xoft spy are on most spyware fighter's most useful tool list.

    NoAdware Adware/Spyware remover - initially considerered a rogue program - see here http://www.adwarereport.com/mt/archives/000023.html . The latest version has since apparently mended its ways: see note http://www.spywarewarrior.com/rogue_...e.htm#naw_note
    http://castlecops.com/startuplist-6393.html


    jv16 power tools can get a lot of novice users into trouble. I would not recommend going there unless you are have serious unresolved issues and are VERY careful in using and understanding this tool. Often it is more of a registry junk (or ophan entry) cleanup process.


    mru blaster is a tool more for people who are concerned with (optional and mostly inconsequencial) traces left behind on their PC.



    A complete toolkit probably needs a trojan scanning capable tool such as 'EWIDO' or 'A Squared'. 'Spybot' is also a good free choice. Eventually you may find a commercial tool is much more complete and reliable foundation such as 'Spy Sweeper'. However, no one tool will EVER be able to do it all. 'Panda' Activescan is also a very commonly used tool. See the trustworthy link provided in my signature, below.




    You really need to setup a dedicated folder for HJT items – to avoid horrible clutter and potential lost backup issues.

    It's best that the HijackThis tool NOT be located in its current location (particularly on your Desktop or in a TEMP folder). This way you can more easily undo any changes if something goes wrong.

    Create a new folder in your C: Drive. Name it HJT (or HijackThis) such as C:\Program Files\HJT, C:\HJT and move the HijackThis.exe file in it. Run HJT from there (and revise your shortcut accordingly).




    Read over the following directions. Ask if anything appears unclear to you.


    Download Clean.bat to your desktop: for later use to clean out your TEMPORARY and PREFETCH files.
    http://www.thatcomputerguy.us/downloads/clean.bat



    We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.

    SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

    O2 - BHO: (no name) - {B8D60EBB-5565-4392-957B-7164BA087AD4} - C:\PROGRA~1\INSTAN~1\IBBar.dll
    O3 - Toolbar: Instant Bu&zz - {7475D3FD-5D85-49DB-8B9B-6968467B2D80} - C:\PROGRA~1\INSTAN~1\IBBar.dll

    O9 - Extra button: Instant Buzz - {066040F0-5018-4E15-8AA0-81D36136D989} - C:\PROGRA~1\INSTAN~1\IBBar.dll

    Make sure that all browser windows and internet links are closed, even this one!
    CLICK ’FIX CHECKED’ with HijackThis.



    HIDDEN FILES: To make sure you can see all hidden files, please follow the directions here

    SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained here if needed).



    Delete TEMPORARY FILES: Now, hunt down the most common temporary file locations and the temporary file clutter contained therein (and of possible malware hiding places):

    Go to Start > Run and type: CLEANMGR.EXE and hit enter.
    When prompted select the C: drive and click ok.
    Check the boxes for:
    • Temporary Internet Files
    • Downloaded Program Files
    • Recycle Bin
    • Temporary Files
    Click OK or Enter

    For additional, more thorough cleaning and for multi-profile user configurations:
    (*) Run Clean.bat to clean up your TEMPorary files.

    ***** Clean out the Recycle Bin for items removed below, ONLY once you have regained the full functional use of your PC.




    Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):


    DELETE FILES:

    (none specified/as needed)



    DELETE APPLICATION FOLDERS:
    1. Go to Add/Remove Programs
    1. In Control Panel>Add/Remove Programs look for any CLEARLY related entries for unwanted items listed below (or anything else you need to investigate or did not put in there).

    2. UNINSTALLER Alternate SEARCH: Otherwise, advisable to locate and try right-clicking on any of the given SEARCH FOLDER items below and further search (tick include subdirectories) for the following exact text:

      UN*.EXE, *UN*.EXE

      This may reveal an uninstaller with label terms such as '...uninstall...EXE', ‘unins000’, or 'unwise.EXE'. [b]Double-click that EXE, if one is found, to remove that particular FOLDER and it contents.[b] Thereafter, check to ensure that the folder is completely gone. Otherwise, consider deleting the folder in question.

    C:\PROGRA~1\INSTAN~1
    (search for exact text INSTAN*)





    POST A REVISED HIJACKTHIS LOG for review:
    Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.
    Last edited by VopThis; 25-02-2006 at 08:26 PM.

  5. #5
    canadacatman is offline Newbie
    please help with this vop this



    i did a virus scan and the scan found 3 viruses
    trojan.pws.goldspy
    trojan.pws.goldspy
    trojan.pws.goldspy
    C:\WINDOWS\system32\fpuext.sys <Trojan.PWS.GoldSpy>
    C:\WINDOWS\system32\extfpu.dll <Trojan.PWS.GoldSpy>
    C:\1.exe <Trojan.PWS.GoldSpy>
    C:\WINDOWS\system32\extfpu.dll <Trojan.PWS.GoldSpy>

    how did i get them if i have an antivirus(avg)
    how do i get rid of them..



    also here is the new hackthis i got

    Logfile of HijackThis v1.99.1
    Scan saved at 8:20:17 PM, on 2/27/2006
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\jessie\LOCALS~1\Temp\Rar$EX07.485\Hija ckThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafficswarm.com/cgi-bin/...5b52d63f63833e
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafficswarm.com/cgi-bin/...5b52d63f63833e
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DD6E6F1D-8C00-4067-8B27-BA100BEC38B3}: NameServer = 198.6.1.125 198.6.100.125
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: extfpu - C:\WINDOWS\SYSTEM32\extfpu.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    also i did the adware settings you put in another post and still have no spyware.
    but help withthem viruses would be appreciated.thanks for the help VOPTHIS

  6. #6
    VopThis is offline Senior Member (Canada)
    [Trojans]
    how did i get them if i have an antivirus(avg)
    how do i get rid of them..
    Many AV tools will catch SOME trojans but it is often necessary to run a dedicated trojan scanning tool or at least one that has very specific strengths against trojans. No tool will necessarily identify every last infection. Multiple tools will often be necessary the higher your PC's risk profile (such as Limewire).


    C:\DOCUME~1\jessie\LOCALS~1\Temp\Rar$EX07.485\Hija ckThis.exe
    You did not address the need for a dedicated HijackThis folder (my last post). For backup purposes, should be something like:
    C:\Program Files\Hijackthis\HijackThis.exe




    The lack of SP1 (and critical updates) is a big security concern for getting and keeping your PC healthy. As long as you are running Limewire you will always potentially be one download away from a virus or other malware. Accordingly, you need to be very vigilant and dedicated with your choice of scanning tools but which may never be truly able to protect you from some potentially horrible consequences.

    You also appear to have disabled some items in MSCONFIG thus hiding some potential infections that might otherwise be flagged for attention.





    Download Clean.bat to your desktop: for later use to clean out your TEMPORARY and PREFETCH files.
    http://www.thatcomputerguy.us/downloads/clean.bat



    We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.

    SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

    O20 - Winlogon Notify: extfpu - C:\WINDOWS\SYSTEM32\extfpu.dll

    Make sure that all browser windows and internet links are closed, even this one!
    CLICK ’FIX CHECKED’ with HijackThis.



    HIDDEN FILES: To make sure you can see all hidden files, please follow the directions here

    SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained here if needed).



    Delete TEMPORARY FILES: Now, hunt down the most common temporary file locations and the temporary file clutter contained therein (and of possible malware hiding places):

    Go to Start > Run and type: CLEANMGR.EXE and hit enter.
    When prompted select the C: drive and click ok.
    Check the boxes for:
    • Temporary Internet Files
    • Downloaded Program Files
    • Recycle Bin
    • Temporary Files
    Click OK or Enter

    For additional, more thorough cleaning and for multi-profile user configurations:
    (*) Run Clean.bat to clean up your TEMPorary files.

    ***** Clean out the Recycle Bin for items removed below, ONLY once you have regained the full functional use of your PC.




    Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):


    DELETE FILES:

    C:\WINDOWS\system32\fpuext.sys
    C:\WINDOWS\system32\extfpu.dll
    C:\1.exe
    C:\WINDOWS\system32\extfpu.dll




    POST A REVISED HIJACKTHIS LOG for review:
    Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.

  7. #7
    canadacatman is offline Newbie
    ok what trojan software should i get and download.also it looks like i should get rid of limewire should I.thanks

  8. #8
    VopThis is offline Senior Member (Canada)
    looks like i should get rid of limewire should I.
    That would be desirable. Most of your current problems are probably linked with that tool.



    Try Ewido for trojan scanning:


    Please download, install, update and scan your system with the free (trial) version of Ewido trojan scanner:
    1. When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
    2. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    3. From the main ewido screen, click on update in the left menu, then click the Start update button.
    4. After the update finishes (the status bar at the bottom will display "Update successful"), click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so time to go get a drink and a snack....
    5. If ewido finds anything, it will pop up a notification. You can select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.
    6. When the scan finishes, click on "Save Report". This will create a text file. Please then paste the contents of the text file to this thread.

  9. #9
    canadacatman is offline Newbie
    ewido anti-malware - Scan report
    ---------------------------------------------------------

    + Created on: 7:42:07 PM, 2/28/2006
    + Report-Checksum: 62D6E6DE

    + Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{7475D3FD-5D85-49DB-8B9B-6968467B2D80} -> Adware.InstantBuzz : Cleaned with backup
    C:\1.exe -> Logger.Goldun.ht : Cleaned with backup
    :mozilla.8:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.28:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Atdmt : Cleaned with backup
    :mozilla.30:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
    :mozilla.36:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.52:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.54:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.55:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.56:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.57:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.62:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.74:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.75:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Liveperson : Cleaned with backup
    :mozilla.77:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.78:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.79:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.80:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.81:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Hitbox : Cleaned with backup
    :mozilla.104:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
    :mozilla.110:C:\Documents and Settings\jessie\Application Data\Mozilla\Firefox\Profiles\to8s7nrq.default\coo kies.txt -> TrackingCookie.2o7 : Cleaned with backup


    ::Report End



    so did this get rid of my trojans.
    will my pc run better now.
    what else do i have todo to get me running faster.
    limewire is now gone.
    will it be easier for me just to reformat my pc or will i get rid of the trojans..
    thanks for the continueing help.

  10. #10
    canadacatman is offline Newbie
    Save 20% on AVG Internet Security 2012 Suite!
    now i ran the other virus scanner i have(big red stop sign)and it still found viruses that the ewido didnt find.i also ran panda active scan.this is the results from(the big red stop sign)C:\WINDOWS\system32\extfpu.dll <Trojan.PWS.GoldSpy>shows 2 from here.
    C:\WINDOWS\system32\fpuext.sys <Trojan.PWS.GoldSpy>



    here is panda active scan results
    0

+ Reply to Thread
Page 1 of 2 1 2 LastLast