InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1101. |
Solve : trojan - downloader? |
|
Answer» mission accomplished!! emtied the vault! |
|
| 1102. |
Solve : strange icon? |
|
Answer» Some ware along the line I picked up an item that resides next to my clock in the bottom bar of my system [Windows XP]. It is a red shield with an X that changes to a blue shield with a [?]. A left mouse click opens your website. A right mouse click does nothing. Periodically this icon will generate a ‘System Alert’ balloon telling me my system is under attack. It also interferes with my eireless keyboard, mouse and ties up my system briefly. I don’t seem to be able to remove it. It has become very annoying. Please help.This is a virus or similar malware PROBLEM. |
|
| 1103. |
Solve : regfix.com? |
|
Answer» my sister is running windows xp on a LAPTOP which was badly infected with spyware. We run ewido and removed what it found (alexa and eurocliock). |
|
| 1104. |
Solve : pages open without control? |
|
Answer» I still see no evidence that the procedures have been followed. However, run Hijackthis and fix the following entries. Ensure that you make backups as my Brazilian isn't that good: |
|
| 1105. |
Solve : Free Trial antivirus protection? |
|
Answer» Does anyone know where a fella like myself can get a free antivirus trial? I am a BROKE college student and I rely on my computer to get me through school. I can’t risk going another day without protection. I appreciate the help SlowBurner.......LOL ...... Don't they teach you how to use Google in College ? Does anyone know where a fella like myself can get a free antivirus trial? I am a broke college student and I rely on my computer to get me through school. I can’t risk going another day without protection. I appreciate the help Here is another good free AV. Its called Avast. http://www.filehippo.com/download_avast_antivirus/If you need to buy better protection sometime, you might be able to get a student discount FlameI'm guessing that AVG free and Avast also free don't do as much or as well as paid-for scanners. But hey, a pile of bricks is a better defense that nothing. Cash, however, is what takes that pile of bricks and makes a Great Wall of Virus Protection. Which is cool because if you pay enough, you can see your virus scanner from space. *Note: Anyone who takes my last sentence seriously needs IMMEDIATE psychiatric help. AVG is good, but there's something to be said about just buying a program yourself... FlameJust for the sake of asking. Is Avast not at least as good as AVG for both being free? Our local computer repair shop recommends Avast highly. I know Avast found 7 viruses in my old Gateway that had Norton on it. I kept Norton updated every week or two the whole time and ran it the same. I'm happy with it. I have not had anything get by it that I know of. I have ran some other stuff (PANDA, etc) to DOUBLE check and it shows clean. |
|
| 1106. |
Solve : Please take a look.? |
|
Answer» Thankyou for your help CBmatt, |
|
| 1107. |
Solve : ntuser.dat file and backdoor spyware?? |
|
Answer» Hello. I am OPERATING on a 2001 DELL Dimension 2300 with WINDOWS XP installed. |
|
| 1108. |
Solve : HELLLLLLP!!! My mother F-ed up my laptop!!!!!!!!!? |
|
Answer» Somebody, Please help me. While I was at work - a window popped up while my mother was using the computer and she downloaded some crap that won't even let me get into my control panel to remove the program. All my personal ACCESS to my own computer is GONE!!! It KEEPS telling me to contact my system administrator. It's called the AVSystemCare - some spyware of sorts. |
|
| 1109. |
Solve : Opera Hijacked!!!? |
|
Answer» I was answering a post about a "keylogger" so I googled and tried to C&P a link. However, when I got back, I couldn't type anything. Cut-and-paste was this: 017 ..... ALL of them UNLESS THEY ARE ASSOCIATED WITH YOUR ISP....... If they are from your ISP ...they are ok to stay ..... as stated . Re ... cfpsys.exe ........ Yes I saw that as well , But I also saw a number of sites that were considering it an issue ....... The fact that you downloaded it confirms it . dl65 |
|
| 1110. |
Solve : Hijackthis log could someone take a look please? |
|
Answer» Logfile of HijackThis v1.99.1 When you conduct a search through our toolbar, we send our advertising partner your IP so that they might be able to serve ads targeted to your location geographically. O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background (This is something I don't believe I've seen before. MSN Messenger is legit, but the filepath isn't normally preceded by a tilde mark (~). You should head over to VirusTotal and scan the file. Post the results here.) Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)... SweetIM Please note any other programs that you dont recognize in that list in your NEXT response. Navigate to and delete the following folder(s) if present... C:\Program Files\Macrogaming Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any problems following my steps.Thanks have not been back round to MAKE the changes but will let you know You also have a Wareout infection indicated by those 017 entries. Do as CBMatt advises then do this ..... Download FixWareout from one of these links .... http://downloads.subratam.org/Fixwareout.exe http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin. Follow the prompts. If your firewall gives an alert (because this tool will download an additional file from the internet) don't let your firewall block it but allow it instead. You will be asked to reboot your computer. Please do so. Your system may take longer than usual to load. This is normal. After reboot a log will open (report.txt). It will be present in the C:\Fixwareout folder. SAVE that report and post it to this thread so CBMatt can review it. OJ Welcome Back, oddjob ! !glad to see you back oddjobDue to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you REQUIRE help, please start a New Topic with information about your computer and your problem. |
|
| 1111. |
Solve : affected virus w32.spybot,then IE auto start? |
|
Answer» My pc affected virus w32.spybot. |
|
| 1112. |
Solve : Virus Turned Off My Windows Firewall, Now Cant Tur? |
|
Answer» I got a virus, and instantly it TURNED off my windows firewall and now it wont let me turn it back on! I immediately disabled my ''local area connection", but now when i go to enable it, it creates this "internet connection" icon too(in network connections), and it wont let me disable it( and when i click to disable it, my boyfriends computer , which is connected to the same router, instantly loses its connection. My internet still works though, unless i do what i just mentioned, but it works again when i unplug the modem and router, etc. But when i disable the local area connection, it goes away! So since then I installed a personal firewall, which hasnt helped, and about everyday I get the BLUE SCREEN OF DEATH(it shows up randomly). I know the BEST THING to do would be to reinstall windows, but i hate doing that, and thought id see if there was another way first. Any help or input would be very much appreciated!!! By the way, im running avg pro, and it caught the virus when it attacked, and said that it healed it, but it kept popping up. Ive also installed trojanhunter and that didnt help, also aluria scanner but no go on that since it doesnt let me remove anything without buying it. Someone on another site GAVE me some links to look at, but they were SO confusing and very tedious. I'm hoping for some help or any info here, IT WOULD BE GREATLY APPRECIATED! Thanks so much! |
|
| 1113. |
Solve : command.exe? |
|
Answer» Hey, i was skimming through my system folders recently to see if anything seemed out of the ordinary and noticed that there was a new file in my Local Disk called command.exe. I didn't think it was anything bad until I realized that command.com is the authentic system file that causes no harm and is located in the same folder. I googled it and certain websites said that it's an undesirable file that should be removed immediately. |
|
| 1114. |
Solve : Nastly Limewire Virus? |
|
Answer» I got this virus a while ago from Limewire called W32.Alcra.f. I got this virus a while ago from Limewire called W32.Alcra.f......W32.Alcra.F is a worm that attempts to propagate through various file-share networks accessible with BearShare, LimeWire, Morpheus and Shareaza applications. It also attempts to disable several programs on the compromised computer and drops a variant of W32.Spybot.Worm onto the compromised computer. Quote Up until now I thought I had properly deleted it.No , you didn't . This is what it does .... [bAttempts to disable several programs by creating the following empty files with the hidden and system attributes set: %System%\cmd.com %System%\netstat.com %System%\ping.com %System%\regedit.com %System%\taskkill.com %System%\tasklist.com %System%\tracert.com Note: %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). MODIFIES attributes of the %System% folder. Copies itself as %ProgramFiles%\outlook\outlook.exe. Note: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.][/b] Which anti virus are you using and is it up to date ....... This is a very recent nasty....... If you havent already done this ...... Go into folder options and make sure your hidden files and folder are shown. Turn off your system restore feature . Reboot into safe mode and run a complete scan ......... Record exactly what is found and where it was located ..... let us know how you make out . dl65 Quote %System%\netstat.comYes, I thought that was the only thing it did. I'm trying to boot into safe mode, but it will not work. I pound on the F8 key during the Windows loading screen, and when I hold it down it's not working. Now I'm on the inscructions at Symantec to boot into safe mode using the msconfig utility. . Why doesn't F8 work though? What am I doing wrong? :-? I'm using AVG which was UPDATED 04/10/06. Yesterday. Why doesn't F8 work though? What am I doing wrong? :-? I'm using AVG which was updated 04/10/06. Yesterday. Wraith..... Quote Why doesn't F8 work though? What am I doing wrong? Sounds like you are waiting too long before hitting the F8 key..... Try this ....... As soon as the machine shuts down and just before it starts to boot back up ......repeatedly tap the F8 key ........ dl65 I have see hidden files and folders on. I booted into safe mode, and scanned with AVG. It didn't find anything. I'll attach a hijackthis log too, but I don't think I have any hijackers. EDIT 1: It won't let me attach the file even though it's only 2 killobytes.Wraith...... Have you gone through all your pc files to be certain that you have removed those DUMMY files that the bug created ? What is the current status ....... is porn still d/l itself ? Zip your hijackthis log , save it to your desktop and then go to ..... http://photobucket.com/login.php?action=logout ......... register , then upload the zipped file and once its up loaded ..post the link here . dl65 |
|
| 1115. |
Solve : slow computer, need help asap, thanks!? |
|
Answer» I believe im infected with viruses... please help, suppose to be giving laptop to my sister tomorrow.. yikes!!! Just give her the virus infected computer. It dont matter if you aint using it. Whats the point of posting a comment like that..... Quote from: Spero-T on September 03, 2007, 09:20:33 AM Run Agv, spy bot search and destroy all in safe mode try a registry cleaner. Try what and said and let me no dl ccleaner too run it and then on the left side click the issues button and run that a couple of times saving each time it asksIf it's slow, it may not be a virus. Although do take the precaution of it being one, don't worget you can also De-fragment / Disk cleanup, that will speed it up.Your HijackThis is in a temporary location. If you leave it there, it (along with its important backups) can and will eventually be deleted. Dowload it again, but this time, save it to its own special folder. You can download CCleaner (install without Yahoo! toolbar) and configure it according to this guide like unlovedwarrior is suggesting and then fix these entries with HijackThis (with all other windows closed)... R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O20 - AppInit_DLLs: O23 - Service: hpdj00 - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj00.exe (file missing) However, I think if this computer is going to go to a new owner, it should have a fresh start. You should reformat it, or instruct your sister to do so. And then she will have a nice clean computer to play with.She TOOK the computer so her boyfriend might have fixed it up... but ill have it again this weekend... sooo... I'll redo the tests and what not... and repost this weekend my results... thanks guys!Alrighty, be sure to keep us updated.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 1116. |
Solve : Trojan question - long story - please read? |
|
Answer» I have a 'file missing' entry too but the file is there, correct SPELLING & path as well. |
|
| 1117. |
Solve : LLDSRNGR.EXE Problem With Trojan? Spyware?? |
|
Answer» I have a windows me computer & last night I was searching the web for birthday graphics for my sons myspace. All the sudden my antivirus (Avast) kept going off & wouldn't repair the viruses it was detecting, my pop-up blocker went crazy & my computer kept freezing & then didn't want to boot up. I finally got my antivirus to scan & it kept popping up some win32-gen something that wouldn't delete, & wouldn't go to the virus chest. I finally downloaded a trojan remover & ran that. My computer seems to be ok...not quite as good...a little slower booting up. I found in my msconfig a couple of places where it says LLDSRNGR.EXE (I know very well that wasn't there before) & they are unchecked. Spybot S&D picked nothing up. Was needing someone to look at my Hijackthis log to see if I got everything. I'm not sure how to post it but here goes: I'm sorry, I've been really sick with pneumonia...feeling slightly better now...I'll get to work on this. Also noticed when I go to start...programs....disabled startup items I see TA_Start.... This is new too I'm figuring spyware or trojan???Sorry to hear about you being sick. I hope you feel better. "TA_Start" is mostly likely a part of Zeno/ThinkAdz, which is adware. Have you tried scanning with SUPERAntiSpyware yet? Also, is your System Restore still off? That file found by Avast is from an old restore point. 1. Download VundoFix and save it to your desktop. 2. Run VundoFix and click on Scan For Vundo. 3. Once it's done scanning, click on Remove Vundo. 4. When it prompts you to remove the files, click on Yes. 5. Your desktop will go blank as it's removing files. Don't worry, this is normal. 6. It will prompt you to restart your computer, so click OK. 7. When your computer is turned back on, your problem should be gone. 8. The program normally produces a Vundofix.txt file. Please locate this file and paste the contents in your next post. Also post a new HijackThis log.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 1118. |
Solve : i need Help deleting a file? |
|
Answer» Ok i have what is supposed to be a film in a folder in my documents im running windows xp pro sp1, i have tried deleting the movie but to no avail all i GET is the ERROR msg this file is being used by another program or person, so i thought in my infinate WISDOM boot into safe mode and delete the file, alas all i got was the same error message, i have tried veiwing the properties but the window just does not appear, i have tried deleting the folder it is in but nothing seems to be WORKING, i had this problem before, but i cannot remember how i resolved it now. Please help, oh and in addition i did disconnect the cable modem whilst trying. |
|
| 1119. |
Solve : Help! Virus!? |
|
Answer» So I was stupid enough to download something from an "adult" website and now I think I've got a virus. It started out with internet pop-ups saying "fatal error" and a bunch of computer lingo I didn't understand. My computer started showing me virus alerts but the software is out of date so I tried downloading some free virus protection offline. It doesn't really seem to work, it just pops up a "detection" window that asks me if I want to delete, deny access, ignore or quarantine the virus. Another part of my computer tells me I've got malware. My computer is really slow and sometimes my icons or tool bar don't show up when I boot up. |
|
| 1120. |
Solve : LIBEAY32.dll??? |
|
Answer» Okay, I use a friends computer from time to time to watch DVDs because my computer doesnt have a DVD drive. He hardly every uses it himself except to listen to music and write documents for school/work, so theres no file sharing or chats as far as I KNOW. Don't feel bad, we all have things to do aside from being here. Ah ok thank you!! Oh...and DivX might be the problem? Im going to UNINSTALL it then. I hate it anyways |
|
| 1121. |
Solve : Panda? |
|
Answer» After a free trial put on by someong fixing our internet, we have decided to pay for Panda ANTIVIRUS - before we send off the order could anyone here say whether Panda is ACTUALLY any good (I've experienced no problems yet) or if Norton or McAfee are much better |
|
| 1122. |
Solve : Internet searching? |
|
Answer» I need help!!!!!! My internet searching is jacked up. It is if I have been HIJACKED. Whenever I put in what I am searching for in my interenet browser the results do not match what I asked for. It is bringing up results for sights like monstermarkertplace.com, toseeka.com, findstuff.com,shopping.com,lowpriceshopper.com etc...... these are just some examples of what I get every single TIME no matter what I say I am searching for. I have re-installed my internet explorer and I don't know whatelse to do now. Does anyone have any suggestions of how this happend and how do I fix it? |
|
| 1123. |
Solve : Relatives comp is dying? |
|
Answer» My grandmother has a computer, but it is dying. My thinking is that viruses got the better of the machine combined with hardware problems. Anyway, her PC won't shut down, not even the power button works, among a slew of other issues. But that's hardly an issue; she has got all her data backed up at my request. I won't dare go through the horror of doing a HijackThis fix by EMAIL. She's going to save and get a new PC, a Dell. I made sure the PC was good enough to handle her needs (she does some photo work and book writing, and Email, but not much else) but not too pricey. The PC we like has Trend Micro PC illin Internet Security with Antivirius, Firewall and Spyware removal on it. She wants to know what to think of it, and I personally have never heard of it before. What do you guys think about this software?What model # is this? Make sure enough RAM and...well, you know the rest. I just got a free copy of that PC-Cillin product (because I was a Beta Tester) and it seems fine for a Windows box. EASY to use and feature rich with regular updates.I am making sure the specs at least match the Sony VAIO she was using. It worked OK for pictures and books. |
|
| 1124. |
Solve : search redirect and other issues? |
|
Answer» Hi. I am new here and I am not computer savvy. I have been reading as many posts as I can trying to FIND an answer to my own problems. I have downloaded programs that were recommended to others but I am at my wits end with this computer. I also downloaded a firewall but I am not sure on the very first thing that comes up. What is iexplore.exe?iexplore.exe is Internet Explorer.Hold up and see if there is anything else you can do but I would recommend reinstalling windows starting with a nice new clean computer... But remember anything installed before this will have been removed. Quote you might get better response if you posted in the virus section Can this post be MOVED to the right section? Quote iexplore.exe is Internet Explorer. iexplore is okay? My firewall says it may be spyware. Quote I would recommend reinstalling windows starting with a nice new clean computer... Posting for some advice is my last resort before doing just that. Well actually it would be, taking my computer to someone to have it cleaned. Thanks for your replys Where to start? Your computer re-directs because a virus changed your settings to re-direct. You may have now removed the virus or not! but the settings it changed remain. To be honest I personally would do a complete re-format and reload everything again. Then load an Anti-Virus and Anti-Spyware first before going back on the internet rather than afterwards. Someone behind me may give you advice on cleaning up what's there if you prefer to go that route. What is your firewall? iexplore.exe is definitely not dangerous, so I don't know why it would say so. Now, as CBMatt would say, post up a HiJackThis log (get it from here).Dark Blade - iexplorer.exe can be used by viruses. It is usually an infected/modified version put in a different folder to the original. Quote from AV site But sometimes the same filename is used to deceive the user. For example: Trojan.KillAV.B was cought using iexplore.exe filename. File iexplore.exe is related to keylogger Power Key Logger. File iexplore.exe is related to trojan DarkSky Trojan. File iexplore.exe is related to trojan Boxer Trojan. File iexplore.exe is related to Ruland. File iexplore.exe is related to Mailbancos. iexplore.exe is an executable file that is responsible for launching Quote What is your firewall? It's Comodo Because my firewall is new and my connection type is new I was not sure if this is something that I should always allow. I found out that I have to allow it or I do not get on line. I have someone helping me with the HiJackThis log findings Thanks Quote from: Dark Blade on September 04, 2007, 12:22:05 AM Now, as CBMatt would say, post up a HiJackThis log (get it from here).That's exactly what I would say. And mektek is right. Although iexplore is a legit file, an infection could be using the same name. You have to pay attention to not only a file's name, but also its location. I HOPE the person helping with your log knows what they're doing, because removing the wrong thing could damage your computer. Be sure to update us on what happens; I'd like to see where this goes.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 1125. |
Solve : Rootkit scan log...? |
|
Answer» I've been scanning for rootkits with RootkitReveal and came up with the following log which I do not understand at all: |
|
| 1126. |
Solve : Yet another request for a HJT log review? |
|
Answer» My computer is at a stage where it takes 35 plus seconds to open a desktop folder. I have looked at the generic recommendations on many of the forum posts and have done the following: read this and this one too and do everything in safe mode and then reboot into normal mode and get hijackthis and post a log (it might take more than one post to fit it all in)read both but MAKE sure you read the clean up one.. i just did a quick look at your log and it looks like superantispyware is installed reboot and look for it in start> all programs> superantispywareUnloved Warrior: I am on an unexpected businees trip and will return next week and take your recommendations for action. Thanks for your help. Irv.no problem i hope i can help |
|
| 1127. |
Solve : okay, i know iam stupid....and yes im getting desperaate with my mousse.? |
|
Answer» 1. Come on, who doesn't like Talking Heads? Matt must have gotten to me before I could get to him..Nope, not me. I didn't even make the connection between your smiting and the karma.There it goes again.. I'm being karmatically assaulted! I can't belive people don't love your sweet, CHEERFUL demeanor!You're the one doing it. I'm really not. In fact, here's an applaud.See, now that I exposed you it starts to go up again. It was at 7, now it's at 10. That's not right. You must have an accomplice.... Who is it? Tell me! HONESTLY, I suspect it's you on another account. Very sneaky of you. Sneaky and weird.Down by 2 in less than an hour. That means at least two people are at work. I'm going to stop caring, too tired. When I wake up in the morning, I'm going to be genuinely pissed if I see a minus 10 karma on my account. Quote from: Raptor on April 18, 2007, 09:17:16 PM Down by 2 in less than an hour. That means at least two people are at work. I'm going to stop caring, too tired. Oh, that's so tempting. HA ha.Another truly off-topic topic........ever since the Off-Topic forum was introduced, loads of topics are going off topic after the op's question is answered...somtimes not even. Quote Another truly off-topic topic........ever since the Off-Topic forum was introduced, loads of topics are going off topic after the op's question is answered...somtimes not even. I think I've pointed that out on many topics! The most recent one (I think, at least) was the keylogger one, started by goodnaturedog. It ended up turning into a topic about tasty recipes and smiting the OP (he's on -13 Karma). BTW, when did Off-Topic board get introduced? |
|
| 1128. |
Solve : RazeSpyware? |
Answer» QUOTEQuoteLOL If Scourged is Backdated, then his grammar has lapsed since he left CH. But it's POSSIBLE and that would shed a certain amount of light on >this thread<.I don't claim to be expert but all of you in answering this newbies post give him the impression that you are. Its you lot that should keep QUIET on subjects that you obviously know nothing about. Redirect users to somewhere that KNOWS how to deal with the issues. The superiority complex is somewhat similar, granted. I never took issue with Backdated over that however, because within many fields on CH, his KNOWLEDGE was superior... :-/ Who knows; perhaps this whole thread is another "test". But I'm very much in favour of second chances, particularly since I c[size=11]o[/size]ck things up so frequently , so I say lets get this thread back on track, with or without Scourged's help (preferably with), and if we're going to make a contribution could we please keep it constructive and respectful? This is not a competition to see who has the biggest ego. This is a facility enabling volunteers to help people. In the vast majority of cases, we do more good than harm. Not a bad way to live, really. Peace. |
|
| 1129. |
Solve : Can't run Adaware or Spybot? |
|
Answer» I am running windows XP home on a Dell 4500 Dimension. I recently upgrade from my 80gb to a 400gb hard drive. When I loaded the operating system back on it gave the drive the letter K . I have SINCE downloaded ADAWARE and Spybot search and Destroy. But when I try to run the programs I get a window that says Windows-No Disk , There is no disk in the drive. Please insert a disk into drive. Then I have 3 choices Cancel , Try Again or Continue. If I click on continue repeadly Spy Bot will run. Any Help This is driving me crazy. Is it because of the drive letter. It was loaded to drive K. |
|
| 1130. |
Solve : Computer Freezes when connect to internet? |
|
Answer» Spider, |
|
| 1131. |
Solve : can't sign in to ebay get blank screen with https://signin.ebay.com/ws/eBayISAPI? |
|
Answer» These two files are in your running processes... How did you set IE to it's defaults?Yes or no would be helpful, did you use the 6 default buttons?yes |
|
| 1132. |
Solve : Pesky dialer? |
|
Answer» Ok, here's one for the pros. I have spent a few hours cleaning out a bunch of crap from my Mom's Windows machine. It's running ME, and had previously been host to Kazaa and a lot of other junk. Fix: Yes it is the entire log. This is not my machine and yes there is a lot of crap on it. I hate this computer with a passion. Hmmmmm..........the funny thing about that is I already deleted that. I deleted about a dozen things, mostly BHOs and some 04s, and then re-ran HiJack and posted the new log, and those two things are back, and it just keeps coming back. I have also found in the C:\WINDOWS directory the following files: Buddy.exe CERES.DLL (obviously) Deleting them does nothing much since they are regenerated upon restart of the machine. The only real visible affects are that it dials constantly, and if someone uses IE you get a lot of "The Best Offers" adds. So, here's a run down of things I have tried so far, that have been in-effective in removing the dialing program(s): SpyBot AdAware Manual Deleting of various exes and dlls Hijack this Manual deleting of various registry entries (with the CLSID that shows up in the Hijack log, as well as HKCU\SOFTWARE\ceres and HKCU\SOFTWARE\TBONAS and a few more. Manual deletion of the CERES.DLL and Buddy.exe in safe mode. This one is baffling me, much as I hate to admit it. Anyone else had a direct problem with the "Best Offers" adds and CERES? Quote mox_PERL....Just had a look at your logfile and in addition to what has been suggested , I would be removing ........Done. Quote In your running processes I note ....... C:\WINDOWS\SYSTEM\WMIDHY.EXE if you know what it is leave it , however if you don't know what it is ..... use your task manager to shut it down .... ( Ctrl , Alt , Del) ........ once its been shut down ...... I left that one because 1> it can't be shut down with TaskManager and 2> I thought it to be a quirk in the Compaq version of WinME. I don't think that's the problem but you never know. I'll leave that for last. Thanks guys. Let us know if that fixes it. And when I said you got a lot of crap on it, I meant that you deleted a lot of crap (i.e. VIRUSES) off the system. You've got the cleanest Logfile I've seen in a while, normally HJT responses require essays! Maybe that clarification explains the "Excellent work" bit. mox_PERL..... This link is all about buddy and ceres http://www.webhelper4u.com/tnewswritigs/ceresbuddy_exe.html Have you done all the things outlined there ? ....... and its still comming back ? dl65 Yup, I did that. Did all that registry stuff, and even cleaned out a few other things while I was there, that were also malware. I got rid of that final process, the O4 - HKLM\..\Run: [wmidhy] c:\windows\system\wmidhy.exe The process could not be disabled in normal mode but in safe I deleted that and the buddy and CERES files for the final time. They haven't returned. this: O2 - BHO: FlashTEnhancer Ext - {D7E588AB-A5D9-4422-B313-22A3470F9700} - C:\PROGRAM FILES\FTK\FTK.DLL Also kept returning but I manually deleted the entire FTK folder and now it is gone. The problem is, it still dials. I am officially boggled now. Here is the most recent Hijack log: Logfile of HijackThis v1.99.1 Scan saved at 12:17:09 AM, on 4/22/2006 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE C:\PROGRAM FILES\NORTON ANTIVIRUS\ADVTOOLS\NPROTECT.EXE C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\PCTVOICE.EXE C:\WINDOWS\SYSTEM\HIDSERV.EXE C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\PROGRAM FILES\INTUIT\QUICKBOOKS\COMPONENTS\QBAGENT\QBDAGENT2001.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\WUAUCLT.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\WUAUCLT.EXE C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE C:\PROGRAM FILES\HIJACKTHIS\HIJACKTHIS.EXE O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb03.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\ADVTOOLS\ADVCHK.EXE O4 - HKLM\..\Run: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.EXE O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMON.EXE /Consumer O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe" O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" O4 - HKLM\..\RunServices: [NPROTECT] C:\PROGRA~1\NORTON~1\ADVTOOLS\NPROTECT.EXE O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg O4 - HKLM\..\RunServices: [KB891711] C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Startup: QuickBooks 2001 Delivery Agent.lnk = C:\Program Files\Intuit\QuickBooks\Components\QBAgent\qbdagent2001.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq.com/falco/SysQuery.cab I am out of ideas. Maybe it's time to just take it out back and shoot it? Quote Let us know if that fixes it. And when I said you got a lot of crap on it, I meant that you deleted a lot of crap (i.e. viruses) off the system. You've got the cleanest Logfile I've seen in a while, normally HJT responses require essays! I thought you meant crap as in MS Office, Quickbooks, and other applications like that. There are a lot of little things like that on it. You should have seen this machine when I first when to work on it with SpyBot. I got literally 150+ red entries the first run. I am ok SKILL wise with Hijack and I took a bunch of stuff out already before I posted. Well, anyways, thanks guys.IE>Tools>Internet Options>Connections>---->Never dial a connection. mox_PERL....... Didnt you say that you deleted the complete FTK file ....... If you did mark this entry for removal....... O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe" dl65 Ok, final update. I got rid of that 04. I had previously left that one because I thought it to be legitimate. I should really know better. Finally, after this, deleting a few other files, and some more registry manipulation, the dialer is finally gone. Hallelujah!! Big thanks to Dilbert, dl65, and Fed for the help. |
|
| 1133. |
Solve : adware.zenoSearch think/adz popups search engine hijack? |
|
Answer» Hello, I am getting a lot of popups and alternate search engine popups. I have scanned with Computer Associates Anti-Virus has found Zenotechinco virus and it says it removed it, AVG Anti-Spyware 7.5 finds Adware.ZenoSearch as malware and says that it quarantines and deletes it but I still have the issues and it is still there. downloaded and RAN HiJackThis based on other posts read here. Below is the Hijackthis log. PLEASE help, the popups are BAD and often unsavory!!! |
|
| 1134. |
Solve : PC on or off?? |
|
Answer» I have a question...Me and my brother both have our own pc's...Mine runs almost 24/7 but I have Norton and firewalls...His doesn't use firewall or security...We use dsl so the internet is on 24/7...His pc got hacked while it was off and mine did not...Does turing a pc off while having 24/7 internet and no security prevent someone from pinging and or hacking you?..Its late here and I need to go, thanks for any info. Quote ...His pc got hacked while it was off and mine did not...Does turing a pc off while have 24/7 internet and no security prevent someone from pinging and or hacking you?..Its late here and I need to go, thanks for any info. If the machine is physically shut down with no power to it, yes it will prevent someone from "hacking" you or anyting else along those lines that involves root access or running code on your machine. May I ASK how he was "hacked"? The particulars I mean. I hear many people say that they are hacked when in fact they just got a hijacker or a program that puts adds/porn on there DESKTOP, usually spyware adds as well. What he is telling me now is when he turned on his pc it said he was HIJACKED...He said he is having problems now running yet mine is unaffected...From what Bellsouth dsl said, you will be pinged all the time so keep a firewall up....i'm confused Quote What he is telling me now is when he turned on his pc it said he was hijacked..What is it exactly that said he was hijacked? Something on his desktop? A popup? Antivirus program? Quote ..From what Bellsouth dsl said, you will be pinged all the time so keep a firewall up....i'm confused Pinging is not necessarily a harmful process. A MALICIOUS ping attack is, but that doesn't seem to correlate with this hijacking situation. Your brother was probably infected the LAST time he was connected, re-booting just allows things to activate. People using unprotected computers on the net should be tracked down & banned.Thanks for the info |
|
| 1135. |
Solve : Downloader :(? |
|
Answer» Well I downloaded SOMETHING today, and Norton popped up saying I got a downloader. So I unplugged my ethernet cable from my computer and ran norton. Norton picked it up and SAID it couldn't remove it. So I removed all the temporary internet files because thats where the downloader was. So now im running Norton again and im not sure if it'll show up or not. So basically I need to find out how to remove the downloader. If it doesn't show up this time in the Norton scan does that mean it gone? |
|
| 1136. |
Solve : new folder.exe help me? |
|
Answer» i scan with avg & norton 2003 but its not detected!its updated man...so,any other UTILITIES antivirus that sure can wipe it?I have had success with the free version of Avast!, so that may be something to look at.Also you can DLoad and RUN Stinger. |
|
| 1137. |
Solve : Continuous Rebooting?? |
|
Answer» I'd like to know how I can get rid of this, what I suspect is a virus: Stop: c0000218 {Registry 4:lei've encoutered similar problems where my pc will boot to the login screen then just reboots again by itself. Unless your boot sequence is corrupted, i'd say 9 times out of ten, it's a virus. I've had it twice. and even if it is your boot sequence which is corrupted, it was probrably caused by a virus. Do you use Norton GHost? If you do, you can use it to restore your system from a pre-saved image.I have the same exact issue....I picked this up by click a link in a email. Definitely a virus. parker, Because the FORUMS can become rather busy at times, I seem to have missed your last reply. That STOP error is TYPICALLY related to a corrupted registry. If you're still having problems, you should CHECK out this article... http://www.jakeludington.com/ask_jake/20050821_stop_c0000218_registry_file_failure.html Try the suggestions and let us know if you have any luck.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 1138. |
Solve : Think-Adz /Zeno Malware Removal? |
|
Answer» Pop-ups have been appearing and my Avira Anti-Virus has continually popped up with numerous alerts of TROJANS and Viruses lately. After a bit of research, and a AVG Anti-Spyware Scan, I believe that I either have Virtumondo or Zeno/Think-adz, I'm leaning towards the latter, but I might have both. I did a scan with HijackThis and here's the log: |
|
| 1139. |
Solve : Can Somebody look over My HJT Log My comp has been acting up again? |
|
Answer» Hey, I don't even know why i posted that new log before, it seems to be working better again. Thanks for all your help.please read this http://www.hijackthis.de/#anl Quote from: 8bamboos on September 20, 2007, 09:01:08 AM Quote from: Frankymobs on September 20, 2007, 07:23:11 AMi don't recommend site like that because they aren't 100% accurate.. its better to have someone who knows how to look at the logs and tell you exactly what to remove.I don't even know why i posted that new log before, it seems to be working better again. Thanks for all your help. OP your very welcome i'm glad mt tuts could help you out. just curious what did the scans find? It didn't find much, Some DinerDash thing, a bunch of processes that were running were deleted one of em was taking up alot of memory. I'm not sure the names though. ok as long as your machine is working fine now. i recommend following those guides once a week or once every two weeks to keep your computer happyYeah, hopefully I can keep up with it, I have adjusted my security on the Computer, so hopefully it won't ever get to this point again. But once again thatnks for all the helpoh one last thing you might want to clear your restore points.. right click my computer > properties > system restore. CHECK the box let them clear then uncheck and click apply and then ok |
|
| 1140. |
Solve : Spybot S&D Immunization Trouble? |
|
Answer» Quote from: FED on September 19, 2007, 03:47:32 PM Upgrading all the way to W2K would be a better option.Heh, I don't currenly have that copy on hand. But it's illegal so I wouldn't USE it anyways. Quote from: Fed on September 19, 2007, 03:47:32 PM I feel LIKE I'm STALKING you lately Comp Guy.Nah, it's fun! |
|
| 1141. |
Solve : AntiVirGear removal - help!!? |
|
Answer» Does anybody know how I can get RID of the AntiVirGear spyware thing. Or at least get rid of the icon that POPS up on the task bar. I don't want to spend 30 or so dollars on proper spyware rempovers to be honest. Cheers folksCheck out this page here... |
|
| 1142. |
Solve : tmp file I can't delete? |
|
Answer» I have 104 temp files in the :windows.c.temp file. Everytime I try to delete them, it says "another PERSON or program is using that program". |
|
| 1143. |
Solve : Could someone check this HJT log please??? |
|
Answer» Logfile of HijackThis v1.99.1 |
|
| 1144. |
Solve : Updating Zone Alarm? |
|
Answer» My LATEST update tells me I must find True Vector in DEVICE Manager and disable it before it will update. My latest update tells me I must find True Vector in Device Manager and disable it before it will update. I'm thinking you really mean disable in the "Task manager" ....not in the Device manager....... Ctrl/Alt./Del ....should get you there . dl65 |
|
| 1145. |
Solve : how safe is demonoid.com?? |
|
Answer» Not really sure where I should post this, but here seemed like the right place: ... I would think that .avi files ... Does anyone know - is it even possible for .avi files to be infected with anything? By default Windows hides extensions of known file types so a nice.avi could easily turn out to be a nasty.avi.exe.just another reason why you should never allow windows to hide file extensions, at all!I've used demonoid.com for almost 2 years now and never encountered any problems. Of course there will be the odd occaision where something bad is there, but all in all it is pretty well maintained on that RESPECT. The community there are, for the most part, pretty decent folk who will inform the moderators or people of authority to have anything malicious removed. Quote from: Fed on September 17, 2007, 07:19:15 PM By default Windows hides extensions of known file types so a nice.avi could easily turn out to be a nasty.avi.exe. While you have an interesting and valid point, I'm still curious to know if it is even possible to INFECT an .avi file. Anyone...?Yes, .avi files technically can in fact be infected. Actually, just about any file can be infected. However, the DEP pretty much prevents such infections from spreading through your system. Anything is possible, of course, but you mostly need to worry about executable files.You can't infect an avi by any of the usual means since an avi file isn't executed, but read by another program. In order to do something malicious with an avi file an attacker would need to 1.) Find a media player or codec (or most likely a combination of the two) with a huge flaw in its file parsing component. 2.) Craft a special avi file to exploit this. I don't think this scenario is particular realistic though, since a humongous flaw like that wouldn't go unnoticed for long in any major media player/codec. Quote from: Deerpark on September 18, 2007, 09:20:38 AM You can't infect an avi by any of the usual means since an avi file isn't executed, ... Which agrees with things I learned a long time ago. Since I know I'm not current on things, just wanted to CHECK and see if my ideas were still correct. |
|
| 1146. |
Solve : Is Panda Antivirus a good program??? |
|
Answer» I used Panda to do a free scan. It came back showing 2 viruses and some adware. It says for 12.95 I can BUY 6 months of service and disinfect my system. |
|
| 1147. |
Solve : Trojan horse and Acrobat reader? |
|
Answer» Problem: May i also add that system restore doesnt get rid of recent viruses. Just fore future refrence Please , don't ever use system restore in an effort to remove a virus .......... dl65 Thanks sooo much for all the information and HELP. I have uninstalled Acrobat Reader and downloaded Foxit in it's place. That seems to have solved the immediate problem. I have never used anything like hijackthis to create a log and may try that. I noticed there were several different download choices...is one better than another? It almost seems like it would be worth while to reformat the hard drive instead. Any thoughts? As far as restoring goes. I had already removed the Trojans before I restored the computer to an earlier date. Quote QuoteMay i also add that system restore doesnt get rid of recent viruses. Just fore future refrence Im sure thats waht i said :-? |
|
| 1148. |
Solve : check this please? |
|
Answer» Logfile of HijackThis v1.99.1 well, don't just gave us thing like this,at least post the the thread,the prob? Actually, he probably posted this log because he was experiencing a problem... It doesn't take a BRAIN surgeon to decipher a HiJackThis log if you know what you're looking for... Here's a link to a good read, skyblue... http://www.bleepingcomputer.com/tutorials/tutorial42.htmlThe first post was the first part of a log, another thread included page 2. I have merged the two topics for you. skyblue, if you could also post what issues you are experiencing and a bit of background info as to why you have posted this log, it would be a great help. Thanks.what it is ,i am staying at my brothers in spain and his computer which he has owned for 3 years DIDNT have any firewall or anti virus and i was wondering if there was anything in his log that shoudnt be there thank youlook at my signature for some program suggestion run them in safe mode then reboot in normal mode and post a new log.. also check out these two guides. http://www.saviour-pc.com/forums/view.php?pg=malware_guide http://www.saviour-pc.com/forums/view.php?pg=win_guideskyblue .... there's nothing on the log that "shouldn't be there" but I would ask ... has your brother been experiencing any "Blue Screens of Death"? OJYes a couple of times , but not for a long while it seems it seemed to happen whilst playing a certain game so he doesn't play it any more. why do you ask skyblueI asked because there is there is evidence in the log of BSODs and I wondered if they were still causing a problem. No matter. From what you say I assume they have stopped now. OJ yes they have thank you for your time skyblueYou're welcome. If the computer is working fully as it should then your brother should do this. He should clear out all old System Restore points then IMMEDIATELY create a new one so he has something to fall back on should anything go awry again. Also remember to make SR points on a regular basis. More on System Restore ... http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx What may have lead up to any infection/BSOD and help keep the computer free of malware … http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html http://www.techsupportforum.com/security-center/general-computer-security/115548-pc-safety-security-what-do-i-need.html There is a little duplication/crossover but all these tutorials are well worth reading. he mustn't forget to download AVG Anti Spyware and/or Superantispyware, keep them updated and use them to scan/disinfect the computer from time to time. If he does suffer an infection again he should run first Ccleaner to clean out his system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) … http://www.ccleaner.com/ Also run through this before posting another HijackThis log … http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html Safe surfing. OJ |
|
| 1149. |
Solve : Removing Annoying Pop-up and Sound Bite...? |
|
Answer» I cancelled a program called moviepass.tv after a 3-day trial period and $1.95. However, they not only didn't acknowledge my cancellation, they send me REGULAR pop-ups, claiming I failed to cancel (untrue) and telling me I must PAY a $29.95 cancellation fee! Even when I minimize their anoying pop-ups, I get a CONTINUOUS, annoying sound track, which I can only mute by muting everything. I tried deleting their programs using Search, but coudn't delete every one. |
|
| 1150. |
Solve : Runtime error msgs keep coming? |
|
Answer» Have Windows XP, Microsoft INTERNET Explorer v 6.0, Norton virus protection program...I am a NOVICE so thats all I know so far...I started getting alot of runtime error msgs so came here and tried to find the codes that kept coming up. (just moved to TN and did not have this problem before) Error msg code #1104 and #17 (unterminated string constant)-what ever that MEANS?? Bought a program and it did man.... What program ? |
|