WinPC Defender was installed on my PC
Astalavista Forum Index :: Windows O/S Support :: WinPC Defender was installed on my PC
Post new topic   This topic is locked: you cannot edit posts or make replies. View previous topic :: View next topic
  WinPC Defender was installed on my PC
Author Message
cheshire72
Special Member
Special Member


Offline
No Image
Joined: 15 Jun 2007
Posts: 411
Location: Japan

Reply with quote
No Image
yesterday i installed some software.
then WinPC Defender was installed...
then strange event happened one after another.
and i deleted trojan with Kav and MBAM.
but WinPC Defender couldn't be uninstalled with Your Uninstaller.
so i deleted that app from appdate directly and scanned with Your Uninstaller.
but still my Internet browser is strange!!
frequently stopped functioning.
i think it also integrated with Internet browser!!
how do i cope with it?

_________________
>>some virus software overreacting
View user's profile Send private message Visit poster's website Yahoo Messenger
PostDate Posted:Mon May 18, 2009 8:59 am
Thanks: 47Thanked 186 Times In 57 Posts

Author Message
Klean
Super Moderator
Super Moderator


Offline
No Image
Joined: 04 May 2007
Posts: 4645
Location: 192.168.1.1

Reply with quote
No Image
Download a copy of HijackThis and save it to your desktop in a folder. Do a scan and save the HijackThis logfile. Do not remove anything. Post your log file here.

http://astatalk.com/subforum/4/1/OS_Support/

Link to HijackThis>

Astatalk download freehost links:
Code:
http://www.trendsecure.com/portal/en-US/_download/HiJackThis.zip


I will look at it later or a staff member from this section will help you.

_________________
A candle loses nothing by sharing its flame.
View user's profile Send private message Visit poster's website
PostDate Posted:Wed May 20, 2009 6:18 am
Thanks: 48Thanked 1751 Times In 841 Posts

Author Message
cheshire72
Special Member
Special Member


Offline
No Image
Joined: 15 Jun 2007
Posts: 411
Location: Japan

Reply with quote
No Image
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:49:30, on 2009/05/20
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 Upset.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Users\cheshire\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\cheshire\Desktop\HiJackThis\HijackThis.exe

O1 - Hosts: ::1 localhost
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {ecdb5ea3-bd30-4b66-9012-0533b14e76e0} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\cheshire\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Speeky - {3c103f63-b6fb-428c-970c-d9490a5cfd70} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {53F4962A-8E27-4601-8B01-79A82B4D7FC9} (LoadPrg Class) - https://member.gungho.jp/front/member/webgs/LoadPrgAx.CAB
O16 - DPF: {A049E723-858B-4EDB-BAF1-87286429FDA5} (GameleonGameControl Control) - http://homage.gameleon.jp/component/GameleonGameControl.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/jpn/crlocx.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{66EADBFC-6DBB-4D89-9C5E-FC2A76D5619A}: NameServer = 218.231.54.19 218.231.54.3
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll,
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 5950 bytes


------------------
thanks. especially when i open GMail that stop frequently
i think malware add-on is installed

_________________
>>some virus software overreacting
View user's profile Send private message Visit poster's website Yahoo Messenger
PostDate Posted:Wed May 20, 2009 9:02 am
Thanks: 47Thanked 186 Times In 57 Posts

Author Message
Klean
Super Moderator
Super Moderator


Offline
No Image
Joined: 04 May 2007
Posts: 4645
Location: 192.168.1.1

Reply with quote
No Image
Umm did you post here:

http://astatalk.com/subforum/4/1/OS_Support/

We are in transition. I may not be able to post here tomarrow.

_________________
A candle loses nothing by sharing its flame.
View user's profile Send private message Visit poster's website
PostDate Posted:Wed May 20, 2009 10:45 am
Thanks: 48Thanked 1751 Times In 841 Posts

Display posts from previous:   
Post new topic   This topic is locked: you cannot edit posts or make replies.    Page 1 of 1 All times are GMT


Back to top


 
Astalavista Forum Index :: Windows O/S Support :: WinPC Defender was installed on my PC



Search This Topic:
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by Astalavista.MS Team © 2004
Image Here Image Here Image Here