 
                 
                InterviewSolution
| 1. | Solve : monitor control pops-up & adjusts randomly by itself, is this a virus?? | 
| Answer» i'm using WINDOWS XP, downloaded a malware once that triggered a trojan-outbreak ... had to reformat my PC. while Windows was already installing the monitor's brightness option kept popping-out and adjusts itself. i even deleted, created, & reformatted the partitions...it's still there, during start-ups til i shut down! 
 
 
 ok, done. what next? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:35:01 PM, on 7/23/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\SERVICES.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\System32\HPZipm12.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe C:\WINDOWS\system32\HotfixQ0306270.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [TSE_PLUtil] C:\Program Files\USB 2.0 Flash Drive Utility\PLBkMon.exe O4 - HKLM\..\Run: [PLFFAP] C:\WINDOWS\system32\HotfixQ0306270.exe O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe -- End of file - 4351 bytesI don't see any malware and the symptoms you describe don't sound like it either. I see you have SUPERAntiSpyware installed, have you done a scan with it? Quote Now the 'brightness' control's the only one that pops-out, from start-ups til shut-down I don't understand what you mean by this. Quote Now the 'brightness' control's the only one that pops-out, from start-ups til shut-down i took pics from the PC next to it... am still scanning SUPERAntiSpyware ... so far it's detected 8 Adware.Tracking Cookies ... [recovering disk space -- attachment deleted by admin]I'm not sure that this is malware related. Let's see if Superantispyware finds anything.Cookies are nothing to worry about. I'm with evilfantasy on this one...it doesn't sound like a malware issue. By the looks of it, your monitor is probably on the fritz. Your graphics card could also be the culprit, but I think that's not as likely. Do you have another monitor you can try? And can you hook your monitor up to a different computer? This is always the first thing you want to try when having significant monitor problems.I found some information on this in the links below. Sounds like it may just be a dust problem. Why does my brightness control on my monitor keep coming up Monitor Problems Quote If the menu keeps coming up the monitor thinks you pressed a button. A button is just a way of completing an electrical circuit. If dust accumulates on a circuit it can cause the circuit to act strangely. Purchasing some canned air from your local office supply store can solve this problem in most cases. Just blow the air in all the vent holes of the monitor to blow the dust out. Be sure to FOLLOW the directions on the can.[/qoute]Quote from: CBMatt on July 22, 2008, 11:34:41 PM Cookies are nothing to worry about. yes, i know the cookies are less of a threat...but...uhm, sure, once i get someone to lift the monitors for me ^^; everyone's busy... the video card's new, GeForce... i may try that thoughQuote If the menu keeps coming up the monitor thinks you pressed a button. A button is just a way of completing an electrical circuit. If dust accumulates on a circuit it can cause the circuit to act strangely. Purchasing some canned air from your local office supply store can solve this problem in most cases. Just blow the air in all the vent holes of the monitor to blow the dust out. Be sure to follow the directions on the can.[/qoute]Yes I think you need to get inside of the monitor and clean it out. Don't worry about the cookies, they are just .txt files so they can't do anything malicious.Quote from: evilfantasy on July 23, 2008, 12:14:20 AM Yes I think you need to get inside of the monitor and clean it out. K, i'll update you when am done... brb... i almost forgot, the same thing happens even if the screen-saver's already on, and even when i'm in safe-mode. I dusted the monitor carefully but i may have to do it again, it's still in the middle of the screen. does that mean i can use my tablet on this computer? it's the only one i could borrow. we're short on cash, can't replace it at the moment. I also want to ask about PREVENTING hardware-hacking, is AVG & SUPERAntiSpyware enough? | |