Author Topic: [In Progress]Windows XP-Word 2003 Clipboard hijacked  (Read 4642 times)

0 Members and 1 Guest are viewing this topic.

Offline Edie

  • Bronze Member
  • Posts: 8
[In Progress]Windows XP-Word 2003 Clipboard hijacked
« on: August 20, 2009, 09:25:38 am »
Hello all,

I have a Dell Dimension 8400, with Windows XP. I am having problems with the Clipboard. It started initially in Word 2003, but now this seems to have spread to other programs.

It started two days ago. I was working in Word with the Clipboard viewer open, and was copying text from a legal research program. All of a sudden, a screen shot of the page where I was copying text began repeatedly to fill up the Clipboard. Now the problem occurs in my browser, on my desktop -- wherever I am working. It happens even when Word is not open.

I have done a scan in safe mode with my virus program, Trend Micro Internet Security, and it found nothing.

I have also tried:

   1. Uninstalling and reinstalling Office 2003 Professional, of which Word 2003 is part.
   2. deleting the normal.dot file in  Word.
   3. Uninstalling the Clipboard in Windows and reinstalling it.
   4. Running Adaware and Advanced System Care -- again, no problems found.

I have removed Adaware and Advanced System Care, in case they were causing a problem, but the problem persists. I would appreciate any help you can give me, as this issue is making it impossible for me to work.

Thanks,
Edie

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:19 AM, on 8/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: (no name) - {06647158-359E-4D10-A8DE-E6145DA90BE9} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SSBkgdUpdate] C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe -Embedding -boot
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1207084274109
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Update Service (gupdate1c9da2e2e537c06) (gupdate1c9da2e2e537c06) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Canon PIXMA iP6000D Memory Card Manager (PDUiP6000DMemCrdMgr) - CANON INC. - C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

--
End of file - 8124 bytes
« Last Edit: August 21, 2009, 12:54:15 pm by bamajim »



Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2865
Re: Windows XP-Word 2003 Clipboard hijacked
« Reply #1 on: August 21, 2009, 12:53:51 pm »
Edie

I'm not sure your problem is malware related. But let's look at a couple of things

1. Go HERE and download File Lister.
  • Save it to your Desktop
  • Rt Click ->> Extract all ->> And extract it to your Desktop
  • Additional help on extracting zip files can be found HERE
  • Open the File Lister Folder.
  • Note: Leave the FileLister.vbe file in the folder and run it from there.
  • Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
  • When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.

2008-2010
With everything comes a price

Offline Edie

  • Bronze Member
  • Posts: 8
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #2 on: August 21, 2009, 01:03:58 pm »
Hi there,

Thanks for that. Here is what was in the log file:


+++++++++++++++++++++++++++++++++
+ File Lister  Version 1.1.1                                 +
+                                                                    +
+  By bamajim / SpywareHammer.com                 +
+++++++++++++++++++++++++++++++++

Report ran on --->>>  8/21/2009 12:02:57 PM


====== Running Processes ======

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Canon\Memory Card Utility\PIXMA iP6000D\PDUiP6000DMemCrdMgr.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 9.0\Reader\LogTransport2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE

====== BHO's ======

BHO: (NO NAME) -  -

====== HKLM\~\Run Keys ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

[UfSeAgnt.exe] = "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
[NvCplDaemon] = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

====== HKCU\~\Run Keys ======

[ctfmon.exe] = C:\WINDOWS\system32\ctfmon.exe

====== DNS Info (List may be empty) ======

HKEY_LOCAL_MACHINE\CCS\~\{0C215C33-D140-4D81-8CB1-1DDE121A6A9C}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{5282E268-4B02-4E98-8217-D2F4A10A7B67}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{7385AB44-453C-4154-8E2F-CF2965B3F868}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{92753D71-5F88-4B1D-ACF1-83DA581781FC}\  NameServer=
HKEY_LOCAL_MACHINE\CCS\~\{AF4854A3-6734-482E-9B43-72E0AD7B93B3}\  NameServer=

HKEY_LOCAL_MACHINE\CS001\~\{0C215C33-D140-4D81-8CB1-1DDE121A6A9C}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{5282E268-4B02-4E98-8217-D2F4A10A7B67}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{7385AB44-453C-4154-8E2F-CF2965B3F868}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{92753D71-5F88-4B1D-ACF1-83DA581781FC}\  NameServer=
HKEY_LOCAL_MACHINE\CS001\~\{AF4854A3-6734-482E-9B43-72E0AD7B93B3}\  NameServer=



====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======

8/18/2009 6:40:27 PM    0    C:\Config.Msi
8/17/2009 5:27:22 PM    294513104    C:\MSOCache
8/17/2009 5:27:22 PM    294513104    C:\MSOCache\All Users
8/17/2009 5:27:22 PM    294513104    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9
8/17/2009 5:27:22 PM    2010844    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES
8/17/2009 5:27:23 PM    1887642    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES
8/19/2009 8:14:10 AM    804080    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON
8/19/2009 8:14:10 AM    804080    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED
8/19/2009 8:14:10 AM    804080    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW
8/19/2009 8:14:10 AM    109120    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\COMMON\MSSHARED\DW\1033
8/17/2009 5:27:24 PM    1083562    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE
8/17/2009 5:27:24 PM    1083562    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11
8/17/2009 5:27:25 PM    295479    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\PFILES\MSOFFICE\OFFICE11\1033
8/19/2009 8:14:11 AM    89136    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\SETUP
8/17/2009 5:27:22 PM    34066    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS
8/17/2009 5:27:22 PM    34066    C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\FILES\WINDOWS\INF
8/21/2009 12:02:58 PM    1758    32    C:\Files.txt
8/19/2009 5:08:41 PM    1071812608    38    C:\hiberfil.sys
8/13/2009 11:56:56 AM    3369911    C:\WINDOWS\$NtUninstallKB956744$
8/13/2009 11:56:56 AM    628151    C:\WINDOWS\$NtUninstallKB956744$\spuninst
8/13/2009 11:57:22 AM    700144    C:\WINDOWS\$NtUninstallKB960859$
8/13/2009 11:57:22 AM    624368    C:\WINDOWS\$NtUninstallKB960859$\spuninst
7/14/2009 7:10:14 PM    822767    C:\WINDOWS\$NtUninstallKB961371$
7/14/2009 7:10:14 PM    624111    C:\WINDOWS\$NtUninstallKB961371$\spuninst
8/13/2009 11:54:24 AM    2131972    C:\WINDOWS\$NtUninstallKB968389$
8/13/2009 11:54:24 AM    627588    C:\WINDOWS\$NtUninstallKB968389$\spuninst
8/13/2009 11:57:06 AM    709129    C:\WINDOWS\$NtUninstallKB971557$
8/13/2009 11:57:06 AM    624137    C:\WINDOWS\$NtUninstallKB971557$\spuninst
7/14/2009 7:11:35 PM    1911912    C:\WINDOWS\$NtUninstallKB971633$
7/14/2009 7:11:35 PM    623720    C:\WINDOWS\$NtUninstallKB971633$\spuninst
8/13/2009 11:57:13 AM    756284    C:\WINDOWS\$NtUninstallKB971657$
8/13/2009 11:57:13 AM    624188    C:\WINDOWS\$NtUninstallKB971657$\spuninst
7/14/2009 7:11:43 PM    1622184    C:\WINDOWS\$NtUninstallKB973346$
7/14/2009 7:11:43 PM    622760    C:\WINDOWS\$NtUninstallKB973346$\spuninst
8/13/2009 11:56:32 AM    1938892    C:\WINDOWS\$NtUninstallKB973354$
8/13/2009 11:56:32 AM    624076    C:\WINDOWS\$NtUninstallKB973354$\spuninst
8/13/2009 11:56:40 AM    682832    C:\WINDOWS\$NtUninstallKB973507$
8/13/2009 11:56:40 AM    623952    C:\WINDOWS\$NtUninstallKB973507$\spuninst
8/13/2009 11:56:18 AM    11777045    C:\WINDOWS\$NtUninstallKB973540_WM9$
8/13/2009 11:56:18 AM    624149    C:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst
8/13/2009 11:54:36 AM    827974    C:\WINDOWS\$NtUninstallKB973815$
8/13/2009 11:54:36 AM    624198    C:\WINDOWS\$NtUninstallKB973815$\spuninst
8/13/2009 11:56:48 AM    752843    C:\WINDOWS\$NtUninstallKB973869$
8/13/2009 11:56:48 AM    624331    C:\WINDOWS\$NtUninstallKB973869$\spuninst
7/11/2009 8:24:49 AM    0    C:\WINDOWS\Performance
7/11/2009 8:24:49 AM    0    C:\WINDOWS\Performance\WinSAT
7/11/2009 8:24:49 AM    0    C:\WINDOWS\Performance\WinSAT\DataStore
8/19/2009 8:17:21 AM    0    32    C:\WINDOWS\0.log
8/19/2009 8:09:48 AM    17642    32    C:\WINDOWS\comsetup.log
8/19/2009 8:09:48 AM    49325    32    C:\WINDOWS\FaxSetup.log
8/19/2009 8:09:48 AM    4869    32    C:\WINDOWS\iis6.log
8/19/2009 8:09:48 AM    4566    32    C:\WINDOWS\imsins.log
8/19/2009 8:09:48 AM    3853    32    C:\WINDOWS\msgsocm.log
8/18/2009 4:13:13 PM    446280    32    C:\WINDOWS\ntbtlog.txt
8/19/2009 8:09:48 AM    14453    32    C:\WINDOWS\ntdtcsetup.log
8/19/2009 8:09:48 AM    60543    32    C:\WINDOWS\ocgen.log
8/19/2009 8:09:48 AM    3869    32    C:\WINDOWS\ocmsn.log
8/19/2009 8:09:48 AM    176    32    C:\WINDOWS\setupact.log
8/19/2009 8:09:48 AM    38207    32    C:\WINDOWS\setupapi.log
8/19/2009 8:09:48 AM    0    32    C:\WINDOWS\setuperr.log
8/19/2009 8:09:34 AM    33574    32    C:\WINDOWS\TmComm.log
8/19/2009 8:17:04 AM    3700    32    C:\WINDOWS\tmevtmgr.log
8/19/2009 8:13:27 AM    108    32    C:\WINDOWS\TMFilter.log
8/19/2009 8:09:48 AM    28208    32    C:\WINDOWS\tsoc.log
8/18/2009 4:19:36 PM    552    32    C:\WINDOWS\SYSTEM32\d3d8caps.dat
8/18/2009 6:44:33 PM    39    32    C:\WINDOWS\SYSTEM32\rp_rules.dat
8/18/2009 6:44:33 PM    54    32    C:\WINDOWS\SYSTEM32\rp_stats.dat

====== Files under "\Administrator\Startup" Last 60 Days======



====== Files under "\All Users\Startup" Last 60 Days======


====== Files and Folders under "\Program Files" Last 60 Days======

6/28/2009 10:28:51 AM    27729    C:\Program Files\IObit
7/27/2009 12:10:57 PM    1372199    C:\Program Files\iPod
7/27/2009 12:10:40 PM    94036415    C:\Program Files\iTunes
8/20/2009 11:39:52 AM    4325031    C:\Program Files\Malwarebytes' Anti-Malware
8/19/2009 8:14:36 AM    208979    C:\Program Files\Microsoft ActiveSync
8/20/2009 10:53:44 AM    12289000    C:\Program Files\Microsoft Easy Assist
8/19/2009 8:14:11 AM    315392    C:\Program Files\Microsoft.NET
8/20/2009 11:30:38 AM    2618612    C:\Program Files\VS Revo Group

====== Files under "\System32\Drivers" Last 60 Days======

8/20/2009 11:39:52 AM    19096    32    C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
8/20/2009 11:39:54 AM    38160    32    C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
7/14/2009 8:30:12 PM    287608    32    C:\WINDOWS\SYSTEM32\DRIVERS\Tmfilter.sys

====== Files Deleted under "%Temp%" ======


4 Files deleted

====== Files and Folders under "All Users\Application Data" Last 60 Days======

8/20/2009 10:53:37 AM    2096128    C:\Documents and Settings\All Users\Application Data\Applications
8/20/2009 10:53:37 AM    2096128    C:\Documents and Settings\All Users\Application Data\Applications\Cache

====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======

HKLM\Software\microsoft\shared tools\msconfig\startupreg\

====== Services ( Services that are Whitelisted are not shown) ======

BCM42U (USB HPNA 10 Mbps Network Adapter Driver)- C:\WINDOWS\system32\DRIVERS\BCM42U.SYS - Manual/Stopped
bvrp_pci (bvrp_pci)-  - Manual/Stopped
ctac32k (Creative AC3 Software Decoder)- C:\WINDOWS\system32\drivers\ctac32k.sys - Manual/Running
ctaud2k (Creative Audio Driver (WDM))- C:\WINDOWS\system32\drivers\ctaud2k.sys - Manual/Running
ctdvda2k (Creative DVD-Audio Device Driver)- C:\WINDOWS\system32\drivers\ctdvda2k.sys - Manual/Stopped
ctprxy2k (Creative Proxy Driver)- C:\WINDOWS\system32\drivers\ctprxy2k.sys - Manual/Running
ctsfm2k (Creative SoundFont Management Device Driver)- C:\WINDOWS\system32\drivers\ctsfm2k.sys - Manual/Running
drvmcdb (drvmcdb)- C:\WINDOWS\system32\drivers\drvmcdb.sys - Boot/Running
drvnddm (drvnddm)- C:\WINDOWS\system32\drivers\drvnddm.sys - Auto/Running
E100B (Intel(R) PRO Adapter Driver)- C:\WINDOWS\system32\DRIVERS\e100b325.sys - Manual/Stopped
emupia (E-mu Plug-in Architecture Driver)- C:\WINDOWS\system32\drivers\emupia2k.sys - Manual/Running
iaStor (Intel AHCI Controller)- C:\WINDOWS\system32\drivers\iaStor.sys - Boot/Running
Lbd (Lbd)- C:\WINDOWS\system32\DRIVERS\Lbd.sys - Boot/Stopped
LHidFilt (Logitech SetPoint KMDF HID Filter Driver)- C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys - Manual/Stopped
LMouFilt (Logitech SetPoint KMDF Mouse Filter Driver)- C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys - Manual/Stopped
omci (OMCI WDM Device Driver)- C:\WINDOWS\system32\DRIVERS\omci.sys - System/Running
ossrv (Creative OS Services Driver)- C:\WINDOWS\system32\drivers\ctoss2k.sys - Manual/Running
PalmUSBD (PalmUSBD)- C:\WINDOWS\system32\drivers\PalmUSBD.sys - Manual/Stopped
PfModNT (PfModNT)- \??\C:\WINDOWS\system32\drivers\PfModNT.sys - Auto/Running
sscdbhk5 (sscdbhk5)- C:\WINDOWS\system32\drivers\sscdbhk5.sys - System/Running
ssrtln (ssrtln)- C:\WINDOWS\system32\drivers\ssrtln.sys - System/Running
tfsnboio (tfsnboio)- C:\WINDOWS\system32\dla\tfsnboio.sys - Auto/Running
tfsncofs (tfsncofs)- C:\WINDOWS\system32\dla\tfsncofs.sys - Auto/Running
tfsndrct (tfsndrct)- C:\WINDOWS\system32\dla\tfsndrct.sys - Auto/Running
tfsndres (tfsndres)- C:\WINDOWS\system32\dla\tfsndres.sys - Auto/Running
tfsnifs (tfsnifs)- C:\WINDOWS\system32\dla\tfsnifs.sys - Auto/Running
tfsnopio (tfsnopio)- C:\WINDOWS\system32\dla\tfsnopio.sys - Auto/Running
tfsnpool (tfsnpool)- C:\WINDOWS\system32\dla\tfsnpool.sys - Auto/Running
tfsnudf (tfsnudf)- C:\WINDOWS\system32\dla\tfsnudf.sys - Auto/Running
tfsnudfa (tfsnudfa)- C:\WINDOWS\system32\dla\tfsnudfa.sys - Auto/Running
tmactmon (tmactmon)- \??\C:\WINDOWS\system32\drivers\tmactmon.sys - Auto/Running
tmcfw (Trend Micro Common Firewall Service)- C:\WINDOWS\system32\DRIVERS\TM_CFW.sys - Manual/Running
tmevtmgr (tmevtmgr)- \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys - Auto/Running
tmpreflt (tmpreflt)- C:\WINDOWS\system32\DRIVERS\tmpreflt.sys - Auto/Running
tmtdi (Trend Micro TDI Driver)- C:\WINDOWS\system32\DRIVERS\tmtdi.sys - System/Running
tmxpflt (tmxpflt)- C:\WINDOWS\system32\DRIVERS\tmxpflt.sys - Auto/Running
USA19H (USA19H)- C:\WINDOWS\system32\DRIVERS\USA19H2k.sys - Manual/Stopped
USA19H2KP (Keyspan USB Serial Port Driver)- C:\WINDOWS\system32\DRIVERS\USA19H2kp.SYS - Manual/Stopped
vsapint (vsapint)- C:\WINDOWS\system32\DRIVERS\vsapint.sys - Auto/Running
wanatw (WAN Miniport (ATW))- C:\WINDOWS\system32\DRIVERS\wanatw4.sys - Manual/Stopped
Wdf01000 (Wdf01000)- C:\WINDOWS\system32\DRIVERS\Wdf01000.sys - Manual/Stopped

====== Uninstall List ======

Across Lite 2.0
Adobe Flash Player 10 Plugin
Advanced Data Management System for the FT-7800
Canon Camera Access Library
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon PIXMA iP6000D
Conexant D850 56K V.9x DFVc Modem
Acrobat.com
Canon Camera Support Core Library
Dell Digital Jukebox Driver
Canon Utilities Digital Photo Professional 2.2
Canon Utilities Easy-PhotoPrint
Easy-WebPrint
Canon Utilities EOS Utility
Handmark® Scrabble® for Palm OS
HijackThis 2.0.2
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
Windows Internet Explorer 8
TBS WMP Plug-in
Broadcom Advanced Control Suite 2
DesignPro 5.0 Limited Edition
Windows Genuine Advantage Validation Tool (KB892130)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 6.4 (KB925398)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows XP (KB938464)
Hotfix for Windows Media Player 11 (KB939683)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Hotfix for Windows Internet Explorer 7 (KB947864)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Security Update for Windows XP (KB952004)
Security Update for Windows Media Player (KB952069)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Update for Windows XP (KB955839)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Critical Update for Windows Media Player 11 (KB959772)
Security Update for Windows XP (KB960225)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows Internet Explorer 7 (KB963027)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Security Update for Windows XP (KB968537)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows Media Player (KB973540)
Update for Windows XP (KB973815)
Security Update for Windows XP (KB973869)
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Mozilla Firefox (3.5.2)
Mozilla Thunderbird (2.0.0.22)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft National Language Support Downlevel APIs
NVIDIA Drivers
Canon Utilities PhotoStitch
Canon RAW Image Task for ZoomBrowser EX
RealPlayer
Canon RemoteCapture Task for ZoomBrowser EX
Revo Uninstaller 1.83
TurboTax 2008
Viewpoint Media Player
VX-6 Programmer
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Windows Media Format 11 runtime
Windows Media Player 11
Microsoft User-Mode Driver Framework Feature Pack 1.0
Canon Utilities ZoomBrowser EX
Adobe AIR
Sonic Update Manager
CDDRV_Installer
Microsoft Plus! Photo Story 2 LE
Qualxserve Service Agreement
Sonic DLA
TBS WMP Plug-in
WordPerfect Office 12
Sonic MyDVD
Java(TM) 6 Update 14
TurboTax 2008 WinPerUserEducation
Broadcom Advanced Control Suite 2
Keyspan USB Serial Adapter
KhalInstallWrapper
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Microsoft Easy Assist v2
Windows Media Player 10
WebFldrs XP
Internet Explorer Default Page
Canon PIXMA iP6000D Memory Card Utility
MSXML 4.0 SP2 (KB927978)
Logitech Registration
NetWaiting
Dell Support
Creative MediaSource
Dell Driver Reset Tool
TurboTax 2008 wcaiper
Windows Genuine Advantage v1.3.0254.0
PowerDVD 5.3
Dell Networking Guide
Apple Software Update
Photo Click
Microsoft Plus! Digital Media Edition Installer
Trend Micro Internet Security
Dell System Restore
TurboTax 2008 WinPerFedFormset
Windows Backup Utility
Acrobat.com
ArcGIS Explorer
AnswerWorks 4.0 Runtime - English
Modem Helper
MSXML 4.0 SP2 (KB954430)
TurboTax 2008 WinPerReleaseEngine
Microsoft Silverlight
Logitech Desktop Messenger
Intel Application Accelerator
Microsoft Office Professional Edition 2003
Sonic RecordNow!
DesignPro 5.0 Limited Edition
iTunes
Sound Blaster Audigy 2 ZS
AnswerWorks 5.0 English Runtime
Trend Micro Internet Security
Google Update Helper
Adobe Reader 9.1.3
MCP-F6F7
WordPerfect Office ProductCode 1 Key
TurboTax 2008 wrapper
TurboTax 2008 WinPerTaxSupport
Microsoft .NET Framework 2.0 Service Pack 1
MSXML 4.0 SP2 (KB936181)
Apple Mobile Device Support
QuickTime
Microsoft .NET Framework 1.1
Google Earth
Canon PhotoRecord
Dragon NaturallySpeaking 9
Digital Line Detect
TurboTax 2008 WinPerProgramHelp
WexTech AnswerWorks
Documents To Go
Logitech SetPoint
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Omron Health Management Software
palmOne

======== Other Info ========

TOTAL PHYSICAL RAM: 1072 MB

Boot Info

[boot loader]
timeout=15
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect


OS Type:  Microsoft Windows XP Home Edition
Build:  5.1.2600
Service Pack:  3.0


====== Files with Hidden Attributes======

C:\hiberfil.sys
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\NTDETECT.COM
C:\DELL\PRIMOSDK.DLL
C:\DELL\PX.DLL
C:\DELL\PXDRV.DLL
C:\DELL\PXMAS.DLL
C:\DELL\PXWAVE.DLL
C:\DELL\VXBLOCK.DLL
C:\DELL\PXCPYA64.EXE
C:\DELL\PXCPYI64.EXE
C:\DELL\PXHPINST.EXE
C:\DELL\PXINSA64.EXE
C:\DELL\PXINSI64.EXE
C:\DELL\PXSETUP.EXE
C:\DELL\PXHELP20.SYS
C:\DELL\PXHELP64.SYS
C:\DELL\PXHELPER.SYS
C:\DELL\PXHLPA64.SYS
C:\DELL\PXHELP20.INF
C:\DELL\PXHELPER.INF
C:\DELL\MEDIAEXE\PRIMOSDK.DLL
C:\DELL\MEDIAEXE\PX.DLL
C:\DELL\MEDIAEXE\PXDRV.DLL
C:\DELL\MEDIAEXE\PXMAS.DLL
C:\DELL\MEDIAEXE\PXWAVE.DLL
C:\DELL\MEDIAEXE\VXBLOCK.DLL
C:\DELL\MEDIAEXE\PXCPYA64.EXE
C:\DELL\MEDIAEXE\PXCPYI64.EXE
C:\DELL\MEDIAEXE\PXHPINST.EXE
C:\DELL\MEDIAEXE\PXINSA64.EXE
C:\DELL\MEDIAEXE\PXINSI64.EXE
C:\DELL\MEDIAEXE\PXSETUP.EXE
C:\DELL\MEDIAEXE\PXHELP20.SYS
C:\DELL\MEDIAEXE\PXHELP64.SYS
C:\DELL\MEDIAEXE\PXHELPER.SYS
C:\DELL\MEDIAEXE\PXHLPA64.SYS
C:\DELL\MEDIAEXE\PXHELP20.INF
C:\DELL\MEDIAEXE\PXHELPER.INF

==End of Report==

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2865
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #3 on: August 21, 2009, 02:41:22 pm »
Edie

That looks o.k. Let's do this

Please perform a BitDefender Online Virus and Malware Scan here:
    * Click on I Agree.
    * An ActiveX warning box will appear, click on Install.
    * Under Select What You Want To Check For Viruses.
    * Please Check My Computer and Click Ok
    * Now Click On Click Here To Scan
    * Next, Click on Click here to export the scan report
    * Save it to your Desktop.
    * In your next reply, please include the BitDefender log.

2008-2010
With everything comes a price

Offline Edie

  • Bronze Member
  • Posts: 8
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #4 on: August 21, 2009, 04:15:17 pm »
Here is the Bitdefender log file:



BitDefender Online Scanner
   

 
   

 

Scan report generated at: Fri, Aug 21, 2009 - 15:12:45

 
   

 
   

 

Scan path: C:\Documents and Settings\Edie\My Documents;C:\Documents and Settings\All Users\Documents;A:\;C:\;D:\;E:\;
   

 
   

 

 
   

 
   

 

Statistics

Time
   

01:23:14

Files
   

399169

Folders
   

10227

Boot Sectors
   

0

Archives
   

28030

Packed Files
   

16613
   

 
   

 

Results

Identified Viruses
   

1

Infected Files
   

4

Suspect Files
   

0

Warnings
   

0

Disinfected
   

0

Deleted Files
   

8
   

 
   

 

Engines Info

Virus Definitions
   

3911633

Engine build
   

AVCORE v2.1 Windows/i386 11.0.0.26 (Jul 24 2009)

Scan plugins
   

17

Archive plugins
   

45

Unpack plugins
   

7

E-mail plugins
   

6

System plugins
   

4
   

 
   

 

Scan Settings

First Action
   

Disinfect

Second Action
   

Delete

Heuristics
   

Yes

Enable Warnings
   

Yes

Scanned Extensions
   

*;

Exclude Extensions
   

 

Scan Emails
   

Yes

Scan Archives
   

Yes

Scan Packed
   

Yes

Scan Files
   

Yes

Scan Boot
   

Yes
   

 
   

 
 

Scanned File
   

 Status

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\03524BC7.cla=>(Quarantine-2)
   

Infected with: Java.Trojan.Downloader.OpenStream.W

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\03524BC7.cla=>(Quarantine-2)
   

Disinfection failed

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\03524BC7.cla=>(Quarantine-2)
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\03524BC7.cla
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\16A146C3.cla=>(Quarantine-2)
   

Infected with: Java.Trojan.Downloader.OpenStream.W

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\16A146C3.cla=>(Quarantine-2)
   

Disinfection failed

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\16A146C3.cla=>(Quarantine-2)
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\16A146C3.cla
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\5691138F.cla=>(Quarantine-2)
   

Infected with: Java.Trojan.Downloader.OpenStream.W

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\5691138F.cla=>(Quarantine-2)
   

Disinfection failed

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\5691138F.cla=>(Quarantine-2)
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\5691138F.cla
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\66C0300E.cla=>(Quarantine-2)
   

Infected with: Java.Trojan.Downloader.OpenStream.W

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\66C0300E.cla=>(Quarantine-2)
   

Disinfection failed

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\66C0300E.cla=>(Quarantine-2)
   

Deleted

C:\Program Files\Norton AntiVirus\Norton AntiVirus\Quarantine\66C0300E.cla
   

Deleted
   

 

 
   

 
   

 

 
   

 
   

 

 

Offline Edie

  • Bronze Member
  • Posts: 8
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #5 on: August 23, 2009, 11:06:53 am »
I noted there was a virus found during the scan.

However, the Clipboard problem remains even after removal of the virus.

I have uninstalled and reinstalled Office on my own, and with the help of a Microsoft Support tech, but again the problem has recurred.

The tech suggested it was a problem with my wireless keyboard and mouse, but I switched these out for a USB-wired mouse and keyboard, and again the Clipboard problem recurred.

I would appreciate any further feedback and help you can give me.

Thanks to all.
Edie

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2865
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #6 on: August 24, 2009, 07:08:13 am »
Edie

The virus found is in the Quarantine folder of Norton AV. It can do no harm from there.

It appeara that your problem is not malware related. I am going to move your thread to the appropriate forum for further assistance

2008-2010
With everything comes a price

Offline Mister2

  • Global Moderator
  • Gold Member
  • Posts: 2380
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #7 on: August 24, 2009, 01:45:00 pm »
Hi Edie,

My first thought is that your Print Screen key (often labelled 'PrtScr' on the top row of keys) has jammed.  Have you tried using a different keyboard?

Try downloading and running ShowOff.  This puts a small window in the top left corner of the screen and lets you know which key has been pressed.  If your keyboard is playing up then I would expect it to show the PrtScr key is constantly being pressed.  When done, you will need to open Task Manager (Start, Run, type taskmgr and click OK), go to the Processes tab, click on 'ShowOff' and then click End Task.

Please note that some security programs may flag this utility as malware due to the way it interacts with your system at a low level.  The program is not harmful.
Never stop learning - visit the SpywareHammer Knowledgebase

Offline Edie

  • Bronze Member
  • Posts: 8
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #8 on: August 24, 2009, 01:57:56 pm »
Hi Mister 2,

Thanks for that feedback.

Actually, I have tried two different keyboard/mouse combos. The Microsoft support people I worked unsuccessfully with said it might be a wireless keyboard/mouse issue, so I traded out a USB-wired mouse and keyboard. Nevertheless, the problem recurred.

I will try your suggestion and get back to you.

Edie


Offline Edie

  • Bronze Member
  • Posts: 8
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #9 on: August 25, 2009, 09:25:38 am »
Mister 2, and all,

I have delayed in replying because so far the Clipboard problem I was having has not recurred.

Yesterday afternoon, a Microsoft Word tech support person walked me through adjusting by "Clip book" settings using Run--services.msc. While in the Services window, she had me double click on "Clip book".

My "startup type" setting was set to disabled. She had me set it to "automatic" and then click on "Start" under "service status." I then restarted my computer.

I assume this change is what has stopped the Clipboard problems. I will update you if this changes.

Thanks to all here for your replies and suggested fixes. You guys are GREAT!

Edie

Offline Mister2

  • Global Moderator
  • Gold Member
  • Posts: 2380
Re: [In Progress]Windows XP-Word 2003 Clipboard hijacked
« Reply #10 on: August 25, 2009, 12:11:14 pm »
That sounds great, Edie, and thanks for letting us know the progress on this one.
If you start getting problems again then post back and we will take another look.

Happy computing! ;D
Never stop learning - visit the SpywareHammer Knowledgebase