|
Answer» Matter of extreme urgency -- finals week, and I now have no internet access...very detrimental to end-of-quarter success.
I've had a Sygate Personal Firewall installed on my machine for several months now. I had never had any problems with it, but with my other problems lately (monitor or video card is dying, unsure which), I've had to restart the machine more than usual. When I restarted this morning, it came back on just fine, but I was denied access to the internet. I checked my wireless connection and it was fine. I did notice, though...that my firewall's icon in the lower right-hand corner was not on. It usually asks me several questions at startup, and the icon is always there. No questions asked, no icon. I've had this problem before with other free firewalls -- they work fine for a few months, then when they die (for reasons unknown to me...) they block everything access to the internet. Usually, I can just uninstall the firewall and everything is back to normal.
The Sygate firewall will not uninstall. When I go into the 'Add/Remove Programs' window, and click "Remove", it tells me my WINDOWS Installer is not installed on the machine, and therefore, it cannot remove the program. I can't even turn the firewall off, because the machine says it isn't on. I'm panicking. Right now, I'm on a campus computer, and it will be difficult to fix this without an internet connection (currently writing post from campus computer). You all have helped me out SO much in the past, and I'm very grateful. If you can give me directions on how to remove Sygate from my machine (or tell me if it's been hijacked/attacked by a virus), I will love you forever!
I have a Dell Dimension 2650 or something like that, run Windows XP, and the computer is 3 years old. The only programs I ever allow to access the internet are Firefox, IE (until I got Firefox), AIM, and Eudora.
Please, the quicker you can help me, the better. I'll even offer to bake cookies and send them!
-KateOh DEAR... can you write to a diskette or burn a CD on that machine? If you can, please go here to download HijackThis, do a scan, then put the log it creates (it's a text file) on a diskette/cd and put that in the campus computer, and post the log. It may span several posts, but that doesn't matter. That log will let us know if there's a hijacker.
If you've done this before, my apologies; I have to assume you haven't. Can't get back to my computer tonight. I did run HijackThis before I left, though. I only remember three or four things popping up in the log.
svchost WindowsInstaller Viewpoint AIM
I know I'm not being much help...but my timeframe is sort of limited, for running back and FORTH between computers. Sorry. :/ It's OK. But I think we'd need to see the full log. If you could do that whenever you can, that would be a big help. Okay, I got the logfile...had to write it all manually. Grumble.
Logfile of Hijack This v1.99.1 Scan saved at 1:25:09AM, on 3/13/2006 Platform: WindowsXP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v. 6.00SP1 (6.00.2800.1106)
Running Processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\AIM\aim.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\User\Desktop\HijackThis.exe
04 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" - atboottime 04 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe - cnetwait.odl 09 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe 023 - Service: Install Driver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel32\IDriverT.exe 023 - Service: LexBceServer (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\System32\LEXBCES.EXE 023 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Okay, that's it. I haven't seen that IDriverT before, and I don't remember ever having a program with that name. Maybe I just never really NOTICED it, but it doesn't look even remotely familiar. Any help on how to uninstall whatever it is that's corrupting my firewall (or the firewall itself) would be greatly appreciated!
-KateKate, that's nowhere near a full logfile. another thing, unless your secretarial skills are absolutely excellent, it's not wise to write these things down manually. IDriverT.exe is safe btw.Well.. since you said you had problems with Windows installer.. you might try this:
1. Open a CMD.EXE prompt.
2. Type msiexec /unregister and press Enter.
3. Type msiexec /regserver and press Enter ------------------
Also.. this might helpIt -was- the full logfile, thankyouverymuch. At least it's all HijackThis gave me. And I had no other options at the time. But my problem is fixed, so THANKS to those who helped me.
Full-copy past logfile, for your viewing pleasure.
Logfile of HijackThis v1.99.1 Scan saved at 1:31:05 PM, on 3/14/2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\AIM\aim.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Semagic\LiveJournalU.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\User\Desktop\HijackThis.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE well what was the fix?That is most certainly not a full logfile! How I wish they were that small!
|