Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

751.

Solve : Re: not genuine microsoft windows?

Answer»

You're mixing two PROBLEMS.

Quote

this just started a few months ago and no-one knows how to get rid of it

Sorry to say, but everyone you've spoken to MUST be a few bytes short of a genuine copy.

How about buying a license?

Quote
It is also affecting sound and different things

That is caused by something else.

You're the only person, along with Microsoft, who can resolve the first SITUATION but we can help you fix the second problem if you give us more information.

What are different things?

Have you scanned for Spyware/Viruses?

Your first step is to buy a legal copy of Windows and install that.

If you FEEL your copy is legal, then call Microsoft right away. They are great about answering these questions.
752.

Solve : keep on getting these cookies?

Answer»

Hi,

I was wondering if anyone MIGHT be ABLE to help me here. I KEEP getting these cookies things from the trend Micro PC-Cillin and are set to be deleted automatically. It's just that i want to know where they come from. I've googled them but am not satisfied with my finding. so i thought i might want to drop off here and get some help from experts.

The cookies i've been getting are

cookies_225
cookies_1198
cookies_1638
cookies_3235
cookies_1020

Your ideas will be appreciated.

Thank you in advanceOpen them and look inside?

If you're going through that much TROUBLE to identify cookies, you might as well manually accept and deny them like I do...

753.

Solve : What is wrong with my computer????

Answer»

will someobody please HELP me out?!?!?!  i just turned on my computer today and a popup said that i have 12 viruses on my computer and it says i should click on the bubble and download an antispyware program.  and it says my system configuration is not safe.  my background has been changed to something that says "Warning! Spyware threat detected on your PC!"

the problem is i downloaded the program and now it says i have to pay $50 to use it!  i decided not to buy it but the *censored* bubble pops up every minute!  i already have norton antivirus but its messed up so i tried uninstalling it but when i RESTART my computer the program is still installed and the same exact THING happens all over again.  i cant change my background or anyting else under display properties and i cant change any settings on my computer either!  

how the *censored* do i fix this!

i WOULD like an answer really soon if possible becuase my computer is getting slower and i think i am getting more and more viruses the longer i wait.What's the name of the antispyware program,... SpyFalcon?its callled antispyware soldier.


how do get rid of it and fix my problem?Download / update / run:

CRAP Cleaner
http://www.filehippo.com/download_ccleaner/


Spybot
http://www.tucows.com/preview/310138


Ewido
http://www.majorgeeks.com/Ewido_security_suite_d4677.html


Adaware
http://www.download.com/3000-2144-10045910.html

Alan <><  i had that too. do what was said and scan in safwe mode with system restore offA brief description from a site that lists rogue spyware apps turned up the following:

AntiSpyware Soldier        antispywaresoldier.com           aggressive, deceptive advertising, stealth installations (1, 2, 3); false positives work as goad to purchase [A: 8-21-06 / U: 8-21-06]

patio.  8-)uninstall the program before the scans

754.

Solve : Spyrecon - how do you find out if you're being key?

Answer»

Have a read here, especially the first few.

http://www.google.com/search?hl=en&lr=&q=malware+with+instant+messagingA friend informed me that my ex-husband is spying remotely on my computer usage via an "undetectable" spyware program. He seems to think it was something called SniperSpy? I use SpywareDoctor to scan my computer daily and also CCleaner to keep my computer cleared of old junk. I have not found anything called SniperSpy or any other spyware thus far... but could it be there lurking and "undetectable" After much research on spyware programs like this, I am confused about a related issue: keylogging, IM malware, etc... raised a question in my not-so-computer-savvy brain...

I use a laptop for home and work usage and gain wireless INTERNET access via wireless network both at home and at work. My home network, I am not so worried about, but can  someone at my work place view what I am doing on my computer via spy-programs on the network, or does this stuff have to obe downloaded directly onto my computer? Recently, a colleague had personal information about me that they WOULD have no way of knowing other than bugging my home phone or accessing my computer!!! Made me wonder about this stuff and how to protect myself. Price not being an option, I would like to know how to make sure my computer is secure wherever I may be.

Thanx in advance for any possible help  First off Welcome Aboard MAIA,

It's best to start a new thread with your problem so things don't get too confused.
DLoad and run Spyware Doctor which is a free program designed to sniff out keyloggers especially.
After that update all your other protection programs and run the scans one at a time.
If you feel you don't have enough protection post back for suggestions.
Most are free and well WORTH having, but you have to remember to use them on a regular basis for them to be effective...

patio.  8-)

755.

Solve : Quake?

Answer»

This Quake program installed itself on my pc from a download on a crack site and now I'm GETTING this message saying 'your computer is infected with a back door virus this trojan aloows the user to PERFORM malicious actions against your computer'.

I ran SB SEARCH and DESTROY and adaware, both of which said they had deleted it, yet i'm still getting this message.

How SERIOUS is this? What should I do to rid it?Download AVG Free, disable system restore and scan in safe mode.also dl smitfaud

and ewido

756.

Solve : Too many viruses?

Answer»

Quote

Do you have the latest Windows updates?
Viruses, Worms & Spyware oh my!  

1. Update AD-Aware, Spybot S&D, AVG & Ewido all one at a time but don't scan yet.

2. Boot into safe mode.

3. Turn off System Restore if you haven't already.
   a. Click Start, right-click My Computer, and then click Properties.
   b. Click the System Restore tab.
   c. Click to select the "Turn off System Restore" check box, click Apply and then click OK.
   d. Click Yes when you receive the prompt to the turn off System Restore.

4. Click Start > Run and paste the following into the Run prompt and click OK
(*Note - You may want to paste this into notepad & save this to a .txt file on the desktop so you can copy it once in safe mode)

Code: [Select]"C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +procnuke +immortal
5. Perform a Full System Scan with Ad-Aware and remove anything it finds. When it's done you won't be able to close the window so just minimize it.

6. Now do scans with the other programs as well one at a time removing anything they find (Spybot S&D, AVG, Ewido)

7. Reboot into Normal Mode

8. Rename HijackThis.exe to HJT2K6.exe

9. Do another HJT scan and attach the new logfile.

If you have any problems along the way let me know.  


Dejavu   I like the way you think JPH. Just adding a bit to your already excellent SUGGESTIONS.  
Maybe this way we can actually get an Ad-Aware scan to work.  updates on problems,   no msblast.exe in task manager.   Windows is fully updated.  i followed the process JPH gave me,  i updated all the viurs programs successfully.  then restarted in safe mode,  (system restore was already turned off by me earlier, but i double checked)  then i opened ad aware  your way,  although i'm not sure what you meant by "+procnuke +immortal"   so if that was important than i missed it,  which might explain the result,  the error message popped up again just as it always does,  however if you don't do anything,  ad aware run's normally,  as far as i can tell,  then promptly after quarentining what it found,  it closed on it's own.    the other's programs  spybod and AVG both ran well, found a bunch of crap,  then got rid of it,  then  when it came time to run ewido,  about half way through the scan, the computer froze.    now what?     should i try again,  also, i should probably find out what you meant by "+procnuke +immortal "  before i try again.        Thanks guys!!i dont know what he meant either but im guessing it was kinda important or he wouldnt have bothered typing it, have u TRIED unistalling reinstall adaware Quote
Your Hijackthis log is full of nasties, the above method is a cleaner way to remove them all.
[highlight]Come back with a fresh HJT log after you have done the cleaning as described.[/highlight]
(Don't skip any steps or change the order)
Fair Enough.  here is the new logfile   also,  the popups have calmed down a bit.   Thanks a lot for all your help,   we're almost out of this.Do you mind if we experiment on you?
Great!

Download and install PrevX 1, just go with the defaults and let it do it's own thing.
http://www.prevx.com/security.asp
PrevX 1 will ask you to re-boot during this process.

After it has scanned & cleaned your computer, re-boot and run a fresh HJT log.

Let's see just how good PrevX 1 really is, so far I have found it to be excellent.
It is touted to remove Surfsidekick so now we can test it. So ,  i gladly tried your experiment,  however, after the program had scaned about 25% the computer froze.   it did say that the computer was infected though.   so  right now i'm trying this again,  and we'll see if it can complete a scan.are you tring in safe modeYes,  i have tried it in safe mode,   It wont' work at all,  because evidently it needs the internet to run.   in normal mode It still freezes the computer upon completing 25% of the scan.   Thanks thoughSometimes you just have to format and reinstall.....Hey Doomsayer, sorry I've been away for a few days. Let's see if we can manually fix the remaining nasties.

Once again, go into Safe Mode with System Restore turned off

Go to Start > CONTROL Panel > Add or Remove Programs
See if there is an entry for SurfSideKick, if so remove it (you might have to enter a code that it gives you)
Also search for an entry called PSDream or something similar and remove it if it's there

Do a HJT scan again and put a check next to the following entries if still present:

R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - _{EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: UserInit=userinit.exe,fmpkhdm.exe
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - C:\WINDOWS\system32\nsu56.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: (no name) - {87E3AC65-4EF0-420D-F7A8-671331AA31B4} - C:\WINDOWS\system32\lcea.dll  
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O4 - HKLM\..\Run: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\isuspm.exe -startup
O4 - HKLM\..\Run: [zmb] C:\WINDOWS\zmb.exe
O4 - HKLM\..\Run: [dywtvu] C:\WINDOWS\system32\dhrcww.exe reg_run
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [yvdvx] C:\WINDOWS\system32\dhrcww.exe reg_run
O4 - HKCU\..\Run: [Utprlvei] C:\Documents and Settings\Byron Irving\My Documents\s?curity\?poolsv.exe
O4 - HKCU\..\Run: [PSDream] "C:\Program Files\PSDream\PSDream.exe"
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\ugpnpmgr.dll (file missing)
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\wsdsp.dll (file missing)
O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\dlvacm.dll (file missing)
O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\mwhtml.dll (file missing)
O23 - Service: FreezeScreenSaver - Unknown owner - C:\WINDOWS\system32\FreezeScreenSaver.exe

Choose "Fix checked" (you might be prompted to reboot, if so boot back into safe mode again)

Delete the following files:

C:\WINDOWS\system32\fmpkhdm.exe (or C:\WINDOWS\fmpkhdm.exe)
C:\WINDOWS\system32\nsu56.dll
C:\WINDOWS\cfg32r.dll
C:\WINDOWS\system32\lcea.dll
C:\WINDOWS\cfg32o.dll
C:\WINDOWS\zmb.exe
C:\WINDOWS\system32\dhrcww.exe
C:\Documents and Settings\Byron Irving\My Documents\s?curity\?poolsv.exe
C:\WINDOWS\system32\FreezeScreenSaver.exe

Delete the following folders (and all their contents):

C:\Program Files\SurfSideKick 3
C:\Program Files\PSDream

After you've done all that, run another HJT scan and post the new log file.PrevX does not NEED the internet to scan but you need to explore the PrevX options.
Does the phrase 'Automatically upload malware for research' ring any bells for you?
Try looking under PrevX>Advanced>Protection Plus
757.

Solve : Need a hand?

Answer»

Yes
Keep it handy. I WOULD recommend backing up any important DATA and using it here, but a lot of folks will be along, no doubt, to assist you in recovering this FUBAR'ed installation. Sometimes you can, sometimes you can't...Barring a repair install you can try the FOLLOWING to recover that wonked up .dll...

Go to Start / Run and type in sfc /scannow and hit Enter.

Have your CD handy as it will ASK for it. Do not interrupt the process, let it run til it's finished.

patio.  8-)

758.

Solve : Backdoor Trojan and spyware?

Answer» THANKS for all the HELP guys, there are no more pop-ups, no more security WARNINGS, the internets WORKING at the normal speed, the system performance is slightly faster but still WELL below how it used to be. How do I get it back to normal?
759.

Solve : Trojan horse viruses...need help?

Answer»

Did you try looking for the installer and removing it? It may be SOMEWHERE in a temporary folder.spybot might helpHJT log.
You need to read the posts in here and absorb what is said, we don't just post links to scanning programs hoping they will fix your problems. Quote

HJT log.
You need to read the posts in here and absorb what is said, we don't just post links to scanning programs hoping they will fix your problems.

Best advice i've seen this month ....

patio.  8-)The MSI popping up all the time is USUALLY the result of an incomplete or corrupted install. If it gives you any detail information you might try removing the program involved and running the installation again (if it's something you want installed). Quote
HJT log.
You need to read the posts in here and absorb what is said, we don't just post links to scanning programs hoping they will fix your problems.

I ran the htl and TOOK care of the stuff  that needed taken care of and what not. The windos installer is still there and i don't know how how to find it's temp folder or the program that it is trying to install. I do have the windows update but it will not update untill i give it's ok,and it hasn't notified me in a few weeks. There's no programs in my add/remove that I didn't put there,and I havn't dowwnloaded ANYTHING in about a month, eversince i have been trying to get rid of viruses,and adware. How do I find whatever is trying to install to get rid of it?
Post the error message from MSI.There is a fix for the Windows Installer at MS's web site...I can't find it any where :-? I'm lost as to where to look. And the only time it ever does it is when i first boot up the pc. this is the message:
      The feature you are trying to use is on a network resource that is not available.
  
Click OK to try again or enter an alternate path to a folder containing the installation package 'WPO2OO2A.msi' in the box below.
Use source: c:\hp\tmp\src



 When I push cancel it still trys to install and then this message pops up again and i have to repeat cancel 3 times for it to disapear so that my pc will continue its start up.  Help :-? Quote
There is a fix for the Windows Installer at MS's web site...

Is MS :Micro Soft?yesOkay after hours and hours of searching, the only thing that i was able to figure out was that the program trying to install was a office word free trial thing that was being activated to install when Piolet was started....so i got rid of piolet and now i don't have it anymore.  Thank you all for all your help THOUGH!! Office Word phoning home ? ? !! I'm aghast !

What is Pioulet ?I believe Office is now "loaded" too.
760.

Solve : I NEED REAL HELP PLEASE!?

Answer»

then what do i do?
change the load thing so cds boot firstcan you please take me through how i do that?
press f2 yell let you get to a screen then U shhand but use your gogle buttoiould i cant remember exactly how off hand but use ur google buttonive gone through it but i cant find anyhting in there to change the boot sequence any more help??i just did it all you do is rapidly press f2 right when u start the computer go to boot sequence and change the order


im running XP HOMEI just can not LOCATE the bott up sequencce ive tried everyting? wehat does the screen look like?
its bluee.. well i got to go to bedI think we have now proven that you need to gather up your legal Windows CD and take it to a shop.

Clearly we can not get you started, and even if we could you would be stuck again very soon.

Some situations can not be fixed with a forum. This is ONE of them.

761.

Solve : explain virus please?

Answer»

Every ten minutes "norton" (that is what we have)keeps popping up saying that they caught this.  I would like to know what it means and this intruder who and what is it.
Details:      

Attempted Intrusion "MSRPC SrvSvc NetApi Buffer Overflow (2)" against your machine was detected and blocked.
Intruder: 216.95.1.60(1377).
Risk Level: High.
Protocol: TCP.
ATTACKED IP: TOWNSHIP-EAXE5D(216.95.155.124).
Attacked Port: netbios-ssn(139).
Many more details are needed. Norton Antivirus only? Norton Internet Security also? See below.

some one is tring to nuke your firewall so they can get in It's probably a worm rather than an attacker that singled you out. Some PC in Hamilton, Ontario is most likely infected with the Wargbot worm (or something similar) and it was trying to spread onto your computer, luckily your firewall/IDS (Norton) blocked it.Sorry about that but we have the whole norton package for the year.  This message is been coming up almost every 10 min. for the past month and who would be trying to nuke the firewall.  We are on a network Is there a way i can find out if it is an intruder and where and who they are?Check your routers log files to see where it is coming from. You can also BLOCK ports 135-139 in the router to prevent any more intrusions. This should not interfere with the internal network using those ports but will prevent any traffic going to or from the internet on them.There should be a setting in your firewall to turn off the notifications.You should look into buying a hardware firewall such as a router.Hi - I have looked at your post, and it is clear what has happened:

The intrusion type was a buffer overflow, which can be serious.
A buffer overflow is the process of trying to put more data in a certain memory location that is too small for that data to go - therefore causing a crash of the computer or program.
If this is done successfully, the attacker can gain access to the computer.

I have knowlege of buffer overflows as I program them to test sofware for security holes and it is most likely that the attacker (which i believe was a person and not a bot) has programmed the exploit in C language.

This can be serious so I suggest that you report it to your ISP or whoever has CONTROL over the network.
(also report it to norton by means of contact).

hope it works out ok! Quote

some one is tring to nuke your firewall so they can get in

see i told you cuz ive done it to my friend with send multiply packs at there computerDo you really think that some HACKER has been attempting to run this exploit against Nancy's computer every 10 minutes for the past month? Besides, if it was a hacker he/she would have tried alternate methods of gaining access after learning that this particular exploit DID NOT work. No one has control over her network   you shouldn't tell her that. The Wargbot worm uses this very same buffer overflow to spread itself and it just so happens that it ATTACKS the same netblock that it's on.

Attacking PC: 216.95.1.60
Nancy's PC: 216.95.155.124

UUNET Technologies, Inc.
NetRange: 216.94.0.0 - 216.95.255.255

See the connection?JPH is exactly right and I believe this is a very common problem.
I have the same thing happening to me & I asked my ISP to track down the user and tell them to clean the infection from their machine.
They weren't interested so neither was I, turning off the firewall notifications works well for me.
762.

Solve : Virus Problem??

Answer»

I have been having problems logging on to the net alot recently, re-booting seems to help for a little while, but not long, so I ran a HijackThis and alot of entry's around 16 on make me wonder about them, I have run the usual spyware/trojan stuff, I know the drill, can someone take a look at my hijackthis files and tell me if they SEE any problems there? I did CHECK the files at http://hjt.networktechs.com/parse.php but that site is a little vague on what needs to be removed....
I'm on WINDOWS XP Pro SP2 Intel Pentium II 256 Mb RAM
Download, INSTALL, update and run in safe mode respectively:

AVG Free
Adaware SE
Windows Defender
Spybot S&D
with system restore off

763.

Solve : spyware virus....?

Answer»

What? People following instructions? A novel idea!  Patio... I went to the link you GAVE me before.. but then the .dat file you advised, I have not got/downloaded it... (because this month my days are pretty hectic....occupied... "sounds stupid"...still....

so... again.. I have been noticing one more change with my computer, as I insert my USB, the computer itself starts downloading or copying.... the files.. it never used HAPPEN before...

its bugger killing..... right now, I am scanning the computer with a malicious SOFTWARE I just downloaded from Microsoft updates.... I will see how it goes... meanwhile please keep advising me... Quote

Perhaps a good format and REINSTALL would solve ALL of these and probably more problems.

I'm sticking with this advice from [highlight]12 days ago[/highlight]. Your problems would have been solved by now.
764.

Solve : A V G Anti Virus?

Answer»

Recently INSTALLED AVG 7.1 professional version on my PC after reisnstalling the OS (98).

After that whenever I click the AVG icon on my desktop to start AVG to scan my PC for virus, I am always getting the message
" A required DLL file MSVCP60.DLL was not found"

What's the problem?Try downloading the dll file to your C:\Windows\System folder

Good luckuninstall reinstall AVGGrab a fresh DLoad and re-install it...packets go missing sometimes.I looked for the dll on google and i found one... if you want me to email it to you my email is
[email protected]

Once you get the DLL:
You have to put this file in System32 folder, if you dont know how to do this go to:
1. My Computer
2. Double click on your hard drive [C:]
3. Go into your WINDOWS folder
4. Scroll down until you see the System32 folder
5. Just drag and drop the DLL file into this folder...(System32)

If you have any problems or other missing dll's email us and we will copy the files for you.
-Hale's Computer Service
Visit us!
www.halescomputerservice.vze.comi won't trust it from the internet a fresh dl and reinstall will doOn top of that unless you're REALLY interested in *censored* and phoney Rolex watches a Forum is probably not a good place to post your e-mail address...And if you looked like you were selling ANYTHING from that website that post would also have been deleted, FYI.   Quote

Grab a fresh DLoad and re-install it...packets go missing sometimes.

They shouldn't, though. As SOON as downloads and installations start corrupting on you you NEED to diagnose RAM and HDD.It can happen from connection problems as well...
765.

Solve : im back,and need some help?

Answer»

k my pc been actin up lately prob from the porn sites to be honest,but before i begin i use avira anti virus,spybot and sygate firewall, k when i click to connect to the internet it connects and makes all the noise andall the sudden it says request is not supported,all devices are plugged in but the request is not supported,so i have to restart my pc and then it works,and another problem i had was my sound it goes on and off,just like my internet connection,now thanks alot guys and i HOPE this makes sense,i havent ran a virus scan yet i was just seeing what u guys thought.go to another computer and DL ewido adaware.. if you cant on your computer do it on your computer...


and what os do you have?? is WINDOWS up to date??

when did this start happening

unlovedwarrior Quote

k my pc been actin up lately prob from the porn sites to be honest,but before i begin i use avira anti virus,spybot and sygate firewall, k when i click to connect to the internet it connects and makes all the noise andall the sudden it says request is not supported,all devices are plugged in but the request is not supported,so i have to restart my pc and then it works,and another problem i had was my sound it goes on and off,just like my internet connection,now thanks alot guys and [highlight]i hope this makes sense[/highlight],i havent ran a virus scan yet i was just seeing what u guys thought.


It would make a lot more sense if you used some punctuation rather than just commas. (This is one long, poorly constructed sentence, k?)

Paragraphs and capital letter can dramatically increase the chances that someone might want to read through all of this and offer help as well.

Is the system clean from malware? If not, all bets are off.  Is there a reason you haven't run your scans yet ? ? ?

I would do that first, in Safemode with System restore turned off...

patio.  8-)I found 1 virus and i did all the scans in safe mode and all the shi bang.Besides that i still get the error "all devices are connected,request is not supported." Has ANY1 had this problem?and how smy grmmer now ?Personally your grammar is terrible, if you need to know ,and by the way that error message makes no sense whatsoever...

Try Again.A Google search on all devices connected error this request is not supported yields numerous finds.  http://www.google.com/search?hl=en&lr=&q=all+devices+connected+error+this+request+is+not+supported&btnG=SearchI am going to call earthlink.Then before that google it and see what comes up.In conclusion my grammer is terrible and you guys rock thanksk let me begin:
some programs on my pc are starting to take way to long to RESPOND, for ex. I will double click on a game it wont pop up until like 5 mins after i clicked on it.Another thing is while I am surfing the net itll all the sudden wont respond,but it is still connected.I ran all my scans and defrags,no spyware and no viruses.I use ccleaner,sybot,anti vir,sygate firewall which isnt up tp date cuz it wont let me update.My pc has over 1 gb ram,and i got a amd anthlon 64 bit processor,so there is no reason for my pc to be acting like this.From what I told you guys what can u conclude whats happening,and hows my grammer now?thanks alotActually your grammar has gotten worse if anything...how much free space is on that HDD and when is the last time you ran defrag ? ? ?Check your Task Manager cpu & ram usage, look at the numbers at the bottom.
How come you have so little running?I like my computer to run as fast as it can so I disabled, or set to manual, all the unnecessary services and stopped all unnecessary programs from running at startup.
766.

Solve : Ive learnt my lesson?

Answer»

Quote

Mainly becuase i would prefer to find the problem and find a fix for it without having to format and lose everything, just seems a bit lazy to me.

I don't know about that, but sometimes a good format and reinstall is quicker, and is a guaranteed fix, for a while.
Quote
Quote
Me personally i would boot into safemode and delete anything that relates to Rhianna just to be safe.

She's not even that good...

Yeah. Did I MENTION I still listen to Ella Fitzgerald? I've got a casket...

Quote
Quote
Mainly becuase i would prefer to find the problem and find a fix for it without having to format and lose everything, just seems a bit lazy to me.

I don't know about that, but sometimes a good format and reinstall is quicker, and is a guaranteed fix, for a while.

I think reformatting is a bit overkill in this situation, though. Quote
I think reformatting is a bit overkill in this situation, though.

It was a general comment. I have seen some of these threads go on for weeks, when a reinstall would have fixed the problem in hours.  
lol but its up to the ownerThere's a lot to be said for both cleaning and reformatting, you can always do both.
That WAY you gain some knowledge in both areas.

I also believe that MANUAL cleaning by deletion of files and or removal of entries with HJT does not necessarily complete the job properly.
I even have my doubts about so called cleaning programs.

You only have to uninstall a program then check your registry and program files to see what crap is left over from LEGITIMATE programs. Quote
lol but its up to the OWNER

And what their time is worth. Ours is free, so I suspect that's why some of the threads do drag on....... Quote
Quote
lol but its up to the owner

And what their time is worth. Ours is free, so I suspect that's why some of the threads do drag on.......

Nope, that's because we get paid by the hour... Quote
There's a lot to be said for both cleaning and reformatting, you can always do both.
That way you gain some knowledge in both areas.

I also believe that manual cleaning by deletion of files and or removal of entries with HJT does not necessarily complete the job properly.
I even have my doubts about so called cleaning programs.

You only have to uninstall a program then check your registry and program files to see what crap is left over from legitimate programs.
no program is prefect and the left over are just a side efffect thats why its always good to reformat every so often
767.

Solve : Anybody feel like helping a noob.?

Answer»

It's probably Windows XP on one CD and SP 1 or 2 on CD 2.. I have that as well, except that mine are copies. So we 'll never know I suppose.

Ah well, I can live with that. Quote

You say that when you go to Run and type msconfig you get an error. I was under the impression that you lost the RUN prompt? Well either way applying the NoRun fix won't hurt anything. About the reg file, it sounds like it is still a txt file. You probably have Windows set to hide file extensions for known file types, which means it's probably actually named fix.reg.txt. You can open any folder and go to Tools > Folder Options > View and UNcheck "Hide extensions for known file types" then click Apply. Then you can make sure it is actually named fix.reg it should look like this if reg files are correctly associated:



Here is an updated version that will also fix MSConfig if it is still present in the correct path:

Code: [Select]Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoRun"=dword:00000000
"NoViewContextMenu"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableConfig"=dword:00000000
"DisableSR"=dword:00000000

[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions]
"NoBrowserContextMenu"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE]
="C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\MSConfig.exe"
I will also attach a copy of the reg file to this post in case you don't feel like messing with the hide extensions setting. Just unzip the reg file to the desktop and either double-click it or right click it and choose Merge. Then after it has been imported successfully, reboot.

Your HJT log looks clean.

- JPH

Well....Some things have returned to normal since the begining of this thread. Like the "Run" prompt. It's there, but can't find msconfig. I assume that some things were fixed while running all the cleaners provided by the kind members here at CHF.

Quote
it sounds like it is still a txt file
Yes it is. And no matter what I do....I can't change it.

Quote
You probably have Windows set to hide file extensions for known file types

No. I thought of that. But my folder options aren't set up that way. And... the zip file you provided extracts as a text file too.
I'm stumped, I tells ya.

And Patio. It is a legal copy of XP PRO. I'm not sure what else I can do to prove it, so I won't bother. Actualy...I'll go one step further to prove it. And that's only because you are trying to make me out to be liar. Here's what ya do. Send an email to MEEC Enterprise.
(Maryland Education Enterprise Consortium)
Ask them if they sell XP pro to their students, for campus use only. Ask them how much they charge for the disks, how many disks are supplied, and what they look like. If ya don't want to do that...I'll take Levi FTW!!! lol I'm kidding dude. Still...You check it out for your peace of mind.
Can you open regedit?By no means was i trying to make you out a liar...FAR from it.
If you knew how many issues we have stumbled through here with people who are not legit you would understand my trepidation...

As to your listed copy of XP i'm glad it is what you say it is. I cannot keep track of every University issued copy of XP and remember what they in fact look like...

Any offense taken comes with my apologies.

Carry on.

patio.  8-) Quote
Can you open regedit?

Yes. regedit opened fine from the run prompt. What should I do with it?


Patio:  [smiley=beer.gif]
OK, open regedit and go to File > Import
Change the "Files of Type" to "All Files" then scroll to the reg file I attached earlier and open it. It should still import anyway even if it's a txt file as LONG as all the text is still there. If it says it successfully imported then reboot and see if msconfig, right-click etc. is working.Well....You F'n rock dude.

Everything has returned to normal. Thanks sooooooo much for your help. And to think....I was so close to giving up.
Again...thank you so much. You really know your stuff. And... thanks to the other members, kind enough to give me a hand.
Oh...incase you can't tell...I'm doing a happy dance.  
Great! You're welcome Levi.  
I'm glad things are back to normal now.
Your reg file associations are still messed up though if they are still showing as txt files.
Let me know if that is the case and we'll fix that too.  

- JPHHmm. Yeah, they are still showing as txt files.OK, I've attached a fix. Just import it the same way you did the last one.JPH where did you learn this stuff?? Quote
JPH where did you learn this stuff??
--> www.vmodeling.com   Quote
OK, I've attached a fix. Just import it the same way you did the last one.


Awesome dude.....You did it. Thanks again, mang. You rock. [smiley=beer.gif]
Quote
Quote
JPH where did you learn this stuff??
--> www.vmodeling.com  


lol Quote
Awesome dude.....You did it. Thanks again, mang. You rock. [smiley=beer.gif]
Great, you're welcome.
Now that you're back to normal you might want to set a new system restore point.  [smiley=beer.gif]

unlovedwarrior:  [smiley=grin.gif]
768.

Solve : Am I infected??

Answer»

Hi all
I had some spyware problems a few days ago but I think I've eradicated them
Can SOMEONE just take a quick look at my attached HijackThis log file and tell me if I'm still infected or not?
ThanksI don't see any infections.  [smiley=thumbsup.gif]

You can fix this:

O23 - Service: PTT - Unknown owner - C:\DOCUME~1\test\LOCALS~1\Temp\PTT.exe (file missing)

The other "file missing" entry refers to msgrapp.dll (MSN Messenger Module) which is often mislabeled by HJT as being missing so you can probably just ignore that. If you want to though you can go to C:\Program Files\MSNMessenger and see if it's there or not, if not you can fix that entry too.

- JPHOK cool
ThanksNo PROBLEM.  [HIGHLIGHT]  hijackthis_030.zip [/highlight]     <<<


** absorb the sarcasm-please! **

769.

Solve : My computer is infected. Logfile review plea?

Answer»

Too many problems to list. I am running XP and have used Adaware and Registry Mechanic.
Here is my Hijackthis file. Can someone please review it and offer some assistance?
Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 1:44:11 PM, on 10/23/2006
Platform: WINDOWS XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=1296000&_lang=EN&lc=1033
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - EXTRA context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.comcastsupport.com/sdcxuser/asp/tgctlsr.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160335230497
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NetMeeting Remote Desktop SHARING (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe (file missing)

From what i can tell your protection package leaves a few blanks...
I see Windows Defender.
And you mentioned you ran AdAware and Reg Mechanic...
DLoad install and add these to your arsenal:
AVG Free.
Spybot Search and Destroy.
Ewido Free.

Update each of them. Run the scans in SafeMode with System Restore turned off and let us know the results...

patio.  8-) Quote

Too many problems to list.

Oh, come on and throw us a bone. List at least 5 big ones.Cannot send email.
Cannot print.
Cannot copy files to CD.
Cannot update Defender.

Only four. Just off the top of my pointy head...

Do you have a real Windows CD if needed?Yes.

Oh yeah, now I get a message that my software may be counterfeit and not genuine.
So that makes five!That may be the biggest problem. What service pack is installed? When did all of this start? Do you know Microsoft's phone number? You will need it, and it is no big deal IF this is a genuine, shiny Microsoft CD.

Personally I think this is a GREAT time for a reinstall based on just the listed problems, but that's just me.when was the last time you reformat if you ever have.. how long have you had it?? youll be able to start over once you reformat
770.

Solve : uncles computer?

Answer»

ok my uncles computer is ACTING werid or i should say one process is acting werid.
its the?? well i cant find it on the hijack this log i TOOK. but the process only acts up when he or some one goes to log off. then it will say the process is trying to stop, then the computer will lock up on the person. i tried googleing the process but the google lord doesnt give me an answer so im thinking its spyware. it says its from my aunts account but she barely gets on that computer. ive done all of the scans the usual way(spybot adaware, avg both of them) its an upgrade xp home from me. so im thinking that it might just be a mess up from the upgrade. but here is the hjt log

oh i removed norton after i did the log scan and installed avg.

TIA

unlovedwarriorYou know the drill by now...
More Info.

How can we assist if we don't even know the name of the offending process ? ?

im trying to get ahold of him to get the name again.. as soon as i get the name you will tooif you think its spyware, go straight to Spybot S&D, its really useful, besides, TRY Ashampoo anti-spyware, Spybot is free but Ashampoo , u can get for a 30day trial ... try it...

Good luck........ Quote

ok my uncles computer is acting werid or i should say one process is acting werid.
its the?? well i cant find it on the hijack this log i took. but the process only acts up when he or some one goes to log off. then it will say the process is trying to stop, then the computer will lock up on the person. i tried googleing the process but the google lord doesnt give me an answer so im thinking its spyware. it says its from my aunts account but she barely gets on that computer. ive done all of the scans the usual way[highlight](spybot adaware, avg both of them)[/highlight] its an upgrade xp home from me. so im thinking that it might just be a mess up from the upgrade. but here is the hjt log

oh i removed norton after i did the log scan and installed avg.

TIA

unlovedwarrior
but thanks for the replyAnd the name of the offending process would be ? ?devldr32.exe, my aunt says but. im GOING to try and ask my uncle when he gets home. i googled that one and its for audio hardware or somethingSince you've been such a good guy this month i'll give you one of my personal favorite links...

Here Ya Go

patio.

p.s. It is installed with Creative LABS software...k thanks i wonder what would have made it go werid
771.

Solve : MSN Messenger hacked?

Answer»

I just ran VBA32 in safe mode and it FOUND:

AdWare.Win32.Dm.n in the location D:\j386\Apps\App07888\luregwmi.exe

TR.Spy.Banco.FR.2.C in the location C:\WINDOWS\system32\SMTP.ocx

Is it safe to delete these?
What else do I need to do to keep my computer safe?

Thanks!dont open anything that you dont trust WITHOUT scanning it first.I hate to say this but I'd reformat and start again. *OUCH!*
I wouldn't save anything that he has sent you.
Then go and change every password you have ever used.
Even if you rid your computer of everything he sent you, he still knows too much already. Quote

[highlight]I hate to say this but I'd reformat and start again. [/highlight]*OUCH!*
I wouldn't save anything that he has sent you.
Then go and change every password you have ever used.
Even if you rid your computer of everything he sent you, he still knows too much already.


Sorry, Fed. I know that does hurt you.   Lucille, I don't know what you decided to do but YES it is safe for you to delete those two files. The SMTP.ocx file is the library file that your ex talked about that gives his malware the ability to e-mail information to him. I agree that reformatting and INSTALLING Windows again is the only way to be 100% certain that your computer is no longer COMPROMISED. If that simply isn't an option for you then you can still boot into safe mode and run HJT and post the logfile here and I will have a look at it for you.

- JPH
772.

Solve : virus program?

Answer»

my o/s  is windows  x home edition.my norton antivirus program  is about to expire plus increase in price.   do you recommend avg is it compatable with windows, I concern about anything that free.what do you recommend :-?AVG works fine, in fact your computer will run much better without Norton.
HINT: Check back here for Norton removal INSTRUCTIONS, I think Patio has them. thanks for the  info. now how do i remove norton from my system . Open Control Panel / Add-Remove Programs  / scroll down to NAV / change-remove.

Make sure you have the Norton cd handy, if necessary.

Alan <><  

Sometimes Norton is a stubborn litte dude and doesn't want to go away.  Here is a tool from Norton to remove the leftovers if Add-Remove programs doesn't do it.

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039

Alan <><  DLoad and run the tool below...
 
Norton Removal Tool
 
1) USE Add Remove Programs first and un-install Norton...
2) From Windows Explorer search for any FOLDERS named Norton and Symantec and delete them...
3)DLoad and install ERUNT and have it make a backup of your registry...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next i      instance of Norton. Continue til you have reached the end of the registry...
5)Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6)Now run the Norton Removal tool you DLoaded...
7)Empty the recycle bin...
8)Go to My Computer and right clik the C: drive and select Properties and run disk cleanup...
9)Re-boot and run disk defrag....
 
There you're done !
 
See how easy Symantec makes it for you to dump their product ? ?
 
Quote

DLoad and run the tool below...
 
Norton Removal Tool
 
1) Use Add Remove Programs first and un-install Norton...
2) From Windows Explorer search for any folders named Norton and Symantec and delete them...
3)DLoad and install ERUNT and have it make a backup of your registry...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next i      instance of Norton. Continue til you have reached the end of the registry...
5)Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6)Now run the Norton Removal tool you DLoaded...
7)Empty the recycle bin...
8)Go to My Computer and right clik the C: drive and select Properties and run disk cleanup...
9)Re-boot and run disk defrag....
 
There you're done !
 
See how easy Symantec makes it for you to dump their product ? ?
 


easy you say?
All this might take a week for an unexperienced user
It would be easier to REINSTALL windows. Quote
my o/s  is windows  x home edition.my norton antivirus program  is about to expire plus increase in price.   do you recommend avg is it compatable with windows, I concern about anything that free.what do you recommend :-?


As Christmas is coming, if you tell me what version of NAV you have installed I will give you a serial number to use forever.no WARES no illegal activity...
773.

Solve : Registry values won't delete a BHO?

Answer»

Hi

I got nailed by about 12 BHO's and one is a VERY annoying pop up called antispyware
soldier. I tried BHO Demon and NORTON and neither of the two are working. I also tried a program "hijack this " to remove the BHO's- The thing is, is that when the programs delete the BHO they reinstall themselves.
I tried also to delete them in the registry and the same thing happens- they come right back. I'm told there is a program somewhere that's reinstalling the BHO. Where MIGHT i look for it to delete it? I'm tempted to format the MACHINE if I can't figure this out.

Tks
JEff blimpguy ....... Is it possible that when you ran hijackthis....that you missed something...... how about POSTING a logfile and let us look at it .

dl65  rename the hijackthis to hjt2k6 to make sure NOTHING is hiding from youYou will need smitfraudfix, here's a very good link...

http://www.bleepingcomputer.com/forums/topic69874.htmlFED- Can I send you a case of beer ? Smitfraud nailed every BHO in the registry and did it amazingly fast. Does the guy who wrote the software have a site to donate to? I was going to post a logfile, but it was huge. I ran it again after smitfraud and it was cut in half. Thanks guys for the help, I dreaded the possibility of my laptop being in the shop for a week.

JeffThat guy from bleepingcomputer (Grinler) sure does a good job, rather than plagiarise him I pay him tribute by sending people to his threads. [smiley=thumbup.gif]
I'm glad you're up & running. Quote

FED- Can I send you a case of beer ? Smitfraud nailed every BHO in the registry and did it amazingly fast. [highlight]Does the guy who wrote the software have a site to donate to?[/highlight] I was going to post a logfile, but it was huge. I ran it again after smitfraud and it was cut in half. Thanks guys for the help, I dreaded the possibility of my laptop being in the shop for a week.

Jeff
Yes, his name is S!Ri.
http://siri.urz.free.fr/Fix/SmitfraudFix_En.phpive the program and i love it
774.

Solve : Program opening problems?

Answer»

How to remove WINFIXER...

HTTP://www.bleepingcomputer.com/forums/topic18610.html

Don't FORGET the Ewido ONLINE scan.

775.

Solve : critical system falure?

Answer»

hi me again this thing is pissing me off!!this icon KEEPS saying crotical SYSTEM falure and whan i click on it it takes me to a website!How can i get rid of it?Its not in my program LIST HELP!!i just got my computer back from getting fixed.See the replies to your other post. It is not fixed.

776.

Solve : how to get AV if getting kicked offline?

Answer»

I'm at work and suspect that a virus is terminating the wireless connection on one computer.  There was no AV program to begin with.  (big nono I know)  The connection is good because I am on the same network right now.  How do I fix this if I can't get online?

comp specs:  Dell Optiplex GX260
XP PRO  Service Pack2 (2002), Pentium 4 1.80 Ghz, 256 Mb RAMDownload it on a different computer then copy the file to the problem computer.what's the most efficient WAY of doing that?  I started with floppies, but AVG FREE is pretty big, and have already gone through 5, should I continue this way?USB memory stick.
I can't remember how big AVG is but I believe it to be less than 10MBs or so.
Floppies hold 1.4MBs.Can you start in Safe Mode + NETWORKING on the problem computer?ok thanks alot.  I'll update and let you know what happens.

777.

Solve : ad - ware se?

Answer»

Hello,

I've got an internal ERROR on my ad - watch event log, and a message that says if I want to correct this error, to import a NEW SITES file. Can anyone please tell me How to import a new sites file. THANK youJust remove the PROGRAM and reinstall it. Quicker and easier.

778.

Solve : Remove a zombe?

Answer»

I think my windows 98 IBM APTIVA has a "zombie". If not is some other KIND of virus. This used to be my only computer and I have had problems with it proccessing in the middle of the night or when it had been left idle for more than a few hours - not consistant. Usualy I would find that the computer would freeze after I would start to use it again, reboot and things would return to normal. Over the years I have replaced the hard drive ( from a bigfoot 6GB to a Maxtor 32GB) and the probem quieted down but never fully went away. I got crazy over this past summer and I decided to restore windows and erase all the junk. So I saved all the files I wanted and burned them to a CD. After reinstalling windows the computer refused to install the CD ROM drive ( the driver is on the recovery CD and I have never had a probem with the CD ROM before). After scouting local repair shops we decided it would be cheaper to buy a refurb computer. So we took the Maxtor hard drive and installed it as a secondary drive in the refurb Windows 2000 NT and reformated it. I have not had a problem with the refurb computer.  We put the Bigfoot back into the APTIVA and it booted right up and the CD ROM worked after I reinstalled windows from the CD.  Now it's baaaaaack to proccessing all the time again.  I still have dial up account and when  I tryed  to connect to the internet with the APTIVA it is so bogged down it won't even load a website ( like a home page).  AVG came with the refurb WIN 2000 NT so I burned the files to a CD and intalled it on the APTIVA and it found nothing ( granted I can't connect the APTIVA to the internet and update it). Same story with Ghost Surf ( spyware) and Spybot S&D.  Im WORKING on a way to get the updated files on to the APTIVA. It seams that every time I get close to finding the infected files something else will go wrong. One week it was the printer driver that was forgotten, now it's the display and it looks as if it's running in safe mode ( but it's not).  So my first concern is how do I get rid of the bug on the APTIVA?  After it's cleaned I plan to never take the APTIVA online again. My second concern is if the virus, bug, zombe whatever could still be on the Maxtor drive and infect my NEWER WIN 2000 NT computer.
Currently I have and use on both systems:  Firefox and Thunderbird, Ghost Surf 2005, Sygate Personel Firewall PRO, Spybot Search and Destroy, AVG Free Edition.
Today I booted the APTIVA into DOS and ran Scandisk. It made a few repairs but it  did not fix the problem.
Thanks in advance for your help.  Aptivas are older machines so it could be hardware or software. I would first start by checking the hard drive with the free diagnostics download from the Maxtor web site. Next test the RAM with a free download from www.memtest86.com  Both are free and just take a little time.

If all check out OK, then save the files and format the drive and reload Windows again. Do not reintroduce the files you saved and do not connect to the Internet. If the problem PERSISTS it is a hardware fault.

779.

Solve : Memory Error, New Dell Laptop?

Answer»

On a new Dell laptop, I get (on startup) an error message "The instruction at ...... referenced location ....... .  The memory at this location could not be 'read' " (SOMETIMES it says 'written'.)  The application program is MsDetct, part of McAfee Spam KILLER.  Dell technical support says it is a software problem, not a problem with a memory chip.  Their diagnostic program PASSES all the memory tests.

So I try to contact McAfee technical support with a question.  WHOO, boy!  They are tighter than King Tut's TOMB.  No way to contact them.

Any helpful suggestions from ANYONE would be appreciated.

HalI would try the free download at www.memtest86.com. If that passes, then I would ignore the McAffee and probably delete it. It's probably just a 3 month trial anyway.

780.

Solve : urgeny help!?

Answer»

I  have a problem that  some  VIRUS files can't kill by the antivirus software,when I try to kill it all by myself  ,and then  the screen JUMP a tip  to TELL you not to kill the virus!who can tell me the way to cut these files !Thank you!What have you USED to run the kill?This should be good...Don't run the kill yet, we need to keep this alive.

Do you know the name of the virus wang?Where's Raptor when I need him?

781.

Solve : Norton Antivirus, My Mortal Enemy?

Answer»

Quote

Glad to see your back Proph.

Sorry,about the bad exchange friend.  

http://www.ats.cornell.edu/helpdesk/win/nav/uninstallnav.html


o and thanks !!  
Quote
Quote
That's why we refer to it as the Norton Virus.  


yes yes now don't get me wrong , I am not saying it fixes problems.... but it does not actively try and destroy ur pc...
lies lies when my sister FRIED the NAV files on our GATEWAY it never worked right again even after taking it to the techs.. so Norton is just evil...I don't get how Norton is still selling there product, with most people either turning to different brands or getting free antivirus software.they still have a huge followingAnother thing, IF you know your program is flawed why not FIX it? Like make it easier to UNINSTALL it. I have to admit though, either then the slowing down of my computer and other assorted flaws, it did a superb job catching anything the internet sent at it.Because their sales have not dropped off enough (yet).
782.

Solve : Being redirected to wrong website (hijacked?)?

Answer»

I'm new to the forum and I have a problem or two.  I am clicking on a hyperlink that should take me to a site where I can sign up to possibly mystery shop ( I can hear the groans.  Just trying it out).  Anyway, when the hyperlink is clicked, I am sent to the proper URL, but the site onlyy lists places where I can spend money on products or services RELATED to mystery shopping.  I know it might be that the site owners intended to send me there, but I don't think that is the CASE.  I'm waiting on contact from them in response to my question to that effect.  I believe the URL is somehow being renamed (tho not in the address line of my browser).  Is this possible.  The URL   IS  the correct URL that I'm clicking on.  If it HELPS, the URL is http://www.mysteryshoppinginfo.com/subshops.html.  Through reading the information at the beginning of the forums, and some info on the virus thread, I downloaded ccleaner and used it.  It found two registry problems.  One said Registry Key   Hkey_local_machine\software\altnet.
The other was HKEY_USERS-1-5-21-220523388-115176313-682003330-1004\software\microsoft\InternetExplorer\Main\FeatureControl\FEATURE_
LOCALMACHINE_LOCKDOWN\iexplorer.exe!=w=1.  Do I need to go into registry and delete these or are they harmless or even usefu even tho ccleaner presented them as an intrusion (my interpretation).  I'll present my hardware here
 
Compaq Presario R3000
Windows XP   svc pack 2
80 gig hard drive
Firefox browser
384 mb of ram
Thanks for any help. Very frustrating being redirected (if that's what it turns out to be)hi and welcome to the forum. i got the email reply from the forum on this topic but i was busy this weekend but what PROTECTIONS do you have? AV ANTISPYWARE etc? what's the address the you get sent to that you think is getting redirected?


unlovedwarriorThanks.  I run AVAST, SpywareBlaster, and AVG 7.5.  The site where I'm directed to is

http://www.mysteryshoppinginfo.com/subshops.html.  Again, I think this in not the site

where I should be directed, but I have a request in to join a forum with the company.  

Someone there should at least be able to tell me what I SHOULD be seeing.  Is there a

way to tell if the site is masquerading as the site I should be going to (the URL is

correct.  Thanks
i get redirected there so its something dealing with the site.. they might be redirecting so contact themThanks for your help.  I'll see what's up.It's not exactly a re-direct it's a spoof and they are responsible.Did you get SpywareBlaster directly from the Javacool website?  There is a rogue anti-spyware product taking advantage of the Javacool product name.  The rogue tool is downloaded from www[dot]spywareblaster[dot]com.  Check out spywarewarrior.com for more info.

783.

Solve : Re: am i getting hacked??

Answer»

what SCANS have u done? what protections do you have? when did this start happening?? did you do the scans in safe mode with SYSTEM restore off

spybot

adaware

avg anti-spyware

and UR AV scan

Ccleaner

unlovedwarrior

784.

Solve : New AntiVirus Program??

Answer»

Hey there,

I'm thinking of getting a new/different Antivirus program.  I use to have Avast and from then to now I have AVG.  Is there another (free) antivirus program out there that's good and worth going for?  BitDefender sounds interesting, has anyone used it?

Later.JacobRichards111 ...... Why do you want to stop using AVG ?
I'm a little surprised to hear that you are looking for something else ........
Are you using the new version 7.5 or the older ONE ?

dl65  It's...............  hm, yup the old one lol.

I like AVG, I just wanted to try and see the other anti virus programs.  You know, Experiement with new ones.  The only programs I've used are Avast and AVG, wanted to see what else is out there.

 ...What IS out there?If you want to experiment take a look at Prevx1 and go for a wander through their site while you're there.
http://www.prevx.com/Slightly off topic:

I just dwnloaded the new AVG and it doesn't seem to have overwritten the previous one. Should I DELETE it? I'm a bit worried it al might go when the 'free trial period' ends.unistall the old one and install the new oneAs of JAN 15 AVG will no longer be free......You didn't read the who thing:

 GRISOFT is announcing a new version of the AVG Anti-Virus Free EDITION. This new 7.5 version with improved performance and full compatibility with the latest Windows Vista version is available. Users that are using AVG Free 7.1 will be provided with a specific dialog, within the next few weeks, with the opportunity to choose the right option fulfilling their needs. [highlight]AVG Free 7.1 version will be discontinued on 15th of Jan 2007.[/highlight]For an online scan, www.trend.com has never let me down yet.

785.

Solve : where is firewall on pc??

Answer»

how do i NAVIGATE to see if the FIREWALL is turned on w/ MS windows XP compaq pc?  thanksGo to Control Panel and OPEN Windows Firewall.It's near the henway.

786.

Solve : win32.mersting.b trojan?

Answer»

everytime i run my zonealarm antivirus/spyware i pick this up but can't remove this.  Does ANYONE know of a way i can get this off my system.

ThanksYou have to use your Google BUTTON to remove it:

http://www.google.com/search?hl=en&q=win32.mersting.b+trojan


&LT;--------------------I've tried that. NONE of those sites really give a good explanation on how to remove it.Run your SCAN(s) in safe mode with system restore turned off.try AVG antispyware free like how JPH sugggested

787.

Solve : Ever heard of "Gameguard"??

Answer»

I just got Phantasy Star Universe and it came with GameGuard. However, I just found out that GG is a form of malware and possibly a trojin. I do not want this, I really want to get rid of it and I don't think deleting the GG folder in the PSU folder is going to help anything. I don't want to be stuck with this and I need some help, badly.I guess it disabled your google button too.

http://www.google.com/search?hl=en&q=delete+gameguard


<------------------Where did you find out that it could possibly be Malware / Trojan.
This other website seems to say otherwise:
http://eng.nprotect.com/nprotect_gameguard.htm


Chris Quote

Where did you find out that it could possibly be Malware / Trojan.
This other website seems to say otherwise:
http://eng.nprotect.com/nprotect_gameguard.htm


Chris


Right here.

http://en.wikipedia.org/wiki/Gameguard

http://nvd.nist.gov/nvd.cfm?cvename=CAN-2005-0295from what i READ from the bottom link. the gameguard just gives any process unrestricted i/o giving access.


but i USE gameguard for my flyff game and i trust ithttp://xforce.iss.net/xforce/xfdb/18952

http://secunia.com/advisories/13928

More stuff here. says it messes with the npptnt2.sys driver.

It's either the npptnt2.sys(says on top link) or npptnt2.vxd(says on bottom link).Personally i wouldn't trust wikipedia to define cat to me...

But that's just me. Quote
Personally i wouldn't trust wikipedia to define cat to me...

But that's just me.
Why not?because anyone can put an article on there and say they are a specialist in that field....And any article is open to being edited.

There have been a few slander lawsuits already of a questionable beginning... Quote
because anyone can put an article on there and say they are a specialist in that field....

KIND of LIKE here.   Quote
Quote
because anyone can put an article on there and say they are a specialist in that field....

Kind of like here.  


yep but we havent had any lawsuits YET Quote
dude, u should go read ur installation terms, and if there's nothing that says u give permission to install gameguard on ur pc; go call the company!

I'm almost SURE it will be in the EULA somewhere...
788.

Solve : AVG not Free?

Answer»

Since AVG is not going to be free ANYMORE, anyone know of any free anti-virus software?It is still free. AVG 7.1 support ends in January, but version 7.5 is available and free. Read the whole web page after drinking some coffee. Quote

Not free ?? how come ??


Now Proph ,our kind is not to know such things we MUST be LEFT in a
dark cave,chained and poorly fed.

The Proph Rocks...With Mad picture looked good. [smiley=vrolijk_26.gif]
Let's try to have a spam free forum for a while guys. Make the EXTRA EFFORT so I don't have to.   Quote
Let's try to have a spam free forum for a while guys. Make the extra effort so I don't have to.  

Okay GX1_Man,I am being serious for a spell.It was explained to me well by
Rob..................in-joke.Never thought about it.Will comply.

Sorry guys.I owe you one.

Robert
789.

Solve : windows defender/virtual memory?

Answer»

microsoft has a phone number for pc security help (866.727.2338). i was on hold over 30 minutes & gave up.  i tried to find out how to SEND microsof t an email or get online support for Windows Defender, but couldn't navigate thru microsoft's  website to their email address nor their online support specific to windows defender---can anyone send me this specific info?

i've been getting the following message w/ windows defender:
windows defender encountered an error: 0x80508012.  An unexpectted problem is preventing the program from scanning your computer for unwanted software.  Try to scan your computer again.

any idea how to figure out this problem?

ALSO getting messages about virtual memory too low---i removed a bunch of stuff from the pc which only has 256 mb of ram, & c drive total size is 7.85gb w/ 1.05 gb free space.  any other suggestions?  thanks!!!!!!!!!!!!!!!!!!Re: the Defender error, I suggest you look at some of the results of a Google search: http://www.google.com/search?hl=en&q=error%3A+0x80508012&btnG=Google+Search

Re: virtual memory: right CLICK on My Computer, select Properties, select the Advanced tab, click on Settings (under Performance), select the Advanced tab, and see what your settings are for virtual memory.XP on 256 MG of RAM is the bare minimum...consider adding some RAM to that system.soybean, i checked my virtual memory & there is 192 mb total paging file size for all drives---do I need to change this, & if so, change to what?  

i heard a suggestion to download CCleaner to free up more space on my computer--is this a good idea?  

also saw "Reminder" on bottom toolbar when I opened pc this afternoon.  I don't know what it is a reminder for as I could not view any properties so I closed it.  Could this be a computer viur or spyware?  thanks, dede Quote

XP on 256 MG of RAM is the bare minimum...consider adding some RAM to that system.
My computer runs amazingly with 256mb of ram, but I have A gigabyte of virtual memory.mikewithaprob:  any suggestions how i can get my virtual memory to a gigabyte?

Quote
soybean, i checked my virtual memory & there is 192 mb total paging file size for all drives---do I need to change this, & if so, change to what?  
Yes, I would change it.  Here's a reference which suggests 250MB on a computer with 256 MB of RAM, as the Minimum setting, but also set a high Maximum size — 700 or 800 MB or even more if there is plenty of disk space.  For more, read the article: Virtual Memory in Windows XP
.

Quote
i heard a suggestion to download CCleaner to free up more space on my computer--is this a good idea?  



CCleaner is a very good cleanup tool to free up some space on your hard drive and to remove some clutter from Windows Registry.  So, it's a good thing to install and use on a regular basis.  

Quote
also saw "Reminder" on bottom toolbar when I opened pc this afternoon.  I don't know what it is a reminder for as I could not view any properties so I closed it.  Could this be a computer viur or spyware?  thanks, dede
Can you post more info on that?  Do you have anti-virus software installed?  Do you have any spyware removal tools installed? Quote
mikewithaprob:  any suggestions how i can get my virtual memory to a gigabyte?
Go to My Computer, Properties, Advanced, Under Performance click Settings then set it to what ever you want it to be.soybean,  initial size virtual memory was set at 192 mb & max size at 384.  the pc said RECOMMENDED size is 381 so i set initial size at 381 & maximum size at 384--will this help the problem w/ messages i've been getting that virtual memory is too low, & will this work w/ only 1.55 gb free space on c drive?

i posted: also saw "Reminder" on bottom toolbar when I opened pc this afternoon. I don't know what it is a reminder for as I could not view any properties so I closed it. Could this be a computer viur or spyware? thanks, dede
soybean's response: Can you post more info on that?  Do you have anti-virus software installed?  Do you have any spyware removal tools installed?
dede:  I don't have any more info about this weird "reminder" that shows up on toolbar---what is this critter? i have NORTON antivirus & windows defender that i run--is this enough?  thanks!  dedeUntil we have more info on the "critter" telling you how to get rid of it would be mere guesswork at this point...

The more you contribute the faster you can arrive at a solution.My pc recommended virtual memory size of 381 so i set initial size at 381 & maximum size at 384--will this help the problem w/ messages i've been getting that virtual memory is too low, & will this setting work w/ only 1.55 gb free space on c drive?  
 
How do I collect more information to report here about the "Reminder" that pops up as an icon on the bottom toolbar on my screen from time to time?  There are no properties provided, I think it only gave me the option to open or close.   i have norton antivirus & windows defender that i run--is this enough?  thanks!  dede  
    
790.

Solve : Backdoor:/win32/hackdef.L?

Answer»

I have been having problems with my internet lately and my ISP TOLD me to run a VIRUS scan. To make a long story short I ended up using Microsoft Windows Malicious Software Removal Tool (I know its a huge name for it). It said there is a Malware on my computer by the name of "Backdoor:/win32/hackdef.L". So I run the Norton full system scan and now I have figured out that Norton sucks a big one! So anyhow I need to know at how to get rid of this so my comp will stop acting weird. Also I am looking for a better Antivirus/Firewall program so I can quit buying the Norton trash! Thanks to all in adv!!


P.s. My comp specs, System:              Comp:
                                Win Xp Pro          INTEL P3
                                Ver. 2002            500mhz
                                Service Pack 2     512 RAMEwido Online Scan now called AVG Antispyware should remove it for you.
Come back when you're clean.look into AVG free 7.5Alright I have done the online scan and I also removed Norton Virus off my comp. Thanks fed for your advice! Also is AVG a good anti-virus? Or is there something better? I have had some problems in the past with AVG.Works for me. What was your issue with it?Whatever you are using has DISABLED your spell checker. Quote

What you mea Norton is crap whut version do you use 1999 , Norton knows what the actual virus or trojan is -----AVG cant even tell the difrennce between WPESPY.DLL and a trojan thas sad,Norton knows that WPESPY.DLL is a program and not always used for haking.
Man you really have a grudge against AVG. But Norton sucks, i mean i suck at PC's but even i know Norton is clumsy. It slows down your P.C, makes loadsa false positives, and costs a fortune for something that AVG CAN do for free!


Chris Quote
Quote
What you mea Norton is crap whut version do you use 1999 , Norton knows what the actual virus or trojan is -----AVG cant even tell the difrennce between WPESPY.DLL and a trojan thas sad,Norton knows that WPESPY.DLL is a program and not always used for haking.
Man you really have a grudge against AVG. But Norton sucks, i mean i suck at PC's but even i know Norton is clumsy. It slows down your P.C, makes loadsa false positives, and costs a fortune for something that AVG CAN do for free!


Chris
Well said, Norton is far too expensive for the (not very good) job it does
Add that to the fact that it's very HARD to remove and can cause problems when it is finally removed, and I see no reason to use it instead of, say, AVG or Avast or Antivir or any other free AV
791.

Solve : file ends up on other computer?

Answer»

Last week a file ended up on my computer from my roomate's computer.  Does anyone know how this would have happened?  We have an unsecured wireless network.  Something similar happened to a friend of mine last year, where files from his computer ended up on his roomate's, but I don't know how.  I wanted to secure both computers so it won't happen again.  Any information would be greatly appreciated so I can solve the problem, if POSSIBLE, and put her MIND at ease.  By any chance , are both of these computers set up on a network to share a common Printer and file share ?

Is the network yours ?


DL65  no they are not networked together other than the internet network...

792.

Solve : AVG Anti-Spyware 7.5?

Answer»

This is a good freeware just LIKE AVG Anti -virus.

Have you OTHERS tried it?

http://free.grisoft.com/doc/20/lng/us/tpl/v5Been runnin it for almost 2 years...formerly known as Ewido.

Good Stuff.

793.

Solve : Norton 2006?

Answer»

A client I support keeps having troubles with Norton 2006 on his system giving him a 1814 ERROR code for Live Updates. When selecting to manually run a live update it comes up as No Connection to Internet, yet he is ONLINE via Broadband.

I uninstalled NAV2006 and reinstalled, and it seemed to go away, but then came back.

I then followed the steps at Symantec for this error, but it's still there. It will take updates via downloading the defininitions from Symantecs site and executing to run the def update. Also the system is clean of any viruses and behaves normal otherwise.... Any suggestions???

I'm thinking it might be a registry problem since he upgraded from Nav2003 to 2006, and maybe an orphan entry is there still for 2003 when he had dial-up via AOL.

Maybe a full rebuild is needed, but he doesnt know where his system restore CD's are for his eMachine and it doesnt have a D partition with the restore set there, so I'd like to fix this without having to rebuild if at all possible...

How did you un-install Norton's ? ?Uninstalled through add/remove programs in CONTROL panel.Check the Norton site for the latest version of LiveUpdate. There might be a CONFLICT with that software that reinstalling LiveUpdate will fix. I've seen this happen before and (thus far) it worked successfully.Thanks...I'll give it a try

794.

Solve : Virus and inability to log onto internet?

Answer»

If I have a virus is it possible this is why I am not able to log onto the INTERNET. :-?  I had two motherboards replaced and then I couldn't log onto internet.  I then was told that I have a virus.  I could log in before the motherboards were replaced.  I'm not sure if replacing the motherboard can bring in a virus. :-/  When I tried my dial-up CONNECTION it said there was no dial tone.  I went through my provider and there was no problem on their end--all my other computers are able to log in on the same phone line but my laptop isn't able.Check that the phone line is plugged into the RIGHT modem socket.

Download, unzip, install and run Everest HOME Edition
Everest

Select Computer>Summary from the left hand screen.
Right click in the right hand screen & select Copy All
Paste the DETAILS in here.Replacing the motherboard and not reinstalling Windows can cause a lot of problems as well. Is that what you did?

795.

Solve : HELP nextpart smtp relayer?

Answer»

I have been running SPY SWEEPER and continue to get that displayed each time.  My computer is running very slow and think that it is the cause please helpdl

avg anti-spyware


adaware


spybot


Ccleaner


uninstall the program


turn off SYSTEM restore

reboot in safe mode

what antivirus and FIREWALL  do u have??

do full scans
unlovedwarrior
What e-mail client are you currently running ? ? ?

Try re-installing it after you have BACKED up your data...

796.

Solve : Pop ups causing stress?

Answer»

I have a problem, I keep getting a pop-ups from the bar at the bottom of the screen, they come from  fashing yellow triangular ICONS (just like the exclimation triangle in the smiles) in the right corner. They are advertising all SORTS of spyware, antivirus ect, they are called virusbusters and antivirmis, what can do to delete them.

Do me a FAVOUR?
DOWNLOAD & run RogueRemover from http://www.malwarebytes.org/
It's a very small download and will only take you a minute to try.Afterwards DLoad and run a little ditty called Shoot The Messenger which ENABLES you to disable or turn on messenger service.

What protection programs do you run on that machine ? ?

797.

Solve : Zone Alarm advice please?

Answer»

By default Zone Alarm installs as Internet zone on stealth mode and TRUSTED zone Med (sharing) zone. As it WOULD SEEM to off better security with both in stealth mode, what would be the PROBLEMS with having the Trusted zone in High (stealth) mode?You wouldn't be able to access shared folders, PRINTERS etc, and no one else on the network would be able to see your computer or access shard folders, printers etc.

798.

Solve : Broadband advice please??

Answer»

I am switching from dial up to broadband and have the below security. Is there any other programs that it would be wise to INSTALL for this purpose?

AVG 7.5
AVG antispyware
Cyber Hawk
Spybot
Spyware Blaster
Spyware Terminator
Ad-Aware
RemoveIt
WIN Patrol
Zone Alarm
 
and use Advance Windows Care2 and CCleaner.
All the above are updated daily and run daily.
 
Quote

I am switching from dial up to broadband and have the below security. Is there any other programs that it would be wise to install for this purpose?

AVG 7.5
AVG antispyware
[highlight]Cyber Hawk [/highlight]
Spybot
Spyware Blaster
Spyware Terminator
Ad-Aware
[highlight]RemoveIt [/highlight]
[highlight]Win Patrol[/highlight]
Zone Alarm
 
and use [highlight]Advance Windows Care2 [/highlight]and CCleaner.
All the above are updated daily and run daily.
 
you look pretty GOOD but i havent heard of some of thoses programs , wheres your antivirusAnti virus is AVG 7.5

All the programs can be found on Majorgeeks.com or Snapfiles.compantherman......  With what you have installed , you should be ok ......

[highlight]AVG 7.5[/highlight]                 Good
[highlight]AVG antispyware[/highlight]    Good
Cyber Hawk
[highlight]Spybot[/highlight]                 Good                                                                
Spyware Blaster
Spyware Terminator
[highlight]Ad-Aware SE[/highlight]           Good
RemoveIt
Win Patrol
Zone Alarm
Advance Windows Care2
[highlight]CCleaner[/highlight]                  Good


I use the ONES marked good on my machines and have never had a problem.

dl65  didnt see your Av until now. just scan your computer often and every once in a while scan in safe modee with system restore turned offSpyware Terminator

im looking into that one Quote
Quote
Spyware Terminator

im looking into that one

I'll help you out.
Crawler, the company behind ST had CONFIRMED links wirth IBIS who, in turn were the vendors of the infamous Wintools, Websearch and Huntbar.
However, Crawler has ceased all affilliations with malware vendors and appear to now be respectable.
That doesn't mean to say that TS is effective at what it claims to be because, simply put, it isn't.
ok
799.

Solve : Spyware/Trojan invasion?

Answer»

Yesterday I made the unfortunate mistake of opening a bad exe and I got flooded with trojans and things like Virus-Busters and WinAntiVirus Pro ect.
I took care of most of that stuff with some info on another site but now I am busy battling these horrendous pop-ups from heavy.com, STOPzilla, and searching for anything on google is a joke, you find the site you want to go to and clicking on it just prompts ANOTHER lesser search site trying to find what you want but sending you to shopping sites and basically sending me in circles.
I also cant check my mail so I had to download mozilla just for that.

I did a scan with Hijack this and this is what I came up with.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\{3CAE5751-07D4-1033-0330-060221060001}\Update.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\SSTEM3~1\winspool.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\W?nSxS\c?rss.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\FlashGet\flashget.exe
C:\Downloads\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=gzcDwIZ4YTF_Mt9gXDLfJSh4VbU
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {F41D3F47-8AFF-8E7A-8FAD-A428E0753197} - C:\WINDOWS\system32\rjudpk.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINDOWS\system32\axxrtvdx.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - C:\WINDOWS\system32\ixt0.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {E025A7B7-ED73-4E0F-B8ED-7129381E0E50} - C:\WINDOWS\system32\jkhfg.dll (file missing)
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
O2 - BHO: (no name) - {F41D3F47-8AFF-8E7A-8FAD-A428E0753197} - C:\WINDOWS\system32\rjudpk.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Ealb] "C:\WINDOWS\system32\SSTEM3~1\winspool.exe" -vt tzt
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\I used both Ad-Aware and SPYBOT S&D and they continuously found new spyware, I had also went into safemode and ran both of the spyware protectors. It seemed like the spyware just reinstalled itself onto the pc right after Adaware and Spybot had gotten RID of them.

And Ive been using Norton Anti-Virus to get rid of the Trojans ect.
Also to answer your question why these things were even allowed onto the pc in the first place is because Norton was myseriously disabled "no idea on that one" and the second I turned it on it spotted the Trojans and deleted them.

So you say I should get rid of Winspool C?rss.exe and these ipv6mons.dll and rjudpk.dll?
I wont until you confirm this. Once fixed/deleted I will redo a scan with Norton, Adaware and Spybot. Quote

I used both Ad-Aware and Spybot S&D and they continuously found new spyware, I had also went into safemode and ran both of the spyware protectors. It seemed like the spyware just reinstalled itself onto the pc right after Adaware and Spybot had gotten rid of them.

And Ive been using Norton Anti-Virus to get rid of the Trojans ect.
Also to answer your question why these things were even allowed onto the pc in the first place is because Norton was myseriously disabled "no idea on that one" and the second I turned it on it spotted the Trojans and deleted them.

So you say I should get rid of Winspool C?rss.exe and these ipv6mons.dll and rjudpk.dll?
I wont until you confirm this. Once fixed/deleted I will redo a scan with Norton, Adaware and Spybot.
Did you have system restore off when you ran the scans?I turned off system restore, and it seems that the spyware still gets reinstalled over and over again.
I need to find a way to stop this soon because the list of stuff it finds is growing.
Also today Norton found 3 different trojans on different occasions within one hour.
This is looking pretty grim  .
And I don't want to install Panda because I will have to uninstall Norton for it to work.
And I dunno if I can find the Norton disk to reinstall.Running another AV program will not break Norton...the scans that were suggested are online scans.Ok, an update, I just downloaded AVG and went into safemode, unplugged my internet connection and ran it. This is what it found and Quarantined:


 Adware.Softomate
 Trojan.Small
Downloader.Nurech.m
Downloader.IstBar
Trojan.Mezzia
Downloader.TSUpdate.j
Downloader.TSUUpdate.o
Worm.Banwarum.f
Downloader.PurityScan.co

After this I ran Spybot and Ad-aware and found minimal problems.

THEN I got out of safemode and did a HJT scan, hopefully this will SHED some light on things.
Lemme know if you want me to POST the log.Would probabaly be a good idea, then we can see whats left over.


Chris
800.

Solve : Computer seems to be alt-tabbing by itself?

Answer»

Hi everyone,

I'm relatively knowledgeable about computers but I've come across a problem that I cannot for the life of me solve.  I've searched these forums and have found no solution.

It all started when I dropped a 1,000 PAGE book on my keyboard.  A few days later I noticed my computer seems to alt-tab randomly.  This is, of course, annoying beyond words.  At first, it only did it when I hadn't used the keyboard in a while, but the situation deteriorated over a month or two to the point where I would be typing a sentence and *poof* alt-tab.  Also, if I'm playing a game (mostly Final Fantasy 11), sometimes I'll be typing something and it'll "lag" -- I'll press keys... ....... ... ......... ... THEN what I typed will appear.

At first I thought it was spyware or something, but I got the idea to change keyboards.  Still does it... not nearly as much or as bad but it still does it. I have (and keep updated) PC-Cillin and Webroot Spysweeper but both come up blank when I do full scans.  This is really annoying me as I can't play most of the games I have because it'll alt-tab and as most of us know, most games shy away from alt-tab support (Half-Life 2 comes readily to mind).

Any help would be much appreciated.  Thanks!hows the keyboard connected?

try USING

avg anti-spyware

adaware

spybot

Ccleaner ( USE the issues scan to clean up ur register just make sure to back up when it asks to)


unlovedwarrior Quote

hows the keyboard connected?

Its a USB keyboard.

So you're saying its most likely spyware/adware causing the problem?  I was kind of hoping it was something like a bad USB port or something...have you tried puting it in another USB port??Do you have a PS/2 keyboard you can try using on that computer?Everyone should own a PS2 keyboard...Never occurred to me to try a different port... I'm at work now but I'll try it when I get home... *crosses FINGERS*

Thanks for the replies

Update - Well that sucks.  Old keyboard is USB and new keyboard is PS/2  Meaning of course the port(s) is/are fine, meaning its probably spyware... yay! Unless someone can think of something else to try, it looks like I'll be scanning my night away...Keep us posted.  did you install any drivers for the new and or old keybord??A real PS/2 keyboard does not need drivers. They are built into Windows.