|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
Servic~1.exe, how do I get rid of i
|
Original Message
|
Name: NYKHouston43
Date: February 25, 2006 at 13:39:19 Pacific
Subject: Servic~1.exe, how do I get rid of iOS: XPCPU/Ram: Pentium M/512 |
Comment: I keep getting random pop-ups that say that I'm infected with the blackworm virus and that I should buy this anti-spyware software. I looked through my processes and found an anomoly in that there is a process called "servic~1.exe". I googled that process and it said I need to disable and remove that immediatly. How do I go about doing that?
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: jabuck
Date: February 25, 2006 at 13:45:36 Pacific
|
Reply: (edit)Normally that file belongs to F-Secure's BlackLight. Please post a Hijack This log so that the files associated with the virus/spyware can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed. Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button. Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum. Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: whatalife
Date: March 26, 2006 at 14:57:55 Pacific
|
Reply: (edit)HELP!!! My computer says I have the Black Worm Virus. I've run "HijackThis" & here are the results. I cannot live without my computer - please help me. Logfile of HijackThis v1.99.1 Scan saved at 4:36:32 PM, on 3/26/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\EQAdvice\EQAdvice.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\LAVASOFT\AD-AWA~1\AD-AWARE.EXE C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\CP6RWP67\HijackThis[1].exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kotv.com/main/home/main.asp R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm R3 - Default URLSearchHook is missing F2 - REG:system.ini: UserInit=userinit.exe O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\Compaq\Easy Access Button Support\cpqeadm.exe O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [HPAIO_PrintFolderMgr] C:\WINDOWS\System32\spool\DRIVERS\W32X86\hpoopm07.exe O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [keyboard] C:\windows\keyboard5.exe O4 - HKLM\..\Run: [mousepad] C:\windows\mousepad5.exe O4 - HKLM\..\Run: [newname] C:\windows\newname5.exe O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe O4 - HKLM\..\Run: [win3208575641904] C:\WINDOWS\win3208575641904.exe O4 - HKLM\..\Run: [q8lg] "C:\WINDOWS\system32\slk8x2peu.exe" O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s O4 - HKLM\..\Run: [WinTask driver] C:\WINDOWS\system32\wintask.exe O4 - HKLM\..\Run: [sgqmnnvA] C:\WINDOWS\sgqmnnvA.exe O4 - HKLM\..\Run: [errorhandler] C:\WINDOWS\errorhandler.exe O4 - HKLM\..\Run: [sys02641904575] C:\WINDOWS\sys02641904575.exe O4 - HKLM\..\Run: [expload.exe] C:\WINDOWS\system32\expload.exe O4 - HKLM\..\Run: [C7CAC9C9C6D0C9CD] 595C5B5B58625B.exe O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\Navnt\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [Norton eMail Protect] C:\Program Files\Navnt\POPROXY.EXE O4 - HKLM\..\Run: [ms04190457564] C:\WINDOWS\ms04190457564.exe O4 - HKLM\..\Run: [WinAntiVirusPro2006] "C:\Program Files\WinAntiVirus Pro 2006\WinAV.exe" O4 - HKLM\..\Run: [CompanionWizard] "C:\Program Files\Common Files\Companion Wizard\compwiz.exe" /silent O4 - Global Startup: Microsoft Office Fast Start.lnk = C:\MSOffice\Office\FASTBOOT.EXE O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: &AOL Toolbar search - res://C:\PROGRAM FILES\AOL TOOLBAR\TOOLBAR.DLL/SEARCH.HTML O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing) O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM32\SHDOCVW.DLL O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Hijacked Internet access by New.Net O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Unknown file in Winsock LSP: c:\program files\winantivirus pro 2006\mailscan.dll O16 - DPF: Win32 Classes - O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.cox.com/sdccommon/download/tgctlcm.cab O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab O20 - AppInit_DLLs: Runner.dll O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\lvn6095se.dll (file missing) O23 - Service: Firewall service (FWSvc) - WinSoftware, Ltd. - C:\Program Files\WinAntiVirus Pro 2006\FWSvc.exe O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing) O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\sgqmnnv.exe
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
|
|
|