InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 801. |
Solve : Borland? |
|
Answer» Ok, let me preface this post letting you know that I am not a genius when it COMES to computers. I am slightly concerned about a name that is FOUND in the file field of my computer search program (not sure what to call it---it's the program used to search for documents, pictures, etc. on your computer). The name is 'borland (spelled in lowercase with the apostrophe). I cannot delete it at all. I can delete all other search words, but not this one. I did a google search and came up with a COMPANY that I feel is legit. Should I be concerned? :-? |
|
| 802. |
Solve : Trojan Horse Generic2: LNI? |
|
Answer» Ok, hi there again guys. Well basically ive googled this 'Trojan Horse Generic2: LNI' but to no avail, but ive found many others that have different endings, for example 'Trojan Horse Generic2: CBF'. However i want information on the trojan that is on my sisters P.C. Im not computer savey at all but i do know how to get around on them and i am the most knolageable in my faimly. There is one other issue that confuses me. Last night i started a scan on her P.C and it didint pick up anything, it got about 30 mins into it then we decided to turn off the P.C. Then this morning my sister booted up the P.C to try and get her coursework out of the way, and as most of you will know AVG has that option to scheduale scans. The schedualing scan on this P.C is 8:00 in the morning and she had started it at 7:45 (early i know but she has a ton of coursework), so the scan went on and found this Trojan with under 5 minuites into the scan. So why didint the scanner pick this up lastnight before i had to terminate it? She hasnt downlaoded anything so i dont think its fresh this morning. Anyway advice and information would be appreciated. As to the last nite today question the only thing i can think of would be that AVG runs the scan differently in scheduled mode because it has access to all the system resources as opposed to running it in an active session.Ok cool, thanks! Like I said ive looked for it all over but cant find that varient. Also it's not a big issue with the P.C having the dodgey wireless for us anymore. Weve just bought another laptop for my sister for christmas, so we wont be having to PUT up with it for much longer. Anyway if you find anything then it would be gratefully apprecaited, if not dont worry because like I said it'll be gone soon. Thanks Chris |
|
| 803. |
Solve : "Aunt Edna" virus? |
|
Answer» EVERYONE be careful, don't accept any e-cards from anyone you don't know CLAIMING to be a "relative" like "Aunt Edna" from 1001 cards. My computer has this virus, it APPEARS to create a link in outgoing e-mail when I "right click" my mouse to EDIT text in my e-mail. I'm gonna try scanning my drives with the AOL brand virus detector and HOPE to remove it. Please be careful. Anyone else get this virus?do u need help removing this? also if u can find a tech article and post it in the news section. unlovedwarrior |
|
| 804. |
Solve : VBS.LoveLetter.C(1) virus on pc? |
|
Answer» i ran a scan of pc today at work (all drives) & on the j drive symantec antivirus notification said i had VBS.LoveLetter.C(1) virus 6 times. The long distance pc "support" said to unplug from the system which i did. desktop support will try to help me tomorrow on work pc. now i use 2 thumb drives on both my home & work pc---i'm scared to insert the thumb drives into my home pc in case there are infected files on them. is it safe to run a norton antivirus scan on each thumb drive (e or f drives) from my home pc w/out infecting my home pc? |
|
| 805. |
Solve : PC-Cillin Blocking Default Gateway? |
|
Answer» Hey guys, I would APPRECIATE a little help, I'm having a little trouble with PC-Cillin Internet security 2006. My computer specs (if it matters) are as follows |
|
| 806. |
Solve : Home Page Can't Change? |
|
Answer» I am having a problem with my Internet explorer that i can not change my Home Page even my account is full access and also there is a problem with my run command "Start>Run" it is not there and also not working. |
|
| 807. |
Solve : HOSTS File redirection? |
|
Answer» Hello EVERYONE ... A friend of mine mentioned use of a large host file with redirection to 127.0.0.1 for sites that he wanted to BLOCK users from snagging adware/spyware at as well as redirection of websites to block access to. |
|
| 808. |
Solve : Is "NTLDR is missing" cause from virus ?? |
|
Answer» I already read NTLDR is missing at this site and this site not told me it can cause from virus. |
|
| 809. |
Solve : Hope this is an easy one.? |
|
Answer» Ok I just finished a diagnostic of my friend's computer: (Dell, Pentium 4 CPU 2.00 GHZ, 1.99 Ghz, 1 Gig RAM, XP Pro 2002 SP2) He already has AdAware...my badFlip81 also stated the scans were ran in safe mode with the system restore off. Quote Flip81 also stated the scans were ran in safe mode with the system restore off. that he did Quote QuoteFlip81 also stated the scans were ran in safe mode with the system restore off. Don't take that serious. I was chiming in and teasing.im not just made me reread the opHow's fordtruckmaniac doin' ? ? Long see No Time.I'm doing OK, thanks. I just mostly HIDE in the background and READ. Meanwhile the original poster has gone missing. Quote As far as I can see there are no experts resident here.You don't see very far then.thanks guys. The problem fixed itself after a reboot. For the RECORD, I have found this site to be full of experts who are not condescending and very helpful.At times we do seem condescending...but that's only when our patience has worn thin. Glad your visit here was a good one and seeya around ! |
|
| 810. |
Solve : Backdoor.trojan how do I remove this??? |
|
Answer» My Norton keeps saying I'm infected with backdoor.trojan. How do I remove it?? My Norton keeps saying I'm infected with backdoor.trojan. How do I remove it??Where does Norton say the file is located? If it is in a RESTORE file, you must first disable system restore, run your scan, then re-enable system restore if desired. |
|
| 811. |
Solve : E-Christmas Card Virus (through MSN)? |
|
Answer» ollylock...... Were you able to remove this running process ? |
|
| 812. |
Solve : Unknown malware on computer.? |
|
Answer» Hi, I need some help. A few weeks ago I scanned my system with the trial version of Spy Sweeper + Antivirus. At that time, it picked up the following (Ignoring the cookies it picked up...): he gave a hijackthis log already reply one and two Thanks guys for your replys. My computer has a partition just for the Symantec system restore. But I don't know how to reformat and bring it back to new at the same time. My warranty has run out so I can't chat or email Dell about backup CDs. Thanks again.Despite the warranty contact Dell. I think you will be pleasantly surprised how they can help you. SOmetimes it helps how you phrase the questions. Actually, after the warranty has run out they are still under some sort of obligation to help you out. Extended warranties are more of a scam than real protection. I don't know where I read that, but I'll try and find it again. It was very informative about how companies are still obliged to support you, even out of warranty . . . unless I'm imagining it . . . |
|
| 813. |
Solve : IE Crashing and closing randomly? |
|
Answer» It started yesterday or the DAY before when I turned on the computer. I realized something was installing so I quickly turned off the computer before it could fully install. I turned it back on to DISCOVER there was only minor damage. |
|
| 814. |
Solve : Browser Stolen? |
|
Answer» Hi, |
|
| 815. |
Solve : computer won't open programs or documents? |
|
Answer» I bought an IPOD off of ebay and after plugging it into my computer, now I can't open documents or programs. It takes 10 minutes or so to boot up and then it wont let me open ANYTHING. Has anyone heard of this? I am guessing the iPod was infected? |
|
| 816. |
Solve : My Computer changed to Recycle Bin? |
|
Answer» Hey everybody ! My system is infected from a virus ? and you say this because ..............? dl65 Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 817. |
Solve : I need help, i have a weird virus i don't know how to get rid of it? |
|
Answer» Sounds like you might have SmitFraud. Give me a few minutes and I'll take a look at your log. Quote from: pleasehelp on June 18, 2007, 11:41:01 PM to personalize avg?The License sales number is for registering AVG - you probably only want the trial so you don't enter anything.You should only need to download... AVG Anti-Virus Free AVG Anti-Spyware Free AVG Anti-Rootkit Free See below,run all three. http://free.grisoft.com/doc/1Dark Blade, I appreciate you trying to help, but please be careful. This sort of THING takes a certain amount of training for one to know what they're doing. It's very easy to get legitimate files and INFECTIONS confused, and if we disable/remove the wrong ones, it can cause a lot of problems. My RESEARCH gives me no reason to see the mentioned files as a threat. In fact, I BELIEVE they are related to the user's BIOS. Of course, this isn't concrete, so... pleasehelp, Please head over to VirusTotal, and copy/paste and scan each of the below files (one at a time)... C:\WINDOWS\system32\PhxPsSvr.exe C:\WINDOWS\system32\PhxVtSvr.exe Once you have done that, please post the results of each file. Before proceding, download AVG Anti-Virus and AVG Anti-Spyware from the link provided by street1 (you may want to disable your CA Antivirus). These programs are free and don't require registration or activation. UPDATE both of them (but don't scan yet). And now, let's go over your log... Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... O2 - BHO: MSVPS System - {218B7D50-BC37-4FA8-A57F-6E8DE692BD79} - C:\WINDOWS\vpsnetwork.dll O21 - SSODL: vpssup - {17495F36-7D6D-4858-ADAA-8DCA6C203EE5} - C:\WINDOWS\vpssup.dll O21 - SSODL: expro - {886C00DD-C91B-4046-83AE-B0FDA18CC0EE} - C:\WINDOWS\expro.dll O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm (This appears to be what's giving you trouble.) Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Navigate to and delete the following folder(s) if present... C:\WINDOWS\privacy_danger Navigate to and delete the following file(s) if present... C:\WINDOWS\vpsnetwork.dll C:\WINDOWS\vpssup.dll C:\WINDOWS\expro.dll Go ahead and scan with both AVG programs, one at a time. If you run them both at the same time, it can cause problems. When your scan has completed, go to Control Panel and open up the Display Properties. Click on the Desktop tab and then click on the Customize Desktop button. From there, click on the Web tab and under Web pages:, you will see a list of items. If you see anything with a name like Privacy Danger, select it and click on the Delete button. If it's not there, then simply exit. Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.how do i reboot into safe mode and enable hidden files and folders? (thanks for all the help by the way)and it keeps resetting my homepage to some weird page.As your computer is booting up, continuously tap the F8 key and it should take you to a menu that will let you choose Safe Mode. If F8 doesn't work, then try the different F keys (F5 and F10 are common ones). Once you have completed all of my above steps, post a new log and we'll see what else needs to be done.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 818. |
Solve : Virus identified Exploit.ANI? |
|
Answer» You're very welcome. I'm GLAD I could help you out!As this issue appears to be resolved, I am CLOSING this topic. If you are the original poster and you WOULD like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. |
|
| 819. |
Solve : Fire walls? |
| Answer» COULD some one tell me if the COMODO FIREWALL program is good or not so good ? Thanks Yes, Comodo is a good firewall, ESPECIALLY for free. | |
| 820. |
Solve : I got security on off problem......? |
|
Answer» Hi, |
|
| 821. |
Solve : very annoying adware? |
|
Answer» The official drivers page is here: |
|
| 822. |
Solve : Please have a look Part 2? |
|
Answer» And what about this one I can see that you have a Mcafee firewall and you have AVG AV But I don't see any antispyware protection or did I look over it?O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL Those entries show that both Spybot - Search & Destroy and SUPERAntiSpyware are present. Quote from: Jonas Wauters on June 22, 2007, 01:46:39 AM Next to this the log looks clean for me accept for:What are you getting at? That file is not infectious. Quote from: Jonas Wauters on June 22, 2007, 01:46:39 AM O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)Although it's usually safe to fix (file missing) entries, there are times when it's not true. HijackThis will sometimes incorrectly list files as missing when they are not. For example... O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) That file often shows up as missing in HijackThis, but it actually usually exists. When it comes to entries like this, if it's not infectious and if it's not causing any problems, I almost always leave it alone, just in case the file isn't really missing. The only exception is when someone asks about unnecessary entries in their logs. In these cases, I'll ask the person to search for the file. If it truly doesn't exist, then I have them fix the entry. Quote from: Jonas Wauters on June 22, 2007, 01:46:39 AM BTW: Chris thanks for the info about HJT. You made it possible for me to read.It's really great that you want to help out, but it's going to take a lot more than just a night of research. It takes months of training before you're ready to start taking on actual logs. Did you read through that whole thread I gave you? It mentions several malware universities. If you would like to join the fight, then you should sign up at one of those training courses. It's a long process, but you learn a lot of very valuable information. Also, if I were you, I would completely avoid using the hijackthis.de site. It can be helpful to see what entries you may have missed, but many of its results are inaccurate. It pays no attention to file extensions. If someone has a virus that changes all .exe files to .usr files, HijackThis.de won't catch it. That's why it's always better to do it all manually.Ok looks like I'm far from there yet Yes indeed I used http://www.hijackthis.de/en Looks like its not a good site Now I know And I'll stop trying to reply at HJT Because it looks like I'm only going to make it worse. NOw I know where I'm at. Jonas The site can be useful, but it should only be used when you already know what you're doing. HijackThis may be small, but it's a powerful little tool, and removing the wrong things can cripple a computer. You might want to check out those universities. GeeksToGo is the one I prefer. They're strict, but friendly. And they have tons of helpful information.Thanks again for that both done Quote Also...Jonas is right; C:\Program Files\HJT How do i MOVE it from my documents to where you suggest, might seem a silly question to you but that's i ended up with two. SkyblueFirst, open My Computer and go to C:\ and then Program Files. Right-click on a white area of the folder and go to New > Folder. Name the folder HJT and then drag and drop HijackThis into that new folder. Download CCleaner (install without Yahoo! toolbar) and configure it according to this guide. Analyze with the Cleaner tool and that should get rid of the extra copy of HijackThis.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 823. |
Solve : slow computer could be a virus? |
|
Answer» Ok guys and girls basically , i posted in Networking i am haveing seriously slow dsl , but it appears my hole pc seems to running on the slow side its like really bad lag , i know i only have a 256mb ram at the moment but my computer has never ran this slow . and i havent gone near any torrent sites since my pc has been wiped , im gunna post a high jack this log feel free you look at it , thanks for looking , if any can see anything i should fix let me know . |
|
| 824. |
Solve : Trojan.Exploit.Vbs.Phel.M Infection!?? |
|
Answer» I have BitDefender v10 on my XP and as it was scanning for viruses a virus alert pop-up showed up saying my computer has been infected by Trojan.Exploit.Vbs.Phel.M and Generic.XPL.Phel.7A2777C0 I have BitDefender v10 on my XP and as it was scanning for viruses a virus alert pop-up showed up saying my computer has been infected by Trojan.Exploit.Vbs.Phel.M and Generic.XPL.Phel.7A2777C0Are there any actual problems occurring with the computer? The virus MAY be being STORED in quarantine.Download CCleaner (install without Yahoo! TOOLBAR) and CONFIGURE it according to this guide. Use this to clean out your temp and Temporary Internet Files folders. Download AVG Free and SUPERAntiSpyware. Upload both programs and then reboot into Safe Mode (continually tap F8 while the computer starts booting). Scan with AVG, and when that's done, scan with SUPERAntiSpyware. Restart your computer, download HijackThis, and post a log here. If there actually are any infections left on your computer, we'll run them out within a couple of days hopefully.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 825. |
Solve : Spycrush irritation? |
|
Answer» As this issue appears to be resolved, I am closing this topic. If you are the original poster and you WOULD like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. |
|
| 826. |
Solve : Help, I have SpyLocked!? |
|
Answer» Is there any way to remove this MESS without buying anything? I have tried deleting it off my computer but to no AVAIL. Please, someone, help!Deleting what?What protection do you have, what EXACTLY have you done to try to remove it, etc. Details are important.Starting your computer in Safe Mode usually lets you delete undeletable files. Please answer the above questions. Hey Patio, what's with the giant tooth?Sometimes, it seems like you have to pull teeth just to get information out of people.Due to lack of feedback, I am CLOSING this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 827. |
Solve : BlackCore - virus?? |
|
Answer» Can someone tell me what BlackCore is? Spybot's found it twice now and I don't know where it's coming from.
At this point, go ahead and update Spybot and AVG. Now that that's taken care of...Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000 O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE (This is a part of your Realtek Event Monitor. Technically, it's not malicious, but it is considered spyware. You don't have to, but I would suggest checking this.) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 207.66.105.14:8080 (Did you set this proxy? If not, check this entry also.) Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Navigate to and delete the following file(s) if present... C:\WINDOWS\system32\ALCMTR.EXE (You don't have to delete this, but it is advised.) Once you've done all of this, scan with Spybot and then scan with AVG. Let them remove whatever they way. Reboot into Normal Mode and post a new HijackThis log, and this time, post the entire thing which includes the header. Let me know how everything's running now and if you had any problems following my steps. Does BlackCore still show up?Due to lack of feedback, I am closing this topic. If you are the original POSTER and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 828. |
Solve : host file change? |
|
Answer» Hi,all. after scaning my mums gateway gm501 |
|
| 829. |
Solve : Talking Trojan Says 'Bye Bye' to Victims' Data? |
|
Answer» A newly identified malicious program not only messes up its victims' computers, it taunts them too |
|
| 830. |
Solve : Uhhm?? |
|
Answer» I've just been running Ad-Aware 2007 and noticed it had found exactly 384 infections. Could this be the cause of my PC freezing?Pretty much... |
|
| 831. |
Solve : Forum login mystery? |
|
Answer» I am a member of several forums on the web and pretty much always use the same login name: Allochthonous. |
|
| 832. |
Solve : HELP SOMEONE!! trojan.vundo, infostealer, WinFixer, MisleadApp, trojan.Metajuan? |
|
Answer» my brother has recently downloaded something and it is freezing up my computer/internet. my internet connection is very very slow and disconnects from time to time. my computer in general has been very slow. i downloaded mozilla firefox thinking it would make my connection a BIT faster but it didn't and started giving me random pop ups. i don't know what to do. do i need to reformat it because i want it to be like how it was when i first bought my laptop. please help me!!! i also get trojan.vundo, infostealer, WinFixer, MisleadApp, trojan.Metajuan, and DriveCleaner on my Norton Antivirus. i just got a TRACKING cookie on my norton scan. risk is lowok.. what operating SYSTEM... |
|
| 833. |
Solve : RE STRANGE DISCONNECTION FROM INTERNET? |
|
Answer» Hi, I have a fujitsu laptop with windows xp home edition |
|
| 834. |
Solve : setup.exe Virus? |
|
Answer» Hi, |
|
| 835. |
Solve : interent explorer goes crazy? |
|
Answer» And what about the VIRUSTOTAL log(s)? Trojan.Malware Is this where the detected infection resides? It doesn't give a SPECIFIC file? What's in that folder?http://www.virustotal.com/vt/en/resultadof?dd4514503d50e8444426b69cad2cfa22 C:\Program Files\MSN Messenger\MsnMsgr.Exe and i can't even find the folder but im going to go check to make sure i have show hidden files on like i shouldhttp://www.virustotal.com/vt/en/resultadof?42029616d9eafcd3a99ff391719731aa thats for the other one so it looks like i might be infected ehh.... ill do some scans tonight and TOMORROW and post findings but im going to bed right now laterAlthough VirusTotal is accurate, it isn't 100%, so it's hard to say if those results are right or not. I STILL suspect the file, but I may be overly paranoid. In any case, scan with your beloved SAS. And try scanning with Panda's online scanner as well. LET me know how it goes. EDIT: Further research tells me that you probably don't have to worry about that "suspicious" file. But go ahead and follow through with the scans still. And I repeat... Quote QuoteTrojan.Malware |
|
| 836. |
Solve : DVD drive have a virus?? |
|
Answer» I have a problem. I have been trying to install some progs. from disk via my dvd/cd drive. I only use it because my cd drive isn't showing up. Anyway, it keeps telling me there are CRC errors for every thing I try to unzip. This just started about a week ago. My dvd drive is new (3 months old) and it's a light scribe. I haven't had a problem with it before. Could there be a VIRUS causing the problem in my dvd drive? Any suggestions?No...as of yet thank goodness a virus cannot attack your CDDrive... |
|
| 837. |
Solve : HJT Logfile? |
|
Answer» I don't put much credence in site advisor at all...I agree that SiteAdvisor does tend to be inaccurate at time. The site for Free Download Manager, for example, is red-flagged because one of the sites it links in turn links to a site with ADWARE. And certain sites like DoubleClick are sometimes green. But it's all still a work in progress. You will still have to use your own discretion at times when using this program. Whenever visiting a site that you're not familiar with, it's always a good idea to actually read the reports, as they give you a lot more information to work with. With that said, perhaps I should start including a disclaimer when suggesting this program. Thanks for making me think of this. Heh. |
|
| 838. |
Solve : Smitfraud-C.Toolbar888 & outerinfo + Trojan Horses? |
|
Answer» PLEASE can someone have a look at my hijack this log file? I have cehcked this and other forums, performed some tasks advised, including smitfraudfix.exe, Bruteforce uninstaller and AVG 7.5 antispyware. SPYBOT originally FOUND the smitfraud and AVG 7.5 antispyware foubd trojan horses. I think/hope I have sorted this now but was hoping for some expert advise. Thanks. Ash72. Hijackthis log to follow...Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 22:41:14, on 11/05/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe C:\WINDOWS\system32\wuauclt.exe D:\Ash\Zip files\HiJackThis_v2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: 3D!Turbo Experience.lnk = C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131197105750 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131208616000 O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing) O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- End of file - 5404 bytes Any help would be greatly appreciated. Thanks.Ash, I've got you at the top of my list right now. I have to go take care of a few things, but I'll get back to you within the hour.A Good Start I would suggest printing out the instructions and becoming familiar with them beforehand... Then run a fresh HJT log and post it and by that time Chris should be back...Sorry, I was busy a bit longer than expected. Patio's advice is sound. Thankfully, though, your log looks relatively clean. The only issue I see is this entry... O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing) Just a leftover Smitfraud registry entry. Close all windows and have HijackThis fix this entry. The file should already be gone, but to be on the safe side, reboot into Safe Mode, enable hidden files/folders, and delete the following file if found... C:\WINDOWS\system32\winrvc32.dll Also, still being on the safe side, follow through with the SmitFraudFix instructions and run another scan with AVG. Then go ahead and post a fresh HJT log along with an update on how things are going.Hi Chris, thanks for you help. I have followed yours and Patio's advice. Here is the new Hijackthis log. Is all OK? Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 09:28:52, on 12/05/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFAGENT.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe D:\Ash\Zip files\HiJackThis_v2.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - Global Startup: 3D!Turbo Experience.lnk = C:\Program Files\MSI\3D!Turbo Experience\3D!Turbo.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aolsvc.aol.co.uk/computercheckup/qdiagcc.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131197105750 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131208616000 O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/prequal/MotivePreQual.cab O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing) O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFSERVICE.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe -- End of file - 5332 bytes It looks pretty clean to me. Looks like you're doing a pretty decent job with protecting yourself. Just a couple of things to go over... In addition to AVG, I would suggest also getting Spybot - Search & Destroy and AdAware SE Personal. For safer browsing you should use, Spyware Blaster and SiteAdvisor. Both are very handy. At this point, it would also be a good idea to clean out your restore points... 1. Go to Start > Programs > Accessories > System Tools > System Restore 2. Click on System Restore Settings. 3. Check Turn off System Restore and click OK. 4. Restart your computer. 5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK. 6. Create a new restore point and close the program. System Restore will now be active again. If you would like to learn more about System Restore, go here. Infections can return if you restore your computer to an older point for any reason, which is why it's best to do this. By following all of my steps here, you should be a lot safer online.Thanks Chris I will do that now. I already use Spybot - Search & Destroy and Adaware SE Personal. I will have a look at the safe browsing options. Thank you very much for your help.You're welcome; come back anytime. And you're right, I see Spybot in your logs. Silly me. Heh.get superantispyware it does good at smitfruad and other things as wellChris Thanks for your advice on this. I have cleaned out my system restore and intalled Spyware Blaster and Site Advisor. I am very impressed with Site Advisor. As far as I can tell my PC is working absolutely fine now. Once again, thanks for your help and recommendations.I'm glad things are going well for you. SiteAdvisor is a handy program, but make sure you actually read the reports before entering sites you're not familiar with. It's still a work in progress, so some sites that are green-lighted aren't always trustworthy (DoubleClick for example). And just because a site is red-flagged, that doesn't always mean it's bad (Free Download Manager for example). Please use your own discretion and common SENSE when viewing unknown sites. |
|
| 839. |
Solve : CWS.feads? |
|
Answer» Got a potential new client that has this little mother. Done some "Googling" and found some very long, contorted fixes. I wonder if any of you have come across this and fixed it short of a wipe & install.
RESTART your computer and as soon as it starts booting up again, continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode. Now run CWShredder. Click I Agree, then Fix, and then Next. Let it fix everything it asks about. Reboot your computer back into Normal Mode. It's fairly simple and straightforward. However, it wouldn't be a bad idea to post a HijackThis log of your client's computer. Infections like this tend to have friends lurking around.And after following the great ADVICE above DLoad and update and run the latest ver. of Stinger just for good measure... This has been known to help.Thanks guys! I'll get those downloaded today. Alan <>< Alan i'm not sure if Stinger will run in safemode but try it there FIRST...yes it does or it did last time i used it |
|
| 840. |
Solve : CiD popups? |
|
Answer» Hi, I think I posted this in the right place... I searched and didn't see any solutions on the board. |
|
| 841. |
Solve : Image Files Won't Show? |
|
Answer» Above is an example of my problem and as you can see, none of the image files appear and it's like this on every website plus where my desktop photo should be. This all started Monday afternoon when I was on a website that I have visited many times over the last 8+ years without a problem but a popup appeared and I couldn't click it off. I restarted my computer only to find a bunch of files including Trojans on my computer that brought in more popups and slowed everything down but I was able to clean them out eventually and now everything is working great.......but still no images. On the other hand, when I right click and hit "Show Picture" it comes right up. I've used Ad Aware, Spybot, Hijack This, Barracuda, Spyware Doctor, Windows Live, Housecall, Vundo Fix and FINALLY Defender Pro which is what cured what the others didn't...except for the LACK images of course. I also tried to defragment the computer and even tried re-installing Windows (XP) but to no avail. Any help will be greatly appreciated! Thank You Computer Info: Dell Optiplex GX280 Internet Explorer 6.0 Windows XP Professionaldl avg anti-spyware superantispyware spybot search and destroy adaware se personel spyware blaster(not a scanner but will help in the furture) CCLEANER MacaFee siteadvisor update them all reboot in safe mode rapidly tap f8 before windows loads run Ccleaner first to clean out junk files then run the other scans save any logs any post them here along with an update on how your computer is doing unlovedwarriorDefinitely do a clean-up with CCleaner (install without Yahoo! toolbar). I'm willing to bet that it'll fix this problem for you. Close all of your windows and run the Cleaner (be sure to include Temporary Internet Files) and Issues. SiteAdvisor and SpywareBlaster will both make your internet browsing a LOT safer. You should still scan with the other programs unlovedwarrior listed, just to be on the safe side. If you do all of this and your problem still persists, we'll provide further instructions.Since malware often changes browser settings, it could be as simple as changing them back. If this is the only problem, that would be the first thing I'd check. Quote from: 2k_dummy on May 10, 2007, 06:07:07 AM Since malware often changes browser settings, it could be as simple as changing them back. If this is the only problem, that would be the first thing I'd check. That did it! Thank you! Thank to the others for their assistance as well. Those programs you guys advised are keepers! THANKS again.Glad to hear it's sorted out. Be sure to keep up with your updates and scans (also, remember to only one run of these programs at a time). And stop by again if you need anymore help.The simple solutions are often overlooked. Apply KISS before getting drastic. |
|
| 842. |
Solve : any body help? |
|
Answer» my PC is Infected by virus all files become word icon and i cant open it they need a converter if im not mistaken the virus exe file is lsass.exe is this a virus? |
|
| 843. |
Solve : Suspected Virus? |
|
Answer» Hi, in the past few months I have had trouble with my computer shutting down on me. It does this only when I run a program or game that uses full screen mode (no window) and it always does it 1 or 2 minutes after the program starts. The computer simply turns off abruptly (blank screen, no power). I have run numerous scans for viruses and spyware and have found nothing (spyware cleared out some stuff, as usual, but not thing that was causing the problem). Any help resolving this issue would be greatly appreciated. I restarted my computer and did a scan again, following where it was scanning up until it crashed, noted the program it was scanning, and removed the program from the system. What program did you remove?The program was called ECLIPSE. It was set up for writing java, however SINCE my recent classes have been in C and C++ I haven't use it for the last 4 months. I've had it there for over a year so I doubt that it was the problem (as demonstrated by the fact that the problem persists even after I removed the program).Well, you could post a HijackThis log just for the heck of it, but I'm not entirely convinced yet that an infection is involved. It wouldn't hurt to look, though.Maybe that was a conflict beetwen hardware that the program used. What devices did you used for that program??? LedioEclipse was a programing interface so it would have used all the devices that most programs that edit text use (mouse, keyboard, etc.) I seriously doubt that it was causing any problems. I only removed it to see if it would fix anything, and a best I can tell it did not. I think the most likely problem at this point is that all these programs are calling on some file or process somewhere that isn't working right (although I have no idea what it could be). Since I can't think of anything better to do right now, here is the log file from the hijackthis scan: Code: [Select]Logfile of HijackThis v1.99.1 Scan saved at 9:39:12 AM, on 5/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Administrator\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by129fd.bay129.hotmail.msn.com/resources/MsnPUpld.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing) Well, computers are crazy things aren't they. In the last little while I've been uninstalling and reinstalling drivers for various parts of my computer to see if any of them where causing the problem. None of that worked. Eventually I gave up, hauled my computer outside, and cleaned all the dust out of it. Suddenly, it's all working. Some little piece of dust somewhere must have been causing a problem that was only encountered by certain programs when interacting with a certain area of the computer. Thanks for your help everyone. Quote from: unlovedwarrior on May 08, 2007, 02:59:25 PM ok make sure your case is free of dust lolGlad to hear you got it sorted out. Your log looks clean, by the way. |
|
| 844. |
Solve : Infected system; new monitor.? |
|
Answer» Is anyone aware of viruses etc. that attack the monitor itself? Or is the monitor a completely "passive" device? My flatscreen flashes on and off with "signal out of range" for the first ten minutes then works without problem. I have reloaded drivers, adjusted resolution, cleaned the registry, scanned etc... Nothing seems to affect the problem except patience (10 minutes). A friend's house is a good idea. Would a thumb drive be a good medium? As you can probably guess i am new to computers... If you don't already have a drive, then even a CD-R would suffice. Also, you should add AVG Free to your list. You'll need to update it before scanning, but thankfully, Grisoft includes manual downloads of the newest definitions so you don't have to worry about doing this at home. And don't worry, your monitor won't carry any sort of infection. Your computer could be infected, though, so be sure to scan with all of the programs.Information asked for: 14 start up operations. Operating System: Windows XP Home Edition (5.1, Build 2600) Service Pack 1 (2600.xpsp2.050301-1526) Language: English (Regional Setting: English) System Manufacturer: Gateway System Model: E-6000 BIOS: Default System BIOS Processor: Intel(R) Pentium(R) 4 CPU 2.66GHz Memory: 512MB RAM Page File: 351MB used, 898MB available Windows Dir: C:\WINNT DirectX Version: DirectX 9.0b (4.09.0000.0902) DX Setup Parameters: Not found DxDiag Version: 5.03.0001.0902 32bit Unicode ---------------- Display Devices --------------- Card name: NVIDIA GeForce4 MX 440 (Gateway) Manufacturer: NVIDIA Chip type: GeForce4 MX 440 DAC type: Integrated RAMDAC Device Key: Enum\PCI\VEN_10DE&DEV_0171&SUBSYS_87311462&REV_A3 Display Memory: 128.0 MB Current Mode: 1024 x 768 (32 bit) (60Hz) Monitor: Gateway FPD1730 Monitor Max Res: 1280,1024 Driver Name: nv4_disp.dll Driver Version: 6.13.0010.3082 (English) DDI Version: 8 Driver Attributes: Final Retail Driver Date/Size: 7/16/2002 13:16:00, 3552826 bytes I have not tested the monitor yet. Last night it flashed on and off for 15 minutes getting gradually better as i put the computer to work. It is acting the way electronics used to act when they were warming up. By the way, I am purchasing a laptop SOON. I assume the above programs are your reccommendations for setting it up for safe use. Use the suggested programs to scan your computer in Safe Mode (make sure you update them first). If the scans come up clean, you should update your Windows XP to Service Pack 2. If there are any issues, consult with us first. Installing SP2 on an infected machine can cause problems. |
|
| 845. |
Solve : The virus can't be deleted? |
|
Answer» Norton has scaned the virus named 'Trojan.PSW.WorldOnline' but it can't be deleted. You can add a remote request in www.pc-onlinehelp.com/supportlist.aspx. They provide live remote desktop support now. You can have a try. Yes, ALWAYS a good IDEA to give total access of your machine to an anonymous Internet site. NOT! |
|
| 846. |
Solve : AVG vs. Avast -- Two major features to look for? |
|
Answer» AVG, as I recall, only scans the files about to be booted during its bootup scan. AVG, as I recall, only scans the files about to be booted during its bootup scan. Ah. Ok. Thanksill try anything thing that works and is not a infections its self but ive grown fond of avg. Quote from: WillyW on May 06, 2007, 04:19:18 PM Quote from: Zylstra on May 06, 2007, 04:15:38 PMAVG, as I recall, only scans the files about to be booted during its bootup scan. This is inaccurate... p.s. Zylstra do me a favor...make a folder and nest it 5 levels deep and place eicar in there and see if Avast finds it even on it's thourough scan....a root beer says it won't. Quote from: patio on May 06, 2007, 09:49:25 PM Quote from: WillyW on May 06, 2007, 04:19:18 PMQuote from: Zylstra on May 06, 2007, 04:15:38 PMAVG, as I recall, only scans the files about to be booted during its bootup scan. Just did, "Caution, a virus has been detected" How is it inaccurate? Quote from: patio on May 06, 2007, 09:49:25 PM Quote from: WillyW on May 06, 2007, 04:19:18 PMI'd like to know why that would make a difference. Any scanner that can't do this would have to be very poorly designed. I wouldn't say that Avast! is the greatest, but it's certainly not that bad.Quote from: Zylstra on May 06, 2007, 04:15:38 PMAVG, as I recall, only scans the files about to be booted during its bootup scan. One thing I would like to point out, though, is that AVG detects Eicar the very second it's created. As soon as I save the file, AVG notifies me.yep same hereTry PACKING it 5 levels deep in an archive then, rather than folders. Quote from: CBMatt on May 06, 2007, 11:13:54 PM Quote from: patio on May 06, 2007, 09:49:25 PMAs soon as I click on the link to download it Avast warns me.Quote from: WillyW on May 06, 2007, 04:19:18 PMI'd like to know why that would make a difference. Any scanner that can't do this would have to be very poorly designed. I wouldn't say that Avast! is the greatest, but it's certainly not that bad.Quote from: Zylstra on May 06, 2007, 04:15:38 PMAVG, as I recall, only scans the files about to be booted during its bootup scan. Chris Quote from: Calum on May 07, 2007, 02:20:13 AM Try packing it 5 levels deep in an archive then, rather than folders.No matter what I try to archive it with, access is denied. Quote from: chriscool9 on May 07, 2007, 04:34:17 AM
Where was that? Please post the link. Quote from: CBMatt on May 07, 2007, 05:23:01 AM Quote from: Calum on May 07, 2007, 02:20:13 AMTry packing it 5 levels deep in an archive then, rather than folders.No matter what I try to archive it with, access is denied. I don't remember now how I did it. Probably booted to DOS. Here's a copy of the zip file I keep. [cleaning up - attachment deleted by ADMIN] Quote from: Calum on May 07, 2007, 02:20:13 AM Try packing it 5 levels deep in an archive then, rather than folders.Compressed "folders" are one single file. They dont technically hold different folders. It also depends on the scan type. (A lot of virus scanners allow a user to not scan .zip and other packers, since it takes longer) I cant even start downloading the virus file, since Avast stops it before I even click "Save As" Quote from: Zylstra on May 07, 2007, 02:09:55 PM ... From where? The eicar.zip file ATTACHED above? or from.... ? Wherever it is from, that is very interesting. I wonder how AV software running on your computer can know what is in a file residing on another computer, before a transfer even begins. |
|
| 847. |
Solve : Norton problems? |
|
Answer» I did superanti, adaware, search and destroy, and AVG anti virus SCANS in SAFE mode. |
|
| 848. |
Solve : Another Anti-Norton testimonial? |
|
Answer» My mom wants me to install VB .NET 2003 on her laptop (compatibility problems with 2005 Express). Now, I've got the discs, but I keep GETTING told that another program wants the PC to reboot. This is a red flag; she didn't do anything to prompt this today. 666 problems between the two programs. It all makes sense now... Glad to have you aboard the anti-Norton bandwagon, Dil.Oh, I've been anti-Norton for a while; it's just that my mother's a LITTLE slow to CHANGE what's "protecting" her laptop. It's the same situation with my friend's computer. It's running really slow, so she asked me to take a look at it. Not only does she have Norton as her only protection, it's also several YEARS old. The poor thing. But worry not, I'll have 'er in tip-top shape soon enough. |
|
| 849. |
Solve : AVG compatiblity with Windows Vista? |
|
Answer» Hey guys, on Wednesday I went with an older senior CITIZEN to help her purchase a laptop computer with Windows Vista. A purchase was made at a Best Buy store. One of the sales reps in the store mentioned anti-virus software; specifically, he mentioned a package they offer which includes making a restore CD from the restore partition on the hard drive, installing anti-virus software (I'm not sure whether this included the software or just the installation of it), and I THINK maybe something else for $149. I told him I would take care of the anti-virus. He asked me what I was thinking of installing. I said AVG Free. He said it's not compatible with Windows Vista. I was skeptical and still declined their package.
or they just want to make the sale |
|
| 850. |
Solve : Windows Firewall and Avast? |
|
Answer» I am using Avast 4.8 Home Edition and have the Windows Firewall on. My OS is Windows Vista SP2. I am puzzled as to the uses for the Standard shield, Network Shield, Web shield, and P2P shields and whether these "count" or together ACT as a firewall. I have a custom set up (excluded D: from any scanning as shadow copies are on D:). Is anyone familiar with Avast? Am I going to have TROUBLE with using these providers with Windows Firewall on> |
|