Keybored Posted June 5, 2009 Report Share Posted June 5, 2009 Hi. About a week ago, I downloaded a file via uTorrent and when it was all done downloading and in the middle of the seeding process, I pressed the "Start" button thinking that it would open the file and instead, something weird has happened. The title of the file was instantly replaced by a long series of the plus sign (+). Not sure if this is a bug or because I did something wrong but it was getting really annoying because the + sign kept coming up whenever I had to type! So I removed the file and I believe I removed something from the "Trackers" section as well. Well, this stopped the constant key repeats but I accidentally pressed the "Start" button again when I downloaded the file again (Sigh, I know). Same thing happened and I removed the file but this time there was nothing in the "Trackers" section. So now I am stuck with the + sign repeating itself even as I type right now. Please help! How do I stop this constant key repeating? It has been a week! Link to comment Share on other sites More sharing options...
Ultima Posted June 5, 2009 Report Share Posted June 5, 2009 O_ONever seen or heard of this. Please provide us with your list of running processes (get both):a) get HijackThis from trendsecure.com, run it, view the log, and post the contents here get Process Explorer from sysinternals.com, run it, Ctrl+D (to show the lower DLL pane), select the µTorrent process from the list, Ctrl+S (and save the list somewhere you'll find easily -- like the Desktop), then post the contents of the saved process list in the .txt file here Link to comment Share on other sites More sharing options...
Keybored Posted June 13, 2009 Author Report Share Posted June 13, 2009 Hey sorry for the late reply but I went to trendsecure.com and it says "You may access your Trend Micro account if you have purchased and installed Trend Micro Internet Security, Trend Micro Internet Security Pro, or Trend Micro AntiVirus Plus AntiSpyware". The + sign started appearing again today after about a week and it was getting out of control. You think maybe it's a virus? Thanks. Here is the data from Process Explorer:Process: uTorrent.exe Pid: 3532Name Description Company Name VersionACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.1.2600.5512adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.1.2600.5512ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.1.2600.5755ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.5.2284.1c_1252.nls CLBCATQ.DLL Microsoft Corporation 2001.12.4414.700COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.0.2900.5512comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.0.2900.5512COMRes.dll Microsoft Corporation 2001.12.4414.700credui.dll Credential Manager User Interface Microsoft Corporation 5.1.2600.5512CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.5512ctype.nls DnsApi.dll DNS Client API DLL Microsoft Corporation 5.1.2600.5625dot3api.dll 802.3 Autoconfiguration API Microsoft Corporation 5.1.2600.5512dot3dlg.dll 802.3 UI Helper Microsoft Corporation 5.1.2600.5512eappcfg.dll Eap Peer Config Microsoft Corporation 5.1.2600.5512eappprxy.dll Microsoft EAPHost Peer Client DLL Microsoft Corporation 5.1.2600.5512f3hkstub.dll MyWebSearch IE Search Box Protector MyWebSearch.com 1.0.0.0GDI32.dll GDI Client DLL Microsoft Corporation 5.1.2600.5698hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.1.2600.5512IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.1.2600.5512Iphlpapi.dll IP Helper API Microsoft Corporation 5.1.2600.5512kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.1.2600.5781locale.nls LPK.DLL Language Pack Microsoft Corporation 5.1.2600.5512mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.1.2600.5512MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.1.2600.5512MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.1.2600.5512msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.1.2600.5512MSVCP60.dll Microsoft ® C++ Runtime Library Microsoft Corporation 6.2.3104.0msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.2600.5512mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.1.2600.5625nbm.dll nBm DLL Netpia 2006.1.9.17netapi32.dll Net Win32 API DLL Microsoft Corporation 5.1.2600.5694netshell.dll Network Connections Shell Microsoft Corporation 5.1.2600.5512ntdll.dll NT Layer DLL Microsoft Corporation 5.1.2600.5755NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 5.1.2600.5512nview.dll NVIDIA nView Desktop and Window Manager 111.75 NVIDIA Corporation 6.14.10.11175ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.1.2600.5512oleaut32.dll Microsoft Corporation 5.1.2600.5512OneX.DLL IEEE 802.1X supplicant library Microsoft Corporation 5.1.2600.5512PSAPI.DLL Process Status Helper Microsoft Corporation 5.1.2600.5512rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.1.2600.5512RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.1.2600.5795rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 5.1.2600.5507rtutils.dll Routing Utilities Microsoft Corporation 5.1.2600.5512SAMLIB.dll SAM Library DLL Microsoft Corporation 5.1.2600.5512Secur32.dll Security Support Provider Interface Microsoft Corporation 5.1.2600.5753SETUPAPI.dll Windows Setup API Microsoft Corporation 5.1.2600.5512SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.0.2900.5622shfolder.dll Shell Folder Service Microsoft Corporation 6.0.2900.5512SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.0.2900.5512sortkey.nls sorttbls.nls unicode.nls USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.1.2600.5512USERENV.dll Userenv Microsoft Corporation 5.1.2600.5512USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.420.2600.5512uTorrent.exe μTorrent BitTorrent, Inc. 1.8.2.15357uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.0.2900.5512VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.1.2600.5512WINMM.dll MCI API DLL Microsoft Corporation 5.1.2600.5512WINSPOOL.DRV Windows Spooler Driver Microsoft Corporation 5.1.2600.5512WINSTA.dll Winstation Library Microsoft Corporation 5.1.2600.5512WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.1.2600.5512WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.1.2600.5512WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.1.2600.5512wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.1.2600.5512WSOCK32.dll Windows Socket 32-Bit DLL Microsoft Corporation 5.1.2600.5512WTSAPI32.dll Windows Terminal Server SDK APIs Microsoft Corporation 5.1.2600.5512xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.1.2600.5512 Link to comment Share on other sites More sharing options...
Ultima Posted June 13, 2009 Report Share Posted June 13, 2009 http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthisIt's possible it may be malware, yes. Don't forget the Process Explorer log too when you paste the HijackThis log. Link to comment Share on other sites More sharing options...
Keybored Posted June 13, 2009 Author Report Share Posted June 13, 2009 If I did anything wrong, please tell me or if you need anything else. There were 3 links in the download section and I clicked on the first one 'Download HijackThis Installer".Here is the data from trendsecure.com:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:54:08 PM, on 6/13/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16850)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\cisvc.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Alwil Software\Avast4\ashMaiSv.exeC:\Program Files\Alwil Software\Avast4\ashWebSv.exeC:\WINDOWS\system32\WgaTray.exeC:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exeC:\Program Files\koreandoumi1.0\netpia.exeC:\Program Files\Microsoft IntelliType Pro\itype.exeC:\Program Files\Microsoft IntelliPoint\ipoint.exeC:\WINDOWS\SOUNDMAN.EXEC:\Program Files\Sovbars\sovbar.exeC:\Program Files\FlatIE\flatbar.exeC:\Program Files\IEinsideBar\ieinsides.exeC:\Program Files\BarplusIE\barplus.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\Program Files\iTunes\iTunesHelper.exeC:\PROGRA~1\MYWEBS~2\bar\1.bin\m3SrchMn.exeC:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\system32\MMTray.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\IHBar\InHold.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\cidaemon.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\WINDOWS\explorer.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLLO2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLLO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO2 - BHO: BrowserHook Class - {09F93072-DE5E-4B5A-B347-F80FD7CB7309} - C:\WINDOWS\system32\webmailHook20081001.dllO2 - BHO: ShoppingReport - {100EB1FD-D03E-47FD-81F3-EE91287F9465} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Æ÷AIÆ®Au¸³ - {3A50EF84-83B9-4E13-9684-E637F68BE475} - C:\PROGRA~1\mpoint2\MPOINT~1.DLLO2 - BHO: MPoints - {40B07384-6FF7-447C-96F1-A68E9426A324} - C:\PROGRA~1\mpoints\MPOINT~1.DLLO2 - BHO: InSideBarCtl Class - {437972F6-9F05-4005-826F-8A9EB3C343A8} - C:\Program Files\ISBar\ISBar.dllO2 - BHO: Mplus Reward Class - {4465BF12-801F-449c-AA43-B01FCA95B830} - C:\PROGRA~1\Mplus\MG_RWD~2.DLLO2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: Mplus Search Class - {8EA9A253-227C-4b03-9DD7-A138E8600430} - C:\Program Files\Mplus\mg_src_1f.dllO2 - BHO: Mpoint - {A17316CA-3F04-4316-92F9-B01853BCE665} - C:\PROGRA~1\mpoint\MPOINT~1.DLLO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: mpoint - {02D72AC8-2839-4A6C-BD08-33E1862E0F97} - C:\PROGRA~1\mpoint\MPOINT~1.DLLO3 - Toolbar: MPoints - {172EB107-0095-47E5-8892-01CF438E2FA4} - C:\PROGRA~1\mpoints\MPOINT~1.DLLO3 - Toolbar: Æ÷AIÆ®Au¸³ - {05D1F24F-0D04-425C-89CF-D461F1A93F1B} - C:\PROGRA~1\mpoint2\MPOINT~1.DLLO3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dllO4 - HKLM\..\Run: [sW20] C:\WINDOWS\system32\sw20.exeO4 - HKLM\..\Run: [sW24] C:\WINDOWS\system32\sw24.exeO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorunO4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXEO4 - HKLM\..\Run: [NetpiaLite] C:\Program Files\koreandoumi1.0\netpia.exeO4 - HKLM\..\Run: [imekrmig7.0] "C:\Program Files\Common Files\Microsoft Shared\IME\IMKR7\IMEKRMIG.EXE"O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"O4 - HKLM\..\Run: [rundl64] C:\WINDOWS\rundl64.exeO4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [sOVbar] C:\Program Files\Sovbars\sovbar.exeO4 - HKLM\..\Run: [NBarHlp] C:\Program Files\NBarhelp\nbarhelp.exeO4 - HKLM\..\Run: [FaltIE] C:\Program Files\FlatIE\flatbar.exeO4 - HKLM\..\Run: [iNsideB] C:\Program Files\IEinsideBar\ieinsides.exeO4 - HKLM\..\Run: [barPlusMgr] C:\Program Files\BarplusIE\barplus.exeO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~2\bar\1.bin\M3PLUGIN.DLL,UPFO4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~2\bar\1.bin\m3SrchMn.exe" /m=2 /w /hO4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [MMTray] MMTray.exeO4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [mpoint] "C:\Program Files\mpoint\mpoint.exe" /startO4 - HKCU\..\Run: [mpoints] "C:\Program Files\mpoints\mpoints.exe" /startO4 - HKCU\..\Run: [mpoint2] "C:\Program Files\mpoint2\mpoint2.exe" /startO4 - HKCU\..\Run: [iHBar] C:\Program Files\IHBar\InHold.exeO4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwsoemon.exeO4 - HKUS\S-1-5-18\..\Run: [mpoints] "C:\Program Files\mpoints\mpoints.exe" /start (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [mpoints] "C:\Program Files\mpoints\mpoints.exe" /start (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKfox000O9 - Extra button: ¸®¼-A¡ - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dllO9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - ESC Trusted Zone: http://*.update.microsoft.comO16 - DPF: {045ADB92-9635-45CE-B25B-F19F825B0E39} (MSTPlayerInstaller Control) - http://update.liztech.co.kr/MSTPlayer/kor/MSTPlayerInstaller.ocxO16 - DPF: {126AADD9-6A80-48B7-864A-5EA9A73F0665} (EZCatchInstaller Class) - http://update.ezcatch.net/cab/EZCatchCom.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {3777C31D-20BE-4D86-A566-E63D37BD2798} (Kdisk File Control1) - http://www.kdisk.co.kr/mmsv/KdiskWebControl.CABO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cabO16 - DPF: {5FB84F9E-70FF-4B98-B47A-8F530F8D4AF0} (BKChatClientX Control) - http://www.koreadaily.com/_dev/activeX/BKChatClient.cabO16 - DPF: {60B33001-5F10-4A94-A7E4-77A3D8F5C78E} (OnAirClient Control) - http://nepod.sbs.co.kr/update/OnAirClient.cabO16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} - http://app.gomtv.com/gom/GomWeb.cabO16 - DPF: {938527D1-CDB7-4147-998A-B20FCA5CC976} (Cdmcco Class) - http://cafeimg.hanmail.net/activex/dmcc2.cab?Version=1,0,0,10O16 - DPF: {B9B38E70-EEF6-4E3A-AE84-DDE59A053B7C} (Daum ActiveX manager Class) - http://mail.daum.net/hanmail-ax/DaumActiveX/2_0_0_4/DaumActiveX.cab?ver=2,0,0,4O16 - DPF: {C021A4D6-173F-4BF4-B38C-B12CAA20E518} (ActiveFormX Control) - http://www.mgoon.com/launcher.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~2\bar\1.bin\mwssvc.exeO23 - Service: npkcmsvc - Unknown owner - C:\Nexon\MapleStory\npkcmsvc.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: MPoint (prmllmm) - Unknown owner - C:\WINDOWS\prmllmm.exe (file missing)--End of file - 12487 bytes Link to comment Share on other sites More sharing options...
DreadWingKnight Posted June 13, 2009 Report Share Posted June 13, 2009 You've got other malware on your system.rundl64.exe is the first flare for me. Link to comment Share on other sites More sharing options...
Keybored Posted June 13, 2009 Author Report Share Posted June 13, 2009 How do I remove them? Link to comment Share on other sites More sharing options...
DreadWingKnight Posted June 14, 2009 Report Share Posted June 14, 2009 Either specialized removal software or a reinstall of your operating system. Link to comment Share on other sites More sharing options...
GTHK Posted June 14, 2009 Report Share Posted June 14, 2009 Malware bytes anti-malware has been recommended to me, seems to work alright. Dunno if it'll fix things for ya but it should clean up some stuff at least. Link to comment Share on other sites More sharing options...
Keybored Posted June 20, 2009 Author Report Share Posted June 20, 2009 So, can anyone tell me how to stop the + sign from keep repeating? Moderators? Anyone? Link to comment Share on other sites More sharing options...
DreadWingKnight Posted June 20, 2009 Report Share Posted June 20, 2009 Clean the malware off your system or reinstall windows completely. Link to comment Share on other sites More sharing options...
Saribro Posted June 20, 2009 Report Share Posted June 20, 2009 Euhm, have you bothered checking your keyboard? Stuck + button? Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.