 
                 
                InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 601. | Solve : "Admin" Account Suddenly Has No Admin Powers? | 
| Answer» OK, I have a Dell Inspiron 6000 laptop running Windows XP. I have Zonealarm and AVG antivirus - the registered version. But for some reason I still ended up with a virus on my system. I have no idea how it happened, but it coincided with my reinstalling Firefox 2 after Firefox 3 pissed me off by running at a snail's pace. OK, I've tried the first part of what you suggested but the thing told me something like "this snapin cannot be used with Windows Home Edition please use the User Accounts menu in the Control Panel". It might be worth seeing if you can get into the built in admin account in safe mode. It certainly won't hurt. *censored* windows "home"... I only replied so quickly cus I was online. But thanks for the props! I'll have a play with my XP Home install later on tonight and see what can be done....Well that's odd; all of my admin powers suddenly CAME back after I did a reboot and pressed ctrl-alt-del at the welcome screen. Someone else suggested that I might still have malware on my system, though, so I'm going to take some steps to get rid of it. Thanks a billion for your help!Your computer may be still infected... Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RECONNECT TO THE INTERNET RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When completed, a log will open in NOTEPAD. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log. DO NOT make any other changes to your computer (like installing programs, using another cleaning tools, etc.), until it's officially declared clean!!! | |
| 602. | Solve : rootkit reaverler? | 
| Answer» here are my results il just wondering if i should DELETE any of these some seem important 
 It's good to run an online scan now and then. (once a month or so) | |
| 603. | Solve : Avast Resident Scanner Not Working?? | 
| Answer» I previously downloaded Avast Free Home Anti Virus software, and received about 5months of good use and no problems. But not to long ago when I booted the avast virus scanner, it wouldn't load and keep'd telling me that there was a problem with the skins or something.  | |
| 604. | Solve : Trojan Need Some Help!? | 
| Answer» I have a laptop that has some trojans on it. I was wondering if there was a fix so I don't have to do a reapair install? I will LATER run Combofix and send you guys the log after the antivirus programs run. I'm thinking rootkit maybe. What do you suggest then? ComboFix 08-07-14.2 - David 2008-07-14 14:01:45.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.475 [GMT -7:00] Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe * Created a new restore point * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . D:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2008-06-14 to 2008-07-14 ))))))))))))))))))))))))))))))) . 2008-07-14 13:02 . 2008-07-14 13:02 d-------- C:\Program Files\Trend Micro 2008-07-14 08:27 . 2008-07-14 08:27 1,374 --a------ C:\WINDOWS\imsins.BAK 2008-07-14 06:47 . 2008-07-14 06:47 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2008-07-14 06:46 . 2008-07-14 06:46 d-------- C:\Program Files\SUPERAntiSpyware 2008-07-14 06:46 . 2008-07-14 06:46 d-------- C:\Documents and Settings\David\Application Data\SUPERAntiSpyware.com 2008-07-14 06:44 . 2008-07-14 06:44 d-------- C:\Documents and Settings\David\Application Data\Malwarebytes 2008-07-14 06:43 . 2008-07-14 12:41 d-------- C:\Program Files\Malwarebytes' Anti-Malware 2008-07-14 06:43 . 2008-07-14 06:43 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-07-14 06:43 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys 2008-07-14 06:43 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys 2008-07-14 06:41 . 2008-07-14 12:40 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys 2008-07-14 06:41 . 2008-07-14 06:41 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll.old 2008-07-14 06:41 . 2008-07-14 12:40 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll 2008-07-14 06:40 . 2008-07-14 12:41 d-------- C:\WINDOWS\system32\drivers\Avg 2008-07-14 06:40 . 2008-07-14 06:40 d-------- C:\Program Files\AVG 2008-07-14 06:40 . 2008-07-14 06:40 d-------- C:\Documents and Settings\All Users\Application Data\avg8 2008-07-14 06:36 . 2008-07-14 06:36 d-------- C:\Program Files\CCleaner 2008-07-13 20:55 . 2008-07-14 08:29 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb 2008-07-13 20:55 . 2008-07-14 08:29 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb 2008-07-13 10:11 . 2008-07-13 10:11 d-------- C:\WINDOWS\Logs 2008-07-13 09:54 . 2008-07-13 09:54 d-------- C:\Program Files\Netflix 2008-06-20 10:46 . 2008-06-20 10:46 245,248 --------- C:\WINDOWS\system32\dllcache\mswsock.dll 2008-06-20 10:46 . 2008-06-20 10:46 147,968 --------- C:\WINDOWS\system32\dllcache\dnsapi.dll 2008-06-20 04:51 . 2008-06-20 04:51 361,600 --------- C:\WINDOWS\system32\dllcache\tcpip.sys 2008-06-20 04:40 . 2008-06-20 04:40 138,496 --------- C:\WINDOWS\system32\dllcache\afd.sys 2008-06-20 04:08 . 2008-06-20 04:08 225,856 --------- C:\WINDOWS\system32\dllcache\tcpip6.sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-14 21:05 8,612,384 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat 2008-07-14 19:43 106,892 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx 2008-07-14 13:41 --------- d-----w C:\Documents and Settings\David\Application Data\MSN6 2008-07-14 13:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-07-14 13:27 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard 2008-07-14 01:18 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-14 01:15 --------- d-----w C:\Program Files\Vstep 2008-07-13 23:33 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll 2008-07-10 02:06 --------- d-----w C:\Documents and Settings\David\Application Data\Apple Computer 2008-07-09 16:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe 2008-07-09 16:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll 2008-07-08 21:03 2,228,736 ----a-w C:\WINDOWS\Internet Logs\xDBF.tmp 2008-07-06 00:55 --------- d-----w C:\Program Files\Microsoft Works 2008-07-06 00:55 --------- d-----w C:\Program Files\Common Files\SureThing Shared 2008-07-06 00:55 --------- d-----w C:\Program Files\Common Files\Sonic Shared 2008-07-02 18:55 --------- d-----w C:\Program Files\Java 2008-07-01 01:17 --------- d-----w C:\Program Files\Common Files\Adobe 2008-06-20 17:46 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll 2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys 2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys 2008-06-19 05:27 1,658,880 ----a-w C:\WINDOWS\Internet Logs\xDBE.tmp 2008-06-13 11:05 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys 2008-06-13 11:05 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys 2008-06-08 13:39 11,218,798 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip 2008-06-07 21:05 --------- d-----w C:\Documents and Settings\David\Application Data\Intuit 2008-06-07 21:04 --------- d-----w C:\Program Files\Quicken 2008-06-07 18:34 --------- d-----w C:\Program Files\StompSoft 2008-06-06 20:36 --------- d-----w C:\Program Files\TomTom HOME 2 2008-06-06 20:18 --------- d-----w C:\Documents and Settings\David\Application Data\TomTom 2008-05-31 17:23 --------- d-----w C:\Program Files\Lavasoft 2008-05-31 17:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-05-30 21:19 507,400 ----a-w C:\WINDOWS\system32\XAudio2_1.dll 2008-05-30 21:18 238,088 ----a-w C:\WINDOWS\system32\xactengine3_1.dll 2008-05-30 21:17 65,032 ----a-w C:\WINDOWS\system32\XAPOFX1_0.dll 2008-05-30 21:17 25,608 ----a-w C:\WINDOWS\system32\X3DAudio1_4.dll 2008-05-30 21:11 467,984 ----a-w C:\WINDOWS\system32\d3dx10_38.dll 2008-05-30 21:11 3,850,760 ----a-w C:\WINDOWS\system32\D3DX9_38.dll 2008-05-30 21:11 1,491,992 ----a-w C:\WINDOWS\system32\D3DCompiler_38.dll 2008-05-27 03:37 --------- d-----w C:\Documents and Settings\David\Application Data\HP 2008-05-27 03:37 --------- d-----w C:\Documents and Settings\David\Application Data\CyberLink 2008-05-25 22:24 --------- d-----w C:\Documents and Settings\David\Application Data\AdobeUM 2008-05-25 21:49 --------- d-----w C:\Program Files\WinDirStat 2008-05-25 20:49 --------- d-----w C:\Documents and Settings\David\Application Data\Corel 2008-05-25 20:37 --------- d-----w C:\Program Files\Microsoft ActiveSync 2008-05-25 20:29 --------- d-----w C:\Program Files\Google 2008-05-25 20:28 --------- d-----w C:\Program Files\Norton CleanSweep 2008-05-25 20:27 --------- d-----w C:\Program Files\Symantec 2008-05-25 20:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-05-25 20:27 --------- d-----w C:\Documents and Settings\David\Application Data\Symantec 2008-05-25 20:15 --------- d-----w C:\Documents and Settings\David\Application Data\Leadertech 2008-05-25 20:03 --------- d-----w C:\Program Files\Microsoft Streets & Trips 2008-05-25 19:00 --------- d-----w C:\Documents and Settings\David\Application Data\MSNInstaller 2008-05-25 18:46 --------- d-----w C:\Program Files\Microsoft Office Outlook Connector 2008-05-25 16:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2008-05-25 15:59 --------- d-----w C:\Program Files\Hp 2008-05-25 15:53 --------- d-----w C:\Documents and Settings\David\Application Data\Talkback 2008-05-25 15:48 1,743 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP Pavilion dv8000 (EX177AV)_YN_0Pavi_QCND62600G3_E413900001_46_I30 A6_SHP_V56.37_BF.13_T060510_WXH2_L409_M 1023_J80_7Intel_8T2400_91.83_#080525_N80861092_(EX177AV)_XMOBILE_CN10_Z_2F.13_G10DE0398.MRK 2008-05-25 15:12 --------- d-----w C:\Program Files\Quickensetup 2008-05-25 15:10 --------- d-----w C:\Program Files\NetWaiting 2008-05-25 15:10 --------- d-----w C:\Program Files\Netscape 2008-05-25 15:10 --------- d-----w C:\Program Files\music_now 2008-05-25 15:10 --------- d-----w C:\Program Files\MSN Encarta Plus 2008-05-25 15:09 --------- d-----w C:\Program Files\Microsoft Office Trial Wizard 2008-05-25 15:08 --------- d-----w C:\Program Files\Microsoft Money 2006 2008-05-25 15:05 --------- d-----w C:\Program Files\CONEXANT 2008-05-25 15:05 --------- d-----w C:\Program Files\Common Files\Palo Alto Software 2008-05-25 15:05 --------- d-----w C:\Program Files\Common Files\muvee Technologies 2008-05-25 15:04 --------- d-----w C:\Program Files\Common Files\LightScribe 2008-05-25 15:00 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec 2008-05-25 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic 2008-05-25 01:40 --------- d-----w C:\Documents and Settings\David Buchanan\Application Data\MSN6 2008-05-20 17:17 --------- d-----w C:\Program Files\Adobe Media Player 2008-05-19 19:48 --------- d-----w C:\Documents and Settings\David Buchanan\Application Data\AdobeUM 2008-05-16 18:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe 2008-05-16 18:25 15,616 -c--a-w C:\Documents and Settings\David Buchanan\Application Data\wklnhst.dat 2008-05-15 21:50 2,661,376 ----a-w C:\WINDOWS\Internet Logs\xDBD.tmp 2008-05-09 10:53 90,112 ----a-w C:\WINDOWS\system32\wshext.dll 2008-05-09 10:53 90,112 ------w C:\WINDOWS\system32\dllcache\wshext.dll 2008-05-09 10:53 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll 2008-05-09 10:53 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll 2008-05-09 10:53 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll 2008-05-09 10:53 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll 2008-05-09 10:53 180,224 ------w C:\WINDOWS\system32\dllcache\scrobj.dll 2008-05-09 10:53 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll 2008-05-09 10:53 172,032 ------w C:\WINDOWS\system32\dllcache\scrrun.dll 2008-05-08 14:02 203,136 ------w C:\WINDOWS\system32\dllcache\rmcast.sys 2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe 2008-05-08 11:24 155,648 ------w C:\WINDOWS\system32\dllcache\wscript.exe 2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe 2008-05-07 09:07 135,168 ------w C:\WINDOWS\system32\dllcache\cscript.exe 2008-05-07 05:12 1,288,192 ----a-w C:\WINDOWS\system32\quartz.dll 2008-05-07 05:12 1,288,192 ------w C:\WINDOWS\system32\dllcache\quartz.dll 2008-04-24 05:16 3,591,680 ------w C:\WINDOWS\system32\dllcache\mshtml.dll 2008-04-22 07:40 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2008-04-22 07:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2008-04-20 05:07 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll 2008-04-17 17:26 2,208,768 ----a-w C:\WINDOWS\Internet Logs\xDBC.tmp 2008-04-14 13:39 2,193,920 ----a-w C:\WINDOWS\Internet Logs\xDBB.tmp . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-24 16:41 68856] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360] "TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 01:42 202088] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784] "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 19:49 454656] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-15 11:26 7561216] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-15 11:26 86016] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 22:46 761948] "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 21:54 102400] "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152] "ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856] "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920] "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-02-22 08:03 40960] "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23 1187840] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 09:05 919016] "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-14 12:41 1232152] "nwiz"="nwiz.exe" [2006-04-15 11:26 1519616 C:\WINDOWS\system32\nwiz.exe] "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe] C:\Documents and Settings\David Buchanan\Start Menu\Programs\Startup\ Salem Public Library Tray App.lnk - C:\Program Files\PermissionTV\bin\dmtray.exe [2008-02-29 19:35:06 57344] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696] HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30 73728] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=APITRAP.DLL,avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"= R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-14 12:40] R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-14 12:41] *Newly Created Service* - CATCHME . Contents of the 'SCHEDULED Tasks' folder "2008-07-14 19:47:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe "2008-07-12 20:13:56 C:\WINDOWS\Tasks\Registry Repair.job" - C:\Program Files\StompSoft\RegistryRepair4\Registry Repair.exe "2008-07-12 20:13:56 C:\WINDOWS\Tasks\Registry Repair4.job" - C:\Program Files\StompSoft\RegistryRepair4\Registry Repair.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-14 14:04:52 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden AUTOSTART entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??? ?[email protected]? ?U???([email protected]? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- PROCESS: C:\WINDOWS\explorer.exe -> ?:\WINDOWS\system32\PSAPI.DLL -> ?:\WINDOWS\System32\msvcp60.dll . Completion time: 2008-07-14 14:05:47 ComboFix-quarantined-files.txt 2008-07-14 21:05:42 Pre-Run: 40,360,603,648 bytes free Post-Run: 40,365,944,832 bytes free 229 --- E O F --- 2008-07-13 16:26:24 Run the F-Secure Online Scanner for Viruses, Spyware and RootKits: This scanner works with Internet Explorer only 
 Quote catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netQuote from: evilfantasy on July 14, 2008, 03:39:49 PM From the combofix log. This is very suspicious to be in that location in the log. I thought so too. What should I do about that? | |
| 605. | Solve : Windows Script error message? | 
| Answer» I am a self taught computer user and only know enough to get by...for some reason my AVG virus protector disappeared so I downloaded it again.  Since then every time I turn on my computer I get the error MESSAGE:   | |
| 606. | Solve : i have computer problems? | 
| Answer» I have a compaq presario 6000, it runs off of windows XP. Yesterday I installed windows service pack3. I have no idea who used this computer after that but i turned it on today and it went through disk check and then when it was finished I booted it up and it came up with the icons and stuff but also it came up with the c-setup black box and then it closed by itself. Im really concerned so I ran hijack this and malwarebytes. I also ran super anti spyware but it didnt give me a log. So here is the log for hijack this.  | |
| 607. | Solve : Virus alert in time bar? | 
| Answer» Dear kind sirs | |
| 608. | Solve : I cannot get my hidden folder? | 
| Answer» Hi , Viewing the porn has made you go blind, and you cannot see that the folder is unhidden? you are so rude .... you dont deserve to be a member of this forumOpen My computer and than click tools....folder options. LOOK for the tab called View and than click show hidden files and folders. You should be able to see the folder now. Quote from: superdupermido on July 14, 2008, 08:30:45 AM i change the folder options and click apply ... i open the properties again and i find that no chane has occuredwhat changes have u made in folder options ?? and whose properties r u talking about Quote from: Spoiler on July 14, 2008, 09:15:07 AM Open My computer and than click tools....folder options. Look for the tab called View and than click show hidden files and folders. i have done this and the folder doesnt show up and when i open the folder options again > view tab .... the (do not show hidden files and folders ) box is ticked Quote from: superdupermido on July 14, 2008, 08:50:18 AM Quote from: Dias de verano on July 14, 2008, 08:45:03 AMViewing the porn has made you go blind, and you cannot see that the folder is unhidden? That's me told Anyway, not being able to view hidden files and folders is one symptom of a malware infection. You should take the appropriate action - virus check, spyware check, etc. superdupermido Print these instructions out. 1. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. PHYSICALLY DISCONNECT FROM THE INTERNET Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for HARMFUL Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply. * Click Close to exit the program. Post SUPERAntiSpyware log. RECONNECT TO THE INTERNET RESTART COMPUTER! 2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop. * Double-click mbam-setup.exe and follow the prompts to install the program. * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the LATEST version. * Once the program has loaded, select Perform full scan, then click Scan. * When the scan is complete, click OK, then Show Results to view the results. * Be sure that everything is checked, and click Remove Selected. * When COMPLETED, a log will open in Notepad. * Post the log back here. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt RESTART COMPUTER! 3. Download HijackThis: http://www.snapfiles.com/get/hijackthis.html Post HijackThis log. Quote Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?This was totally uncalled for, and rude indeed. Quote from: Broni on July 15, 2008, 12:37:43 AM QuoteViewing the porn has made you go blind, and you cannot see that the folder is unhidden?This was totally uncalled for, and rude indeed. Well, I didn't see why we had to hear about his porn collection: he could have just said he couldn't unhide a previously hidden folder, so I commented on that.Ehhh....whatever. Quote Umm actually you couldn't be anymore wrong. The only reason he can't see his folder is because the viewing options arn't in place? You shouldn't just go and say he might have some sort of virus. Quite and unnesseary comment? He wrote, Quote now i try to make it unhidden from the folder options but it doesnt show up So I think you are the person who is wrong. Don't click on Pink Floyd's scam link. Don't follow his pretend "advice", which is just an EXCUSE to spread his scam message. Pink Floyd's post deleted. Your signature is spam Pink Floyd!. Quote from: superdupermido on July 14, 2008, 08:30:45 AM Hi ,well dude I had the same problem (I couldn't see my hidden file when I active in folder option it return to "Do not show hidden file" automaticly) so by Regedit you should do like this: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL Correct the value CheckedValue in the right window to 1. that should solve your problem........ enjoy watching porn | |
| 609. | Solve : I have a question concerning ShowDeskFix? | 
| Answer» Just a question, I'm studying about fighting malware right now, I love to look around for frsh HJT log to PRACTICE by myself. And today i come across these entries To restore the show desktop icon: http://www.msfn.org/board/lofiversion/index.php/t91884.html Quote To restore the show desktop icon:INTERESTING... Since that command is set to run every time, computer starts, it may actually keep restoring desktop icons to some "bad" state, preferred by some malware ...but, as you said: Quote Tough call without seeing some other virus scans.Thank you for your answer. I just google ShowDeskFix, and come up with many problem helper forum that include this entry in HJT. As it original, I seem to forget which and where I saw it first But what if I will not look at the word "[ShowDeskFix]" but look at command line "RunOnce" instead, will it mean that it is safe to have HJT fix it? Sorry for asking too many questions? I SEE you asked at BC also. Maybe they can shed some light on it. Until then. Understanding and Interpreting HijackThisI think, it's perfectly fine to fix it through HJT. Remember, HJT always creates backup, but I don't think, it'll be necessary to use it in this case. I'm pretty sure, I recall these entries in someone else HJT log, and deleting them caused no harm. | |
| 610. | Solve : I need help with NIS? | 
| Answer» A new threat to protect against. But every time I click "protect me" I still get this: | |
| 611. | Solve : Adware on (older) Mac? | 
| Answer» I made a big boo-boo at work and HOPE you can help me out.  | |
| 612. | Solve : Blackworm Virus? | 
| Answer» I know I am late to share this, but here is some interesting reading. It says it will overwrite information on Feb. 3rd... Of this year? February is almost over... So it is basically harmless now, RIGHT? If it will only erase information on this date? FlameSome variants STRIKE on the 3rd of every month. | |
| 613. | Solve : Upgrade MS Anti Spy to MS Defender?? | 
| Answer» I guess MS Anti Spy is now MS Defender. I installed Windows Defender on a few other computers, and I like AntiSpy more... Hmmm. [smiley=undecided.gif] Flame, Any particular thing about Defender you liked less or more than Anti Spy? Just curious.Well, for one thing, I like having an icon on the System Tray to tell me that it's running PROPERLY. I also like having a progress Window that shows me how much LONGER an update will take, etc. The Defender does not show an update window, and if it takes a while, one might assume the program has frozen. Those are the only major concerns I have with the program. Flame | |
| 614. | Solve : Mcafee Virus scan? | 
| Answer» I have Mcafee VirusScan Enterprise 8.0.0 Installed on my computer. When I first start up my computer for the first time during a day I have to manually enable on access scan.Sometimes, It shows It being on, most of the time It appears off. I have tried settings but no luck, Any Ideas?.http://www.tcd.ie/iss/security/virusscan_8.php | |
| 615. | Solve : java highway? | 
| Answer» New to the boards and have a question / the last two times AVG has detected viruses in my system, they CAME in through java    system is xp home with avg free and windows firewall.  generally this system stays clean, but is something up with java ? any ideas ?  Look in add/remove programs and tell us what all versions of Java are listed.  that is exactly what is there; What is/was there? The only entry of Java that should be in add/remove programs is Java (TM) 6 Update 3 The rest need to be uninstalled in add remove programs. Old versions of Java are entry points for malware. You should run the scans in this post to be sure nothing else is hidden in the system. RAN THE SCANS, DOWNLOADED THE "SUPER" PROGRAM AND EVERYTHING IS IN ORDER NOW.......THANKS FOR THE TIP Good to know. Safe surfing...... To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? | |
| 616. | Solve : All .exe extensions changed to *exe.vir. and quarantined. Pleeeeas Help!!? | 
| Answer» All .exe extensions changed to  *exe.vir. and quarantined. Pleeeeas Help!! when I look in the Quarantine folder What quarantine folder? McAfee? Is it a paid version? Update it.....then let us know. Also in this instance more info would be a good idea... Windows version ? ? Protection apps installed CURRENTLY ? ? Any new software installed in the last month ? ?Sorry guys!! It is an IBM thinkpad T20 running win xp pro 2 edition. McAfee antivirus, perpetual. But McAfee ALWAYS says it is 19 months old when scanning. LATEST software run was RockXp , just for product key retrieval. P.s. The quarantine folder is located in c:\windows\Quarantine. Any hope?? 10X again ofr all the help, guys!! More bkgd info, the laptop doesn't let me run anything. Even tried to update the McAfee, but says can't find ''Windows Installer''. Plus, the activity bar doubled and the start menu disapeared. And the CPU is almost always 100%. Hope that helps.Probably not what you want to hear but with all your file extensions wonked and things seemingly getting worse a format and clean install of XP may be in order here...You can run anything at all? Not even HijackThis? What about in Safe Mode? This sort of infection is possible to clean, but I'll tell you right now that even if we can clean your infection, it probably won't be easy. | |
| 617. | Solve : a lots of problem? | 
| Answer» hi is thr anyone to help me... i have got lots of problem in my PC:- | |
| 618. | Solve : is this overkill? | 
| Answer» I have xp sp2 I have threatfire, COMODO avg, and windows defender on my pc just wondering if it too MUCH. I don't have any PROBLEMS REALLY I'm just curious thanksNot overkill. I would ALSO install Spywareblasterokay great thanks Evil.No problem | |
| 619. | Solve : Msn, Based Virus,? | 
| Answer» Hello, i have seen this quite alot. But is it a virus or WHATNOT, when someone sends you a FILE of the NET and its says like 'do i LOOK dumb in this pic?' and with an attached file. This happens in msn live? any thoughts on what type of software COULD be running it etc. its really annoying. I opened one on my virtual pc, its bad, some pritty bad stuff it sends you.http://www.msnvirusremoval.com/ | |
| 620. | Solve : need help removing a program!!!!? | 
| Answer» i accidently downloaded a anti-virus on my pc and it has been causing me problems EVERY since. i've tried removing it from my control panel and it still won't leave. can somebody please help me to figure this out?First and foremost, welcome to CH Forums. i accidently downloaded a anti-virus on my pc and it has been causing me problems every since. Welcome to CH. Please see our standard pre-cleaning PROCEDURE. Once the logs are posted we will go from there. Click >>HERE<< thanks anyway. the software i downloaded was called antivirus xp 2008. i read a few of your other members problems and got help just from reading their REPLIES. malwarebytes helped me solve my problem. thanks so much. Quote from: mowett on July 13, 2008, 01:52:02 PM thanks anyway. the software i downloaded was called antivirus xp 2008. i read a few of your other members problems and got help just from reading their replies. malwarebytes helped me solve my problem. thanks so much. It would be a good idea to go ahead with your own and have the experts at CH do a diagnosis on your system and prescribe cleaning instructions - instructions for cleaning, other than the general first steps, are unique to each set of circumstances. BEST of luck."It would be", or wouldn't be? Quote from: Broni on July 13, 2008, 02:12:09 PM "It would be", or wouldn't be? Check my edit above - it the original was ambiguous; thanks. Better Good catch - made sense to me when I wrote it; probably should have been my first clue! Quote made sense to me when I wrote itIt's always like that. Only when you re-read it, you may catch it | |
| 621. | Solve : I NEED HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!? | 
| Answer» Well if you can't positivly fix the problem really the only OPTION you have, is to reinstall windows, which would WIPE your hard drive clean. The positives here are also that your COMPUTER, after being wiped, would run as FAST as when it was bought   | |
| 622. | Solve : malewarebytes blocking MPC video player? | 
| Answer» so for some reason malwarebytes is treating MPC as a MALICIOUS program. Ive been using it forever then all the SUDDEN when i go to click on a video it gives pop up "ransom.filelocker" | |
| 623. | Solve : I seem to have a browser redirect issue which is not being detected? | 
| Answer» I ran adwcleaner and MBAM again as requested. 
 ***************************************** Please download Farbar Service Scanner to the desktop and run it on the computer with the issue. Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version. Make sure FRST is run under administrator privileges. Make sure that the Whitelist section is checked.Otherwise, the log will be very long. You Security programs may prevent the tool from running. If this happens, disable the security program until the scan is completed. 
 Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ******************************************* This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments... This is a very crucial step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked: 
 Once finished a logfile will be created. You don't have to attach it to your next reply. ********************************************** I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! | |
| 624. | Solve : Some questions about Tails? | 
| Answer» Hi, I would like to ask some security-focused questions on Tails, the Linux privacy OS. As you can see, the questions are mainly about persistence...When a program closes, either in Linux or Windows, the memory is not cleared. It is merely set to FREE space. A clever hacker can do some trick to prevent the memory from being used by the next program. The the bogus MALWARE in memory can do its wicked objectives. How it is done is not the issue. It is done. That is what matters. I do not want to tell you how it is done. Just believe it. With the advent of 64 bit software and hardware, there are now some new ideas about how to protect your PC for malware. Bat that is a new topic. But you can Google it. One thing is the NX bit. Start here: https://en.wikipedia.org/wiki/NX_bit Quote Intel markets the feature as the XD bit, for eXecute Disable. AMD uses the marketing term ENHANCED Virus Protection. The ARM architecture refers to the feature as XN for eXecute Never; it was introduced in ARM v6.[1]So future PCs might have more built-in protection. | |
| 625. | Solve : Tricky Malware?? | 
| Answer» I got a notification from Windows Defender SAYING that it detected malware. Malwarebytes didnt find anything. I ALSO RAN Malwarebytes anti root kit and it found nothing. Any suggestions would be appreciated. Does Defender not GIVE any indication of the specific FILE(s) in question? | |
| 626. | Solve : Anti virus-McAfeeSetup? | 
| Answer» Your COMMENT has been removed. Please do not post MALWARE advice, or post here in the malware forum, UNLESS you NEED help.Superdave. | |
| 627. | Solve : Ransomware... My husband let them in his computer!? | 
| Answer» My husband answered the phone yesterday to a man who said his computer had been hacked. He said he could find the hacker and fix it for him. So he turned on the computer and typed in what the man told him to...then the man took control of the computer saying he was searching for the hacker. When I walked in the room I overheard my husband say I don't have that much money right now...and I ASKED him who he was talking to...I seen the cursor moving around his computer and I told him that's a scam HANG up. But it was too late....now he can not get his computer to come on... Any help would be appreciated The phone number is deleted by allan the people that called.1) I deleted the phone number from your post 2) If your system wasn't backed up you will almost certainly lose all data. You can either PAY the ransom or format and reinstall. You should wait for Super Dave to confirm, but I think you're out of luck The phone number was the ransom people's... not mine He has it backed up...but how do we get the computer to boot up...it won't come on?? Thanks for the fast response Quote from: SheIsMe on November 18, 2015, 11:24:53 AM ...Which backup program did you use? Backup software has some way of rebooting your computer. See the instruction manual. You may need another computer to CREATE the 'boot media' needed to restart your computer.I think I got it...it says it is resetting the computer. Will let you know if it works | |
| 628. | Solve : Suspicious IP's in Wireshark? | 
| Answer» Bought a laptop which had preinstalled malware in it. Wiped it clean and installed Windows 7 from scratch. No signs of malware anymore, but I'm thinking the UEFI might be flashed with malicious software. | |
| 629. | Solve : Which is the best antivirus KasperSky or Norton?? | 
| Answer» Which is the best ANTIVIRUS KasperSky or NORTON?This might help: http://www.tomsguide.com/us/best-antivirus,review-2588.html Quote from: DaveLembke on September 28, 2015, 10:35:39 AM This might help: http://www.tomsguide.com/us/best-antivirus,review-2588.html Not MUCH love for Win Defender!AV reviews vary widely. Here is another review: http://www.techradar.com/us/news/software/applications/best-antivirus-10-programs-on-test-924608 They put Norton down on the list. The top spot is Avira.For what it's worth there are not many viruses around these days. Most of the crap I find on computers zips right on by the AV. The only sure way to stop them is to install a full version of MBAM. Quote from: SuperDave on November 07, 2015, 10:53:38 AM Most of the crap I find on computers zips right on by the AV. I imagine people running an AV that are exposed to viruses that are caught/quarantined/deleted by the AV aren't going to be asking for virus help, THOUGH, so that could just be sample bias. Quote from: BC_Programmer on November 07, 2015, 06:02:34 PM I imagine people running an AV that are exposed to viruses that are caught/quarantined/deleted by the AV aren't going to be asking for virus help, though, so that could just be sample bias.Yes, that could very well be true.BTW, I had MBAM PRO on 4 systems and after an update last month all 4 systems would not boot properly. Eventually I was able to get to the desktop(s) and disable MBAM from loading at boot. After that everything ran normally on all systems. Odd. I no longer run MBAM as a resident app - only use it for on demand scanning. That is strange. Have you talked to MBAM about this problem?No, been too busy. And didn't see any other reports about a bad update - but that's the only think I can point to that the systems had in common | |
| 630. | Solve : Internet activity accessed by flatmates- how?? | 
| Answer» Recently my internet activity has been accessed by a flatmate of mine. Whatever software was used required both my laptop to be on and close proximity to work, as he would enter the room ADJACENT to mine (despite that room not being his) shortly after I entered my own room on several occasions. Therefore my question is what software requires both the target laptop to be on and close proximity? Thank you.? Have you run any virus scans and come up with any troubles ? Do you know of any programs that require proximity? Every program or service that uses bluetooth or wifi has to stay within a proximity/operating range .... that doesnt help MUCH because too many to guess you have installed & list. Have you looked for any programs or services that look questionable. You can run Get-WmiObject -Class Win32_Product | Select-Object -Property Name > C:\Software\PCapps.txt as seen here to gather a list and share it with us to look at: http://www.howtogeek.com/165293/how-to-get-a-list-of-software-installed-on-your-pc-with-a-single-command/ Then attach the txt file for us to look at after running that instruction from command shell. You can also take a screen shot of task manager and sort alphabetically and "show processes from all users" selected so we can look for questionable services. Although the best hackers will hide rogue services under like names of legit services to mask them from easy capture. Your best bet really is to backup your data and wipe it clean back to factory install and start fresh, and keep it secure with password and no physical access by them. A simple thumb drive or disc can bypass computer security with HACKSAW tools that run in Linux that can alter hard drive contents to plant things. When bringing your data back to the computer make sure you have antivirus with realtime protection and latest definitions running and fully scan it before opening any files or running any backed up programs. | |
| 631. | Solve : Quick Question - Data Recovery on infected system? | 
| Answer» Just checking here on this... friend of mine had a severely INFECTED system. I booted off of Linux Mint 15 DVD in Live OS environment which allows me to connect and mount a 32GB USB flash drive and the virus to be inactive. Currently copying over 18GB of data from his USER profile to the 32GB USB STICK. IntroductionThere are also such things made by Avira and others. http://www.avira.com/en/download/product/avira-rescue-system Hope that helps. | |
| 632. | Solve : Can my mouse have a virus? | 
| Answer» http://www.amazon.in/DragonWar-ELE-G7-Bluetrack-Gaming-Function/dp/B00IJ69B0M this is my mouse, i used it for my old computer, and this computer full of virus. And now i use this mouse for my new PC, can my computer be infected from my mouse?No. Really? Oh thx G, im so scared because my last computer have many many dangerous virusIs this for real? The mouse could have a virus. Where has it been? The only solution is to get a virgin mouse. http://security.stackexchange.com/questions/100743/can-my-mouse-have-virus-and-infect-other-machines Quote c't (a German computer Magazin) once discovered mice offered as gifts were reacting to signs on mousepads. These mice then tried to send keyboard strokes to the computer. Of course the article is only in German and you can only read part if itThe ASSERTION has been made that a mouse does not have enough silicon space to hold a virus.But this has not been verified. I have used many mouse in different brand. Pointer could freeze sometime but I haven't encounter it. Not unless I plug usb stick from other computer who had virus.The OP needs to get another mouse and run virus scans. How he got the virus is less important. He needs to get rid of it.No. It is not possible. a virus in mouse Quote from: ZAHID TOG on September 28, 2015, 10:17:17 AM No. It is not possible. a virus in mouseCITATION needed. Three and four years ago the answer was yes. Do you proof that this has somehow changed? Here is a link to a social blog. http://answers.microsoft.com/en-us/windows/forum/windows_vista-update/my-mouse-is-uncontrollable-possible-virus/526fd59c-7a96-4665-8244-0b3fc0451b67?auth=1 The post had many contributors. The general answer was to just get another mouse. | |
| 633. | Solve : windows vista hanging up on boot up. crcdisk.sys? | 
| Answer» Hi guys. | |
| 634. | Solve : Hijack Software and FBI Warning on my iPad.? | 
| Answer» Never had problems with a Apple product with VIRUS or Hijacking. I KNOW a LOT about Windows based product, but not a thing about Apple problems. | |
| 635. | Solve : Can't Install Norton AntiVirus or any AntiVirus Software? | 
| Answer» Same thing happens when I use Chrome.Please go to Kaspersky website and perform an online antivirus SCAN. | |
| 636. | Solve : Cleanup after attempted scam? | 
| Answer» Quote Presumably that is the END of the CLEANUP processUnless you're EXPERIENCING other problems.No – all is well. Again, MANY thanks.You're WELCOME. I will lock this thread. If you need it re-opened, please send me a pm. | |
| 637. | Solve : Malware Removal Logs? | 
| Answer» i looked for the last day and could not find any solutions unfortunately.  so frustrating.  i dowloaded an UPDATED "photo GALLERY" to try and view the photos and still nothing. this new viewer says "photo gallery can't open this photo or video. the file may be unsupported, damaged, or corrupted."  i unchecked boxes that hide files on my computer. i feel like im running out of options, i dont know what to do next with these photos.The fact that I couldn't open the file you sent me SUGGESTS that the file has been altered in some way. One last resort would be to try a System Restore to before this happened.Ok, ya the virus that hit my computer wiped out all my restore points. If you can find a solution to this problem could you post it here?no luck on finding any solution, but hoping you can help me with a couple questions: 1. do you know if after running the cleaners that you told me to run, is my computer now clean of any viruses or malware?Yes, as sure as I can be from this distance. You can run them again and see if anything turns up especially ESET. Quote do you know of any other forums on this website where someone can assist me with the picture issue?You could try posting in the Windows Vista and 7 forum. Someone there might be able to come up with at solution.Should I sent you the logs for that test? Ok will do. Only send the logs if something is found. | |
| 638. | Solve : Windows 10 asks "How do you want to open this file" upon boot? | 
| Answer» The past few days after turning on my computer, I get a message from Windows saying "How do you want to open this file?" even though I have nothing set to start when I turn on the computer besides what Windows 10 includes. It goes away after a few seconds and Norton Says a malicious PROGRAM was blocked. Is this a virus?Download Security Check by screen317 from one of the FOLLOWING links and save it to your desktop. 
 Please download Junkware Removal Tool to your desktop. •Warning! Once the scan is complete JRT will shut down your browser with NO warning. •Shut down your protection software now to avoid potential conflicts. •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator •The tool will open and start scanning your system. •Please be patient as this can take a while to complete depending on your system's specifications. •On completion, a log (JRT.txt) is saved to your desktop and will automatically open. •Copy and Paste the JRT.txt log into your next message.That program worked! No more problems!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. | |
| 639. | Solve : Can a Computer Virus infect the BIOS?? | 
| Answer» I've been learning C++ for the past couple of months and I've learned how to create simple programs that BASICALLY annoy the crap out of people. They're nowhere near ACTUAL viruses due to the fact that all they do is DISCONNECT your mouse and keyboard, display, unpin everything from the task bar, change language settings, make the mouse go crazy etc.. | |
| 640. | Solve : Police-Report virus/ransomware? | 
| Answer» At this point I feel that you should re-install XP but save your important data first then boot with the OS disk in and follow the directions.Thanks for your help. Darn A-holes....why do they do this? No, there's no need to answer that. I wish people like that didn't EXIST. People who make VIRUSES and malware make me sick. Thank you for trying to help me with the computer, but I guess they win this time. Don't FORGET to put a good AV on your computer when you get it repaired. | |
| 641. | Solve : TOTAL BEDLAM? | 
| Answer» I TRIED that, no change. SUGGESTIONS?What happens in SAFE Mode? | |
| 642. | Solve : Need Scan Log Help?!!? | 
| Answer» Quote The one thing I've noticed that has been happening a lot lately is when I OPEN anything up I keep getting a "(not responding)" in the window heading and I have to waitThis has to do with your internet connection. You can check you net speed with this tool. Here's the site to test your ISP speed. Quote also I think the computer may be running a little slow/sluggishIs it slow while on the net or is it just slow all the time? You can run MBAM, ADWCLEANER and JRT again if this is the case.Nice... Thanks for the link, I will check it out. Slow when on the net, it doesn't seem to load webpages in general as fast as it did when I FIRST had the O/S installed? It seems to take longer when loading webpages and when I watch YouTube clips in "full SCREEN" they PLAY "choppy" and it never used to do that?? Do you think any of this could be related to Chrome browser? Also do you suggest me using any particular browser if that be the case? Try IE or FireFox.Will do ,Thank's SuperDave! | |
| 643. | Solve : Hacked contacts. Would really appreciate advice.? | 
| Answer» Hi Guys, | |
| 644. | Solve : Bing came uninvited and refuses to leave?? | 
| Answer» Have a Dell desktop running Vista. Click on tools icon or the cog icon depending on the version of internet explorer you are using. If you cant see the toolbar, press ALT key on your keyboard to reveal the toolbar. Scroll down and locate Bing Bar – SELECT it by clicking and then click the disable button to disable it a shown in the image below.Aug 13, 2014YourTube. Which version of IE? Thanks so much for your response. I am running Explorer 9 , Vista Ultimate. Dell System. I don't know enough to not get into trouble when I try to follow advice and my computer doesn't look like I think it should. So let me be sure I understand your advice. Can I delete the Bing tool bar? There are three Bing SEARCH boxes at the top of my screen now. I see Bing in the internet option box when I click on it. Sometimes a lovely picture titled Bing appears and fills the screen. Nice enough to keep, but I didn't order it. What should I delete first? Mysterious to me. Copas~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows Vista (TM) Ultimate x86 Ran by copas on Sat 07/11/2015 at 15:31:42.28 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{97B5F05A-2A66-4652-B817-90EFF6642AAE} ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted the following from C:\Users\copas\AppData\Roaming\mozilla\firefox\profiles\6f0n8d8v.default-1427546345409\prefs.js user_pref("browser.search.defaultenginename", "Ask Web Search"); user_pref("browser.search.selectedEngine", "Ask Web Search"); user_pref("extensions.mywebsearch.prevKwdEnabled", true); user_pref("extensions.toolbar.mindspark._4jMembers _.BUTTON_STRUCTURE", "[{\"b\":224541925,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224541926,\"c\":\"mindspark.enterse user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.prev ", "Ask Web Search"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.save dPrev", "true"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.tb", "Ask Web Search"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.prev", "Ask Web Search"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.savedPr ev", "true"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.tb", "Ask Web Search"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.homepage.savedPrev", "true"); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA&n=781b892a&p2=^Z user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.page.savedPrev", 1); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.page.tb", 1); user_pref("extensions.toolbar.mindspark._4jMembers _.browser.version.last", "39.0"); user_pref("extensions.toolbar.mindspark._4jMembers _.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"refreshPeriod\":604800000,\"list\":[{\"url\":\"h user_pref("extensions.toolbar.mindspark._4jMembers _.firstKnownVersion", "7.18.7.19764"); user_pref("extensions.toolbar.mindspark._4jMembers _.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA&n=781b892a&p2=^ZX^xdm003^YYA^us&si= user_pref("extensions.toolbar.mindspark._4jMembers _.hp.enabled", true); user_pref("extensions.toolbar.mindspark._4jMembers _.hp.guardType", "HPR"); user_pref("extensions.toolbar.mindspark._4jMembers _.hp.user.defined", false); user_pref("extensions.toolbar.mindspark._4jMembers _.initialized", true); user_pref("extensions.toolbar.mindspark._4jMembers _.installKeysSource", "Cookies"); user_pref("extensions.toolbar.mindspark._4jMembers _.installType", "XPI"); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.contextKey", ""); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.dlpCountryCode", "US"); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.installDate", "2015070506"); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.partnerId", "^ZX^xdm003^YYA^us"); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.partnerSubId", "CJTyh5WFxcYCFQ-IaQodvCkKrA"); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.pixelUrl", "hxxp://download.radiorage.com/install_pixels.jhtml?partner=^ZX^xdm003^YYA^us⊂_id=CJTyh5WFxcYCFQ user_pref("extensions.toolbar.mindspark._4jMembers _.installation.success", true); user_pref("extensions.toolbar.mindspark._4jMembers _.installation.toolbarId", "FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA"); user_pref("extensions.toolbar.mindspark._4jMembers _.isCompliantUninstallImplementation", true); user_pref("extensions.toolbar.mindspark._4jMembers _.lastActivePing", "1436135401746"); user_pref("extensions.toolbar.mindspark._4jMembers _.lastKnownVersion", "7.18.7.19764"); user_pref("extensions.toolbar.mindspark._4jMembers _.options.defaultSearch", true); user_pref("extensions.toolbar.mindspark._4jMembers _.options.homePageEnabled", true); user_pref("extensions.toolbar.mindspark._4jMembers _.options.keywordEnabled", true); user_pref("extensions.toolbar.mindspark._4jMembers _.options.tabEnabled", true); user_pref("extensions.toolbar.mindspark._4jMembers _.partnerPixelFired", true); user_pref("extensions.toolbar.mindspark._4jMembers _.successUrl", "hxxp://download.radiorage.com/installComplete.jhtml"); user_pref("extensions.toolbar.mindspark._4jMembers _.toolbarCollapsed", false); user_pref("extensions.toolbar.mindspark._erMembers _.toolbar.ownSearch", true); user_pref("extensions.toolbar.mindspark._erMembers _.toolbarCollapsed", true); user_pref("extensions.toolbar.mindspark.hp.enabled", true); user_pref("extensions.toolbar.mindspark.hp.enabled .guid", "[email protected]"); user_pref("extensions.toolbar.mindspark.lastInstal led", "[email protected]"); ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Sat 07/11/2015 at 15:35:04.58 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ | |
| 645. | Solve : Problem with "ads by name" in Firefox? | 
| Answer» Hi, | |
| 646. | Solve : ''Help, SuperDave-Genius!''? | 
| Answer» Any improvement in your laptop?yes, less freezing, thanks a lot but I wonder why still when I enter my password during login of my email accounts Rootkit scanning is now incorporated into the Malwarebytes Antimalware, so we don’t need to run the beta toolQuote for your info, this is what MBytes told me :That is good news. I was not aware of the development. Sorry, I can't help much with the email accounts. Click Start> Computer> right click the C Drive and choose Properties> enter Click Disk Cleanup from there. Click OK on the Disk Cleanup Screen. Click Yes on the Confirmation screen. This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive) ******************************************** This step will remove all cleaning TOOLS we USED, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments... This is a very crucial step so make sure you don't skip it. Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles. Double-click Delfix.exe to start the tool. Make sure the following items are checked: 
 Once finished a logfile will be created. You don't have to attach it to your next reply. ******************************************** I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT WARNS you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! | |
| 647. | Solve : Malware error 895-system 32.exe? | 
| Answer» As usual, I'm having problems downloading the program you want me to use. 
 Once finished a logfile will be created. You don't have to attach it to your next reply. ********************************************* I suggest using WOT - Web of TRUST. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! | |
| 648. | Solve : SUPERSpyware hiccup? | 
| Answer» Hi | |
| 649. | Solve : Norton Security download question? | 
| Answer» I ordered, what I thought was a CD, for Norton Security and it turned out to be nothing more than Product Key, good for 5 computers. I only need it for three, however, I am limited to 250MB/day and I have no idea how many MBs this download needs as it is not stated on the box. If I get up at 2:00AM I can download unlimited amounts of MBs until 7:00AM. Does anyone know whether Norton Security could be downloaded to a DVD and then loaded on to my 3 computers. I really don't want to have to get up 3 mornings at 2:00AM to download this program ONTO 3 computers. I'm avoiding calling Norton as they route their calls to India and I know those FOLKS there are very computer savvy, but it doesn't do me any good as I can't understand what they say, so I was hoping someone here had the answer as to whether I can use the product key to download to a DVD. THANK youI did a search and I can't find any Norton Security ISO FILE. | |
| 650. | Solve : Unauthorized Remote Control? | 
| Answer» Dont know if this applies in this area but i dont know where else it would go so sorry if it doesnt fit the category. I think it is odd that nobody thinks to simply pull the network cable when this happens. First thing you should do is check for malware, I think. | |