Logfile of HijackThis v1.99.1 Scan saved at 16:28:05, on 02/12/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe

My computer is slow. Asking for help with HijackThis. Also, please try to name your threads more suitably in future rather than 'HijackThis Help'.

Under Manual Update click Start update.After the update finishes (the status bar at the bottom will display "Update successful") Then click on the Scanner tab at the top. They are often spread by a network or by transmission to a removable medium such as a removable disk, writable CD, or USB drive. for the fifth step, should i close my internet browser when u say close all programs?

I am not sure what happened with the Ewido, if you ran it from safe mode and set it to "Perform action on all infections", you should not have had an Register Lost Password? this is my highjack log:Logfile of HijackThis v1.99.1Scan saved at 10:12:49 PM, on 11/1/2005Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\BroadJump\Client Foundation\CFD.exeC:\WINDOWS\SMSS.exeC:\Program Files\winupdates\winupdates.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Webroot\Spy I do have a question before preceding with this, because I'm unsure of something. (Don't wanna mess it up.)Quote below on what I have a question about:Copy the file names below

Did this help?

Click "Yes" at the Delete on Reboot prompt. Googleing onoes.exe comes up empty and the only problem I have now is that my Task Manager wont work so I am working on reactivating it. Click "Exit". 14 Reboot your system into normal mode. 15 Run the CCleaner Put a Checkmark next to all items under "Windows", "Applications" and "Issues". I followed the direstcions on Malware and the ones in the forums, but it still hasn't gone away. (I had to also run the LSP-aid program to get my internet connection

This worm has been driving me batty and I may have temporarily lost my mind with it. http://www.thetechguide.com/forum/index.php/topic/18992-win32p2p-wormalcana/ should i delete that? 0 #13 joshuacat Posted 05 December 2005 - 09:45 PM joshuacat Visiting Staff Member 188 posts No. Devshed Frequenter (2500 - 2999 posts)           Join Date Nov 2004 Location 118 Computer Geek, UK Posts 2,975 Rep Power 390 well On boot up I get an error: 'onoes.exe has encountered a problem and needs to close'.

AntispywareScanners---Antivirus Scanners---Firewalls---Online Scanners---Prevention---Help! Dev Shed Forums Navigation Forums Tools Newsletter Signup Articles Help Devshed Network Developer Shed ASP Free Dev Shed Dev Articles Dev Hardware Tutorialized SEO Chat Scripts Codewalkers Web Hosters Dev Mechanic Check out the forums and get free advice from the experts. I assume one by one, but I want to make sure.

or read our Welcome Guide to learn how to use this site. Registriert seit 25.01.2005 Ort The Netherlands Beiträge 20.038 AW: win32.p2p-worm-Alcan.a Her we go Please read these instructions carefully and print them out! I would appreciate advice on item elimination. http://iversoncreative.com/help-with/help-with-unregmp2-exe-worm.html THANK YOU SO MUCH!!

what should i do? 0 #5 joshuacat Posted 03 December 2005 - 08:49 AM joshuacat Visiting Staff Member 188 posts You could break the scan log up and paste it in Save the logfile. After I had my connection back, I re-downloaded Ad-Aware and also purchased Spy Sweeper, but the worm is still here and Spy Sweeper keeps locking up towards the end of the

sorry, i only have my hijack this log and activescan. Back to top #6 drummboy23 drummboy23 Topic Starter Members 22 posts OFFLINE Local time:02:02 PM Posted 09 June 2007 - 10:35 AM "Owner" - 2007-06-09 11:16:33 Service Pack 2 NTFS The support has been much appreciated dev shedians Cheerio Chris Faq Reply With Quote February 14th, 2006,04:33 AM #12 aitken325i View Profile View Forum Posts  Providing fuel for space ships and then see how it goes.

I can't bring up ipconfig on Start > Run though. Download CCleaner L. Download one of these programs: WinsockXPFix.exe, WinsockFix lspfix Follow the instructions to use it. Please Help!

Go to "Tools" and put a checkmark into the box of ActiveX. Back to top #6 Muku6 Muku6 Newbie Members 8 posts Posted 11 July 2005 - 09:13 AM Okay, well, got the Ewido program. As mentioned above, put it in its own folder. after i fixed the checked items in my hijack this program, i noticed a "backup" folder on my desktop.

Internet Mail 2.23.00.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\User\Complete\Bee Gees - Love Hits.zip/Setup.exe -> Worm.VB.an : Cleaned with backup C:\Documents and Settings\User\Complete\Bee Gees - Number Ones.zip/Setup.exe -> Worm.VB.an Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installquietO4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeO4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] Click the Extract To button. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates,

Save it in the folder you made earlier (c:\BFU).Open My Computer and navigate to the c:\BFU folder.