# virus, program on my PC

**URL:** <https://forums.speedlife.net/t/virus-program-on-my-pc/185881>\
**Category:** PittSpeed Off Topic\
**Created:** [October 28, 2006, 10:55am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881 "2006-10-28T10:55:11Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 28, 2006, 10:55am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/1 "2006-10-28T10:55:11Z")

</div>

OKAY Gurus, i got a problem, whenever i click “Home” a message appears stating i have A VIRUS, AND IT IMMEADIATLY CONNECTS ME TO A WEBSITE IN WHICH I NEED TO DOWNLOAD A PROGRAM, (Pest Control?) i know its a file i downloaded and i know where it is in my programs list but it will not allow me to delet it, if I click remove program, it pops a box that states the pc must reboot before the program can rebook, well i tried that and the program still exists.  
Please help, im going to wait to post more info untill i see intrested parties to assist in the repair,

I have already run Windows Defender, but it says my PC is operating normally, and being this is a program it doesnt see it being a threat. Thanks

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 28, 2006, 11:12am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/2 "2006-10-28T11:12:28Z")

</div>

![http://www.pittspeed.com/uploaded/save.bmp](http://www.pittspeed.com/uploaded/save.bmp)

sorry bout the size, resizing it took the quality of the letytering away

---

<div class="post-metadata">

**Author:** ![slowcamaro](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/slowcamaro/32/5975_2.png) [@slowcamaro](https://forums.speedlife.net/u/slowcamaro)\
**Post date:** [October 28, 2006, 11:13am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/3 "2006-10-28T11:13:06Z")

</div>

this web forumn helped me and kanaut with a lot of problems

> **[All Discussions](http://icrontic.com//)**
>
> A warm community of gaming & tech geeks discussing whatever they're nerding out about lately.

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 28, 2006, 11:14am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/4 "2006-10-28T11:14:03Z")

</div>

can you link it to here, i dont want to sign up for it

---

<div class="post-metadata">

**Author:** ![slowcamaro](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/slowcamaro/32/5975_2.png) [@slowcamaro](https://forums.speedlife.net/u/slowcamaro)\
**Post date:** [October 28, 2006, 11:14am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/5 "2006-10-28T11:14:24Z")

</div>

looks like you got hijacked

i would go to the forumn i posted and run HIjack this to see wehats on your system

---

<div class="post-metadata">

**Author:** ![slowcamaro](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/slowcamaro/32/5975_2.png) [@slowcamaro](https://forums.speedlife.net/u/slowcamaro)\
**Post date:** [October 28, 2006, 11:15am UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/6 "2006-10-28T11:15:52Z")

</div>

> [@What are you listening to RIGHT NOW? Pt. NYSpeed](https://forums.speedlife.net/t/what-are-you-listening-to-right-now-pt-nyspeed/183/728):
>
> can you link it to here, i dont want to sign up for it

sign up …trust me its worth it

---

<div class="post-metadata">

**Author:** ![jinxxycat](https://avatars.discourse-cdn.com/v4/letter/j/71c47a/32.png) [@jinxxycat](https://forums.speedlife.net/u/jinxxycat)\
**Post date:** [October 28, 2006, 12:10pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/7 "2006-10-28T12:10:59Z")

</div>

i was reading some on this and it seems some ppl have isamonitor.exe and isamini.exe attached to this. :dunno:

---

<div class="post-metadata">

**Author:** ![JackdUp](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jackdup/32/6015_2.png) [@JackdUp](https://forums.speedlife.net/u/JackdUp)\
**Post date:** [October 28, 2006, 2:28pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/8 "2006-10-28T14:28:43Z")

</div>

jeebus, just post the hijackthis log here and I’ll decipher it.

---

<div class="post-metadata">

**Author:** ![SCHMEIDER](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/schmeider/32/6032_2.png) [@SCHMEIDER](https://forums.speedlife.net/u/SCHMEIDER)\
**Post date:** [October 28, 2006, 2:38pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/9 "2006-10-28T14:38:17Z")

</div>

i’ve got them happenin on my puter all the time!!!

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 28, 2006, 7:01pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/10 "2006-10-28T19:01:56Z")

</div>

> [@how to get road salt out of car carpet?](https://forums.speedlife.net/t/how-to-get-road-salt-out-of-car-carpet/25409/20):
>
> i was reading some on this and it seems some ppl have isamonitor.exe and isamini.exe attached to this. :dunno:

i have both these in my applications/processes

> [@fs:paint kits fer sale](https://forums.speedlife.net/t/fs-paint-kits-fer-sale/25426/8):
>
> jeebus, just post the hijackthis log here and I’ll decipher it.

not sure what you mean, please explain futher.

on a side note i got macafee, and im still haveing problems, althought it did remove 112 files 1 of which was trojen

---

<div class="post-metadata">

**Author:** ![JackdUp](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jackdup/32/6015_2.png) [@JackdUp](https://forums.speedlife.net/u/JackdUp)\
**Post date:** [October 28, 2006, 8:06pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/11 "2006-10-28T20:06:32Z")

</div>

HijackThis:

> **[Trend Micro HijackThis](http://download.cnet.com/archive/3000-8022_4-10379544.html)**
>
> Trend Micro HijackThis digs down into parts of your hard drive and Registry that malicious programs often target to help you eliminate them for good. It works

  
download, decompress & run the HijackThis.exe enclosed…

Choose “scan and log”…

Reply to this message, and take the log and enclose it in code tags

[code] \<— without the spaces in the tags, please…  
log…  
[/code] \<— without the spaces in the tags, please…

I’ll figure out what you should “click” in HijackThis to remove the annoyance, or if Spybot S&D would be a better choice for removing this.

> **[Spybot - Search & Destroy for Windows XP](http://download.cnet.com/archive/3000-8022_4-10401314.html)**
>
> Spybot - Search and Destroy is a free malware and spyware detection and removal tool that utilizes open source malware definitions to protect your computer

---

<div class="post-metadata">

**Author:** ![SloWhite\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/slowhite_z/32/5969_2.png) [@SloWhite\_Z](https://forums.speedlife.net/u/SloWhite_Z)\
**Post date:** [October 28, 2006, 8:40pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/12 "2006-10-28T20:40:41Z")

</div>

go to here

> **[Please help "http://safeiepage.com/" has taken over](https://forums.techguy.org/threads/511869/)**
>
> Please assist as the title states...I did do what I think the very first step to every problem I see and ran Hijack this...
> 
> 
> Logfile of HijackThis...

#4 post will give you a download and then you have to uncompress it and the #6 post will tell you what to do make sure you do it in safe mode

the funny thing is I just had to do this earlier today :bowrofl:

---

<div class="post-metadata">

**Author:** ![berad](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/berad/32/5953_2.png) [@berad](https://forums.speedlife.net/u/berad)\
**Post date:** [October 28, 2006, 8:52pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/13 "2006-10-28T20:52:08Z")

</div>

:owned:

---

<div class="post-metadata">

**Author:** ![SloWhite\_Z](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/slowhite_z/32/5969_2.png) [@SloWhite\_Z](https://forums.speedlife.net/u/SloWhite_Z)\
**Post date:** [October 29, 2006, 2:14pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/14 "2006-10-29T14:14:12Z")

</div>

Did you get it fixed?

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 30, 2006, 5:59pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/15 "2006-10-30T17:59:47Z")

</div>

nope i been really busy and i dont know what to do with this pc, any chance a hammer and a wrench will fix it?

---

<div class="post-metadata">

**Author:** ![berad](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/berad/32/5953_2.png) [@berad](https://forums.speedlife.net/u/berad)\
**Post date:** [October 30, 2006, 6:02pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/16 "2006-10-30T18:02:19Z")

</div>

you go through pc’s like $1’s in a strip club

---

<div class="post-metadata">

**Author:** ![newchic](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/newchic/32/5989_2.png) [@newchic](https://forums.speedlife.net/u/newchic)\
**Post date:** [October 30, 2006, 6:04pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/17 "2006-10-30T18:04:51Z")

</div>

Don’t worry about cleaning it… it will take you forever. Just use Mozilla Firefox and the hijack doesn’t happen. Worked on my dad’s old ME machine.

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 30, 2006, 6:12pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/18 "2006-10-30T18:12:37Z")

</div>

```auto
Logfile of HijackThis v1.99.1
Scan saved at 9:00:23 PM, on 10/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VideoKeyCodec\isamonitor.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\X-Charge\XChrgSrv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\GPN\HdaCom.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\VideoKeyCodec\isamini.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\DM\DMCom.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\iTunes\iTunes.exe
C:\DOCUME~1\Chaz\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
O2 - BHO: (no name) - {8bf5b8fc-11cb-409f-8c91-4d4ca04a1b6d} - C:\Program Files\VideoKeyCodec\isaddon.dll
O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\VideoKeyCodec\iesplugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CAMMonitor] C:\Program Files\X-Charge\XChrgSrv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154639755421
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Task Scheduler (mctskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: X-Charge Server (XCService) - Unknown owner - C:\Program Files\X-Charge\XCService.exe

```

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 30, 2006, 6:14pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/19 "2006-10-30T18:14:50Z")

</div>

is that what you wanted?

---

<div class="post-metadata">

**Author:** ![F-B-A](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/f-b-a/32/6022_2.png) [@F-B-A](https://forums.speedlife.net/u/F-B-A)\
**Post date:** [October 30, 2006, 6:16pm UTC](https://forums.speedlife.net/t/virus-program-on-my-pc/185881/20 "2006-10-30T18:16:06Z")

</div>

> [@RIPP modifications question?](https://forums.speedlife.net/t/ripp-modifications-question/25465/23):
>
> Don’t worry about cleaning it… it will take you forever. Just use Mozilla Firefox and the hijack doesn’t happen. Worked on my dad’s old ME machine.

yes you are correct it does not do it to me in firefox, only ie

[Next page](https://forums.speedlife.net/t/virus-program-on-my-pc/185881.md?page=2)
