Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

601.

Solve : "Admin" Account Suddenly Has No Admin Powers?

Answer»

OK, I have a Dell Inspiron 6000 laptop running Windows XP. I have Zonealarm and AVG antivirus - the registered version. But for some reason I still ended up with a virus on my system. I have no idea how it happened, but it coincided with my reinstalling Firefox 2 after Firefox 3 pissed me off by running at a snail's pace.
I still have no idea what the virus was, but my dad and I spent an entire evening trying to figure out. He eventually tracked down a .dll FILE with a gibberish name we couldn't find anywhere on the internet. It was creating bogus files willy-nilly and was somehow protecting itself from being deleted, so we eventually resorted to using a different computer to hack into my harddrive and get rid of the piece of *censored* that way.

Everything went back to normal after that, except I noticed I'd lost some data in the process; Windows updates had disappeared, and at least one of my programs refuses to run anymore.

So I went to reinstall that program, and ran into a brick wall.

While fighting the virus, we'd created a second user account on my computer, given it admin privelages and changed my own account to the limited version. After the fuss was over I got annoyed by having to switch between accounts all the time, so I changed my original account to admin again, and tried to delete the other one.

The computer wouldn't let me, claiming I didn't have "permission". So I changed the other account to limited, and then tried to delete it.

No dice.

Then today, when I tried to uninstall a program while logged into my regular account, Windows suddenly started claiming that I didn't have admin powers. My User Accounts list claims that I do. Everything else says otherwise.

I tried the other account, but, oops, it's now limited and can't do anything. My other (supposed admin account) won't let me change that setting again.

End result: neither of my logins will let me install, uninstall, change account setting or, in fact, use any admin powers whatsoever. I'm LOCKED out of my own frigging computer.


Please for the love of gods, does anyone have a suggestion that isn't "reinstall Windows and lose everything", or "hurl computer out the window"?If you open the Management Console (In the Run dialog box type "mmc" and press enter), and add the Local Users and Groups snap-in (file - add/remove snap in - "Add" button - find "Local Users and Groups" and double click - "Finish" button - "Close" button - "Ok" button), expand the drop down menu in the left hand pane, and select Users.

Now, Double click "ADMINISTRATOR" in the right pane.  That opens the properties box for the built in Admin account.  Clear the "This account is disabled" box, and click "ok".  Now right click on the admin account and set the password to something you'll remember.

Now I'd reboot into Safe Mode (rapidly press f8 as your computer loads, just after the bios hands over the machine to Windows...where the screen goes black) and log in as the Administrator and you should be able to give your account it's privilages back.  It might be worth running another virus check while in safe mode before rebooting and logging back in as your main profile.

Also, you needn't move between a limited account and an admin account to do stuff as an admin, you can "Run as Admin".  Normally, if you hold shift and right click something the option becomes avail.  Just pop in the Admin credentials and you're away.  Probably a good idea to adopt this approach instead of constantly running around as an admin for the 10mins when you need to install/config something.  Might prevent future problems with viruses.

Let us know how you get on.

SidDear gods that is like the fastest reply EVER.
Dude, you're the man. I don't care if this works or not; you're still the man.

I'll give it a shot! Thanks a heap!   OK, I've tried the first part of what you suggested but the thing told me something like "this snapin cannot be used with Windows Home Edition please use the User Accounts menu in the Control Panel".

Should I go on and try the second part anyway? Quote from: Beak_Hookage on July 16, 2008, 07:35:50 AM

OK, I've tried the first part of what you suggested but the thing told me something like "this snapin cannot be used with Windows Home Edition please use the User Accounts menu in the Control Panel".

Should I go on and try the second part anyway?

It might be worth seeing if you can get into the built in admin account in safe mode.

It certainly won't hurt.

*censored* windows "home"...

I only replied so quickly cus I was online.  But thanks for the props! 

I'll have a play with my XP Home install later on tonight and see what can be done....Well that's odd; all of my admin powers suddenly CAME back after I did a reboot and pressed ctrl-alt-del at the welcome screen. Someone else suggested that I might still have malware on my system, though, so I'm going to take some steps to get rid of it.

Thanks a billion for your help!Your computer may be still infected...

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT  FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in NOTEPAD.
    * Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.


DO NOT make any other changes to your computer (like installing programs, using another cleaning tools, etc.), until it's officially declared clean!!!
602.

Solve : rootkit reaverler?

Answer»

here are my results il just wondering if i should DELETE any of these some seem important
Rootkits can be tough to find, even with rootkit revealer. Everything looks OK.

Do you know what this is?

8-6_xp32_dd_64873.exe

Do you think you have a rootkit?i dont think i do just making shure you can never be to careful that file was the newest version of ati catalysist control Run the F-Secure Online SCANNER for Viruses, Spyware and RootKits.

Note: This Scanner is for Internet Explorer Only!

  • Click on Online Services and then Online Scanner
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to FINISH,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the SHOW Report button and Copy&Paste the entire report in your next reply.
ok ill get back to you on the resultsok that found the one thing and it seems to say it got rid of iti think i will try that too!
  It's good to run an online scan now and then. (once a month or so)
603.

Solve : Avast Resident Scanner Not Working??

Answer»

I previously downloaded Avast Free Home Anti Virus software, and received about 5months of good use and no problems. But not to long ago when I booted the avast virus scanner, it wouldn't load and keep'd telling me that there was a problem with the skins or something.

After I keep getting that problem I un-installed the program and rein-stalled it again. Hoping to get the virus scanner to work again. I did get the scanner to work, but another problem has arised. One of the most important services avast offers, which is real time virus protection (resident scanner) does not appear in the ICON tray. 

Therefore does not work for some reason? I'm not sure why       
? Can you HELP me out, it seems that the program installed correctly etc, its just that the resident scanner doesn't work?

System Specs, 
Op: Vista Home
Ram:3G
Intel MotherBoard and Components

Regards Kieran
Resident scanner is the most important part of antivirus program. It gives you real-time protection.

Download HijackThis:
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
Click on Download HijackThis Installer
Post HijackTHis log.Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:57:21 PM, on 7/14/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Norman\Npm\Bin\eLogsvc.exe
C:\Program Files\Norman\Npm\Bin\Zanda.exe
C:\Windows\system32\svchost.exe
C:\Program Files\avast1thegood\aswUpdSv.exe
C:\Program Files\avast1thegood\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Norman\Npm\Bin\Zlh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Norman\Nvc\BIN\NIP.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\Norman\Nvc\bin\nvcoas.exe
C:\Program Files\avast1thegood\ashMaiSv.exe
C:\Program Files\avast1thegood\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Norman\Nvc\bin\cclaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper CLASS - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Program Files\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-au.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\avast1thegood\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\avast1thegood\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\avast1thegood\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\avast1thegood\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\Bin\eLogsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 8573 bytes
The log is clean, BUT you have TWO antivirus programs running: Norman Virus, and Avast.
Big No, NO. One of them has to go.But the problem is, resident scanner isn't working. Its not appearing in the icon tray. And i cant access its interface?You HAVE TO uninstall one of antiviruses, and then we'll see.I will try that, but let me just say, i have bee running Avast and Norman perfectly fine before. The problem has only risen recently. But ill do wat ever you think is good.Running two antivirus programs is nothing more, then ASKING for problems, and I'm saying this for the very last time.I'm not saying this to be rude or a smart alec, but im accually not running two. I'm only running one, thats the problem. Avast isn't running, only norman is? so if i stop norman then i have no anti virus running?I'd download fresh copy of Avast, or Avira, disconnect from the Internet, uninstall BOTH, Avira, and Norman, then install one AV.I'll see how it goesSee'ya tomorrow...Excellent, works now. Must have just been a faulty copy or what not. Well thats great. thanksI told you so.
You're not off the hook, yet.
I'd like to see fresh HJT log.By the way im not running Norman, i uninstaled it. But it still comes up in the log.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:57:21 PM, on 7/14/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Norman\Npm\Bin\eLogsvc.exe
C:\Program Files\Norman\Npm\Bin\Zanda.exe
C:\Windows\system32\svchost.exe
C:\Program Files\avast1thegood\aswUpdSv.exe
C:\Program Files\avast1thegood\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Norman\Npm\Bin\Zlh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Norman\Nvc\BIN\NIP.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
C:\Program Files\Norman\Nvc\bin\nvcoas.exe
C:\Program Files\avast1thegood\ashMaiSv.exe
C:\Program Files\avast1thegood\ashWebSv.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Norman\Nvc\bin\cclaw.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Norman ZANDA] C:\Program Files\Norman\Npm\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-au.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\avast1thegood\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\avast1thegood\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\avast1thegood\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\avast1thegood\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\Norman\Npm\Bin\eLogsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Program Files\Norman\Npm\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\Norman\Npm\Bin\Zanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\Norman\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\Norman\Nvc\BIN\NVCSCHED.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe

--
End of file - 8573 bytes

604.

Solve : Trojan Need Some Help!?

Answer»

I have a laptop that has some trojans on it. I was wondering if there was a fix so I don't have to do a reapair install? I will LATER run Combofix and send you guys the log after the antivirus programs run.

Zone Alarm Anti Virus caught these:


not-a-virus:AdWare.Win32.Agent.aeh
Trojan-Downloader.Win32.Zlob.ods
Trojan.Win32.Buzus.hpp

....................................... ........... ...............


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:03 PM, on 7/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet EXPLORER v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF READER Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\s wg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - S-1-5-18 Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q306&bd=pavili on&pf=laptop
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/...ws-i586-jc.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: APITRAP.DLL,avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 9648 bytesWe don't need a combofix log at this point. What we do need are the logs from hereI'm already ahead of you. I'm running those scans right now.

Zone Alarm has them quarantined.The HJT log looks fine by the way besides needing to update Java.

If ZA quarantined the files then you are probably OK. It never hurts to run SAS and MBAM just to be sure though.I keep getting these errors that say do you want to send this report to Microsoft. It won't let me install programs like windows media player. closes with an error do you want to send this report to Microsoft. Also Doctor Watson had a error and wanted it to be sent to Microsoft.Sounds like you may have something going on that HJT cant see. Best to see what the other scans find and then we will do some more if needed.Is there a program or patch for those Trojans?ZA caught them so you already have one...Maybe... But aparently it has caused damage to the data.I'm thinking rootkit maybe. Quote from: evilfantasy on July 14, 2008, 03:05:12 PM

I'm thinking rootkit maybe.

What do you suggest then?



ComboFix 08-07-14.2 - David 2008-07-14 14:01:45.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.475 [GMT -7:00]
Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe
 * Created a new restore point
 * Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
(((((((((((((((((((((((((   Files Created from 2008-06-14 to 2008-07-14  )))))))))))))))))))))))))))))))
.

2008-07-14 13:02 . 2008-07-14 13:02      d--------   C:\Program Files\Trend Micro
2008-07-14 08:27 . 2008-07-14 08:27   1,374   --a------   C:\WINDOWS\imsins.BAK
2008-07-14 06:47 . 2008-07-14 06:47      d--------   C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-14 06:46 . 2008-07-14 06:46      d--------   C:\Program Files\SUPERAntiSpyware
2008-07-14 06:46 . 2008-07-14 06:46      d--------   C:\Documents and Settings\David\Application Data\SUPERAntiSpyware.com
2008-07-14 06:44 . 2008-07-14 06:44      d--------   C:\Documents and Settings\David\Application Data\Malwarebytes
2008-07-14 06:43 . 2008-07-14 12:41      d--------   C:\Program Files\Malwarebytes' Anti-Malware
2008-07-14 06:43 . 2008-07-14 06:43      d--------   C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-14 06:43 . 2008-07-07 17:35   34,296   --a------   C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-14 06:43 . 2008-07-07 17:35   17,144   --a------   C:\WINDOWS\system32\drivers\mbam.sys
2008-07-14 06:41 . 2008-07-14 12:40   96,520   --a------   C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-14 06:41 . 2008-07-14 06:41   10,520   --a------   C:\WINDOWS\system32\avgrsstx.dll.old
2008-07-14 06:41 . 2008-07-14 12:40   10,520   --a------   C:\WINDOWS\system32\avgrsstx.dll
2008-07-14 06:40 . 2008-07-14 12:41      d--------   C:\WINDOWS\system32\drivers\Avg
2008-07-14 06:40 . 2008-07-14 06:40      d--------   C:\Program Files\AVG
2008-07-14 06:40 . 2008-07-14 06:40      d--------   C:\Documents and Settings\All Users\Application Data\avg8
2008-07-14 06:36 . 2008-07-14 06:36      d--------   C:\Program Files\CCleaner
2008-07-13 20:55 . 2008-07-14 08:29   23,392   --a------   C:\WINDOWS\system32\nscompat.tlb
2008-07-13 20:55 . 2008-07-14 08:29   16,832   --a------   C:\WINDOWS\system32\amcompat.tlb
2008-07-13 10:11 . 2008-07-13 10:11      d--------   C:\WINDOWS\Logs
2008-07-13 09:54 . 2008-07-13 09:54      d--------   C:\Program Files\Netflix
2008-06-20 10:46 . 2008-06-20 10:46   245,248   ---------   C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 10:46 . 2008-06-20 10:46   147,968   ---------   C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 04:51 . 2008-06-20 04:51   361,600   ---------   C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 04:40 . 2008-06-20 04:40   138,496   ---------   C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 04:08 . 2008-06-20 04:08   225,856   ---------   C:\WINDOWS\system32\dllcache\tcpip6.sys

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-14 21:05   8,612,384   --sha-w   C:\WINDOWS\system32\drivers\fidbox.dat
2008-07-14 19:43   106,892   --sha-w   C:\WINDOWS\system32\drivers\fidbox.idx
2008-07-14 13:41   ---------   d-----w   C:\Documents and Settings\David\Application Data\MSN6
2008-07-14 13:38   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-14 13:27   ---------   d-----w   C:\Program Files\Common Files\Wise Installation Wizard
2008-07-14 01:18   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-07-14 01:15   ---------   d-----w   C:\Program Files\Vstep
2008-07-13 23:33   43,520   ----a-w   C:\WINDOWS\system32\CmdLineExt03.dll
2008-07-10 02:06   ---------   d-----w   C:\Documents and Settings\David\Application Data\Apple Computer
2008-07-09 16:05   75,248   ----a-w   C:\WINDOWS\zllsputility.exe
2008-07-09 16:05   1,086,952   ----a-w   C:\WINDOWS\system32\zpeng24.dll
2008-07-08 21:03   2,228,736   ----a-w   C:\WINDOWS\Internet Logs\xDBF.tmp
2008-07-06 00:55   ---------   d-----w   C:\Program Files\Microsoft Works
2008-07-06 00:55   ---------   d-----w   C:\Program Files\Common Files\SureThing Shared
2008-07-06 00:55   ---------   d-----w   C:\Program Files\Common Files\Sonic Shared
2008-07-02 18:55   ---------   d-----w   C:\Program Files\Java
2008-07-01 01:17   ---------   d-----w   C:\Program Files\Common Files\Adobe
2008-06-20 17:46   245,248   ----a-w   C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51   361,600   ----a-w   C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40   138,496   ----a-w   C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08   225,856   ----a-w   C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 05:27   1,658,880   ----a-w   C:\WINDOWS\Internet Logs\xDBE.tmp
2008-06-13 11:05   272,128   ----a-w   C:\WINDOWS\system32\drivers\bthport.sys
2008-06-13 11:05   272,128   ------w   C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 13:39   11,218,798   ----a-w   C:\WINDOWS\Internet Logs\tvDebug.zip
2008-06-07 21:05   ---------   d-----w   C:\Documents and Settings\David\Application Data\Intuit
2008-06-07 21:04   ---------   d-----w   C:\Program Files\Quicken
2008-06-07 18:34   ---------   d-----w   C:\Program Files\StompSoft
2008-06-06 20:36   ---------   d-----w   C:\Program Files\TomTom HOME 2
2008-06-06 20:18   ---------   d-----w   C:\Documents and Settings\David\Application Data\TomTom
2008-05-31 17:23   ---------   d-----w   C:\Program Files\Lavasoft
2008-05-31 17:23   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-30 21:19   507,400   ----a-w   C:\WINDOWS\system32\XAudio2_1.dll
2008-05-30 21:18   238,088   ----a-w   C:\WINDOWS\system32\xactengine3_1.dll
2008-05-30 21:17   65,032   ----a-w   C:\WINDOWS\system32\XAPOFX1_0.dll
2008-05-30 21:17   25,608   ----a-w   C:\WINDOWS\system32\X3DAudio1_4.dll
2008-05-30 21:11   467,984   ----a-w   C:\WINDOWS\system32\d3dx10_38.dll
2008-05-30 21:11   3,850,760   ----a-w   C:\WINDOWS\system32\D3DX9_38.dll
2008-05-30 21:11   1,491,992   ----a-w   C:\WINDOWS\system32\D3DCompiler_38.dll
2008-05-27 03:37   ---------   d-----w   C:\Documents and Settings\David\Application Data\HP
2008-05-27 03:37   ---------   d-----w   C:\Documents and Settings\David\Application Data\CyberLink
2008-05-25 22:24   ---------   d-----w   C:\Documents and Settings\David\Application Data\AdobeUM
2008-05-25 21:49   ---------   d-----w   C:\Program Files\WinDirStat
2008-05-25 20:49   ---------   d-----w   C:\Documents and Settings\David\Application Data\Corel
2008-05-25 20:37   ---------   d-----w   C:\Program Files\Microsoft ActiveSync
2008-05-25 20:29   ---------   d-----w   C:\Program Files\Google
2008-05-25 20:28   ---------   d-----w   C:\Program Files\Norton CleanSweep
2008-05-25 20:27   ---------   d-----w   C:\Program Files\Symantec
2008-05-25 20:27   ---------   d-----w   C:\Program Files\Common Files\Symantec Shared
2008-05-25 20:27   ---------   d-----w   C:\Documents and Settings\David\Application Data\Symantec
2008-05-25 20:15   ---------   d-----w   C:\Documents and Settings\David\Application Data\Leadertech
2008-05-25 20:03   ---------   d-----w   C:\Program Files\Microsoft Streets & Trips
2008-05-25 19:00   ---------   d-----w   C:\Documents and Settings\David\Application Data\MSNInstaller
2008-05-25 18:46   ---------   d-----w   C:\Program Files\Microsoft Office Outlook Connector
2008-05-25 16:32   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Symantec
2008-05-25 15:59   ---------   d-----w   C:\Program Files\Hp
2008-05-25 15:53   ---------   d-----w   C:\Documents and Settings\David\Application Data\Talkback
2008-05-25 15:48   1,743   --sha-r   C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP Pavilion dv8000 (EX177AV)_YN_0Pavi_QCND62600G3_E413900001_46_I30 A6_SHP_V56.37_BF.13_T060510_WXH2_L409_M 1023_J80_7Intel_8T2400_91.83_#080525_N80861092_(EX177AV)_XMOBILE_CN10_Z_2F.13_G10DE0398.MRK
2008-05-25 15:12   ---------   d-----w   C:\Program Files\Quickensetup
2008-05-25 15:10   ---------   d-----w   C:\Program Files\NetWaiting
2008-05-25 15:10   ---------   d-----w   C:\Program Files\Netscape
2008-05-25 15:10   ---------   d-----w   C:\Program Files\music_now
2008-05-25 15:10   ---------   d-----w   C:\Program Files\MSN Encarta Plus
2008-05-25 15:09   ---------   d-----w   C:\Program Files\Microsoft Office Trial Wizard
2008-05-25 15:08   ---------   d-----w   C:\Program Files\Microsoft Money 2006
2008-05-25 15:05   ---------   d-----w   C:\Program Files\CONEXANT
2008-05-25 15:05   ---------   d-----w   C:\Program Files\Common Files\Palo Alto Software
2008-05-25 15:05   ---------   d-----w   C:\Program Files\Common Files\muvee Technologies
2008-05-25 15:04   ---------   d-----w   C:\Program Files\Common Files\LightScribe
2008-05-25 15:00   ---------   d-----w   C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-05-25 15:00   ---------   d-----w   C:\Documents and Settings\All Users\Application Data\Sonic
2008-05-25 01:40   ---------   d-----w   C:\Documents and Settings\David Buchanan\Application Data\MSN6
2008-05-20 17:17   ---------   d-----w   C:\Program Files\Adobe Media Player
2008-05-19 19:48   ---------   d-----w   C:\Documents and Settings\David Buchanan\Application Data\AdobeUM
2008-05-16 18:58   12,632   ----a-w   C:\WINDOWS\system32\lsdelete.exe
2008-05-16 18:25   15,616   -c--a-w   C:\Documents and Settings\David Buchanan\Application Data\wklnhst.dat
2008-05-15 21:50   2,661,376   ----a-w   C:\WINDOWS\Internet Logs\xDBD.tmp
2008-05-09 10:53   90,112   ----a-w   C:\WINDOWS\system32\wshext.dll
2008-05-09 10:53   90,112   ------w   C:\WINDOWS\system32\dllcache\wshext.dll
2008-05-09 10:53   512,000   ------w   C:\WINDOWS\system32\dllcache\jscript.dll
2008-05-09 10:53   430,080   ----a-w   C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:53   430,080   ------w   C:\WINDOWS\system32\dllcache\vbscript.dll
2008-05-09 10:53   180,224   ----a-w   C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:53   180,224   ------w   C:\WINDOWS\system32\dllcache\scrobj.dll
2008-05-09 10:53   172,032   ----a-w   C:\WINDOWS\system32\scrrun.dll
2008-05-09 10:53   172,032   ------w   C:\WINDOWS\system32\dllcache\scrrun.dll
2008-05-08 14:02   203,136   ------w   C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-08 11:24   155,648   ----a-w   C:\WINDOWS\system32\wscript.exe
2008-05-08 11:24   155,648   ------w   C:\WINDOWS\system32\dllcache\wscript.exe
2008-05-07 09:07   135,168   ----a-w   C:\WINDOWS\system32\cscript.exe
2008-05-07 09:07   135,168   ------w   C:\WINDOWS\system32\dllcache\cscript.exe
2008-05-07 05:12   1,288,192   ----a-w   C:\WINDOWS\system32\quartz.dll
2008-05-07 05:12   1,288,192   ------w   C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-24 05:16   3,591,680   ------w   C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:40   625,664   ------w   C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39   70,656   ------w   C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:39   13,824   ------w   C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07   161,792   ------w   C:\WINDOWS\system32\dllcache\ieakui.dll
2008-04-17 17:26   2,208,768   ----a-w   C:\WINDOWS\Internet Logs\xDBC.tmp
2008-04-14 13:39   2,193,920   ----a-w   C:\WINDOWS\Internet Logs\xDBB.tmp
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-24 16:41 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 01:42 202088]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-14 19:49 454656]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-15 11:26 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-15 11:26 86016]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 22:46 761948]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 21:54 102400]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 16:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 16:30 81920]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-02-22 08:03 40960]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 10:23 1187840]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 09:05 919016]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-14 12:41 1232152]
"nwiz"="nwiz.exe" [2006-04-15 11:26 1519616 C:\WINDOWS\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 04:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]

C:\Documents and Settings\David Buchanan\Start Menu\Programs\Startup\
Salem Public Library Tray App.lnk - C:\Program Files\PermissionTV\bin\dmtray.exe [2008-02-29 19:35:06 57344]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe [2005-09-24 10:39:30 73728]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APITRAP.DLL,avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-14 12:40]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-14 12:41]

*Newly Created Service* - CATCHME
.
Contents of the 'SCHEDULED Tasks' folder
"2008-07-14 19:47:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-07-12 20:13:56 C:\WINDOWS\Tasks\Registry Repair.job"
- C:\Program Files\StompSoft\RegistryRepair4\Registry Repair.exe
"2008-07-12 20:13:56 C:\WINDOWS\Tasks\Registry Repair4.job"
- C:\Program Files\StompSoft\RegistryRepair4\Registry Repair.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 14:04:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden AUTOSTART entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??? ?[email protected]? ?U???([email protected]?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\explorer.exe
-> ?:\WINDOWS\system32\PSAPI.DLL
-> ?:\WINDOWS\System32\msvcp60.dll
.
Completion time: 2008-07-14 14:05:47
ComboFix-quarantined-files.txt  2008-07-14 21:05:42

Pre-Run: 40,360,603,648 bytes free
Post-Run: 40,365,944,832 bytes free

229   --- E O F ---   2008-07-13 16:26:24
Run the F-Secure Online Scanner for Viruses, Spyware and RootKits:

This scanner works with Internet Explorer only

  • Click on Online Services and then Online Scanner
  • Accept the License Agreement.
  • Once the ActiveX installs,Click Full System Scan
  • Once the download completes,the scan will begin automatically.
  • The scan will take some time to finish,so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and Copy&Paste the entire report in your next reply.
I was guessing that some of the system files are corrupted?From the combofix log. This is very suspicious to be in that location in the log.

Quote
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 14:04:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?Huh?? [email protected][email protected]? Huh?U?Huh??([email protected][email protected]

scanning hidden files ...

scan completed successfully
hidden files: 0
Quote from: evilfantasy on July 14, 2008, 03:39:49 PM
From the combofix log. This is very suspicious to be in that location in the log.

Quote
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-14 14:04:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?Huh?? [email protected][email protected]? Huh?U?Huh??([email protected][email protected]

scanning hidden files ...

scan completed successfully
hidden files: 0



I thought so too. What should I do about that?
605.

Solve : Windows Script error message?

Answer»

I am a self taught computer user and only know enough to get by...for some reason my AVG virus protector disappeared so I downloaded it again.  Since then every time I turn on my computer I get the error MESSAGE

'Can not find Script file "c:\windows\Systems32\KillVBS.vbs"'  I haven't a clue what that means and I do not know how to get rid of this message.

Thanks for your help...I have another question related to my digital camera I will post as well...thanks!Your computer is infected...

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT  FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are CHECKED (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * BACK on the main screen, under "Scan for Harmful Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the CURRENT dated log and PRESS View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log.


DO NOT make any other changes to your computer (like installing programs, using another cleaning tools, etc.), until it's officially declared clean!!!

606.

Solve : i have computer problems?

Answer»

I have a compaq presario 6000, it runs off of windows XP. Yesterday I installed windows service pack3. I have no idea who used this computer after that but i turned it on today and it went through disk check and then when it was finished I booted it up and it came up with the icons and stuff but also it came up with the c-setup black box and then it closed by itself. Im really concerned so I ran hijack this and malwarebytes. I also ran super anti spyware but it didnt give me a log. So here is the log for hijack this.

[recovering disk space -- attachment deleted by admin]Post Malwarebytes log, please.
HJT log has to be from after running Malwarebytes.okay here is the malwarebytes log and the new hijack this log

[recovering disk space -- attachment deleted by admin]I see only very minor issues...

*** You need to update Java:
http://java.sun.com/javase/downloads/index.jsp
Java Runtime Environment (JRE) 6 Update 7
Uninstall all previous versions of Java through Add\Remove.

*** Go Start>Control Panel>Add\Remove, and uninstall:
- AskSBar

*** Download, and run  CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in CASE that you need the CTFMON sometime in the future there is also an option to restore the original one.
Note:The CTFMON.EXE is among other THINGS responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark NEXT to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

- R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
- O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
- O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
- O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
- *O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
- *O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
- O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
- *O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
- *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- *O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- *O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

4. Click on Fix checked button.

5. Restart computer in Safe Mode (keep tapping F8 KEY, when your computer starts, until menu appears)

6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to Show hidden files, and folders.

7. Delete following files/folders (if present):

- AskSBar folder from C:\Program Files
- ALCXMNTR.EXE file from C:\Windows
 
8. Restart in Normal Mode.

9. Post new HijackThis log.

607.

Solve : Virus alert in time bar?

Answer»

Dear kind sirs

I downloaded a virus I tried every thing from Norton AVG and one care but I still had the Virus alert next to my time in the bottom right of the computer.  In addition I could not open the programs in the windows file nor FIND the icons that display my C and D drives.  I have completed the initial scans as explained in the "Read this before requesting malware removal help" and EVERYTHING seems to be normal now.  Please could you go through my logs to see if any more help is required thankyou.  PS Im not very computer savy so I will need a lot of explaining when it comes to remedies thanks.

[recovering disk space -- attachment deleted by admin]*** Download, and run  CTFMON-Remover: http://www.gerhard-schlager.at/en/projects/ctfmonremover/
The CTFMON-Remover helps you removing the annoying CTFMON.EXE from your Windows operating system. The program is easy to use and displays whether the CTFMON.EXE is installed and running or not. If it was found then you can remove it within seconds. Just in case that you need the CTFMON sometime in the future there is also an option to restore the original one.
Note:The CTFMON.EXE is among other things responsible for changing the language schema of your keyboard (e.g. for switching between the German and English keyboard layout). So in case you are using this feature you shouldn't remove or disable the CTFMON.EXE!

*** Download, and run QuickTime Killer: http://www.softpedia.com/get/System/Launchers-Shutdown-Tools/QuickTime-Killer.shtml
QuickTime Killer will remove QuickTime from start up and kill any running QuickTime processes. This application runs silently at start up and closes itself as soon as it takes care of QuickTime

*** Did you install Win-Spy?

1. Print this post out, since you won't have an access to it, at some point.

2. Close all windows, except for HijackThis.

3. Put a checkmark next to the following HijackThis entries (some entries will be checkmarked to disable unnecessary startups; in those cases [marked with *], no actual program will be removed):

- O2 - BHO: (no name) - {3BA3028F-FD37-46BF-AD27-733734684F06} - (no file)
- O2 - BHO: (no name) - {51664F3E-54BC-4EF7-ADF9-98F6FDDBCE70} - (no file)
- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
- O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file)
- O3 - Toolbar: (no name) - {80123684-A222-4009-8220-A867294D6DE8} - (no file)
- *O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
- *O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
- *O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
- *O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
- *O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
- *O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
- *O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- *O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
- *O4 - HKCU\..\Run: [SUPERANTISPYWARE] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
- O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present (to be fixed if not done intentionally)
- *O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
- O20 - Winlogon Notify: awtqnkhe - awtqnkhe.dll (file missing)

4. Click on Fix checked button.

5. Restart computer.

6. Post new HijackThis log.here is my new hijack this log (i did as you requested)


[recovering disk space -- attachment deleted by admin]Your computer is clean

1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. Get "Slim" version.
Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html.
Run CCleaner.

2. Turn off System Restore:

- Windows XP:
   1. Click Start.
   2. Right-click the My Computer icon, and then click Properties.
   3. Click the System Restore tab.
   4. Check "Turn off System Restore".
   5. Click Apply.   
   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
   7. Click OK.
- Windows Vista:
   1. Click Start.
   2. Right-click the Computer icon, and then click Properties.
   3. Click on System Protection under the Tasks column on the left side
   4. Click on Continue on the "User Account Control" window that pops up
   5. Under the System Protection tab, find Available Disks
   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
   8. Click OK

3. Restart computer.

4. Turn System Restore on.

5. Download, and install McAfee SiteAdvisor: http://www.siteadvisor.com/download/ff.html. It'll warn you (in most cases) about dangerous web sites.

6. (optional) Download, and install free version of ThreatFire: http://www.threatfire.com/. It'll give you an extra protection against malwares. It won't interfere with your antivirus program

7. Read "So how did I get infected in the first place?": http://www.castlecops.com/postlite7736-.html

8. Let me know, how your computer is doing.

Thanks alot for your time and effort your a star. 
Just one last question I paid for Norton 2 months ago how come this didnt pick up the viruses?
1. There is no PERFECT antivirus program.
2. Norton is pretty lame antivirus application.hi guys... have the same problem virus alert in taskbar, can't see c drive in my computer, can't open task manager and various thigs in my tart menu are no longer available... have ran hijack this and checked the boxes you instrutced roughbernie and after fixing them everything is still on the computer.... any idea's??

thanksungerey
You need to start your own topic.

608.

Solve : I cannot get my hidden folder?

Answer»

Hi ,

I have made a folder hidden as it contains porn and stuff ,

now i try to make it unhidden from the folder options but it doesnt show up

and after i change the folder options and click apply ... i open the properties again and i find that no chane has occured

so what could be the problem ?Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?



Quote from: Dias de verano on July 14, 2008, 08:45:03 AM

Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?





you are so rude .... you dont deserve to be a member of this forumOpen My computer and than click tools....folder options. LOOK for the tab called View and than click show hidden files and folders.

You should be able to see the folder now.

Quote from: superdupermido on July 14, 2008, 08:30:45 AM
i change the folder options and click apply ... i open the properties again and i find that no chane has occured

so what could be the problem ?
what changes have u made in folder options ??
and whose properties  r  u talking about

Quote from: Spoiler on July 14, 2008, 09:15:07 AM
Open My computer and than click tools....folder options. Look for the tab called View and than click show hidden files and folders.

You should be able to see the folder now.



i have done this and the folder doesnt show up

and when i open the folder options again > view tab .... the (do not show hidden files and folders ) box is ticked Quote from: superdupermido on July 14, 2008, 08:50:18 AM
Quote from: Dias de verano on July 14, 2008, 08:45:03 AM
Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?





you are so rude .... you dont deserve to be a member of this forum

That's me told 

Anyway, not being able to view hidden files and folders is one symptom of a malware infection. You should take the appropriate action - virus check, spyware check, etc.
superdupermido

Print these instructions out.

1. Download SUPERAntiSpyware Free for Home Users:
http://www.superantispyware.com/

    * Double-click SUPERAntiSpyware.exe and use the default settings for installation.
    * An icon will be created on your desktop. Double-click that icon to launch the program.
    * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.)
    * Close SUPERAntiSpyware.

PHYSICALLY DISCONNECT  FROM THE INTERNET

Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen

    * Open SUPERAntiSpyware.
    * Under "Configuration and Preferences", click the Preferences button.
    * Click the Scanning Control tab.
    * Under Scanner Options make sure the following are checked (leave all others unchecked):
          o Close browsers before scanning.
          o Scan for tracking cookies.
          o Terminate memory threats before quarantining.
    * Click the "Close" button to leave the control center screen.
    * Back on the main screen, under "Scan for HARMFUL Software" click Scan your computer.
    * On the left, make sure you check C:\Fixed Drive.
    * On the right, under "Complete Scan", choose Perform Complete Scan.
    * Click "Next" to start the scan. Please be patient while it scans your computer.
    * After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
    * Make sure everything has a checkmark next to it and click "Next".
    * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
    * If asked if you want to reboot, click "Yes".
    * To retrieve the removal information after reboot, launch SUPERAntispyware again.
          o Click Preferences, then click the Statistics/Logs tab.
          o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
          o If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
          o Please copy and paste the Scan Log results in your next reply.
    * Click Close to exit the program.
Post SUPERAntiSpyware log.

RECONNECT TO THE INTERNET

RESTART COMPUTER!

2. Download Malwarebytes' Anti-Malware: http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the LATEST version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When COMPLETED, a log will open in Notepad.
    * Post the log back here.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

RESTART COMPUTER!

3. Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
Post HijackThis log. Quote
Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?
This was totally uncalled for, and rude indeed. Quote from: Broni on July 15, 2008, 12:37:43 AM
Quote
Viewing the porn has made you go blind, and you cannot see that the folder is unhidden?
This was totally uncalled for, and rude indeed.

Well, I didn't see why we had to hear about his porn collection: he could have just said he couldn't unhide a previously hidden folder, so I commented on that.Ehhh....whatever. Quote
Umm actually you couldn't be anymore wrong. The only reason he can't see his folder is because the viewing options arn't in place? You shouldn't just go and say he might have some sort of virus. Quite and unnesseary comment?

He wrote,

Quote
now i try to make it unhidden from the folder options but it doesnt show up

and after i change the folder options and click apply ...

So I think you are the person who is wrong.
Don't click on Pink Floyd's scam link. Don't follow his pretend "advice", which is just an EXCUSE to spread his scam message.
Pink Floyd's post deleted.

Your signature is spam Pink Floyd!. Quote from: superdupermido on July 14, 2008, 08:30:45 AM
Hi ,

I have made a folder hidden as it contains porn and stuff ,

now i try to make it unhidden from the folder options but it doesnt show up

and after i change the folder options and click apply ... i open the properties again and i find that no chane has occured

so what could be the problem ?
well dude I had the same problem (I couldn't see my hidden file when I active in folder option it return to "Do not show hidden file" automaticly) so by Regedit you should do like this: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL

Correct the value CheckedValue in the right window to 1.
that should solve your problem........
enjoy watching porn
609.

Solve : I have a question concerning ShowDeskFix?

Answer»

Just a question, I'm studying about fighting malware right now, I love to look around for frsh HJT log to PRACTICE by myself. And today i come across these entries
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')

And I wonder what is ShowDeskFix? As I try to GOOGLE around and check in many forums. and all I can find is, some experts adviced the user to have HJT fix it, and some forums just ignore it. But no information about it what so ever??? I check them with hijackthis and here is the result;

O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE') Unknown application.

O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE') Unknown application.

O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM') Unknown application.

O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user') Nasty (2.99 / 5.00)


Still, confuse, what is it? And should it be fixed by HJT or should it be left alone?I can't find any source of that entry, either, but since this command silently (/s) unregisters (/u) vital Windows dll (shell32.dll), I'd definitely consider it as nasty.Tough call without seeing some other virus scans. I like Bronis DIAGNOSIS. Looks bad. I did find this though.

Could it be some rouge desktop hijacker?

Quote

To restore the show desktop icon:

    run:
    regsvr32 /s /n /i:U shell32

http://www.msfn.org/board/lofiversion/index.php/t91884.html Quote
To restore the show desktop icon:

    run:
    regsvr32 /s /n /i:U shell32
INTERESTING...
Since that command is set to run every time, computer starts, it may actually keep restoring desktop icons to some "bad" state, preferred by some malware
...but, as you said:
Quote
Tough call without seeing some other virus scans.
Thank you for your answer. I just google ShowDeskFix, and come up with many problem helper forum that include this entry in HJT. As it original, I seem to forget which and where I saw it first   
But what if I will not look at the word "[ShowDeskFix]" but look at command line "RunOnce" instead, will it mean that it is safe to have HJT fix it? Sorry for asking too many questions?  I SEE you asked at BC also. Maybe they can shed some light on it.

Until then. Understanding and Interpreting HijackThisI think, it's perfectly fine to fix it through HJT.
Remember, HJT always creates backup, but I don't think, it'll be necessary to use it in this case.
I'm pretty sure, I recall these entries in someone else HJT log, and deleting them caused no harm.
610.

Solve : I need help with NIS?

Answer»

A new threat to protect against. But every time I click "protect me" I still get this:



I clicked on it again and again - I still can't get rid of this message! What can I do? I was INSTRUCTED to do this:

Click Protect Me Now
Click Ok
Click Finished

I did all that. Why doesn't it work?I'd check the symantec web site or e-mail them for assistance.

Can you run the free virus scanner at www.trendmicro.com and see if that clears up the problem?Ah, too late to delete. I had just installed the thing, and forgot to restart. A dumb mistake: As soon as I rebooted, everything worked fine.

Or, as Merlin would say:

Delete! Ah, too late to do so!>>>>Did you REBOOT, yes...... are you on 98...... should be....... no problems!

OH, darn, he MISSED the upgrade.

Anyways... never mind, basically.  Glad all is well. HAPPY New Year!

611.

Solve : Adware on (older) Mac?

Answer»

I made a big boo-boo at work and HOPE you can help me out.
I OPENED an EMAIL on their older Mac graphite and got an ad from lowermybills.com that perpetually opens IE and displays the ad.
The Mac is RUNNING OS9.2.

Where can I get help for this? The boss is PO'd

Thanks all,
STry posting in the Apple SECTION.

612.

Solve : Blackworm Virus?

Answer»

I know I am late to share this, but here is some interesting reading.

http://isc.sans.org/diary.php?storyid=1067Wonderful link! Updating definitions now. ONE thing though... It says it will OVERWRITE information on Feb. 3rd... Of this year? February is almost over...

FlameEvidently this is the KamaSutra that was damaging systems even BACK in mid-January.

Attention Newbies and be safe!   Quote

It says it will overwrite information on Feb. 3rd... Of this year? February is almost over...

Flame

So it is basically harmless now, RIGHT? If it will only erase information on this date?

FlameSome variants STRIKE on the 3rd of every month.
613.

Solve : Upgrade MS Anti Spy to MS Defender??

Answer»

I guess MS Anti Spy is now MS Defender.

Is it a worthwhile upgrade or just leave my MS Anti Spy alone?Fordtruckmaniac......  Have a read at the link below.

http://www.microsoft.com/athome/security/spyware/software/about/faq.mspx


dl65  dl65,

Thanks for that link.

I guess I will have to check it out.


I wonder, will Anti Spy just quit working someday if you don't switch over? Fordtruckmaniac.....MS Antispyware Beta ........ should work until July 31st of this year ..... I am going to D/l it onto ONE of my other pcs and see how it looks ...... I have read a few MINOR things about it but I think those issues have been corrected .  I have D/L and installed it and am currently running a scan ......  I removed MS Antispyware before I D/L  MS Defender ......
I'll let you know what I think in a bit .

dl65   Fordtruckmaniac.....Well, I just ran a full scan ......... looks ok ........ There are more setup options than in MS antispyware ........ I don't see any reason not to try it .


dl65  Thanks for the info.

I will more than LIKELY load it tonight when I have more sit down time.

ThanksI'm going to wait until AntiSpy is almost out of BETA days... I installed Windows Defender on a few other computers, and I like AntiSpy more...

Flame Quote

I installed Windows Defender on a few other computers, and I like AntiSpy more...

Flame



Hmmm. [smiley=undecided.gif]


Flame,    
           Any particular thing about Defender you liked less or more than Anti Spy?

Just curious.Well, for one thing, I like having an icon on the System Tray to tell me that it's running PROPERLY. I also like having a progress Window that shows me how much LONGER an update will take, etc. The Defender does not show an update window, and if it takes a while, one might assume the program has frozen. Those are the only major concerns I have with the program.

Flame
614.

Solve : Mcafee Virus scan?

Answer»

I have Mcafee VirusScan Enterprise 8.0.0 Installed on my computer. When I first start up my computer for the first time during a day I have to manually enable on access scan.Sometimes, It shows It being on, most of the time It appears off. I have tried settings but no luck, Any Ideas?.http://www.tcd.ie/iss/security/virusscan_8.php

To configure a customised scan:

   1. Click Start, Programs, Network Associates, VirusScan Console.
   2. Click on Task and ‘New On Demand Scan Task’
   3. The new task appears in the task list where you are prompted to give it a name. Type in a descriptive name and hit return or double click on the new task to configure it
   4. On the ‘Where’ tab highlight the ‘All Local Drives’ item and click on the edit button
   5. From the drop down ‘item to scan’ list choose ‘Drive or Folder’ and browse to the location you WISH to scan. It will appear in the location field. Click OK
   6. On the ‘Where’ tab under scan options ensure that ‘Include Subfolders’ is ticked
   7. On the ‘Detection’ tab ensure that ‘All Files’ and ‘Scan inside archives (for example Zips) are SELECTED
   8. If you wish to SCHEDULE the task click on the ‘Schedule’ button
   9. On the Task tab tick the ‘Enable’ button
  10. On the Schedule tab configure the schedule as required
  11. Click on apply, ok and ok
  12. To run the scan right-click on it in the VirusScan console window and click on start

615.

Solve : java highway?

Answer»

New to the boards and have a question / the last two times AVG has detected viruses in my system, they CAME in through java    system is xp home with avg free and windows firewall.  generally this system stays clean, but is something up with java ? any ideas ? Look in add/remove programs and tell us what all versions of Java are listed.

Things with JDK, J2SE or any variation of Java.
Be sure to look for anything like MICROSOFT Java Virtual Machine (MSJVM) also.that is exactly what is there; I moved everything "java" to the recycle bin until I get this settled Quote from: gator on November 26, 2007, 12:08:44 AM

that is exactly what is there;

What is/was there?

The only entry of Java that should be in add/remove programs is Java (TM) 6 Update 3

The rest need to be uninstalled in add remove programs. Old versions of Java are entry points for malware.

You should run the scans in this post to be sure nothing else is hidden in the system.
RAN THE SCANS, DOWNLOADED THE "SUPER" PROGRAM AND EVERYTHING IS IN ORDER NOW.......THANKS FOR THE TIP Good to know.

Safe surfing......

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?
616.

Solve : All .exe extensions changed to *exe.vir. and quarantined. Pleeeeas Help!!?

Answer»

All .exe extensions changed to  *exe.vir. and quarantined. Pleeeeas Help!!

When evr I try to open any program, a windows error message pops up saying,
" Could not find C:\ WINDOWS\system32\rundll32.exe  .
No program runs. And when I look in the Quarantine folder, all the programs I tried to run are there with their exe files changed to fro ex. wmp.exe.vir and so on.
All and any tips are most welcome and highly appreciated. Thanks all. Quote

when I look in the Quarantine folder

What quarantine folder? McAfee?

Is it a paid version? Update it.....then let us know.

Also in this instance more info would be a good idea...
Windows version ? ?
Protection apps installed CURRENTLY ? ?
Any new software installed in the last month ? ?Sorry guys!!
It is an IBM thinkpad T20 running win xp pro 2 edition.
McAfee antivirus, perpetual. But McAfee ALWAYS says it is 19 months old when scanning. LATEST software run was RockXp , just for product key retrieval.
P.s. The quarantine folder is located in c:\windows\Quarantine.
Any hope??

10X again ofr all the help, guys!!




More bkgd info, the laptop doesn't let me run anything. Even tried to update the McAfee, but says can't find ''Windows Installer''. Plus, the activity bar doubled and the start menu disapeared. And the CPU is almost always 100%.

Hope that helps.Probably not what you want to hear but with all your file extensions wonked and things seemingly getting worse a format and clean install of XP may be in order here...You can run anything at all?  Not even HijackThis?  What about in Safe Mode?

This sort of infection is possible to clean, but I'll tell you right now that even if we can clean your infection, it probably won't be easy.
617.

Solve : a lots of problem?

Answer»

hi is thr anyone to help me... i have got lots of problem in my PC:-
1. folder OPTION from tools menu has gone
2. all the folders of my pc showing size 180kb but contains all my files.
3. when i TRIED to open my any folder it fails to open
4. msconfig id not working

pls anyone help me getting my pc ok
please please please You're ALREADY being helped, awyes.  Please don't make new threads when it isn't necessary.  Have patience and we will try to help you sort your problem out.Topic Closed.
Please see your other thread for replies.

618.

Solve : is this overkill?

Answer»

I have xp sp2 I have threatfire, COMODO avg, and windows defender on my pc just wondering if it too MUCH. I don't have any PROBLEMS REALLY I'm just curious thanksNot overkill. I would ALSO install Spywareblasterokay great thanks Evil.No problem

619.

Solve : Msn, Based Virus,?

Answer»

Hello, i have seen this quite alot. But is it a virus or WHATNOT, when someone sends you a FILE of the NET and its says like  'do i LOOK dumb in this pic?' and with an attached file. This happens in msn live? any thoughts on what type of software COULD be running it etc. its really annoying.  I opened one on my virtual pc, its bad, some pritty bad stuff it sends you.http://www.msnvirusremoval.com/

620.

Solve : need help removing a program!!!!?

Answer»

i accidently downloaded a anti-virus on my pc and it has been causing me problems EVERY since. i've tried removing it from my control panel and it still won't leave. can somebody please help me to figure this out?First and foremost, welcome to CH Forums.

Before we begin, it would be good if you gave a bit more info about the problem at hand.

What OS are you using?

what's the program you downloaded called?

You say you've tried uninstalling it from control panel, i'm assuming you're talking about add and remove programs? If so, what EXACTLY went wrong? any error messages? Quote from: mowett on July 13, 2008, 12:58:39 AM

i accidently downloaded a anti-virus on my pc and it has been causing me problems every since.

Welcome to CH.

Please see our standard pre-cleaning PROCEDURE. Once the logs are posted we will go from there. Click >>HERE<<

thanks anyway. the software i downloaded was called antivirus xp 2008. i read a few of your other members problems and got help just from reading their REPLIES. malwarebytes helped me solve my problem. thanks so much. Quote from: mowett on July 13, 2008, 01:52:02 PM
thanks anyway. the software i downloaded was called antivirus xp 2008. i read a few of your other members problems and got help just from reading their replies. malwarebytes helped me solve my problem. thanks so much.

It would be a good idea to go ahead with your own and have the experts at CH do a diagnosis on your system and prescribe cleaning instructions - instructions for cleaning, other than the general first steps, are unique to each set of circumstances.

BEST of luck."It would be", or wouldn't be? Quote from: Broni on July 13, 2008, 02:12:09 PM
"It would be", or wouldn't be?

Check my edit above - it the original was ambiguous; thanks.
Better Good catch - made sense to me when I wrote it; probably should have been my first clue! Quote
made sense to me when I wrote it
It's always like that. Only when you re-read it, you may catch it
621.

Solve : I NEED HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!?

Answer»

Well if you can't positivly fix the problem really the only OPTION you have, is to reinstall windows, which would WIPE your hard drive clean. The positives here are also that your COMPUTER, after being wiped, would run as FAST as when it was bought 
KieranHe doesn't have any disks.I'm quite aware of that, but im saying he might NEED to purchase them in a sense, its probably the only option.

622.

Solve : malewarebytes blocking MPC video player?

Answer»

so for some reason malwarebytes is treating MPC as a MALICIOUS program. Ive been using it forever then all the SUDDEN when i go to click on a video it gives pop up "ransom.filelocker"

see attached

any idea why it suddenly decides to do this? I redownloaded it and CLICKED on another video and same thing, then MPC program gets ERASED from default video player and cannot be found or opened again. I just uninstalled.

[attachment deleted by admin to conserve space]False Positive.

https://forums.malwarebytes.org/index.php?/topic/176926-media-player-classic-x64-ransom-file-locker/

Looks like a database update is available already that FIXES it.

623.

Solve : I seem to have a browser redirect issue which is not being detected?

Answer»

I ran adwcleaner and MBAM again as requested.

These are the log files

Adw cleaner

# AdwCleaner v5.026 - Logfile created 27/12/2015 at 00:16:17
# Updated 21/12/2015 by Xplode
# Database : 2015-12-23.1 [Server]
# Operating system : Windows 8.1 Single Language  (x64)
# Username : Vedan - ESHLIN
# Running from : C:\Users\Vedan\Downloads\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\Users\Vedan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd

***** [ Files ] *****

File Found : C:\Users\Vedan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage
File Found : C:\Users\Vedan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_cdncache-a.akamaihd.net_0.localstorage-journal

***** [ DLL ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

[C:\Users\Vedan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : fcfenmboojpjinhpgggodefccipikbpd

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1106 bytes] ##########



Mbam

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 12/26/2015
Scan Time: 9:30 PM
Logfile:
Administrator: Yes

Version: 2.2.0.1024
Malware Database: v2015.12.26.04
Rootkit Database: v2015.12.26.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Vedan

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 347692
Please download MiniToolBox to Desktop and run it.



Checkmark the following boxes:


    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • List content of Hosts
    • List IP Configuration
    • Lst Last 10 Event Viewer Errors
    • List Users, Partitions and Memory Size
    • [/b]
    Click Go and copy/paste the log (Result.txt) into your next post.
    *****************************************
    Please download Farbar Service Scanner to the desktop and run it on the computer with the issue.
    Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

    Make sure FRST is run under administrator privileges.
    Make sure that the Whitelist section is checked.Otherwise, the log will be very long.
    You Security programs may prevent the tool from running. If this happens, disable the security program until the scan is completed.
    • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.

    • Press "Scan".





    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.
    • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    Thank you very much Supedave. It seems like my problem is no LONGER existent. You were very helpful and I appreciate the fact that you never gave up on me. Did the problem disappear after you ran the last two scans?Minitoolbox seems to have eliminated the problem. Ok, let's do some cleanup.

    Click Start> Computer> right click the C Drive and choose Properties> enter
    Click Disk Cleanup from there.



    Click OK on the Disk Cleanup Screen.
    Click Yes on the Confirmation screen.



    This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
    *******************************************
    This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create Registry backup
    • Purge System Restore Points
    • Re-set system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.
    **********************************************
    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from online scams, identity THEFT, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    624.

    Solve : Some questions about Tails?

    Answer»

    Hi, I would like to ask some security-focused questions on Tails, the Linux privacy OS.

    1. We know that Javascript and plugins are removed from the Firefox Tor browser, because these are 2 of the most common ways to hack a browser. But, is there any way to hack Firefox that doesn't depend on these 2 things..? The NSA has documents where they were confident to exploit so-called "native" Firefox exploits. I would like to see someone link me proof of any such exploits. The only thing I could think of would be things like, using GIF images or something like that. I've heard of exploits that Involve nothing other than GIF images.

    2. Let's just say that the answer to (1) is "yes, they can hack Firefox EVEN with JS and plugins disabled"... So, the question is.... what happens next...? We know that Tails runs in non-administrator/non-root mode, and we know that Tails blocks access to the user's local hard drive.... So the question is..... how would any hacker achieve persistence...? Surely when the browser window closes, the virus is now gone for good.... Or is it...? That's what I'm asking.... How would they achieve persistence...? Can programs be run SIMPLY out of the computer's RAM alone...? Or, could they install the virus to any USB hard drive that was plugged in..? Does Tails allow executable files to be run off of an external USB device..?

    3. Question 3 is another question about persistence.... Would it be possible for a hacker to hack Firefox, and then install the drivers required to read off of the user's local hard drive...? Or not...? Does it require a computer restart in order for such drivers to take effect..? If so, then obviously it's useless for the hacker, because once Tails is restarted, it's back to its original non-modified state all over again.

    That's it...

    As you can see, the questions are mainly about persistence...
    Thanks Quote

    As you can see, the questions are mainly about persistence...
    Thanks
    When a program closes, either in Linux or Windows, the memory is not cleared. It is merely set to FREE space. A clever hacker can do some trick to prevent the memory from being used  by the next program. The the bogus MALWARE in memory can do its wicked objectives.

    How it is done is not the issue. It is done. That is what matters. I do not want to tell you how it is done. Just believe it.

    With the advent of 64 bit software and hardware, there are now some new ideas about how to protect your PC for malware. Bat that is a new topic. But you can Google it.
    One thing is the NX bit.
    Start here:
    https://en.wikipedia.org/wiki/NX_bit
    Quote
    Intel markets the feature as the XD bit, for eXecute Disable. AMD uses the marketing term ENHANCED Virus Protection. The ARM architecture refers to the feature as XN for eXecute Never; it was introduced in ARM v6.[1]
    So future PCs might have more built-in protection.


    625.

    Solve : Tricky Malware??

    Answer»

    I got a notification from Windows Defender SAYING that it detected malware. Malwarebytes didnt find anything. I ALSO RAN Malwarebytes anti root kit and it found nothing. Any suggestions would be appreciated. Does Defender not GIVE any indication of the specific FILE(s) in question?

    626.

    Solve : Anti virus-McAfeeSetup?

    Answer»

    Your COMMENT has been removed. Please do not post MALWARE advice, or post here in the malware forum, UNLESS you NEED help.Superdave.

    627.

    Solve : Ransomware... My husband let them in his computer!?

    Answer»

    My husband answered the phone yesterday to a man who said his computer had been hacked. He said he could find the hacker and fix it for him.

    So he turned on the computer and typed in what the man told him to...then the man took control of the computer saying he was searching for the hacker.

    When I walked in the room I overheard my husband say I don't have that much money right now...and I ASKED him who he was talking to...I seen the cursor moving around his computer and I told him that's a scam HANG up.

    But it was too late....now he can not get his computer to come on...

    Any help would be appreciated

    The phone number is deleted by allan the people that called.1) I deleted the phone number from your post
    2) If your system wasn't backed up you will almost certainly lose all data. You can either PAY the ransom or format and reinstall.

    You should wait for Super Dave to confirm, but I think you're out of luck
    The phone number was the ransom people's... not mine

    He has it backed up...but how do we get the computer to boot up...it won't come on??

    Thanks for the fast response  Quote from: SheIsMe on November 18, 2015, 11:24:53 AM
    ...
    He has it backed up...but how do we get the computer to boot up...it won't come on??
    ...
    Which backup program did you use?
    Backup software has some way of rebooting your computer. See the instruction manual. You may need another computer to CREATE the 'boot media' needed to restart your  computer.I think I got it...it says it is resetting the computer.

    Will let you know if it works
    628.

    Solve : Suspicious IP's in Wireshark?

    Answer»

    Bought a laptop which had preinstalled malware in it. Wiped it clean and installed Windows 7 from scratch. No signs of malware anymore, but I'm thinking the UEFI might be flashed with malicious software.

    I just have started experimenting with Wireshark to see if I have browsers closed and so on, will the system connect anywhere. It seems to connect to Amazon IP in the US (I'm located in Europe), and therefore I'm really concerned about the security of this system. I have booted it in Windows 7 compatibility mode, have ran Avast, MBAM and MBAR, MBAR in compatibility mode too. In the startup it says it has found a possibly rootkit activity; appinit_dlls -folder. I found in regedit that there are a few of them there, other is in win.ini -subfolder and other seems to be an nVidia file.

    I have tried to get some clue about the wireshark, but it seems like I'm too much of a newbie to find anything out without help. There are lots of UDP protocol based connections, a few TCP, ARP, SSDP and a few HTTP's as well. Also NBNS and IGMPv2.

    Is there any possible way of really finding out if my system is still infected? I thought that if I use CCleaner to clean up the system of any cookies or so, I woudl see better if they have anything to do with connecting randomly to some IP but don't even know if that's possible.

    I'm willing to find out and can do things as directed, so any help is appreciated.I doubt there is anything to worry about, its totally normal to see network connections going out from a PC, it's most likely things checking for updates, weather apps updating, software checking its activation status and so on.

    Loads of companies rent space on Amazon's servers through Amazon Web Services so it's common to see connections to Amazon IP addresses from software doing as I described above.

    Also bear in mind that wireshark SHOWS every packet going in and out of the system, so while you may be seeing data flying by when you do a capture, it probably isn't as much data as it looks.  One update for a piece of software running in the background could result in hundreds of packets appearing in Wireshark.I had to make another account as I forgot the password and used an anonymous email which had similar password and forgot that too...  Anyhow. How about finding out if the UEFI is secure? I really wouldn't want to have my personal info and/or files (especially credit card info) to be available to someone who could have infected the system. How can I check the security of UEFI and the system, that there is only tiny tiny tiny chance of it having anything infected?"but I'm thinking the UEFI might be flashed with malicious software."
    It isn't. You know enough to poke around in REGISTRY editor and snoop with wireshark, but not enough- by your own admission - to know what you are looking at.For a laugh I just ran Wireshark on a Windows 7 machine of my own.  This machine is a laptop that I use exclusively as a radio receiver and it therefore has very little software installed on it, nothing apart from Windows and the Antivirus (Microsoft Security Essentials) runs in the background.  To be clear this laptop is a ThinkPad T400 from 2008 and therefore has nothing that remotely resembles a UEFI.  As soon as I started the capture, just like you found, there was hundreds of packets being captured.  These ranged from TCP connections to Microsoft and AKAMAI IPs which appeared to be serving Windows updates, a bunch of IPv6 addresses I couldn't be bothered to look up, SSDP packets coming from another Windows 10 PC on my network, ICMP packets coming from my router and ARP packets coming from my Samsung Smart TV.



    I agree with BC, your UEFI is almost certainly fine - To attack a UEFI you would effectively need to build a virus to attack every specific model of laptop, they would all need to be treated differently, this is totally impractical.  While UEFI attacks are certainly possible, I have never heard of any of them being discovered in the wild, it's a classic case of something that can be done, but isn't easy or useful enough for someone to have any reason to do it.It's fundamentally the same as "BIOS Viruses". It's something that can be done but for which it simply isn't worth doing. Even if you infect the system at that level- both the BIOS and UEFI stop having any control over the system after the boot, so any "infection" that takes place would be effectively the use of the low-level infection to infect the higher level OS. The problem, then, is that there simply isn't room for it- the "malware" would need to effectively replace significant portions of the BIOS firmware as a data storage location for OS-targeted malware, in addition to the NEW logic to try to detect what is on the HDD to infect it properly. It would be difficult to keep the system functioning after stripping out that much, let alone make it look and function similarly during boot.

    it's simply not worth the trouble when you can send a spam e-mail with a download link and infect a significant number of systems.Thank you both for quick and relieving answers. I'm quite COMFORTED now as what comes to the probability of the malicious file, so I think I'll just keep the *censored* thing. Hopefully this ain't the wrong decision. All further info towards this matter is still welcome though.

    629.

    Solve : Which is the best antivirus KasperSky or Norton??

    Answer»

    Which is the best ANTIVIRUS KasperSky or NORTON?This might help: http://www.tomsguide.com/us/best-antivirus,review-2588.html Quote from: DaveLembke on September 28, 2015, 10:35:39 AM

    This might help: http://www.tomsguide.com/us/best-antivirus,review-2588.html

    Not MUCH love for Win Defender!AV reviews vary widely.
    Here is another review:
    http://www.techradar.com/us/news/software/applications/best-antivirus-10-programs-on-test-924608
    They put Norton down on the list.
    The top spot is Avira.For what it's worth there are not many viruses around these days. Most of the crap I find on computers zips right on by the AV. The only sure way to stop them is to install a full version of MBAM. Quote from: SuperDave on November 07, 2015, 10:53:38 AM
    Most of the crap I find on computers zips right on by the AV.

    I imagine people running an AV that are exposed to viruses that are caught/quarantined/deleted by the AV aren't going to be asking for virus help, THOUGH, so that could just be sample bias. Quote from: BC_Programmer on November 07, 2015, 06:02:34 PM
    I imagine people running an AV that are exposed to viruses that are caught/quarantined/deleted by the AV aren't going to be asking for virus help, though, so that could just be sample bias.
    Yes, that could very well be true.BTW, I had MBAM PRO on 4 systems and after an update last month all 4 systems would not boot properly. Eventually I was able to get to the desktop(s) and disable MBAM from loading at boot. After that everything ran normally on all systems. Odd. I no longer run MBAM as a resident app - only use it for on demand scanning. That is strange. Have you talked to MBAM about this problem?No, been too busy. And didn't see any other reports about a bad update - but that's the only think I can point to that the systems had in common
    630.

    Solve : Internet activity accessed by flatmates- how??

    Answer»

    Recently my internet activity has been accessed by a flatmate of mine. Whatever software was used required both my laptop to be on and close proximity to work, as he would enter the room ADJACENT to mine (despite that room not being his) shortly after I entered my own room on several occasions. Therefore my question is what software requires both the target laptop to be on and close proximity? Thank you.? Have you run any virus scans and come up with any troubles ?

    There are too many programs out there to list that would fly under the radar of an antivirus, but require the other person to have physical access to your computer to install a service. Did they ever send you anything to install or run, or have they ever had access to your system in an accessible mode to install a service such as if your computer is left unattended and logged on?

    Most simplistic fix if you cant target to remove the software or service would be to back up your data to an external drive and restore the computer back to factory default. Then be sure to set a password on the system and a screen saver with a lock to lock the computer after say 5 minutes of inactivity. This might be a pain as for if you walk away to get coffee and more than 5 minutes pass you need to enter your password to get back to whatever you were working on, but its the most secure method with a questionable flatmate causing troubles.

    Additionally they might not have anything installed on your system at all and are just sniffing the wireless with a tool that watches packets. They can see TRAFFIC to and from your devices and know where you have been based on IPs and any unencrypted data transferred in packets. So if this is the case, you will want to lock them out of your wireless network if they are on it. This is a wireless ROUTER config change.

    Lastly how do you know they accessed your internet activity, are they sharing information as a threat or something else that gave you hints that they are snooping in your private activities?I've run several virus scans and nothing (to my mind) of any significance has cropped up; up until I suspected that something was up my laptop did not have a password so I guess all sorts of programs could have been installed. It's complicated as to why I know this has been done, but rest assured I know it has been. Do you know of any programs that require proximity? Quote

    Do you know of any programs that require proximity?

    Every program or service that uses bluetooth or wifi has to stay within a proximity/operating range .... that doesnt help MUCH because too many to guess you have installed & list. Have you looked for any programs or services that look questionable.

    You can run Get-WmiObject -Class Win32_Product | Select-Object -Property Name > C:\Software\PCapps.txt as seen here to gather a list and share it with us to look at:
    http://www.howtogeek.com/165293/how-to-get-a-list-of-software-installed-on-your-pc-with-a-single-command/

    Then attach the txt file for us to look at after running that instruction from command shell. You can also take a screen shot of task manager and sort alphabetically and "show processes from all users" selected so we can look for questionable services. Although the best hackers will hide rogue services under like names of legit services to mask them from easy capture.

    Your best bet really is to backup your data and wipe it clean back to factory install and start fresh, and keep it secure with password and no physical access by them. A simple thumb drive or disc can bypass computer security with HACKSAW tools that run in Linux that can alter hard drive contents to plant things. When bringing your data back to the computer make sure you have antivirus with realtime protection and latest definitions running and fully scan it before opening any files or running any backed up programs.
    631.

    Solve : Quick Question - Data Recovery on infected system?

    Answer»

    Just checking here on this... friend of mine had a severely INFECTED system. I booted off of Linux Mint 15 DVD in Live OS environment which allows me to connect and mount a 32GB USB flash drive and the virus to be inactive. Currently copying over 18GB of data from his USER profile to the 32GB USB STICK.

    I know that Linux is immune to the virus that is on the system to transfer the data to the USB flash drive.

    Question I have is ... is there a Linux based antivirus tool out there that can scan the thumb drive for Windows based virus's or am I forced to go the method I have gone in the PAST with using a spare computer with latest AV running with realtime protection and then have that discover the potential virus's on the flash drive when flash drive is plugged in, and then have that remove the problems that might be on this USB stick in potentially infected files?YES, some of the 'Rescue Disks' for Windows are actually Linux OS with a Windows AV installed.
    http://free.avg.com/us-en/226162
    Quote

    Introduction
    The AVG Rescue CD is a standalone set of tools that can be started from CD or USB flash disk. It can be used to recover computers that are not able to boot or are infected in a way that will not allow normal operation. The whole CD or USB flash drive is a live CD with Linux operating system and AVG preinstalled on it.
    This document will guide you through basic operations of AVG Rescue CD and its features. You can also get additional information in the Knowledge base section of the AVG web pages.
    There are also such things made by Avira and others.
    http://www.avira.com/en/download/product/avira-rescue-system
    Hope that helps. 
    632.

    Solve : Can my mouse have a virus?

    Answer» http://www.amazon.in/DragonWar-ELE-G7-Bluetrack-Gaming-Function/dp/B00IJ69B0M
    this is my mouse, i used it for my old computer, and this computer full of virus. And now i use this mouse for my new PC, can my computer be infected from my mouse?No.
    Really? Oh thx G, im so scared because my last computer have many many dangerous virusIs this for real?
    The mouse could have a virus. Where has it been?
    The only solution is to get a virgin mouse.
    http://security.stackexchange.com/questions/100743/can-my-mouse-have-virus-and-infect-other-machines
    Quote
       c't (a German computer Magazin) once discovered mice offered as gifts were reacting to signs on mousepads. These mice then tried to send keyboard strokes to the computer. Of course the article is only in German and you can only read part if it
    The ASSERTION has been made that a mouse does not have enough silicon space to hold a virus.But this has not been verified.
    I have used many mouse in different brand. Pointer could freeze sometime but I haven't encounter it. Not unless I plug usb stick from other computer who had virus.The OP needs to get another mouse and run virus scans.
    How he got the virus is less important. He needs to get rid of it.No. It is not possible. a virus in mouse  Quote from: ZAHID TOG on September 28, 2015, 10:17:17 AM
    No. It is not possible. a virus in mouse 
    CITATION needed.
    Three and four years ago the answer was yes.
    Do you proof that this has somehow changed?
    Here is a link to a social blog.
    http://answers.microsoft.com/en-us/windows/forum/windows_vista-update/my-mouse-is-uncontrollable-possible-virus/526fd59c-7a96-4665-8244-0b3fc0451b67?auth=1
    The post had many contributors.
    The general answer was to just get another mouse.
    633.

    Solve : windows vista hanging up on boot up. crcdisk.sys?

    Answer»

    Hi guys.
    So I'm using a TOSHIBA satellite a200-28p.  It can't boot further than loading  files screen  where  it hangs on the crcdisk.sys. I have TRIED booting  in all the safe  modes but I just end up on the same screen. I have also  tried to run a xp RECOVERY  disc but again  I can't get a response... anyone got any idea what to do please help!!Is this the XP OS disk that you RECEIVED with your laptop or is this a recovery disk you made yourself? You will need to change the BIOS to boot from the disk.
    If you do not know how to set your computer to boot from CD follow the steps here

    634.

    Solve : Hijack Software and FBI Warning on my iPad.?

    Answer»

    Never had problems with a Apple product with VIRUS or Hijacking. I KNOW a LOT about Windows based product, but not a thing about Apple problems.
    Please help me get RID of this locked up Safari problem on my iPad.Sorry, I can't help with Apple products. You might try the Apple forum on this site.

    635.

    Solve : Can't Install Norton AntiVirus or any AntiVirus Software?

    Answer»

    Same thing happens when I use Chrome.Please go to Kaspersky website and perform an online antivirus SCAN.

    1. READ through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and VIRUS definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    Spyware, Adware, Dialers, and other potentially dangerous programs
    Archives


    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the RESULTS. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply.

    636.

    Solve : Cleanup after attempted scam?

    Answer»

    Quote

    Presumably that is the END of the CLEANUP process
    Unless you're EXPERIENCING other problems.No – all is well.  Again, MANY thanks.You're WELCOME. I will lock this thread. If you need it re-opened, please send me a pm.
    637.

    Solve : Malware Removal Logs?

    Answer»

    i looked for the last day and could not find any solutions unfortunately.  so frustrating.  i dowloaded an UPDATED "photo GALLERY" to try and view the photos and still nothing. this new viewer says "photo gallery can't open this photo or video. the file may be unsupported, damaged, or corrupted."  i unchecked boxes that hide files on my computer. i feel like im running out of options, i dont know what to do next with these photos.The fact that I couldn't open the file you sent me SUGGESTS that the file has been altered in some way. One last resort would be to try a System Restore to before this happened.Ok, ya the virus that hit my computer wiped out all my restore points. If you can find a solution to this problem could you post it here?no luck on finding any solution, but hoping you can help me with a couple questions:

    1. do you know if after running the cleaners that you told me to run, is my computer now clean of any viruses or malware?

    2. do you know of any other forums on this website where someone can assist me with the picture issue?

    THANKS SUPERDAVE for all your help! Quote

    1. do you know if after running the cleaners that you told me to run, is my computer now clean of any viruses or malware?
    Yes, as sure as I can be from this distance. You can run them again and see if anything turns up especially ESET.
    Quote
    do you know of any other forums on this website where someone can assist me with the picture issue?
    You could try posting in the Windows Vista and 7 forum. Someone there might be able to come up with at solution.Should I sent you the logs for that test?

    Ok will do. Only send the logs if something is found.
    638.

    Solve : Windows 10 asks "How do you want to open this file" upon boot?

    Answer»

    The past few days after turning on my computer, I get a message from Windows saying "How do you want to open this file?" even though I have nothing set to start when I turn on the computer besides what Windows 10 includes. It goes away after a few seconds and Norton Says a malicious PROGRAM was blocked. Is this a virus?Download Security Check by screen317 from one of the FOLLOWING links and save it to your desktop.

    Link 1
    Link 2

    * Double-click Security Check.bat
    * Follow the on-screen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt
    * Post the contents of that document in your next reply.

    Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
    No good. Norton deleted the SecurityCheck.exe file because it is unsafe.Tell Norton to allow it.Results of screen317's Security Check version 1.008 
       x64 (UAC is enabled) 
     Internet Explorer 11 
    ``````````````Antivirus/Firewall Check:``````````````[/u]
     Windows Firewall Enabled! 
    Norton Internet Security   
    Windows Defender           
     WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````[/u]
     Advanced WindowsCare Personal   
     Java 7 Update 76 
     Java 8 Update 45 
     Java 8 Update 51 
     Java 8 Update 60 
     Adobe Flash Player    18.0.0.232 
     Mozilla Firefox (40.0.3)
     Google Chrome (44.0.2403.157)
     Google Chrome (45.0.2454.85)
    ````````Process Check: objlist.exe by Laurent````````[/u] 
    `````````````````System Health check`````````````````[/u]
     Total Fragmentation on Drive C:  %
    ````````````````````End of Log``````````````````````[/u]
    Please download AdwCleaner by Xplode onto your Desktop.

    Before starting AdwCleaner, close all open programs and internet browsers, then double-click on the AdwCleaner icon.



    If Windows prompts you as to whether or not you wish to run AdwCleaner, please allow it to run.
    When the AdwCleaner program will open, click on the Scan button as shown below.



    AdwCleaner will now start to search for malicious files that may be installed on your computer.
    To remove the files that were detected in the previous step, please click on the Clean button.



    AdwCleaner will now prompt you to save any open files or data as the program will need to reboot the computer. Please do so and then click on the OK button. AdwCleaner will now DELETE all detected adware from your computer. When it is done it will display an alert that explains what PUPS (Potentially Unwanted Programs) and Adware are. Please read through this information and then press the OK button. You will now be presented with an alert that states AdwCleaner needs to reboot your computer.
    Please click on the OK button to allow AdwCleaner reboot your computer.A log will be produced. Please copy and paste this log in your next reply.
    *********************************************
    Please download Malwarebytes Anti-Malware from here.
    Double Click mbam-setup.exe to install the application.

    • It should update automatically if the computer is connected to the internet.
    • Click on Threat Scan and click on Scan Now.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete make sure all the infections have "quarantine" selected in the Action box.
    • Click on "Apply actions" You may be asked to Restart your computer to completely remove the infections.
    • When disinfection is completed you can click on "Copy to Clipboard".
    • Paste the log in you next reply (CTRL+ V)
    *************************************************
    Please download Junkware Removal Tool to your desktop.

    •Warning! Once the scan is complete JRT will shut down your browser with NO warning.

    •Shut down your protection software now to avoid potential conflicts.

    •Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    •Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

    •The tool will open and start scanning your system.

    •Please be patient as this can take a while to complete depending on your system's specifications.

    •On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

    •Copy and Paste the JRT.txt log into your next message.That program worked! No more problems!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
    639.

    Solve : Can a Computer Virus infect the BIOS??

    Answer»

    I've been learning C++ for the past couple of months and I've learned how to create simple programs that BASICALLY annoy the crap out of people. They're nowhere near ACTUAL viruses due to the fact that all they do is DISCONNECT your mouse and keyboard, display, unpin everything from the task bar, change language settings, make the mouse go crazy etc..

    However it raised the question in my mind: is it possible for a virus to not only infect the BIOS but also alter it's settings? If it is possible would a virus be able to once in the BIOS, overclock a stock cooled CPU to the point were it fries? That SORT of thing?Based on the content in your post, we're not interested in assisting you. Thread LOCKED.

    640.

    Solve : Police-Report virus/ransomware?

    Answer»

    At this point I feel that you should re-install XP but save your important data first then boot with the OS disk in and follow the directions.Thanks for your help. Darn A-holes....why do they do this? No, there's no need to answer that. I wish people like that didn't EXIST. People who make VIRUSES and malware make me sick. Thank you for trying to help me with the computer, but I guess they win this time. Don't FORGET to put a good AV on your computer when you get it repaired.

    Remember to only install one antivirus!
     
    1) Avast! Home Edition
    2) AVG Free Edition
    3) AVIRA AntiVir Personal
    4) MicroSoft Security Essentials   All versions and all languages.
    5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)

    It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false VIRUS alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.I have the same issue. I did get the OTL.txt file and attached it. have no clue what to do now.

    [attachment deleted by admin to conserve space]newatthis, don't hijack someone else's thread. Please start a new thread of your own and I'll help you as best I can.

    641.

    Solve : TOTAL BEDLAM?

    Answer»

    I TRIED that, no change.  SUGGESTIONS?What happens in SAFE Mode?

    642.

    Solve : Need Scan Log Help?!!?

    Answer»

    Quote

    The one thing I've noticed that has been happening a lot lately is when I OPEN anything up I keep getting a "(not responding)" in the window heading and I have to wait
    This has to do with your internet connection. You can check you net speed with this tool.

    Here's the site to test your ISP speed.
    Quote
    also I think the computer may be running a little slow/sluggish
    Is it slow while on the net or is it just slow all the time? You can run MBAM, ADWCLEANER and JRT again if this is the case.Nice...
    Thanks for the link, I will check it out.

    Slow when on the net, it doesn't seem to load webpages in general as fast as it did when I FIRST had the O/S installed?

    It seems to take longer when loading webpages and when I watch YouTube clips in "full SCREEN" they PLAY "choppy" and it never used to do that??

    Do you think any of this could be related to Chrome browser? Also do you suggest me using any particular browser if that be the case?

    Try IE or FireFox.Will do ,Thank's SuperDave!
    643.

    Solve : Hacked contacts. Would really appreciate advice.?

    Answer»

    Hi Guys,

    Really looking for some expert advice.
    I have received an email that APPEARED to be from me. On CLOSER inspection the email address was my name but some bogus account at fluiddata. The problem however was that in the CC line were a number of my contacts from address book. So although emails are not being sent from my account, somehow this spammer has harvested my address book and is SENDING emails that 'appear to be from me'. Any thoughts about has happened and what I should do would be appreciated. Can't work it out.

    Really APPRECIATE any help

    thanks

    DomYour account has been hacked. Give me more information about your account. What type is it; gmail, hotmail etc?

    644.

    Solve : Bing came uninvited and refuses to leave??

    Answer»

    Have a Dell desktop running Vista.

    I have been SAILING along without a glitch since SUPER Dave helped me clean uo my computer last year.
    Now, Bing came uninvited (knowingly) and refuses to leave. It seems to be attached to IE.

    Any advice or help will be greatly appreciated.

    Ivan CopasDid you try this:
    Quote

    Click on tools icon or the cog icon depending on the version of internet explorer you are using. If you cant see the toolbar, press ALT key on your keyboard to reveal the toolbar. Scroll down and locate Bing Bar – SELECT it by clicking and then click the disable button to disable it a shown in the image below.Aug 13, 2014
    YourTube.

    Which version of IE?  Thanks so much for your response.
    I am running Explorer 9 , Vista Ultimate. Dell System.

    I don't know enough to not get into trouble when I try to follow advice and my computer doesn't look like I think it should. So let me be sure I understand your advice.

    Can I delete the Bing tool bar? There are three Bing SEARCH boxes at the top of my screen now.

    I see Bing in the internet option box when I click on it.

    Sometimes a lovely picture titled Bing appears and fills the screen.  Nice enough to keep, but I didn't order it.

    What should I delete first? Mysterious to me.

    Copas~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 6.4.2 (02.02.2015:1)
    OS: Windows Vista (TM) Ultimate x86
    Ran by copas on Sat 07/11/2015 at 15:31:42.28
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{97B5F05A-2A66-4652-B817-90EFF6642AAE}



    ~~~ Files



    ~~~ Folders



    ~~~ FireFox

    Successfully deleted the following from C:\Users\copas\AppData\Roaming\mozilla\firefox\profiles\6f0n8d8v.default-1427546345409\prefs.js

    user_pref("browser.search.defaultenginename", "Ask Web Search");
    user_pref("browser.search.selectedEngine", "Ask Web Search");
    user_pref("extensions.mywebsearch.prevKwdEnabled", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.BUTTON_STRUCTURE", "[{\"b\":224541925,\"c\":\"mindspark.magnify\",\"p\":\"L.0\"},{\"b\":224541926,\"c\":\"mindspark.enterse
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.prev ", "Ask Web Search");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.save dPrev", "true");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.defaultenginename.tb", "Ask Web Search");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.prev", "Ask Web Search");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.savedPr ev", "true");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.search.selectedEngine.tb", "Ask Web Search");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.homepage.savedPrev", "true");
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.homepage.tb", "hxxp://home.tb.ask.com/index.jhtml?ptb=FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA&n=781b892a&p2=^Z
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.page.savedPrev", 1);
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.startup.page.tb", 1);
    user_pref("extensions.toolbar.mindspark._4jMembers _.browser.version.last", "39.0");
    user_pref("extensions.toolbar.mindspark._4jMembers _.competitorDNS", "{\"comment\":\"refresh every 1 week (7*24*60*60*1000)\",\"refreshPeriod\":604800000,\"list\":[{\"url\":\"h
    user_pref("extensions.toolbar.mindspark._4jMembers _.firstKnownVersion", "7.18.7.19764");
    user_pref("extensions.toolbar.mindspark._4jMembers _.homepage", "hxxp://home.tb.ask.com/index.jhtml?ptb=FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA&n=781b892a&p2=^ZX^xdm003^YYA^us&si=
    user_pref("extensions.toolbar.mindspark._4jMembers _.hp.enabled", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.hp.guardType", "HPR");
    user_pref("extensions.toolbar.mindspark._4jMembers _.hp.user.defined", false);
    user_pref("extensions.toolbar.mindspark._4jMembers _.initialized", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.installKeysSource", "Cookies");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installType", "XPI");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.contextKey", "");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.dlpCountryCode", "US");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.installDate", "2015070506");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.partnerId", "^ZX^xdm003^YYA^us");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.partnerSubId", "CJTyh5WFxcYCFQ-IaQodvCkKrA");
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.pixelUrl", "hxxp://download.radiorage.com/install_pixels.jhtml?partner=^ZX^xdm003^YYA^us⊂_id=CJTyh5WFxcYCFQ
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.success", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.installation.toolbarId", "FD3CFEA1-D4F3-4933-A51C-BE75A4B72DAA");
    user_pref("extensions.toolbar.mindspark._4jMembers _.isCompliantUninstallImplementation", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.lastActivePing", "1436135401746");
    user_pref("extensions.toolbar.mindspark._4jMembers _.lastKnownVersion", "7.18.7.19764");
    user_pref("extensions.toolbar.mindspark._4jMembers _.options.defaultSearch", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.options.homePageEnabled", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.options.keywordEnabled", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.options.tabEnabled", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.partnerPixelFired", true);
    user_pref("extensions.toolbar.mindspark._4jMembers _.successUrl", "hxxp://download.radiorage.com/installComplete.jhtml");
    user_pref("extensions.toolbar.mindspark._4jMembers _.toolbarCollapsed", false);
    user_pref("extensions.toolbar.mindspark._erMembers _.toolbar.ownSearch", true);
    user_pref("extensions.toolbar.mindspark._erMembers _.toolbarCollapsed", true);
    user_pref("extensions.toolbar.mindspark.hp.enabled", true);
    user_pref("extensions.toolbar.mindspark.hp.enabled .guid", "[email protected]");
    user_pref("extensions.toolbar.mindspark.lastInstal led", "[email protected]");



    ~~~ Event Viewer Logs were cleared





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Sat 07/11/2015 at 15:35:04.58
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    645.

    Solve : Problem with "ads by name" in Firefox?

    Answer»

    Hi,
    yesterday popup ads started showing up not BLOCKED by adblocker. This problem only occurs in Firefox not on the other browsers. The popups are claiming to be "ads by name" or "powered by name". PLEASE help, my browser is very SLOW and I can't get RID of the popups.Un-install and re-install FF to see if that MAKES a difference.

    646.

    Solve : ''Help, SuperDave-Genius!''?

    Answer»

    Any improvement in your laptop?yes, less freezing, thanks a lot but I wonder why still when I enter my password during login of my email accounts
    yahoo does not recognize it [''try again to enter your password''], sometimes I need to login 4-5 times in a row/refresh
    before I get access to my email account..

    RE the MBytes beta version,

    for your info, this is what MBytes TOLD me :

    Quote

    Rootkit scanning is now incorporated into the Malwarebytes Antimalware, so we don’t need to run the beta tool
    “Rootkits: Enabled”
    Quote
    for your info, this is what MBytes told me :
    That is good news. I was not aware of the development. Sorry, I can't help much with the email accounts.

    Click Start> Computer> right click the C Drive and choose Properties> enter
    Click Disk Cleanup from there.



    Click OK on the Disk Cleanup Screen.
    Click Yes on the Confirmation screen.



    This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
    ********************************************
    This step will remove all cleaning TOOLS we USED, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create Registry backup
    • Purge System Restore Points
    • Re-set system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.
    ********************************************
    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT WARNS you before you interact with a risky website. It's easy and it's free.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    647.

    Solve : Malware error 895-system 32.exe?

    Answer»

    As usual, I'm having problems downloading the program you want me to use.

     I click on the RUN ESET ONLINE SCANNER and the ESET Online Scanner EULA opens up and I select that I agree to the terms and conditions and click on START.
     
    Then a installer opens up and it reads; "This website wants to install the following add-on "OnlineScanner.cab" from "ESET, spol. s r.o.
    click on INSTALL.

    ---------------------------
    Windows Internet Explorer
    ---------------------------
    To DISPLAY the webpage again, the web browser needs to
    resend the information you've previously submitted.

    If you were making a purchase, you should click Cancel to
    avoid a duplicate transaction. Otherwise, click Retry to display
    the webpage again.
    ---------------------------
    Retry   Cancel   
    ---------------------------

    I click on retry and another window opens and it says add-on failed.

    Please let me know what I should do next.

    Thank you,
    Sheila
    Allow the add-on. It should work.I did allow the add-on and nothing happened. Start over again and see what happens.Still  no luck.  I've tried it MANY, many times.  Add-on failed.  Ok, please tell me how your computer is running now?So far, so good.  Thank you so MUCH for your help. Ok, we can do some clean up.

    Click Start> Computer> right click the C Drive and choose Properties> enter
    Click Disk Cleanup from there.



    Click OK on the Disk Cleanup Screen.
    Click Yes on the Confirmation screen.



    This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
    ********************************************
    This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally USING some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:

    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create Registry backup
    • Purge System Restore Points
    • Re-set system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.
    *********************************************
    I suggest using WOT - Web of TRUST. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
    Safe Surfing!
    648.

    Solve : SUPERSpyware hiccup?

    Answer»

    Hi

    I operate two identical Dell desktops both running Windows & Pro 64 bit

    Both have the same anti spyware programs, however when running a FULL SUPERSPYWARE scan one consistently reports a fault and is unable to continue and has to CLOSE, whereas the other scans time after time without a qualm!

    On the malfunctioning PC nothing changes no matter what action is taken, including twice a total clean uninstall & reinstall
    It simply does not MAKE sense and sadly the SUPERSpyware F&Q’s do not supply any guidance

    The other antivirus PROGRAMMES I use are fine and report no problems
     
    What anti-spyware program are you trying to run?

    649.

    Solve : Norton Security download question?

    Answer»

    I ordered, what I thought was a CD, for Norton Security and it turned out to be nothing more than Product Key, good for 5 computers. I only need it for three, however, I am limited to 250MB/day and I have no idea how many MBs this download needs as it is not stated on the box. If I get up at 2:00AM I can download unlimited amounts of MBs until 7:00AM. Does anyone know whether Norton Security could be downloaded to a DVD and then loaded on to my 3 computers. I really don't want to have to get up 3 mornings at 2:00AM to download this program ONTO 3 computers.  I'm avoiding calling Norton as they route their calls to India and I know those FOLKS there are very computer savvy, but it doesn't do me any good as I can't understand what they say, so I was hoping someone here had the answer as to whether I can use the product key to download to a DVD.  THANK youI did a search and I can't find any Norton Security ISO FILE.

    650.

    Solve : Unauthorized Remote Control?

    Answer»

    Dont know if this applies in this area but i dont know where else it would go so sorry if it doesnt fit the category.

    previously i was speaking too an ex friend who I didnt wanna see anymore on a website "meetme.com" after the conversation ended abruptly he took over my computers MOUSE and keyboard for about an hour. I was would like too know how he did it and how I can fight this. I know it was him because of what he was typing while I had notepad open.

    - thanks to ANYONE who can help!Some of the PEOPLE on the Microsoft forum say that it can happen.
    Unauthorized Remote Access
    Quote


        If you connect to the internet DIRECTLY from your Computer to a Modem, consider purchasing a Router and placing it between your Computer and the modem.  A router will block most all unexpected inward connection attempts to your network.
        If you have a Wireless Router in your network, make sure you have wireless security enabled.  WEP security has been cracked.  WPA2 is currently the best CHOICE for security on your router.  Pick a good password.
        If you have XP Home or XP Pro with Simple File Sharing enabled, deactivate the Guest account.  All network connections will authenticate through the Guest account.  To do this, bring up a command prompt window (Start -> Run -> "cmd") then enter the command:     net user guest /active:no
        If you have XP Pro with Simple File Sharing Disabled,  then make sure the "Administrator" user has a password (by default, it doesn't).  Also make sure all users on your computer have passwords in place.
        Consider installing a Firewall product on your computer.
    I think it is odd that nobody thinks to simply pull the network cable when this happens.

    First thing you should do is check for malware, I think.