Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1151.

Solve : Windows Fixer?

Answer»

I am sick of it...literally.

When I am WRITING a long message, it pops up, when I click back I have to start again, it just comes up on my net screen.

I dont no much about it. Its called "Windows Fixer" and it says its found so many problems on my pc. Do I trust it, nope, so I click X on it, but it keeps popping up.

Is there anyway to make it go away...LIKE forever? I am sick of it. Literally.


Thank You AllIf it is winfixer2006 you will need to scan and remove the Vundo virus first.  There is a program that is called Vundofix.exe, works great freeware/donations.  Then scan with Spybot Search & Destroy to remove winfixer.

Make sure you clean out all of the vundo virus, it usually has 3 or 4 backup FILES.  The FILE names are spelled backwords with the extensions .bak  .ini  .tmp.

other suggustions would be to clean out BROWSER cache/system temp and prefetch and turn offsystem restore to purge it from coming back later.

1152.

Solve : Disk Cleaning & Software Removal?

Answer»

I need to KNOW how to clean confidential INFO, website info, and/or any other things off my hard drive without needing to reinstall Windows, etc.  I made the mistake of signing up for "surveys" about 10 days AGO, and I don't know if I've left myself vulnerable or not--but I do know I'm getting some emails from places that I, personally, did NOT go...can you recommend SOFTWARE for cleaning all that up?  Also, any recommended way to remove software for things like Quick Time player and/or other things that I never use?Download CCleaner and use this guide to configure it.
That will clean internet history, cookies etc as you want.
It also includes an uninstall tool, which you can use instead of the Windows one if you like to remove software you don't want.
If you are getting emails you don't want, chances are you may have picked up some malware too, what protection do you have?My computer has Webroot Spysweeper, and Trend Anti-Virus.  I don't think anything on your computer is at risk.  To me, it sounds like you're probably getting e-mails from the survey site's affiliates.  You should unsubscribe from the site's mailing list, as well as the mailing lists of any of these other sites.  Also try out Calum's suggestion and let us know how everything goes.If you're getting emails from places that you didn't subscribe to then chances are that unsubscribing will result in even more emails.
You are better off blocking them with your email program via the email header or keywords within the email text. Quote from: Fed on September 13, 2007, 02:10:53 PM

If you're getting emails from places that you didn't subscribe to then chances are that unsubscribing will result in even more emails.
You are better off blocking them with your email program via the email header or keywords within the email text.

Very good point, Fed.  Unsubscribing will let them know that your e-mail is active, which may result in more spam.  Ignore my suggestion and take Fed's instead.  Block these people and set up filters so similar e-mails will automatically be sent to your trash or a special folder.  What e-mail CLIENT are you using?Using Yahoo email.  I'll try your suggestions.  I hadn't even considered that the unsubscribe would generate even more.  Don't know why, that does sound like an obvious ploy they would use.  Thanks.  I'll get working on this...Yahoo! should hopefully make the task a bit easier for you.  As far as I know, it has a decent filtering system, and there's a Bulk Mail folder specifically for junk mail such as this.
1153.

Solve : Unwanted system tray icons, spyware related?

Answer»

Hey,
I recently got rid of some spyware, but I think there is some left over. I've tried Spybot S&D, Ad-Aware, Ez Anti-Virus, and Norton, and nothing can remove this paticular problem. I've taken some screens of this thing and posted them below.


(red arrows point to the two icons)

The virus/spyware has put these two icons on my system tray, and I can't remove them. Every 30 seconds or so, I get a little yellow bubble appear near the icons and tells me that "Your system is infected! Please click here for special offers on SpyWare removal software". It then adds a desktop icon, shown below.


(I put a red box AROUND newly added icon)

So far no anti-viral or anti-spyware software can remove this thing. Any tips on manual or other means of removal would be much appreciated.

Also, I have a hunch that the problem might be "wupdmgr.exe", because I cannot end the process (It keeps reappearing) or delete the exe, but I don't KNOW much about this stuff, so I COULD be wrong. Thanks for any help.

OS: WIN XP Service Pack 2

It should be easy enough to find. Could you please download HijackThis, run it on the infected PC, save the logfile, zip it with WinZip, and attach the zip file to your next post? We'll be able to take a look and suggest fixes from there.Thanks, Here's the log file.Look and see if you have a program RUNNING called MSSearchnet.exe in your windows/system32 directory.  you will need to use your windows install CD and go into recovery and delete this file if it is present.File Name:   osaupd.exe  

--------------------------------------------------------------------------------
 
Description:
 osaupd.exe is related to a variant of [highlight]SpyFalcon[/highlight] rogue anti-spyware which displays false messages that your system is under control of remote computer. You should remove this file and related infections from your computer immediately.
 

Carry out the steps listed at the following site then return here with a fresh Hijackthis logfile.
http://www.bleepingcomputer.com/forums/topic43659.htmlIn addition to what Fed has outlined .........
[highlight]wupdmgr.exe [/highlight]..........
C:\WINDOWS\wupdmgr.exe    
running process. (wupdmgr.exe)
Added as a result of a Troj/Soromo-A trojan infection ....... This must be removed as well .


dl65  
Okay, had to reboot in safe mode to delete wupdmgr.exe, and so far so good. Thanks for all the help guys.

1154.

Solve : Spyware Info You Should Know?

Answer»

Here is some interesting info. It hasn't been posted in a while, so ENJOY!

http://www.spywarewarrior.com/rogue_anti-spyware.htm#productsI find this infomration, although old, HIGHLY disturbing. The list is much longer since the LAST time I was there a while BACK.

1155.

Solve : Possible worm? or hardware failer??

Answer» HI, Everyone recently i had problems with my computer and it might be because i clicked on a link to a site and possibly got a very nasty virus or mabe a worm, ive tired system restores reinstalling my C and D drives...couple of days ago i restored just the C drive because thats uselly where all the virus end up at when i get them and if it gets bad i usally do a system restore to the C drive...but after i restored C a couple days ago my computer started acting up again. when starting up the screen would stay black, some times it would say there was no power to the monitor, and basicly when i got it to get to the restore screen it would usally freeze during the process and on the screen it seemd to look like dead pixels on some parts of the screen....finally i got it to restore C and D drive and now here i am, and i dont think that fixed the problem.

   so im thinking i have a worm, ive had a problem like this before on my old dell computer and i called up tech support and after about 10 calls someone on the phone actually knew something about computers and walked me threw  steps of what he said was basicly cleaning out the drives? i basicly had to type in a bunch of commands and after that the problem was fixed. but my question is...anyone know what exactly the steps for basicly wiping your entire computer threw commands? not sure if thats understandable, but he basicly walked me threw and told me /commands that fixed my computer...

and now my computer is showing signs of acting up again, just now i started up my computer and it tried to make me go into safe mode...anyone please help?

need help asap thanks for your help!   killafawk......  Ok , for openers , what anti virus do you have installed and is it up to date?
Never use your system restore when you are INFECTED ...that probably the worst thing you could do .
When you answer the question , we can proceed to clean up your machine .
BTW , what O/S are you using ?


dl65  currently AVG which i just downloaded yesterday... i usally have norton which comes with the computer but i think norton is a joke. i ran AVG yesterday with no virusesxpwell i justed tried to update avg and it said it was damaged and i need to reinstall so im pretty sure THERES a big problem with my computer killafawk......  For the record ..... Norton is a very good anti virus .......

I would suggest you D/L and install the following .....
CCLeaner   http://www.filehippo.com/download_ccleaner/
Ewido V3.5    http://www.filehippo.com/download_ewido/
Spybot  http://www.pcworld.com/downloads/file_description/0,fid,22262,00.asp

Once you have these programs installed and have the latest updates.......
please do the following .....

1 Turn off your system restore .
2 Go into folder options..."view" and make sure that the hidden files and folders are being shown.
3 Run CCleaner ..... in Normal mode ....run both the "cleaner" and "issues"
Delete anything that it brings up.
4 reboot into SAFE mode and run a full system scan with Ewido ......
Remove anything it finds .
5 Run Spybot in Safe mode and delete anything it finds .
6 Finally run a full system scan with AVG .......... remove anything it finds .....
Report back the findings .........
We will go to the next level if NECESSARY .

dl65  Do you have a floppy drive on your pc ........ If you do D/L stinger and run it .

http://vil.nai.com/vil/stinger/     ...if you dont D/L it to your desktop and run it from there ....... go -off line while you run stinger ......... then see if you can uninstall AVG and then D/L it and reinstall it .......

dl65  

quick question what do you mean by turn off system restore?Click start/control panel/system ........when system properties opens ......click on the system restore tab ...... and puit a tick in the box where it says turn off system restore on all drives ..... then click apply and ok
Bugs , particularly trojans love to hide in the system restore files .......... and then you simply reinfect your machine all over again .

dl65  ok last night i ran it in safe mode and did all that you said and the scans came up with nothing....infact, today i opened up my computer and the video card was very very hot, i actually think i blew my video card because i left the computer on to scan last night and i left the computer on and i turned on the monitor today only to find the screen dark and bunch of what looked like dead pixels, i checked the video card and the fan isnt on there anymore, i took it out because i was gonna throw my old video card in there to check but i couldnt find it...so i let it cool off and put it back in and tried again, in less than min. the video card was extremely hot again, then the screen starting to go dim and dead pixels came up everywhere i moved the mouse so i dont think i have a worm or virus, i think i might have just blew my video card, but i still have to make sure...by the way do you guys think my video card can be repaired? i spent 250$ on it bought it on newegg so dont think there is a warrenty so you think its possible to repair it?
If you bought it fairly recently and have the receipt I would contact Newegg. They are very good with RMA's for covered problems. If the fan was not working, that could sure ruin the card. Best to get that issue resolved, then we can move forward, if needed.ok well i think the whole problem was just my video card over heating and now it finnaly died out, but as i was writing my last post i was on my sisters computer...its a peice of junk 128mb type dell computer and i shut it off and was going to put my ram into the computer to make it faster while this computer is out but now it says the monitor has no power or something...basicly the computer starts up but there seems to be no connection between the monitor and computer...i was kinda having the same problem with this computer anyone have any idea what it might be?

oh and ANOTHER quick question....the fan fell off my video card and there is some wires that need to be put back, it over heats very fast now and i was wondering if it can be saved? i can replace it for like 100$ now but i bought it for 200$ last year and i dont wanna have to pay extra money if i can get it easily fixed for couple bucks..thanks again.
AVG has had an update on the 2nd of May, I think you just missed the new one.
I've seen AVG throw up error type messages in the past when they have a program update.
Download the latest version & you'll be ok.
Program Version # 7.1.392Well, you could do an online virusscan just to be sure.

Here are some good sites for that purpose :

Panda ActiveScan --> http://www.activescan.com

Trend Micro HouseCall Antivirus --> http://www.trendmicro.com

If you suspect spyware/adware being installed on your computer , install these apps to scan for spyware/adware.

1)  Spybot Search & Destroy  1.4 --> http://www.spybot.info

2)  Ad-Aware SE Personal 1.06 --> http://www.lavasoft.de or http://www.lavasoftusa.com


To prevent spyware/adware from being installed , install these apps :


1) SpywareBlaster 3.5.1 --> http://www.javacoolsoftware.com

2) SpywareGuard 2.2.0 --> http://www.javacoolsoftware.com



Oh , one more thing : Don't install Norton or Mcafee as a anti-virus protection , it does suck as you said.
I use Panda Platinum Internet Security 2005 and it works well here.


If you have scanned your system for virusses , spyware/adware and it doesn't result in finding it, I would suggest downloading Hijack This 1.99.1 --> http://www.merijn.org and post it on this forum or another one. Then specialists can have a look at it and tell you what you can delete from the log and what you don't need to delete.

Warning : Hijack This is not a program to play with ! Only for advanced users !


I hope I have helped you with all of this. If not , just send me a PM or an e-mail.
1156.

Solve : Invisible hijacker??

Answer»

I was in the school's computer lab doing some research for English I. (The PC is the exact one in GX1_Man's avatar) I had to use IE 6 SP1 and of course it was going slowly. I wanted to get Email, so I could get a link I Emailed myself. I try to go to hotmail.com. That's exactly what I type. However, it takes me to http://hotmail.com.org, which is NOT what I wanted. I think to myself, "browser hijacker". So, I pull out my binder and extract my HJT diskette* (yeah, floppies have a use), pop it in, and scan. I don't see anything out of the ordinary. In fact, I've never seen a cleaner log:

Quote

C:\WINNT\Explorer.EXE
C:\WINNT\SYSTEM32\DWRCST.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
A:\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization MANAGER] mobsync.exe /logon
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1126832105875
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = amity.k12.or.us
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = amity.k12.or.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = amity.k12.or.us
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINNT\SYSTEM32\DWRCS.EXE
O23 - Service: IM Detector (imdetector) - Unknown owner - C:\Program Files\IMLogic\IM Detector\detector.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Symantec AntiVirus Client (NORTON AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

I Google'd for a few .exe files (difficult) but found nothing. It appears clean, even the last one appeared to be OK. Typing in the http and all the rest RETURNS a 404 error (as it turns out, Email is blocked in the lab...). But at this point, my concern is ridding the PCs of the hijacker, because if that can get through, what else can? We only have Norton for protection there, and if a virus gets on there... well, we use floppies a lot in that lab... other PC's nearby were slow as well, but I didn't check for the hijacker there. So what's up?

*I don't know if there is a rule about floppy programs or not, but I haven't heard one... Quote
The PC is the exact one in GX1_Man's avatar
<----------------

A fine machine indeed!
DWRCST.exe could be Cptv.Windir.Malware, can you get the file byte size?

Check the HOSTS file.

I'll see about getting that as soon as I can.  Dilbert...   DWRCST.exe  

The dwrcs.exe is process required to allow other computers to connect to you computer using the DameWare remote control client. If you do not use DameWare remote administration software you should terminate this process.

dwrcs.exe is an application that does NOT appear to be a security risk

Given that nothing showed up in the scans , I would say its harmless.

dl65  

Malware Group
Cptv.Windir.Malware

Vendor
DameWare Development
Product DWRCST Tray Icon
Version 5, 0, 1, 1

Path Name
%WINDIR%\
SYSTEM32\

File Name
DWRCST.exe

Behaviour
Modifies the hostsfile

File Size
85504

Observed Behaviour - Cptv.Windir.Malware was first detected by Prevx1 on Jul 16 2005.
Could use your PC to send mass mail using SMTP protocols. Modifies Internet Browser Settings:(HomePage). Creates multiple copies of the Malicious infection on your PC. Creates registry run keys to ensure it is restarted every time you boot your PC. Installs other malicious programs. Examines which processes are running on your PC allowing it to explore vulnerabilities in Windows and your antivirus and anti-spyware products. Modifies the HostsFile which could stop your antivirus or anti-spyware protection or PUT your personal information at risk. Connects with 3rd party computer systems and forwards data via the internet. Hijacks other processes.

You will find out for sure when you check the file size.
Check your HOSTS file for re-directs.OK. Soon as I can. I couldn't get into the computer lab today though; testing. :-/
1157.

Solve : Mp3's, Avi's Etc?

Answer»

Helllo chappys,
                       Ok well got a video off the internet the other DAY and well, tbh as soon as i opened it it said the  one or more CODES are needed to play this letter, fair enough i thought to my self. So i deleated it, but ever since i opened it strange things started to happen, although my scanner pict up NOTHING. So obviously it was a coinsidence. But it got me thinking is it possible to get viruses or spyware and all that rubbish with Mp3's and Videos?

Just a question.
C}{r1$its not related buddy dont worry.

R0SS Quote

But it got me thinking is it possible to get viruses or spyware and all that rubbish with Mp3's and Videos?
Yes, FILE extensions can be hidden so what you see as file.xyz could in fact be file.xyz.exe.That's why I turn off "Hide extensions for known files". Extra security and the ability to finally create the .dilbert extension! Ahhhh ok thanks guys, much appreciated. Because once i downlaoded a song and it said something along the lines of
"the file you are trying to play has a different extension then the one shown, runnig this file could cause SYSTEM instability" something like that anyway, so just deleated it.

Ok thanks again guys.If you have all codec supported it shouldnt be a problem
1158.

Solve : Trojan Horse---Threat found?

Answer»

So, my antivirus software Symantec DETECTED through "Auto Protect Scan" that a threat has been found and it so happens to be indentified as the "Trojan Horse". It was located in a .dll area of my Cdrive, but was already quarantined. But I wanted to make sure by running a scan through all my drives and such. OBVIOUSLY it found it and took the necessary steps to delete it following the scan.
But why does it still pop-up a window about detecting the "Trojan Horse" again..was it not deleted the way it should have been? Did I not delete it correctly?

I've also noticed that when my computer starts up and loads my icons onto my taskbar that it will pause for about 2mins before resuming (maybe just a slow processor to begin with) but also has had an affect on my internet surfing...been DRAGGING..does this have something to do  with Trojan or is it that time for my old computer to get an upgrade?

so confused on what to think of this..
fyi: comp specs...still running on a compaq presario mv520 back in 2000!!! probably a 16-bit at that..(sad, i know..) jbm808.... Norton ,may have quarintined the trojan but it may not have been able to remove it ....so the first thing to check is ...... open Norton , go to the quarinte file  ....reports ..... then click on activity threats and see if the threat that was detected was removed or it the removal failed ....... Norton , while very good in dealing with vires , doesn,t do so well with trojans ........
If you see the trojan in the quarintined file ...... delete the etry there and then do this ......
1   Turn off system restore on all drives.
2   Go into the control panel .... folder options/view ........ and tick show hidden files and folders ..... then click apply and ok
3 Go to ... http://www.filehippo.com/download_ewido/   and d/l Ewido v3.5
4 reboot into Safe mode ......
5 Scan your system with Ewido ...and remove anything it finds .
6 RUN a full system scan with Norton ....... just to be sure things are clean....
If things are clean , reboot back into normal mode and turn system restore back on .......

dl65

1159.

Solve : Virus Issue?

Answer»

hi everybody!!!

i'm in need of some serious help here  

i've got this virus (edlm.exe if u wanna Google it), which my anti virus program never fixed for me. so i read in this forum that you have to try and rename its 3 FILES. so i did that, and restarted.  But after logging in to my USER account on windows XP as usual and my desktop loads, after a few seconds i get a black screen  

now what i'm really asking for is how to access MS DOS without having to log in to windows??  :-?  i want to access DOS to rename the virus files back to their original state.

PLEASE HELP   :-/in XP there is no way to BOOT into MS-DOS.
however, if XP is not installed in a NTFS partition you can try booting the machine with a boot disk for win95 or win98abz....  I believe that you are infected with a trojan ....not a virus and that is PROBABLY why your AV didnt catch it .........
I would be inclined to do this ....... D/L Ewido V3.5      http://www.filehippo.com/download_ewido/    .... once installed , get the latest updates ...and then ..........Reboot into Safe mode , and run Ewido ...it should find and remove the trojan ........

let us know how you make out .

dl65  ok i managed to start windows in safe mode during those 20 seconds hehehe

so now i did a system restore, but the trojan is still in its original state.

i'm downloading Ewido rite now (thanks dl65  ).... i have Ad-Aware... shouldnt THAT have removed the trojan:-?

thanks again  abz  ....... Several things , First Ad-Aware is not designed to remove trojans .
Second , Never use System restore to attempt to remove trojans or viruses ....all that happens is the infection is in the restore files and everything just comes back ......
If you suspect you have either a trojan or a virus ...the first thing to do is turn off the system restore feature on all drives ....... and then go into safe mode and run your scans .......  Then once the system is clean ...it's safe to turn system restore back on .

dl65  you misunderstood me....

I did the system restore to go back to the original state of the virus, before i tried to fix it and ended up making it even worse.  

I'm formatting my pc now anyway... cant seem to get rid of this trojan (i wanted to FORMAT anyway.... but i go crazy thinking about all the backups i gotta do hehehe   )

I tried loads of stuff that i read on the internet about it but it always results in that black screen after loggin in to window  :-/

thanks anyway for your help... much appreciated  

1160.

Solve : http://www.securitybulletin.net?????

Answer»

I once had a nasty that Panda Online Scan picked up, Panda didn't remove it, only reported it to me.
For the life of me I couldn't find it, I even emailed Panda but received no reply.
Eventually I was able to find it by using a dos prompt and removing all the file attributes via dos from the files that were supposed to be in the directory.
I have no idea why it allowed me to see stuff that windows would not show?
I even found some leftover norton virus files in there too..... a bonus!

Anyway, try using the dos attrib -R -A -S -H command on the file & directory followed by the dir & del commands.

If you are shaky with dos as I am and you need some help, just ASK as there are a few people in here who could easily lead you through it.What should I do about this hijacker? UnknownUser..... What is the current status of your machine ....... The last hijack log I saw was taken on May1 ...thats 3 days ago ........

How about a new one .....

dl65  Further up this thread you put a LINK to [highlight]'a screen'[/highlight], you need to double click on the [highlight]'My Documents'[/highlight] folder to see what's in there because that's where this [highlight]\??sks\c?rss.exe[/highlight] directory & file are supposed to be.

If you see them, delete them along with the startup entry using Hijackthis.
O4 - HKCU\..\Run: [Zwhzglwr] C:\Documents and Settings\Compaq_Administrator\My Documents\??sks\c?rss.exe  

If you can't see them, tell us & I will guide you through the previously mentioned DOS process unless someone else volunteers,..... c'mon guys.

As DL65 said, give us a fresh Hijackthis log too.When I ran Hijackthis I deleted everything it found. The site no longer comes up as my homepage. Heres a log just incase you guys still need it.

 UnknownUser....  Ok , your logfile looks fine now ...... WELL DONE .
If you had your system RESTORE turned off , you can SAFELY turn it back on now ,

dl65  Cool, thanks for all the help guys. How did you manage to delete c?rss.exe?
Hijackthis won't delete it for you, it will only delete the startup entry.

1161.

Solve : W32.IRCBot virus- any fixes out there??

Answer»

I work as a PC tech, I got a computer in that keeps generating tmp files in the windows/temp folder that are DETECTED by Norton AV as having the W32.IRCBot VIRUS.  Norton deletes the infection but they keep coming one after the other.  

I have ran AV scans with Norton, trend Micro and Sophos, Spyware scans with Spybot S&D and Ad-aware.  I have ran HJT, XP_procexp, TcpView.  I also ran a program by McAfee/Avert called stng260.exe.  Everything comes back clean, but I am still getting these infected tmp files.  Has anyone dealt with the W32.IRCBot virus and successfully cleaned it?  All the AV sites out there just give generic worm removal instructions that do not work.
lex.....  From what my research has turned up ..... "W32.IRCBot virus" isn't a virus , but rather a trojan. If it was my machine , this is what I would try .....
Run CCleaner ...... delete all entries it brings up . Then run the "Issues" function as well. ( be sure to backup registry when prompted ) fix anything issues FINDS .  THEN
1.... D/l   Ewido ....... from  http://www.filehippo.com/download_ewido/   make sure you have the latest version .......
2.... Make sure that if there are more than 1 user accounts setup that you sign in with the Admin account .
3.... Go into control panel , folder options and click the view tab ..... scroll down and make sure that "Show hidden files and folders" is ticked . then apply and ok
4....While in control panel ...... click system , then when system properties opens ...click the system restore tab and turn off system restore on all drives .
5....Reboot into SAFE mode ....... Now run Ewido .........
record anything it finds ....... then remove what is found .
6....Run Norton again in safe mode and see if it picks up the nasty ...... ( it wont fix it if its still there ,but it will detect it . ( also check Norton quarintine FILE and see if it has quarintined it but failed to delete it......)
7 ... Then if Ewido found anything ( from what you recorded ) manually check the registry and see if any entries are still present .......( use the "find" function in the EDIT portion of regedit .)

Hopefully it will have been removed .......
If for some reason its still there , post a hijackthis log here .......

dl65  


Your right, I should not have called it a virus, it is actually a back door Trojan horse.  I have a hard time separating virus/Trojan/worm, my users get confused so I always just say virus, lol

I will try your solution, I hope it finds it.  Some how those temp files are being created or downloaded from somewhere.  It is a little disconcerting that the scanner finds the infected tmp files and has a name for them in their LIBRARY but can not find the infection  responsible for putting them there.

1162.

Solve : Security software comparisons?

Answer»

OK, well I'll be making a fresh start with my laptop soon, and I want to get everything right first time, when I first got it I went a bit crazy installing things and I've never really got rid of it all, there's always something left.
Security software is obviously a major consideration, so I'm looking for opinions.
I'm thinking of using Spyware Blaster, Spybot Search & Destroy, and of course an antivirus program.
But which one?
I've tried Norton (urgh), Avast!, Avira Antivir PE and AVG Free.
AVG was the only one I liked out of those, but does anyone else have a program they really like?
It needs to be effective, customizable, include real-time scanning, and it must be light on resources.  I don't need anti-spam, firewall or anything like that, just AV.  And it doesn't have to be free either, although I would prefer it.
I've been looking at AOL Virus Shield (yes, AOL, the spawn of Satan.  But, it's based on Kaspersky 6 and is apparently very effective - and free), Kaspersky Antivirus 7 or Steganos (based on Kaspersky, but cheaper), NOD32, and F-Secure.
If anyone has any other recommendations I'd like to hear them.
Anyone with any of the mentioned AV programs, or one they want to suggest to me, can you please tell me what you think of it as regards resources, customizability and so on?
Thanks in advance.
Calum.F-Secure got on of the best AV engines available and is on the forefront of rootkit detection. Unfortunately it has a rumor as a resource hog (which was still true last time I tried it) and slow scan speeds.

I think I've mentioned this a couple of times but I use NOD32 on my main machine and I really like. It is light on memory, has a high detection rate, doesn't have a lot of unnecessary features, fast at file scanning and it doesn't bother you every time it does something. You know it's important if it pops up with a warning. And it also got rootkit detection.
Only negative thing I can say about it is that its spyware detection could be better. But you'd probably be better of using a dedicated anti spyware solution no matter what AV software you end up with.

Kaspersky is also a good choice. Good engine, fast, rootkit detection. And as far as I remember it also monitors suspicious activities in the registry. Only negative thing I can say about it is that it has some compatibility issues. It doesn't WORK with the Comodo firewall for example.

Well that was just my two cents... but I think you'd be PRETTY well protected no matter which one you end up choosing.You got any figures on memory usage and scan times for the programs you've used?Sorry no, the above post is a mix of my personal experiences with the programs, AV-Comparatives, and my interest for security related IT news.AVG Antivirus and SpyBot S&D Resident are still doing it for me Calum.
What firewall are you going for? Quote from: FED on September 14, 2007, 08:15:47 PM

AVG Antivirus and SpyBot S&D Resident are still doing it for me Calum.
Same here.  I'm quite partial to TrojanHunter, though, but it's not freeware.AVG Free
AdAware
SpyBot
AVG Anti-Virus
aSquared Free

This package has kept me completely clean for some time now. I also DLoad and run the latest Stinger once every 2 weeks just to be sure.
Opinions will vary on protection apps but with them all free and effective i'm not about to change anything soon.

BTW the last report i read documented that AVG had the smallest footprint/memory usage of the top 15 A/V apps...i'll dig out the article for you. Quote from: Deerpark on September 14, 2007, 04:49:33 PM
Sorry no, the above post is a mix of my personal experiences with the programs, AV-Comparatives, and my interest for security related IT news.
OK, no problem.  I couldn't find any figures either, I find them easy to deal with, they're something that's just easy to recognise with one being clearly better or worse.
Quote from: Fed on September 14, 2007, 08:15:47 PM
AVG Antivirus and SpyBot S&D Resident are still doing it for me Calum.
What firewall are you going for?
Hardware firewall.  See this topic.
Quote
BTW the last report i read documented that AVG had the smallest footprint/memory usage of the top 15 A/V apps...i'll dig out the article for you.
I have heard people saying it's got a small footprint, one of the reasons why I was using it.  Just trying to find something better as always, not that there's anything wrong with it.  I'd be interested to see the article if you can find it.

Another thing is that what I was using, Spybot, Adaware 2007, Spyware Blaster, AVG and Comodo Firewall, plus common sense, Firefox with manual cookie control and Noscript, kept me clean for as long as I was using that combination.  I'm DITCHING Adaware (no real-time protection or immunization) and Comodo and I'm just looking at whether I should replace AVG.  So I do have a rounded security suite in other respects.Calum,
Didn't fimd the link but here's part of yhe article...

[Saving disk space - attachment deleted by admin]Interesting.
Thanks for that, it does show a bit of difference.
Although, technically AVG could have very few processes using 3Gb of memory each, and Norton's thousands of processes could use 2Kb each.
But, we all know it's the other way round.
1163.

Solve : videos wont work properly?

Answer»

my VIDEOS only go to like 30 secouds then STOP im not sure if it is a virus but can u helpmore specification plz?
what player did you use?have you try different player?WINAMP,real player?windows media player?power DVD?
check you video setting

1164.

Solve : Windows Office Installer Premium?

Answer»

Maester....   Quote

Those two I cant get rid of. The computer I used, is shared- basically, there are more than one password. I am not the admin on it, maybe that will help. If I have to, I will go onto the admin settings on the computer.
  Pity you hadn't mentioned the fact that there are other user accounts and that you weren't the admin ....we could have saved some time ......
This is what you should do......
log on to the infected machine as the admin.........
1...Then D/L ...... CCLeaner .... http://www.majorgeeks.com/download4191.html
2...Then D/L Ewido V3.5 .... http://www.filehippo.com/download_ewido/
3...Now go to control panel/folder options ...then click "view tab" .....now scroll down until you see show hidden files and folders ..... and put a tick in the box ....then click apply and then ok .
4.... Before you leave control panel ...click on system ..... then the system restore tab ....... and tick " turn off system restore on all DRIVES ..... then apply and ok .....then exit the control panel.
5 .... Now run CCleaner ....... ( cleaner part ) ......remove all that is listed .
5a ... Next run the "issues" part of CCleaner ...... fix anything thats found ( remember to back up the entries when prompted to do so )
6.... Now reboot into safe mode .....
7 ...From Safe Mode , run Ewido ......... remove anything thats found .
8... Still in Safe mode ... Run whatever ANTI virus program is installed. ( removing anything found )
9...Now go back into Normal mode ....... ( still as the Admin ) and run a hijackthis scan and POST it here please .

dl65  

Another case of witholding information!sorry, didnt think it MATTERED, why give more information then you need to give.Maester...... So where are we at with this machine now ....did you do what was suggested in reply #15 ??
Also where is the new hijackthis log ?
The importance of knowing about additional users is that if the infection is residing in any of the files shared by the various users ......... cleaning out just your user account wouldnt necessarily clean up the machine .


dl65   Quote
sorry, didnt think it mattered, why give more information then you need to give.

Because that is how you get an appropriate solution to the problem.  
I been busy. Quite. I am juggling several things at once.

I downloaded one of the things you said, however....

the link http://www.filehippo.com/download_ewido/- doesnt work. I get a blank page went clicked.

Also...Safe mode...I no what it is, what it does...how do you get it on?

I will try and get it up soon the log that is...I am however...in "busy week"




Maester .......  Odd the link ....   http://www.filehippo.com/download_ewido/
seems to work fine here and I tried it on 3 differant machines .
Try pasting the address directly into your browser address box....

Safe mode ....... Usually at the beginning of a reboot , repeatedly tap the F8 key and you should be OFFERED some options as to how to start ....choose SAFE mode .....

Quote
I will try and get it up soon the log that is...I am however...in "busy week"  
..... It only takes a minute or two to run the scan with highjack this and post it here .......   Your week can't be that busy ....LOL

dl65
1165.

Solve : Spyware prob - I'm not the most clever at this!?

Answer»

Darren....  If you are CONVINCED that your copy of XP is a non pirated ONE , I would phone MicroSoft ...... ( in the USA )  at 716,871-2781 or 888-352-7140
They should be abe to assist you.  ( make sure you have the product registration code handy when you call.

Good luck,

dl65  For a while there Micro$OFT was giving a free copy of XP if you could identify the SOURCE for a pirated copy you ended up with.  

Are we really to that point in software?The problems started around a week ago and now the comp is just really slow, usually TAKING a long time to do what I do eg right click. Would it be easier if I deleted this account and transferred my documents etc to a new one, as I have had to in the past when the comp froze while I was on Windows Media Player?

1166.

Solve : I just need a quick fix!?

Answer»

It's been so long since I used Win 98 ....I cant remember .....

Ok ...... try and BOOT it up in NORMAL mode ......dont be connected to the internet .........  If it loads up ... OPEN up the cd drive and install AVG FIRST .......
then go back into safe and run the system scan

dl65  Well, I tried LOADING the cd in safe mode and normal mode but...no luck. thanks anyway DL.

1167.

Solve : TCP/IP connection was unexpectedly terminated?

Answer»

Help!

I have Windows XP using Microsoft Outlook 2000 and have Norton's Internet Security which I turn off so email can go through.  Today, I came in and I am getting email but can't get email out of the outbox.  I get this error:

The TCP/IP connection was unexpectedly terminated by the server.  (ACCOUNT: gives NAME, SMTP server:"smtpout.secureserver.net", Error Number: 0x800ccc0F

I have internet access and access to my server and I don't understand what the problem is, why it CHANGED and more importantly what to do about it.  Can anyone help me?  Many THANKS in advance.That mail server is currently online and responding to connections.  Are you still exeriencing the problem?  If so, it may be that you have been temporarily tarpitted (blocked) by the mail server for some reason.  Best taking that up with your ISP.

1168.

Solve : Reinstalling Symantec Internet Security?

Answer»

I bought Symantec Internet Security 2004, and each year after I have bought the renewal online.

I want to format my computer and reinstall it, but I can't find the installation files and the updated files.

Also, I'm wondering if I just backup the folders onto disc and then move them back into the c drive, will that be the same as being installed?

The Symantec web chat support is terrible.  Very slow typing and couldn't answer this question.  Also said he was only trained for the 2005,2006 editions.  

(by the WAY, this is a Japanese version of the program, but the file names are in English and I assume everything is pretty much the same as English versions)
Unfortunately, I would suggest you contact Symantec directly about GETTING a current copy of the program SINCE you have paid for it and are a regular customer.  buy the newest version of it. its cheap and my scan times were cut by 35-40% with the new one. i was in the same position as you are and its so much easier, and saves a *censored* LOAD of timeIf I was you (I've been renewing my symantec online for 5 years) I would copy all your files to CD and then re-install them where ever and attempt to go online and renew your subscription. You wanna find the files, pain in the arse but your gunna have to kick your little 'search files' buddy into gear. They shouldn't be too far spread (the FILS I mean), as long as you get the main application, you don't need all your 'update' files cos when you re-apply it should update automatically. Is this too easy or am I missing the point?...Thanks for the replies.
I kept renewing my 2004 version simply because it is cheaper that way and it works.
I renewed it only a few months ago (for a year) so I'd really rather avoid formatting the computer and then losing my 9 months of remaining subscription and paying again.
  
Actually, I found the original installation file, but I can't find the update file that I downloaded after paying for it.  Since it doesn't seem as easy as I thought, I guess I'll have to contact Symantec Japan, which I would have rather avoided.  
My brother had the same problem. Called Symantec and problem solved in 10 minutes.

1169.

Solve : A series of suspicious events?

Answer»

Specs:
Windows XP home edition
cersion 2002 service pack 2

Packard bell computer/ intel R
Celeron (R) CPU 2.93ghz
192 mb Ram
Physical address extension

I'll list a few of the things that have been to my pc and internet, I don't know anything about viruses so maybe somone can get something from them. I run Spybot S&D and Adaware alot, and I also use Norton But these don't help.

1. Explorer will suddenly stop working, giving me a page not found for everything.
2. Explorer will stop working and my internet connection will completely switch off - the usb light on my router also goes off - forcing me to reset the cpu and my internet connection.
3. Downloads will suddenly stop, mostly with limewire - all the downloads would just fail and SOMETIMES my save folder is erased.
4. PC will go really slow when anything else is open, this only started to happen recently.
5. An end program now message about something called ccAp often appears when I turn off the cpu. I don't know what that is, so I imagine it is a virus.
6. Often, there is a program in the task bar called active movie window I can't get rid of it, nor can I click on it to open it.
7. PC will go slow for no reason.
8. Computer would sometimes reset itself for no reason.
9. Sometimes I get an update message from windows telling me it will reset the pc in 60 seconds to install some files. Even after letting it go through it has come up again.
10. Some file are highlighted with blue writing.
11. Sometimes when I rename files I get a message saying something like: changing the name or LOCATION of this file will stop it from working. When I do the file turns into one of those files that lead you to a selection list of programs. I forget what they're called.
12. Often when I'm browsing the internet my cpu will just go really slow and a blank JPEG image will open up on screen. I know this is a virus but what kind of damage can it do? And can I use the usual programs to get rid of it?

These are a few I can remember. Sorry if it's too much.

Thanks in advance A clean install of Windows will fix everything for you.Well CCAPP is an startup item that is associated with the Norton antivirus and Internet Security suite.  So ccAPP is not a virus but a part of Norton's security software. For the rest of the problems, I would have to say EITHER try restoring to a previous point by using the restore console for XP or I would recommend doing a total reformat.Download, install & update...
CLEANUP
Ccleaner
(During install, uncheck the Yahoo Toolbar option)
(After install, set Options>Advanced> 'Uncheck the 48 hour box')
ANTI SPYWARE
Ad-Aware
Spybot S&D
ANTI VIRUS
AVG Free (After install, set Options to 'scan all files')
ANTI TROJAN
EWIDO (W2k & XP Only)
      and/or
a-squared (a² Winall)

Turn off System Restore if applicable. (ME & XP users)

Run Ccleaner
Run Ad-Aware
Run Spybot
Run AVG Free
Run Ewido and/or a-squared (a²)
Re-start in Safe Mode
Re-run AVG Free

Re-start in Normal Mode
Turn on System Restore if applicable. (ME & XP users)Another good antivirus solution that is good to install especially to prevent future occurances like this would be Avast Home Edition, free and include several nifty shields such as resident shield, mail shield, p2p and 4 other shields. The only negative is the scanning rate is a little low than others in what is found regarding trojans and some viruses.

1170.

Solve : Spybot or CounterSpy??

Answer»

I just PURCHASED a laptop (fujitsu lifebook Nseries)  about a week ago and I don't know whether to use spybot or COUNTERSPY.  Maybe SOMEONE can help me decide which one I should GET or if anyone has a better suggestion i would gladly appreciate it.OS?
What other protection are you considering, AV, Firewall? roba_ent.....Well for openers , Spybot will do a decent job and its free ........Counterspy , also will do a decent job , but I think its only free for 15 days and then you pay ........ I tested it on 2 of my machines and it did a decent job ........
I suppose it all depends what your looking for these apps to do ......

dl65  If you use Spybot, use the Immunize feature.  It HELPS prevent a lot a spyware from getting into your computer in the first place, rather than detect and remove it after the fact.

1171.

Solve : Wierd setting or Trojan??

Answer»

Since tuesday, my computer has been acting strange.  Whenever I hit the E, U, L, M keys on the keyboard OR on the windows On-Screen Keyboard, it does certain functions which I have never chosen.  Hitting E would bring out the My Computer with folder options, U would bring out the Util Manager, L would bring me to the Windows Log-In screen, and M would minimize the program I am currently in.  It's impossible to type in ANY program without having the binds being used.  Games, chatting, MSWord, WordPad, IE will always have these things appear when I press those certain keys.  When I close the things that appear, the letter is not typed.  I have to type in websites by highlighting letters and pasting them.  I have not downloaded anything unsafe and I mostly use my computer for online gaming and AIM chatting.

I have scanned with Ewido, AVG Free, Spybot, CCleaner, and Trend's Internet Housecall with system restore off.  So far, only the Internet Housecall had reported 3 trojans, 2 of which I am sure is now DELETED but the troubles are still there with the keys popping out random stuff.  It was working quite nicely on Thursday from 3pm-12am but the things popped out again.  I tried this afternoon to use the Housecall again but it won't load.

So, any ideas? yihkun  ..... You SAY you removed 2 of the 3 ........ the one you havent removed is whats causing the trouble ..........
I would be inclined to make sure system restore is off , then reboot into SAFE mode and run Ewido again ....... and then your AVG ...as well ....
If the trojan is located ....write down exactly where it is .........
If you are unable to find it ..... D/L  hijackthis and post a logfile here for us to look at ......
Do you have your file and folder options set to show hidden FILES and folders ? If you don't please do so .

dl65  Scanned again and found nothing.  Posted hijackthis log into the first post.yihkun..... Your log reveals SEVERAL things .......
You do not appear to be using the most recent version of IE ..........You should update it .
Also you appear top be using a accelerator program ......... I would be very surprised to hear it actually increswed your D/L speed ...I would be uninstalling it .......

Now then in your hijackthis log ....... Mark for removal the following :

O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs    ...... Dont think you really need this ....

O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe    

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)    ..... for some reason this entry is in here twice....... mark both to remove .

Ok , when you have marked them click fix marked .

let us know how things are .

dl65  I have uninstalled the download accelerator and have removed the items you have told me.  The keys still go to the things I described in the first post.  However, I have found out that if I hold shift and type the key, it will not have something happen.  That should help me out.  Any more suggestions?  Could this have something to do with keyboard binding in which i can unbind the keys?

And ya, the accelerator program.  It increased my speed by 20% and really organized my downloaded files.  Been using it for 5 MONTHS but I uninstalled it like you asked.  And what is the recent version of IE?

Thanks. yihkun ...... Ok ....if you really think the accelerator is speeding up your system ( which I doubt) ...put it back in ........ but as a test , go to ..... http://www.bandwidthplace.com/speedtest/   and do a free speed test ...... one without the accelerator and one with it ...... and see if there is any differance.


 The version [highlight](6.00.2900.2096) is out of date. [/highlight] this is what you have installed
Check Windowsupdate to update the Internet Explorer.

 Newest Version is: 6.00.2900.2180

dl65  
  This happened to me several times. In windows 98, whenever I hit E I ran the windows explorer, R would bring up the Run prompt, etc. What happened, at least to me, was that because of some problem, the "windows" key (the one with the windows logo on it) had gotten "stuck", like it was constantly being pressed. Try pressing and letting go each one of your "windows" keys (if you keyboard has them), and see what happens. If not, I'm clueless.

TheCount

1172.

Solve : Possible trojan/harmful process?

Answer»

I was looking up my PROCESSES in a directory and I found that the LSASS.EXE process is a trojan and should be terminated. I tried to, but I got an error MESSAGE saying it was a critical process and COULD not be terminated.

Was the website I was using wrong or is it so bad that it won't let me remove it? If it really is a trojan, what can I do to get rid of it?

Thanks for the help in advance.Have a read Armando:

http://www.google.com/search?hl=en&lr=&q=lsass.exe


<-----------------Well half of them say it's a virus/trojan and half of them say it's a legitimate process, so I don't know which it is.

I'm assuming since I can't remove it that I don't have the bad one.Sorry if I replied a little late. One THING I have found out is this: lsass.exe, is a legitimate process, while lssas.exe is a virus. Hope it helps.

TheCount

1173.

Solve : AVG free, good scanner??

Answer»

I just DOWNLOADED avg free (free.grisoft.com) & installed, because a lot of people told me it was good, but is it? I downloaded some viruses (like psp downgrader) and none of the files were detected! Does anyone has good expierences with avg free, or know a test virus because I don't think avg stops a virus :sGoogle for eicar.
Is psp downgrader a virus? Quote

Google for eicar.
Is psp downgrader a virus?

I downloaded Icar, even before the post, and NOTHING happened. Norton provides PSP downgrader as a virus...

I'm a bit worried that avg don't stop any viruses. However auto-protect is on. Is it because I have avg FREEThat's strange, I just tried to download eicar & AVG stopped it straight away?
Are you sure you have the AVG Resident Shield turned on? Quote
That's strange, I just tried to download eicar & AVG stopped it straight away?
Are you sure you have the AVG Resident Shield turned on?

after the reboot it found the virus. But it still don't stop the psp downgreader...I think Norton made a test Virus only Norton could find. This WOULD "help" people like you who are SMART enough to question each scanner pick what they feel is the "right" scanner. Wouldn't surprise me, anyway.Keep using Norton if it makes you happy. Quote
Keep using Norton if it makes you happy.

No it doesn't. I tested with a program my startup time (I think it was boofish, whatever) and with norton on my computer the startup time was doubled! Ok, I know antivirus slow down you computer, but I don't want that it really "BLOCKS" my computer...All AV has different procedure in scanning
and i read from other forum the same.
Some of them if they found its a virus, they delete it automatically, but some not and some cannot delete it, you must do it manually.

 psp downgreader--is it a virus?

Norton-- its a little bit sensitive (even "key GENERATOR" its virus for NAV)
im using AVG in start-up and optional KASPERSKY
1174.

Solve : Time to clean up?

Answer»

If you DOWNLOADED and ran the Process Scanner on your computer as well as running full SYSTEM scans with you MALWARE protection and CAME up clean, you can pretty much rest assured your system is clean.

However, you may want to wait for our RESIDENT malware guru to show up to read your HiJack This log...so, just hang in there.

1175.

Solve : can someone teach me some known methods to get rid of viruses im trying tolearn?

Answer»

Hey anyone KNOW some known methods for curring viruses and maybe Making a comp run quicker here

here Thx welcomeCb MAT can refer you to some great info on hi JACK UNDERSTAND hi jack this logs

1176.

Solve : After virus removed, little problem?

Answer»

After removing the virus (Spyware Doctor and Norton) my husband downloaded, I can't change my wallpaper.  I go to the properties, then desktop, and the box is shaded, as in inactive.  The little picture of the monitor shows a blue screen - the same blue that was there when the virus was active.  Everything else works fine, but I can't change my wallpaper.  Any ideas?  I tried system restore and refresh driver, it didn't work.  Thanks for the help.

ASlater

My specs:

    Operating System             Microsoft WINDOWS XP Professional
      OS Service Pack             Service Pack 2
      DirectX                           4.09.00.0904 (DirectX 9.0c)
      CPU Type                       Intel Pentium 4, 3200 MHz (16 x 200)
      Motherboard Name          Dell Dimension XPS Gen 2
      Motherboard Chipset        Intel Canterwood i875P/E7210
      System Memory              1024 MB  (PC3200 DDR SDRAM)
      BIOS Type                      Phoenix (02/19/04)
      Video Adapter                 256MB DDR ATI Radeon 9800 XT Sec
      Video Adapter                 256MB DDR ATI Radeon 9800 XT
      3D Accelerator                ATI Radeon 9800 XT (R360)
      Monitor                           Dell 1901FP (Analog)  [19" LCD]
      Audio Adapter                 Creative EMU10K2 Audigy / Audigy 2 Audio Processor
Download and run Hijack This and post the log file here for analysis. (You can zip it up, or use several posts to include it all!)

http://www.majorgeeks.com/download3155.html

Your system may still have issues.  Logfile of HijackThis v1.99.1
Scan saved at 10:29:47 AM, on 5/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Adriana\Desktop\Adriana\Stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slaterhome.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
Continue...O4 - HKLM\..\Run: [QD FastAndSafe] C:\Program Files\Norton SystemWorks\Norton CleanSweep\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [funk] funk.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094088646531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1124301311875
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.skibanff.com/skicam/AxisCamControl.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (file missing)
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
I feel very exposed...  But thanks for the help!

And the last...

O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exeI see one PROBLEM file:

O4 - HKLM\..\Run: [funk] funk.exe

Are there more?  I saw some that had the dreaded "unknown" along with it.  Again, thanks for your help.

ASlater aslater........  Here's what I would be removing ........

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [funk] funk.exe

O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)  


Just out of curiousity , what was your machine doing that prompted you to post the hijackthis log file ?


dl65  

It had a false virus warning/trojan ALERT, and now it keeps me from changing my "wallpaper."  Let me try removing those things and I'll post the results.  Thanks for the help.
ASlater Quote

aslater........  Here's what I would be removing ........

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [funk] funk.exe

O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file)  


Removed them, run CCleaner, panda activescan, owido and spyware doctor.  Other than some cookies - that I removed - they didn't seem to find anything.  I attached a picture of my screen when I right click on the properties.  As you can see, my wallpaper is that picture but it shows as a blue screen.  I'll attach a second screen shot on the next post.
ASlaterAnd by the way, it happens only when it's my log-on, the other "PEOPLE" can change their wallpaper just fine.  Should I try to roll back the display adapter?  This screen shot shows the "locked" window.  A puzzle for you guys...  and I appreciate the help.
ASlaterHey, all!

This morning I couldn't even get my wallpaper up, the screen was all blue again.  But I found the solution at another forum, they sent me to this post - at another forum.

http://www.bullguard.com/forum/12/Cant-change-wallpaper-after-sp_22825.html

I deleted the H_KEY they mentioned, at least I can change my wallpaper and all, but it changed other stuff, it just doesn't look the same - the color, etc.  I hope this helps someone else.

ASlater
1177.

Solve : Port Scanning??

Answer»

Is PORT Scanning Illegal? If so what are the consequences. BTW I live in Australia.

Thanks in advance.Port scanning is like ringing the doorbell to see whether someone’s at home. The POLICE usually can’t do anything about it. They have to wait until a crime is committed. The police might give it more consideration if the doorbell is repeatedly rang causing the homeowner to complain of harassment. Sometimes, if a computer SYSTEM is affected too much by a port scan, one can argue that the port scan was, in fact, a denial-of-service (DoS) attack, which is usually an offense.
With many ISPs port scanning is a violation of their terms of service. So if they receive complaints about port scanning they might choose to boot you off their network. Quote from: jjbtcp on September 10, 2007, 06:56:56 AM

Is Port Scanning Illegal? If so what are the consequences. BTW I live in Australia.

Thanks in advance.
It depends on the computer misuse act established in your country. Port scanning may be illegal in some countries but are GREY areas in OTHERS.
1178.

Solve : (Dilbert) Sudden Slow Down?

Answer»

My System Idle Process sits on 99.

Firefox is using 3x what my IE is using with 3 screens open but I did read somewhere that Firefox had memory leak problems.

What is CCAPP.EXE?
My svchost.exe (I have 2) seem to run about 5000K each.

My explorer.exe runs at 4392 K.

What is your overall memory usage, read it from the bottom of your taskmanager.
Mine is 176524K / 1341172 K. Quote

What is CCAPP.EXE?

CCAPP is part of Norton AntiVirus.

It doesn't show mem usage on the bottom for me, I don't THINK. I got Processes, CPU Usage, and Commit Charge. However, in the performance tab I get, under Physical Memory:

Total: 1048048 K
Available: 653500

PC has been on for about 7 minutes.Firefox---->IE
Norton---->AVGmore like
Norton>AVG>Kaspersky
Firefox>Firefox
Windows>Linux Quote
more like
Norton>AVG>Kaspersky
Firefox>Firefox
Windows>Linux

A lot of good reports about Kaspersky. [smiley=thumbup.gif]
A fresh install of Firefox wouldn't hurt but sooner or later everyone will come crawling BACK to IE.
Linux---->No Games. What does commit charge mean anyway?Huh? What are you talking about?  :-?commit charge  (k&-mit´ chärj) (n.) In the Windows operating system, the name for the amount of physical memory (RAM) and virtual memory that is ALLOCATED to all running programs, or applications, and the operating system itself.Increasing the virtual memory for your system NEVER hurts, I have mine set at  4 GB and I never have to worry about programs slowing me down. Quote
I have mine set at  4 GB and I never have to worry about programs slowing me down.

That's easy for you to say. I have about 15,8 GB total space in my main HD, and about 2,53 GB of free space, and 64MB of RAM   . I run (or should run) 9 processes (plus idle process) after bootup. My process manager (not the one from windows) says I have "7.00%" of commit charge. Is that good? :-?
1179.

Solve : I must still have a Kling-on?

Answer»

[size=16]hi, yesterday I got my problem solved with all the popups and crap, but a new problem has arisen...

Every time I start my puter I get a nortons warning box saying it has stopped a virus, always the same virus, everytime it starts up.. it hasn't even had time to log on to the net..[/size]

message Im getting is,
C:\WINDOWS\system23\ld1B72.tmp"
Virus, "Download.Trojan

How do I get rid of this new annoying LITTLE brother? ....dreamweaver_73.....  Here's what I would try .......
I am assuming you downloaded all the apps Fed SUGGESTED ....... and in particular Ewido .......
Boot up in safe mode .
Go into control panel/system ....and turn off system restore .
while still in control panel ...... go to folder options/view tab ........ then scroll down until you see show hidden files and FOLDERS .....put a tick in the box in front of it ....click apply and ok .
Now go BACK out to the safe mode desktop and run ....Ewido ..........
Once its finished and anything found has been removed ....... go to ........
C:\WINDOWS\system23\ld1B72.tmp  .......  Should be [HIGHLIGHT]C:\WINDOWS\system32\ld1B72.tmp[/highlight]
If for some reason its still there delete it ..... ( [highlight]ld1B72.tmp [/highlight])  just that part .

Now reboot and see if you are still getting the message from Norton.

dl65

1180.

Solve : ATTN: NORTON AV SYMANTEC USER?

Answer»

Verify here
http://www.washingtonpost.com/wp-dyn/content/article/2006/05/25/AR2006052501081. html
 
Researchers: Antivirus Software Has Flaw
By TED BRIDIS
The Associated Press
Thursday, May 25, 2006; 3:06 PM
 
WASHINGTON -- Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday.
 
Symantec said it was investigating the issue but could not immediately corroborate the vulnerability. If confirmed, the threat to computer users would be severe because the security software is so widely used, and because no action is required by VICTIMS using the latest VERSIONS of Norton Antivirus to suffer a crippling attack over the Internet.
 
Symantec has boasted its antivirus products are installed on more than 200 million computers. A spokesman, Mike Bradshaw, said the company was examining the reported flaw but described it as "so new that we don't have any details."
 
Researchers from eEye Digital Security Inc. of Aliso Viejo, Calif., discovered the vulnerability and provided evidence to Symantec engineers this week, said eEye's chief hacking officer, Marc Maiffret. He demonstrated the attack for The Associated Press.
 
Maiffret's company _ which has discovered hundreds of similar flaws in other software products _ ALSO produces intrusion-protection software, called "Blink," that he said already blocks such attacks and can operate alongside Symantec's antivirus products.
 
Maiffret PUBLISHED a note about the company's discovery on its Web site but pledged not to reveal details publicly that would help hackers attack Internet users until after Symantec repairs its antivirus software. eEye said it intends to describe the problem in detail privately for some of its largest customers.
 
"People shouldn't panic," Maiffret said. "There shouldn't be any exploits until a patch is produced."
 
The reported flaw comes at an awkward time for Symantec. Its chief executive, John Thompson, has campaigned in recent months to convince consumers they should trust Symantec _ not Microsoft Corp. _ to protect their personal information.
 
Maiffret said eEye's testing showed the problem affects Norton Antivirus Version 10, including its corporate editions. He said Symantec's current security suite _ which includes both antivirus and firewall features _ did not appear to be vulnerable.[QUOTE[ The reported flaw comes at an awkward time for Symantec. Its chief executive, John Thompson, has campaigned in recent months to convince consumers they should trust Symantec _ not Microsoft Corp. _ to protect their personal information. [/quote]

Frankly I would trust neither. Ever.

1181.

Solve : Thought you might want to see this...?

Answer»

This is funny. Guess what? NIS wanted to let me know a program was trying to connect to a remote server. It was Setup.exe, and in my TEMP folder. Naturally, I was worried. However, it gave me the IP, so I looked it up. It was my ISP. Below is the message and the WhoIs info I got. Heh heh... I was laughing when I saw this:



NORTON WANTS PERMISSION TO ACCESS THE INTERNET! Ha ha ha ha ha ha *cough cough hack* HA ha haha....

Quote

OrgName:    Verizon Internet Services Inc.
OrgID:      VRIS
Address:    1880 Campus Commons Dr
City:       Reston
StateProv:  VA

PostalCode: 20191
Country:    US

NetRange:   68.236.0.0 - 68.239.255.255
CIDR:       68.236.0.0/14
NetName:    VIS-68-236
NetHandle:  NET-68-236-0-0-1
Parent:     NET-68-0-0-0-0
NetType:    Direct Allocation
NameServer: NS1.BELLATLANTIC.NET
NameServer: NS2.BELLATLANTIC.NET
NameServer: NS2.VERIZON.NET
NameServer: NS4.VERIZON.NET
Comment:    Please send all abuse reports to [email protected]
Comment:    DO NOT send e-mail to [email protected] as it will not be answered.
RegDate:    2003-07-18
Updated:    2005-04-21

RNOCHandle: ZV20-ARIN
RNOCName:   Verizon Internet Services
RNOCPhone:  +1-703-295-4583
RNOCEmail:  [email protected]

OrgAbuseHandle: VISAB-ARIN
OrgAbuseName:   VIS Abuse
OrgAbusePhone:  +1-214-513-6711
OrgAbuseEmail:  [email protected]

OrgTechHandle: ZV20-ARIN
OrgTechName:   Verizon Internet Services
OrgTechPhone:  +1-703-295-4583
OrgTechEmail:  [email protected]

Oh, BTW, the Setup.exe thing was because I accidentally clicked on "send report" when closing a faulty installer. So those things do get sent out... hmm...Well, Dilbert, it looks to me like normal firewall behavior.  Am I missing the point? Quote
It was my ISP.
But why do programs try to conenect to the ISP? Once my firewall warned me that Winamp (Winamp!) was tryng to connect to an adress from my ISP. Besides, my firewall's intrusion control logs say countless timas that it stopped connections from my ISP. But then again, my broadband connection WORKS fine! :-?
Quote
Well, Dilbert, it looks to me like normal firewall behavior.  Am I missing the point?


Norton Internet Security wants permission for SYMANTEC (the maker of Norton) to access the internet. What is a legit Symantec setup.exe file doing in your temp directory?
Not the sort of place for a permanent file to reside. :-? Quote
Quote
Well, Dilbert, it looks to me like normal firewall behavior.  Am I missing the point?


Norton Internet Security wants permission for Symantec (the maker of Norton) to access the internet.
OK, I get your point, but it doesn't seem like a bad thing to me.  It makes the user aware of every process that attempts an Internet connection, and that's probably a good thing.  On the other hand, I suppose it opens the possibility that some users might dumbly prevent important and legitimate updates from happening.
Quote
What is a legit Symantec setup.exe file doing in your temp directory?
Not the sort of place for a permanent file to reside. :-?

Well, I had downloaded a program, and I chose to "open" instead of "save", and I ran the Setup, which crashed (oddly, the program appears to be fully functional...).

Yeah, it may be standard, but it got a chuckle out of me. Quote
What is a legit Symantec setup.exe file doing in your temp directory?
Not the sort of place for a permanent file to reside. :-?

the recycle bin would be a better location.  
It wasn't a Symantec setup, it was a WAV editor. Third-party. Quote
Norton Internet Security wants permission for Symantec (the maker of Norton) to access the internet.
Quote
It wasn't a Symantec setup, it was a WAV editor. Third-party.
Is that you Flame?
1182.

Solve : Missmurder.exe??

Answer» OK i was browsing through my task manager and i saw missmurder.exe i have no CLUE it said it was being run bye the system anyone know anything about it?Google returns no results . . . broadening the search a little I see it is a fairly popular online name and is also a song.
You sure it's missmurder.exe and no typo? Quote
ok i was browsing through my task manager and i saw missmurder.exe i have no clue it said it was being run bye the system anyone know anything about it?


This post proves you do have a basic COMMAND of English...keep this in mind in future.You can Process Explorer or HijackThis to find out the path of the file (if it's still running).  You should then upload the file to VirusTotal and post the results here.kk i TRIED that but nothing appeard it just sayd on the thing file no to be tampered withGibberish.try in searching for the file Quote from: Fed on August 29, 2007, 01:15:39 PM
Gibberish.

After my suggestion he reverted right back to 3 days ago.

wefr-o this is not meant to be harsh just a heads up...you need to post both problems and responses in coherent sentences here to get any decent responses.
We don't do txtspk...
We don't do shorthand.

Thanx.As this issue appears to be RESOLVED (I think...), I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
1183.

Solve : Open Source Windows Anti-virus?

Answer»

Please FIND the Open Source Windows Anti-Virus http://www.clamwin.com/

And

Windows Open Source Anti-spyware http://winpooch.free.fr/home/index.php

Note:

If ur to install them, 1st install clamwin anti-virus then install winpooch kwebihaf....... Why would you use either of these products when there are many proven alternatives .........   How long have you been using them ........

The latest version of Clamwin Free ANTIVIRUS is 0.88.2.3
Please note that [highlight]ClamWin Free Antivirus does not include an on-access real-[/highlight][highlight]time scanner.[/highlight] You need to manually scan a file in order to detect a virus or spyware.


Why ClamWin Free Antivirus is not recognised by Windows Security Centre?    
ClamWin Free Antivirus does not scan files automatically (that is when you access or open a file), you need to scan a suspicious file manually before opening it. Hence ClamWin does not offer fully automatic virus protection and does not integrate with Windows XP SP2 Security Centre.

This will change once the on-access scanning component is released and ClamWin team is working on it.

Please note that if you use [highlight]MS Outlook email client (not MS Outlook Express)[/highlight] then all emails are scanned automatically when you open them.

Reading comments from users indicate that it works , but just how well doesnt seem to be documented ....nor have I seen any comparisons to some of the more established AV scanners .   If you have that info , please post it as it may be useful.

dl65  
 

I'm good with AVG free and spybotdl65 ...

About Clamwin, [highlight]ClamWin Free Antivirus does not include an on-access real-time scanner[/highlight], this true but when Winpooch is installed, it  (Winpooch) acts as the on-access real time scanner. if you visit the winpooch site http://winpooch.free.fr/home/index.php you will see that when Winpooch is combined with Clamwin, the combination makes a powerful security tool..

More on Winpooch, it uses API hooking to detect spywares, which an effective method to detect spywares and viruses.

So i say install both Winpooch and  Clamwin and you will realise you ave got  Powerful security tools that r  free..

Abou how long iave used it, its not so for long about 1 month, but i ave realised the difference btn them and other anti-virus and anti-spyware programs.

The choice is yours.
With better solutions readily available, why would you EVEN consider this? Just curious.GX1_Man... just to answer your QUESTION
Quote

With better solutions readily available, why would you even consider this? Just curious.
.
Its because of cost and effectiveness.

Both the Anti-virus and Anti-spyware i'm talking about are free and their source codes are readily available incase u want to contribute or make your own customized  programs.

aVG and AdAware are free also, well known and work well.
1184.

Solve : IS THIS A VIRUS?????????????

Answer»

Hi guys i recently recieved a file through msn which i believed to be from a friend as it was his name sending it. but when i contacted him to see what it was he said it was not him! how is that possibe

The file in  question is DO NOT CLICK THIS LINK:-



www.G038_jpg-msn
i was at the friends in question when i was remotley connected to home and saw that he wz\sw sending me the same file again but i know he couldn't because i was using his pc to connect to mine
the wife acidently accepted it and i am now a little weary of what it has done to my pc as she opened it and she said that nothing had happened when she did

please please help am i in trouble
Kind regards Matt
You should run a scan with Kaspersky's Online Scanner and post the log here.  When that is done, also post a HijackThis log for us to take a look at.Why post a link that shouldn't be clicked ? ?

I don't get it.The first thing I did was click on the link (wet paint syndrom) and got exactly what I expected. Do not click on that linkThankfully, it's not a proper link, so none of us have anything to worry about.This is an MSN worm. These can pretend to be from a friend whose machine is infected. Also this one exploits the fact that nobody under about 25 knows about the old MS-DOS .com file extension for executable files. They think .com means a web site so they click on it.

Backdoor.Win32.IRCBot.aex (Kaspersky Lab) is also known as: W32.Esbot.B (Symantec),   BackDoor.IRC.Sdbot.126 (Doctor Web),   Win32.Worm.EsBot.B (SOFTWIN),   Worm.ESBot.B (ClamAV),   Bck/IRCbot.KG (Panda),   Win32/IRCBot.OO (ESET)

    * The following behaviors have been observed for this OBJECT:
    * Installs programs.
    * Deletes programs.
    * Invokes dll COMPONENTS.
    * Creates Run Keys.
    * Runs other programs.
    * Communicates with web sites using httpout protocols.
    * Has outbound communications.
    * Creates known malware.
    * Creates copies of itself.Due to lack of feedback, I am closing this topic.  If you are the original poster and you would LIKE this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

1185.

Solve : Which scanner would you choose??

Answer»

According to PC World, this is the scanner chart... HTTP://www.pcworld.com/reviews/article/0,aid,124475,00.asp ... Now, setting that aside, which would you prefer on your computer? Which do you trust? Don't think about the ratings when you do this.

FlamePC World historically is a *censored* for advertising dollars. Also, any study that rates Mcafee second (or even in the top 5) is suspect by definition.

Could we have a third selection of "Anything Else"?Oops, forgot about that option    Yes, the option has been created, however please specify which scanner you prefer then. I'm getting tired of Norton taking up all my resources lol  Wasn't a problem until I started gaming some more... Never should have done it...

FlameAVG free 'till I fall. If I WANT a really good scanner, I'd get a trial version of NOD32.AVG- with Kaspersky (at the back)

this link
http://www.pcworld.com/reviews/article/0,aid,124475,00.asp

is not far from here
http://anti-virus-software-review.toptenreviews.com/
Looks like Kaspersky is the best one... All the REST totally switched places really... Bit Defender getting Gold? Hard to believe, but maybe...

FlamePut me in the AVG column for a windows installation, ALTHOUGH I do use PC-Cillin on one box (because I got it for free).I voted Another, but I'm really not sure at this point what I'll do when my subscription to Norton AV expires in Sept.  I'm still using NAV 2002, with multiple annual renewals due to the length of time I've used it.

However, I think I may be looking at one I don't often see mentioned in forums, or so it seems.  I'm talking about EZ Trust Antivirus from Computer Associates.  AVG Free because it's free & offers unlimited realtime protection.
Prevx1 looks like a good thing too.

1186.

Solve : help w/ Windows Defender?

Answer»

When I s topped scanning w/ Windows Defender (Beta 2) today I got the following error message:
Windows Defender encountered an error:  0x8050800d
Anyone know what this error is or how to fix?

Also does anyone know if Windows Defender (Beta 2) also automatically updates Norton Antivirus Corporate Edition on the PC & if not, if it is POSSIBLE to INCLUDE it in the same update?  Than ks, Dede

uninstalling and reinstalling may solve the problem.

Not sure I understand you second question; it does not make sense to me.  Defender and Norton are two separate programs.  Why would one update the other?can anyone help me w/ the following:

When I s topped scanning w/ Windows Defender (Beta 2) today I got the following error message:
Windows Defender encountered an error:  0x8050800d
Anyone know what this error is or how to fix? Is it anything to worry about?  thanks, dede Quote

can anyone help me w/ the following:

When I s topped scanning w/ Windows Defender (Beta 2) today I got the following error message:
Windows Defender encountered an error:  0x8050800d
Anyone know what this error is or how to fix? Is it anything to worry about?  thanks, dede

Did you try already the advice of SOYBEAN?
You can click on link below so you can read what happen to others on same problem
http://forums.microsoft.com/WindowsOneCare/ShowPost.aspx?PostID=378597&SiteID=2I removed Windows Defender but then when I went to install it I got a message if I want to install active x control during MS validation.  How can i insstall Windows Defender w/out installing active x control?  Aren't ther e PRIVACY invasion issues w/ active x control?  Thanks, Dede Quote
 How can i insstall Windows Defender w/out installing active x control?  
If you don't want to install the ActiveX component for validation, follow the link, at the bottom of the main web page for Windows Defender, for Alternate Validation Method.

While it's good to be cautious about installing ActiveX from a WEBSITE, I don't think you have anything to worry about as far as installing the ActiveX component from MS in order to download Windows Defender.
In respo nse to Soybean, I went to Windows Defender website & did not see an alternate validation method to download Windows Defender w/out installing active x control.  Here's the website I FOUND:

http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&displaylang=en

Can you provide the link you were talking about to download w/out installing active x control?  thanks, dedeCan you go directly to http://www.microsoft.com/downloads/exeValidation2.aspx?familyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D&displayLang=en ?Thanks Soybean.  I was able to install windows defender w/ your link.  dede
1187.

Solve : Keyboard hijacked???

Answer»

As some of you know i have just
posted here for HELP and everything
was fine, Then i went to login to my email accounts
but when i pressed shift to get .  these " 2
little marks appeared instead then it happend
for other keys not showing what was pressed??
i hope you understand what i mean the keys pressed
do not corrospond to what is on screen??
Is this virus behaviour???
Once agian thanks for your time.........

Is this problem STILL happening?  Have you tried a different keyboard?
This sort of thing can be caused by a virus, but it can be caused by a lot of other things as well.  It could also be no more than a fluke.
You should try another keyboard; if the problem persists, then we'll brainstorm and come up with other possible solutions.Hi,CBMatt. i have just tried another keyboard
 off mums gateway pc and it was still happening
 dell help site had me checking that, regions was in
 english usa, and it was, other keys affected are the
 pound sign comes up as HASH,hash comes up as
 forward slash ill run all my spy and virus programs
 and get back to you i wont list them all as ive got
 all the wons u recomend..cheers..P...As you know it takes sometime to scan and
 i still havent finished in normal mode avg-anti virus
 and spy found nothing,xoftspy,spybot search destroy,
 spyware detector,spyware doctor.havnt found anything
 ill try in safe mode and get back dont know how LONG
 it will TAKE please give me time i still have to scan with
 avast virus..RESULT!!!! Hi,CBMatt i dont know what was
wrong but just to let you know before i spent
the night scaning in safe mode i tried system restore
 it went back to 24 aug,and everything is fine so far,
 i dont know if any KB updates were released that
 might of been bad but im just glad its working agian
 Once again thank for your time fella..
 cheers..P...It's hard to say what the cause might've been, but it's entirely possible that a hotfix was causing problems.  I would more prone to suspect some third-party program, but System Restore would've uninstalled whatever it was.  In any case, I'm glad your issue is resolved, and I hope it stays that way.Thanks so do i..As this issue appears to be resolved, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

1188.

Solve : More Problems after Formatting - Wierd!?

Answer»

I will try to make a long story short:
Computer originally kept restarting with no BSOD. Just would shut off and turn back on. (Sometimes during boot up and maybe 10-15 times in a row... like maybe a few seconds after the last had hit). Tried a bunch of the stuff in one forum about restarts, but didn't really do anything (other free online scanners I could never finish because it would reboot before finishing). Finally it just got out of hand, brought it to my school's computerplace, they scaned it and said it was fine. Took it home, upon turning it on it immediately started restarting again. This time I noticed it was with slightly less frequency. Then I decided to format my computer. I did the whole "erase to factory settings" thing and it STILL rebooted. Then I went on spring break and when I came back my computer miraculously stopped rebooting, BUT now it has a myriad of other problems.

(Also I must add the restarting may have come from a download 3 days before. I tried to dl an onscreen keyboard without knowing that the computer already had one. -- My roommate is a b**** when it comes to complete and utter silence for her studying and sleep. )

I must note when I erased my computer I noted a lot of things I had added on (software) before weren't erased... Why is that?

Current Problems include:
- Occasional freezing
- My DVD-RW drive sometimes doesn't work. It starts beeping like crazy. Also sometimes If I have a DVD or CD in there when starting the computer up it keeps beeping loudly with a black screen. I need to take out the disc for it to work.
- major one: The computer won't let me update some of its software... esp. back to Windows XP (the 2 pack or whatever it is). I need to update it so I can reinstall my school's virus remover and their computer monitoring software. But when I try to dl the 2nd pack from their site it always gets to the very END of installation and it gets an error. Then it erases everything it added.
- Also I'm having a problem retrieving movies (we're not talking bootleg, we're talking videocamera burned onto computer, then onto disc--I'm the VIDEO editor for one of my clubs) from dvd-r's. Some of them work, but some don't. (I get the beeping noise with some of burned dvds/cds. I also get halted whirring "duuuuuuck... duck duck duuuuuck" and "squeeeee" noises. After the non working ones... don't work... either the computer freezes or nothing happens.)

I know I have had other problems I've encountered but I can't remember them at the moment...

I'm in an HP Media Center... Windows XP (Assuming Service Pack 1 as the updating thingie says I need SP 2).Oh yeah I forgot to mention that my TV Tuner is also no longer working...

And at the moment I am scanning with Housecall. We shall see if that does anything. (I am noticing too at the bottom of the screen w/ the files scanned flashing by... every now and then it goes "ERROR.")

Okay I'll be back... need to go to class.cookiemunstahh....... Usually , HP provides 3 cds ( I believe ) with their machines .......  the 1st on will have the operating system on it with the service pack ..... for example Win XP Media Centre  SP1 or perhaps Win XP Media Centre  SP2 .
In your case you probably have the first one .
Then ...there should be a second cd ....CALLED Application and Driver Recovery DVD.
Then the 3rd cd ...is called Application Recovery CD ..... ( this one is for doing a system restore back to as shipped condition )

The odd thing is that you say you did a format and clean install , but it didnt remove some programs ...... that suggests that you only did a repair ....... as opposed to a complete format .......

Perhaps you could describe how you did "your format" and which cds you used .
I ask this because I just did a format and a reinstall on a HP laptop and it formatted the whole hard drive ....not just part of it ........ or did you have partitions set and the programs which were not removed were stored in those partitions ?

dl65  Well I asked the HP ppl on the site (I chatted with them). I told them I wanted to do the erasing to "factory settings" because I did that a long time ago on a different computer.  They gave me a set of instructions... (Let me find them because this was a few weeks ago and I forgot exactly what it said)

So this one doesn't have CDs. (I only have CDs for the original software I bought at the same time as the computer, old virus scan stuff and Microsoft Office... I don't think I threw it away cuz I always keep all my computer stuff in one box... Also, this is a bummer too, this comp is relatively NEW... maybe a year and half old. So I remember wondering where the other CDs were...) I think because it has that extra drive we don't need it. It was like during the boot or something we pressed f8 or something and you come to a series of screens they have choices like "completely format" and "format to original factory settings."

Oh sorry... it's "System Recovery" (I must add, I never changed the recovery settings... like I never saved the "new" settings after dling software.  Never bothered to.)

OK Found the site... here's what it says:
NOTE:  HP PCs that ship with Microsoft Windows XP do not come with recovery CDs. Instead, they use a hidden space (partition) on the hard drive to store the recovery information. The use of a hidden partition provides a convenient process that eliminates the use of recovery discs that may be lost or scratched. Recovery discs for Windows XP are available from HP for a minimal cost. Go to the section " Related support " for ordering information. Your PC may also CONTAIN Recovery Creation software.  

So yeah I just used the partition thingie... Well some of the things I noticed that didn't change were updated drivers (I updated drivers recently before formatting because I thought that might be the problem... but I dunno).

Other things that weren't deleted were like remnants of programs... like a LOT of icons were left on my desktop but most of them didn't work... like you click em and either an error shows up or nothing happens.

Also, wierdly, the internet was already set up. (When I originally came to school I needed to go through this whole process to set up the internet.)

Do you think I should order these disks and just completely erase it? Or is there another way to clean up the problems on here?OH wait, I think I must have read this wrong... I tihnk I did a system recovery... I thought I remembered the destructive one as totally erasing EVERYTHING. But it says here not... is this true?

"CAUTION:  Performing a Destructive Recovery will format the hard drive. This will delete all the information on the hard drive and reinstall Windows XP and the original software that came with the PC.Performing a System Recovery replaces system files and original software with the files that originally came with the PC. This process may move or remove certain files, like those stored in My Documents. Before performing a System Recovery backup important files and the files stored in the My Documents folder.In either case, be prepared to reinstall software that was not originally included with the PC. You will also need to reconfigure an Internet Connection and obtain all critical Windows Updates, Virus definition updates, and anti-spyware updates.  "If you use the full restore ALL of the things you added yourself will be gone, along with the problems hopefully. If there is any important data you need to back up do so.So really the "destructive" one is the one I want to do right... "Back to Factory Settings" was on my old computer... yeah I don't mind that reg. files/progs will be lost... I understand that I need to reupdate everything right?

Just making sure LOL.That is correct.

1189.

Solve : Need Help! something weird just happen on my computer?

Answer»

I'm still not sure if the problem is a virus, hardware, or software:

while i was browsing the net, my COMPUTER suddenly froze then the monitor suddenly showed a screen with vertical rainbow colored lines.
that in the WORLD did just happen to my PC??I think this means your HARD drive has corrupt !?  I would wait for a SECOND opinion thofind the make of your harddrive go to the manufacture's website and dl the diagnosic tool and run it

1190.

Solve : tried and failed to remove spyware?

Answer»

i downloaded some programme that had some spyware in it, the spyware puts up an icon at the very bottom right END of my com screen (where the norton antivirus is etc) and keeps having pop ups about my com being affected by some virus (which cant be true cuz i have scanned with zonealarm)!!!

it also keeps changing my homepage, thus i cant change it BACK!!!there are also alot of random popups

i used my spyware detector and scan through my WHOLE computer and destroyed all the files my spyware detector says that is a spyware but that icon and the problems above are still there...

if u need more info pls tell meforevayoung......  Download hijackthis from  http://www.majorgeeks.com/download3155.html    create a folder on your desktop and save it there........ Then once it's downloaded , open it and click on run scan and save log...... save the log to desktop and then post the log here and we HOPEFULLY can assist you .

dl65  ok here it is...pls help me...


Logfile of HijackThis v1.99.1
Scan saved at 5:08:10 PM, on 6/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SOUNDMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\InterVideo\Common\bin\WinCinemaMgr.exe
C:\Program Files\3DNA\Resources\3dnasys.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\dcomcfg.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\WINDOWS\system32\atmclk.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Messenger\msmsgs.exe
C:\antispy\hijackthis_1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.singnet.com.sg:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.*.*;
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp102.tmp
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: RefresherBand Class - {B24BA06E-FB7B-4757-95C2-DC01125F750E} - C:\PROGRA~1\YREFRE~1\YREFRE~1.DLL
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [WildTangent CDA] "C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" /startup "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\LEEYAN~1\LOCALS~1\Temp\200663163655_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\LEEYAN~1\LOCALS~1\Temp\200663163647_mcinfo.exe /insfin
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Startup: 3DNA Auto-Update.lnk = C:\Program Files\3DNA\WiseUpdt.exe
O4 - Startup: 3DNA Desktop.lnk = C:\Program Files\3DNA\Resources\3dnasys.exe
O4 - Global Startup: Event Reminder.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.moreatonce.com
O15 - Trusted Zone: http://schdnavdo.schooldna.com
O15 - Trusted Zone: http://schdnaweb.schooldna.com
O15 - Trusted Zone: http://schdnaweb1.schooldna.com
O15 - Trusted Zone: http://schdnaweb2.schooldna.com
O15 - Trusted Zone: http://www.schooldna.com
O15 - Trusted Zone: http://*.schooldna.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! Gin - http://download.games.yahoo.com/games/clients/y/nt1_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab
O16 - DPF: Yahoo! Towers 2.0 - http://download.games.yahoo.com/games/clients/y/ywt0_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {2885EE05-A26B-11D1-B49B-00C04F98EFE0} (In Fusio, Exen Simulator) - http://www.ageofempires2-mobile.com/site/Activex/simulator.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8C4A2492-3FED-41F2-BBAB-34E802844F8D} (IESettings Class) - http://schdnaweb.schooldna.com/schooldna/login/dnaClientIE.CAB
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

1191.

Solve : I need the best?

Answer»

K.... I have a toshiba satilte and they enable you to create a master password that activates as soon as the computer BOOTS up (after it tells you to push f1 and F12 for some otha stuff) The problem is... the password got changed some how and I cannot even access a profile or anything. It won't even allow me to push f1 or f12 to try and set up. before that, the computer wouldn't power up when i PUSHED the button with the battery pack fully charge and or plugged into a socket... I need some HELP!!!!!!!
thanx Which OS are you running?  Can you boot into safe mode?  I know in Windows XP there is a guest account that shows up in safe mode.  If you could use that you can use the command prompt to run this command

net users (your user name goes here) "password"

Whatever you put in the quotes will be the new password.  So for example:

net users Sally "newpass"

That would change Sally's password to newpass.  However we will still need more info on your current SYSTEM so we can make sure you have the correct answer.  Also one more thing....this master password you are talking about.  Is this for an account in windows?  Or for the cmos?  If it's for the cmos the above recommendation won't work.This is a laptop...and it's not a Windows password it's a BIOS password.
Call a local Toshiba service center and get your wallet out... :-\Yeah... it's the bios password and not being able to TYPE in my password cuts me out from everything!   thanx a bunchYup, you're going to have to do what Patio said.....unfortunately.

1192.

Solve : Trojan.Nebuler?

Answer»

I got an issue here. I was at a site a few weeks ago, and I wanted to download a utility. However, Norton swooped in and cancelled the download. Too late, however. I got at least one instance of Trojan.Nebuler. I'm having a devil of a time getting rid of it, because every time it fires, Norton quarantines and deletes the throwaway .exe file (giving me a popup to tell me).

I've already closed about 25 popups, let's SEE how many more I get:

....................................... ................................

Each dot represents a popup from Norton. Each .exe file destroyed is a series of random numbers, occasionally letters. I can't find a trace of it since the throwaway .exe files get erased. Now, this HAPPENS every few days, fluctuating INTERVALS of time. No noticeable pattern, other than if I try to d/l again I get slammed again (I only tried it once more to see if it was indeed that PROGRAM; it was).

HELP!Dilbert.......  Post a copy of your hijackthis log file please .

dl65  Dilly, do you remember what you were trying to downlaod & where from?
I'd like to replicate your dilema.Unfortunately, the site was one of many I looked up in a google search, and FF's weekly cleaning of cache, history, etc. has occured since. I Googled so many different keywords I wouldn't recognize the site unless I saw the particular page that had the download.

But, anyways:

EDIT: I've been hit again! I've closed 100+ popups from Norton about the matter and counting!

1193.

Solve : Any AVG user here??

Answer»

Hi all!
I am using AVG free 7.5.
I downloaded a zipped file from a WEB site last night, and as usual, I scanned it with my AVG before opening it. Then AVG REPORTED to me that a virus was found:


Still, my AVG didn't provide me any tool or next step to kill the viruses found.
I am totally new to AVG and need some help from experienced AVG users

Please help if you could!DELETE the zip file to recycle bin then delete it from there. Then run a manual scan to check for viruses.Yes, basically that report means there is a virus inside the compressed file (.zip / .rar).
Locate that zipped file, select it and hold SHIFT down while pressing DELETE. This will get rid of it from your system.

Then do as Mektek suggests and run another scan.I this person want to keep the file but delete the virus can this be done ?According to the information we currently know, the file is the virus...Spero - It's not worth the risk trying to clean infected files IMHO. Better to get rid of completely. Understood ! Thank you all so so ... much!

---

I really wanna see the contents inside the zipped file, but just couldn't act bravely...when thinking it may be a very strong virus and would trigger off crisis to my PC.
Is it a strong virus actually?

BTW, what do you think of AVG?
Is it a good anit-virus software ever?

I think it is one of the best ! A lot of the folk on here prefer AVG as their anti-virus protection.

Personally I love it after years of putting up with Norton hogging my resources.

They do a great anti spyware as well. Would also go for this if you don't already have it, or at least add it to your anti spyware arsenal  Quote from: GX44 on September 03, 2007, 09:39:47 AM

A lot of the folk on here prefer AVG as their anti-virus protection.

Personally I love it after years of putting up with Norton hogging my resources.

They do a great anti spyware as well. Would also go for this if you don't already have it, or at least add it to your anti spyware arsenal 
Thanks GX44!
AVG CAPTURED another virus from the main drive:

It's reported as Trojan, what it was trying to steal from my PC is a mystery to me.
Can I simply block it from getting access to the internet to avoid any information leakage from my PC?

Quote from: GX44 on September 03, 2007, 09:39:47 AM
....They do a great anti spyware as well. Would also go for this if you don't already have it, or at least add it to your anti spyware arsenal 
Is this service free or paid? I don't have any anti-spyware installed on my PC currently. Quote from: kwfine on September 03, 2007, 10:04:10 AM
...
Is this service free or paid?   ...

Both are available.
Here is the link for the free one:
http://www.free.grisoft.com/doc/download-free-anti-spyware/us/frt/0

You can read about the commercial one there too, and compare.

Run the Free version of AVG Anti-Spyware  in safemode with system restore turned off and the machine dis-connected from the web...the infection is hidden in one of your restore points if not elsewhere.
Post back with the results,Whatever those files are, they're not worth the infection.  Just delete the zip file.

And patio's right; that trojan is in your System Restore files.  It's an old infection that may have already been removed, but your computer keeps a copy of it.  You should follow these steps.

1.  Go to Start > Programs > Accessories > System Tools > System Restore
2.  Click on System Restore Settings.
3.  Check Turn off System Restore and click OK.
4.  Reboot into Safe Mode.
5.  Run a full scan with AVG and when complete, restart your computer.
6.  Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK.
7.  Create a new restore point and close the program.

System Restore will now be active again.  If you would like to learn more about System Restore, go here.
1194.

Solve : AVG Virus Scan results?

Answer»

Hello Forum: WindowsXP SP2 ,IE6.0.29, 2.39 GHZ, 512MB RAM .  Question: When I get my AVG Virus scan test results, one line in test results shows the Object  " C\windows\system32\shell32.dll"  . The next column says Result  "Change".  The last column says Status "Changed".  This occurs on every Virus Scan. Is this something to be concerned about. Is AVG finding a problem every time and correcting it. AVG test runs every day. Also use AD-AwareSE, SpywareBlaster and SPYWAREGUARD, Windows Firewall. All are UPDATED continually.   Any help would be appreciated.  ThanksNot to worry in the absence of any threats being found.  Thanks for your help. I TRY to keep the MACHINE clean and am always on the lookout for anything out of the ORDINARY.

1195.

Solve : Are there security issues with Wireless??

Answer»

I recently bought a new wireless laptop along with a basic wireless router. But the salesman scared me when he quickly discussed with me the inherent security problems with a wireless computer. He said that if there are any neighbors of mine within a 600 sq. ft. distance, they could conceivably read and/or pick-up what I am typing on my computer (ie. credit card information, emails, etc.). And he added that I should encrypt my wireless (whatever that means?). When I did first turn my new laptop on, it gave me a listing of about 6 wireless networks which apparently my laptop was picking up, which I assume means these were signals coming from neighbors? Should I be concerned about this? And if so, how do I set up my wireless laptop so no neighbor might pick up what I am doing on my computer? Thank you.  Do a GOOGLE search for WEP. That's what you need to setup (wireless encryption). Quote

Do a google search for WEP. That's what you need to setup (wireless encryption).

Actually...WEP is no longer what you want to USE. WEP is easily cracked within a matter of minutes by using one of many free programs on the internet.  If you really want to be secure you should use WPA encryption with a really good password (good being at LEAST 8 characters long with letters and numbers).  Using WPA and a good password should give you the protection that you want.In agreement with using WPA...definitely the WAY to go.

There is one other thing that most people tend to forget when using wireless routers:

When you set up your router, you have to log into your router's control panel via an IP address typed into your browser's address bar.  You'll be prompted for a username and password.  Most of the time, the initial usernames and PASSWORDS for router control panels are admin/admin.  Sometimes, people neglect to change their password and, after a short period of time, start experiencing CONNECTION issues.  This basically happens because someone has logged into your router's control panel and has made changes to your router's setup...actually stealing your connection.

Be secure!  Your first step should be to change the password you use to log into your router's control panel. [smiley=thumbsup.gif]That's great advice right there Saviour.  Jason, you'd do well by remebering that.
1196.

Solve : Help to remove virus and spyware?

Answer»

I have run anti-spyware as well as anti-virus software, and have files quarantined with both issues. My question is this-what do I do to remove them? If I remove the files containing these things, does it impact my COMPUTER?

Do I simply leave them quarantined and not delete them?

I`m completely confused and lost about what to do about these issues.

I have a Dell 8400 Dimension desk top computer, with Windows XP HOME Edition.

Can someone PLEASE help?What software are you using? Where are the files stored? What are rhey called?Software? I have a Dell 8400 which is running Windows XP. The anti-virus software I run is Symantec. The quarantine says the file is NjlDekRVVXl0Sm9BQURmb0Bhb0FBQU9I[1].wmf, and it says the ORIGINAL location was C:\Documents and settings\greg russell\local settings\temp

The second one says the file is jar.jar-2ad522e1-7123a023.zip and it`s original location was C:\Documents and settings\greg russell\Application Data

Both original locations have more to them, but I can`t see it all.

The virus software has these files quarantined, so do I delete these files? The virus software says it can`t clean them. Does it hurt to simply leave these in quarantine?

I have NO IDEA what to do.Files in quarentine can't run anyway. If you have not experienced any problems with the computer or any apps, there is no reason you can't delete them. It won't hurt to leave them there, but they are just occupying disk space.

1197.

Solve : Malware help?

Answer»

HELP!! lately my computer has been running super sloooow and I'm getting these annoying popups on the bottom corner righ of my screen saying "security alert" and that I need to download protection. My homepage has also been changed to a page saying I download protection plus im getting a load of explicit ads. what should I do?! and btw, im a total computer moron i don't much about computers... Please Help!

windows xp home edition, 1.53GHzYou are the victim of spyware/adware (which is collectively known as malware), at least one homepage hijacker, and probably a few viruses. First, read this article to acquaint yourself with the problem: http://www.bleepingcomputer.com/tutorials/tutorial41.html

Next, run Ad-Aware. What's Ad-Aware? Please read this thoroughly: http://www.bleepingcomputer.com/tutorials/tutorial48.html

Then run SpyBot. What's SpyBot? Please read this thoroughly: http://www.bleepingcomputer.com/tutorials/tutorial43.html Note: I've had to run SpyBot several times in a row to completely remove some of the more STUBBORN varieties of malware. Also, remember to immunize your computer. Read the article and you'll understand.

Now run HijackThis. What's Hijack this? Please read this thoroughly: http://www.bleepingcomputer.com/tutorials/tutorial42.html Note: It is possible to do significant damage to your computer with HiJack This! Because of this, when you create a log file (Read the article and you will understand what a log file is) post it as an attachment to this message board. We'll help you through it. Also, the above article is rather lengthy. You really don't need to read it all, just the first five "chapters".

Next run Panda Software's free online virus scan: http://www.pandasoftware.com/products/activescanpro/ Note: The link for the free scan is rather hard to see. Its in the upper right corner just underneath the red rectangle that says "Buy ActiveScan Pro". The link says "Free Online Virus Scan". Click the word "Online". It *REQUIRES* Internet Explorer 5.0 or higher to run. It supposedly removes any viruses it finds, but you need to upgrade to the Pro version to remove spyware/adware. Don't worry, Ad-Aware, SpyBot, and HiJack This do just fine (and their free!!).

Then, just for good measure, run Ad-Aware and Spybot once more.

Finally, Get Spyware Blaster. What's SpywareBlaster? Please read this thoroughly: http://www.bleepingcomputer.com/tutorials/tutorial49.html

If you really want to be thorough, use SpywareGuard. What's... Okay I'll stop. Just read this: http://www.bleepingcomputer.com/tutorials/tutorial50.html Note: I've never used it myself, but it looks like a good idea.

You've got enough tasks ahead of you to burn through a few evenings.   Keep us up to DATE with your progress.


--Oober NooberJust out of curiosity were you using ANYTHING for spyware/virus protection?A well researched post Oober  [smiley=thumbup.gif] but you forget that Fiery is a self confessed total computer moron   and I doubt his ABILITY to carry out your suggestions.  :-?
Added to this, whatever is causing his problem may not NECESSARILY be classed as malware so all the scans will do nothing for him.
He may even be able to remove the offender via Add/Remove Programs in the Control Panel.
Perhaps he should give us a Hijackthis log to see what's going on first. Quote

A well researched post Oober  [smiley=thumbup.gif] but you forget that Fiery is a self confessed total computer moron   and I doubt his ability to carry out your suggestions.  :-?

Awww. I thought all the posted articles were fairly easy to follow. My name is Oober Noober, after all.

Quote
Added to this, whatever is causing his problem may not necessarily be classed as malware so all the scans will do nothing for him. He may even be able to remove the offender via Add/Remove Programs in the Control Panel. Perhaps he should give us a Hijackthis log to see what's going on first.

Sounds good. My experience has never yielded me any solution as easy as using the add/remove programs cpl.

Fiery, SORRY for being pedantic. Listen to Fed.  


--Oober
Oober, have you conisdered authoring a FAQ topic? Speaking of Q&A Dilbert , when did you plan on restoring what was lost ........ from your backup ?

Some of the info there was pretty helpful to a lot of folks .......


dl65  hey guys,
sorry I havnt been replying to you guys..I've been busy. Thanks for all your help..my brother fixed the problem for me with some help from you guys Thanks a lot. 1 more question...how do you know if you have spyware and adware? :-?

BTW Fiery is a GIRL Quote
how do you know if you have spyware and adware? :-?

Well, adware can do some funny things to your computer. The biggest two complaints that I hear are "My computer is running slow" and/or "I'm getting alot of popups all the time," followed closely by complaints about homepages being changed, spontaneous shutdowns, etc., etc. The best way to tell if you have malware problems is to frequently (repeat: frequently) scan your computer with the major spyware scanners (see my first post). They'll tell you about any spyware present on your system and, most importantly, remove it for you. Remember, spyware isn't just an inconvenience, it can also compromise your security and even lead to identity theft if you purchase anything online. Check out those links I posted above if you really want a good starter course in Malware 101.

Quote
BTW Fiery is a GIRL




--Oober NooberAnd if you EVER get  a random popup announcing you have spyware and click here to remove it - DON'T!!!!
1198.

Solve : 8 viruses found, unable to delete.?

Answer»

DAVE9999....Well the 2 files I was refering to are just questionable .........thats all.
Quote

Now that those nasties have been enprisened in the "Avenger" zip file.
    why dont you delete the quarantined files ?

Now as far as the files on D: drive ....... If in fact some of them are corrupted or infected  , then whats the POINT of having them on your machine ...... the contents of that drive is useless . I would wipe D: clean . ........  the fact that there are infected files on that drive are a potential threat .

dl65   Quote
DAVE9999....Well the 2 files I was refering to are just questionable .........thats all.
Quote
Now that those nasties have been enprisened in the "Avenger" zip file.
    why dont you delete the quarantined files ?

Now as far as the files on D: drive ....... If in fact some of them are corrupted or infected  , then whats the point of having them on your machine ...... the contents of that drive is useless . I would wipe D: clean . ........  the fact that there are infected files on that drive are a potential threat .

dl65  


i agree, the corrupted files can damage C:, which would make this relatively small problem a headache to fixDl65, I suppose I could contact them,  mind you if Gatesy brings out a new Windows program soon. I may well end up buying that.
They may well have sorted out WMP by then as well, Many people have the same problem with WMP when they changed up to the none deletable  version 10.

Looks like we have done as much as we can on it then,  I never knew about the "Preload files" and all that being on the D:\ drive.  
Theres been quite a lot of stuff I have learnt over the last few days about software, systems, viruses and that.
Sometimes though due to laziness on my part, "Not getting it all recorded down on disk" from brand new.
to perhaps not running enough virus scans, we can come a cropper.

I'll delete those 3 particular files then with Avast.
How is the best way of deleting the virus  files in the avenger program.
C:\avenger\backup.zip/avenger/cs_mary.exe/Realtime.dll  Infected: Trojan-Spy.Win32.Delf.fk  skipped  
 
C:\avenger\backup.zip/avenger/cs_mary.exe  Infected: Trojan-Spy.Win32.Delf.fk  skipped  
 
C:\avenger\backup.zip/avenger/setup_ares.exe/data0037  Infected: not-a-virus:AdWare.Win32.NavExcel.i  skipped  
 
C:\avenger\backup.zip/avenger/setup_ares.exe  Infected: not-a-virus:AdWare.Win32.NavExcel.i  skipped  
 
C:\avenger\backup.zip/avenger/WarezP2P_DLC.exe/stream/data0035  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped  
 
C:\avenger\backup.zip/avenger/WarezP2P_DLC.exe/stream  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped  
 
C:\avenger\backup.zip/avenger/WarezP2P_DLC.exe  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped  
 
C:\avenger\backup.zip  ZIP: infected - 7  skipped  
DAVE9999      

C:\avenger\backup.zip/avenger/[highlight]cs_mary.exe/Realtime.dll  Infected[/highlight]: Trojan-Spy.Win32.Delf.fk  skipped  
  
C:\avenger\backup.zip/avenger/[highlight]cs_mary.exe  Infected[/highlight]: Trojan-Spy.Win32.Delf.fk  skipped  
  
C:\avenger\backup.zip/avenger/[highlight]setup_ares.exe/data0037  Infected[/highlight]: not-a-virus:AdWare.Win32.NavExcel.i  skipped  
  
C:\avenger\backup.zip/avenger/[highlight]setup_ares.exe  Infected[/highlight]: not-a-virus:AdWare.Win32.NavExcel.i  skipped  
  
C:\avenger\backup.zip/avenger/[highlight]WarezP2P_DLC.exe/stream/data0035  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped   [/highlight]
 
C:\avenger\backup.zip/avenger/[highlight]WarezP2P_DLC.exe/stream  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped   [/highlight]  

C:\avenger\backup.zip/avenger/[highlight]WarezP2P_DLC.exe  Infected: not-a-virus:AdWare.Win32.NewDotNet  skipped   [/highlight]

navigate to to folder high lited in yellow and delete it .....
When you finished deleting them , run your AV again for peace of mind.

You mention you cant delete wmp 10 ??  why not ......... in add/remove programs , wait until the list is published and then over on the left side click on add/remove windows components ...... when the list appears go to wmp 10 and delete it ......

BTW .... NEWDOTNET is bad news .

dl65  dl65,, Is it safe to open that zip file to get at them,  I would have to extract the file to somewhere using Windows explorer?.  
Using the delete funtion from , Windows explorer, file, delete.  And that would do it.
And its safe?.DAVE9999 ....dont unzip the file just delete the ZIPPED file


dl65  Hey Mark .....Dave has infected and corrupt files in his D: restore partition ....and has no cds. Any thoughts ?

dl65    

Buying a CD and reinstalling would solve this whole problem.   Dl65,
Great, done that with some "terminating" deleting program onboard.
Ran find and they are gone.

I would sooner run another onboard Anti virus program to check if those files are corrupt, a second oppinion,
Not every AV pick up every viruses and some might pick up a wrong bit of data.
Do they still have that "Disc repair" funtion with Windows Running it for ages as it fixes any errors in that segmont??  I'll have a look.  Maybe some freeware scan disc type program might help I'll check it out.

I'll delete and reload WMP and see if I can get it to stream off a web page with WMP stream videos.

Mayby all the improvements over the last few days has fixed it.

Youv'e been a great help over the last few days.

I thought you would have given up on me ages back, I got into a muddle when you asked me did I have Awido installed, then to run my anti virus program.  Like a clot I thought you ment the Ewido!!

Things like that, I guess you pick up Patience, and some degree of understanding from all your experiences at what you do.
A lot of people like myself have some knowlege of the workings of things and then a compleat blank in other areas.  We all just BUMBLE allong, not having any school training like they do nowerdays, doing the best we can.
I'll mosey on off then, and all those people and their virus's and other ills will present themselves to you as they continue to do.

THANKS for all the info and computor knowledge youv'e imparted.
I've learnt quite a lot and I intend to put it to good use.
Good luck. And thanks again.DAVE9999 .... I'm glad we able to of some help for you........
Quote
We all just bumble allong, not having any school training like they do nowerdays, doing the best we can.
  You don't have to have attended classes to learn ...... lol ......  It never ceases to amaze me just how much we learn in our bumbling along ........
Please come back again anytime .

Cheers
dl65  Hello dl65,

I'm glad you said "Please come back again anytime".
Cause following on from
8 viruses found, unable to delete.  Topic.
  Reply #26 - Jun 6th, 2006, 10:58pm
Mark for removal
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE .


I have since found out,   having no sound,    that ALCMTR.EXE is part of
my Realtek audio files.

The emachines 5250 Computor I have has a Realtek Audio chip.
It looks like ALMCMTR.EXE was part of the process in delivering sound to the headphones.

The web page at   http://www.digit-life.com/articles2/intel-hdaudio/intel-hdaudio.html
Shows the Realtek sound manager, The very first diagram of the Realtek sound manager (coloured in shades of blue) just under heading of "Control panel".  (Slightly scrolling down)
The very first one with all the eq slider knobs and that.
Clicking on it gives a much bigger picture.  at http://www.ixbt.com/multimedia/intel/hdaudio/shot2.png
I have found the only way to activate my sound is to go to "Control Panel", click on "Sound effects manager" and when it openes click on the 6th button on the top of that picture.  the one called  "Audio Wizard".  then this picture appears
http://www.ixbt.com/multimedia/intel/hdaudio/shot3.png  
And the sound can be heard.  It is then activated.

Isn't that a strange thing!.  by pressing that button, "Audio Wizard" the sound is then activated.
A total fluke that I found that!.

Alcmtr.exe  is described as "Realtek Azalia Audio - Event Monitor"    and is currently located at C:\Program Files\Realtek\InstallShield  allong with 12 other files.

The Realtec Sound Manager used to load up at start up,  in the little task bar thing next to the clock at bottom right of screen.

I think somehow entering O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE  into HJT has disabled it from running.  And has turned off the sound until the procedure, (by chance found) above is gone through.

I dont know where to turn.  
Ideally, I'd like the Realtec control manager to "Come on " at start up like it did.
And all the sound to work from start without going through the above.

I of course haven't a clue how to bring this about.
Maybe if the ALCMTR.EXE  is put back into O4 - HKLM\..\Run: the whole sound thing will automaticly work again.

It "sounds" a bit of a sod to fix,

In the list of drivers for the realtek driver in control panel "sounds and audio devices"
there is
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\RTLCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
and 11 others.

The top one being the one that HJT got its hands on.
ALCMTR.EXE is still in the C:\WINDOWS location it hasn't been deleted.

Any ideas on how to fix it please,
I'm a bit buggered up with it.  Isn't it a strang thing.
        Many thanks.DAVE9999

ALCMTR.EXE  ....... is spyware and thats why it is singled out for removal......
Your sound is on board I think ...so if you reinstall the drivers for the onboard sound , it should be ok ........  what it does is harvest info about your system and send it back to Realtek.....
    "Description: Realtek AC97 Audio - Event Monitor. "Spyware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers"


Hope this explains .

dl65  



Hello dl65,

I would imagine realtek has made the software so that if part of it's software program for its realtec audio chip is took away from, then there is no sound.
Which is what has happened.
There is no sound,
 
When you say about reinstalling the drivers, would that mean deleting it first from Add/remove and then going to control panel,, sounds and audio devices,,,Hardware,,,realteck high definition audio,,properties,,,driver,,update driver,,,WELCOME to the hardware wizard.

I've tried the latter, (Not deleting the drivers first) and it says I have the best drivers fitted already.
I can't  reinstall the drivers.  Ive no idea where they are. and how to reinstall them.

Can you help us out reinstalling the drivers.  If that is all that is needed to get the sound back automaticaly..
Thanks.

DAVE9999  ...... check the device manager and look at each item in the sound part see if you see any yellow exclamation marks .  

The other thing you can do is ..... click start /run ...... in the run box type dxdiag ........press enter ...... now click the sound 1 tab and run the tests...if anything fails it will tell you what to do...... then click sound 2 tab and run the test there as well.


dl65  DAVE9999
try this link
http://www.kellys-korner-xp.com/xp_tweaks.htm

using IE double click line # 6 then follow the instruction (click ok/yes)
if it will not work
double click on line # 316 then follow the instruction (click ok/yes)
if it still not
double click on line # 371 then follow the instruction (click ok/yes)

let us know what happen
1199.

Solve : WAR ZONE?

Answer»

about 30 mins ago, someone did a port scan on my computer. that is usually not a good thing. I instantly cranked up my firewall to the max setting. (my avs was updated yesterday) I was also monitoring my PORTS. I saw nothing for a a while, but when I clicked on my firefox shortcut, my computer restarted with out prompting my to SAVE my work in anything. so I logged back in, and right clicked my firefox icon, and the target was "%windir%\system32\shutdown.exe -r -F -t 00" which I did not set the target to, because the would be stupid for me to do. I scanned my computer with AVG, and found hundreds of trogans and such, whick were all deleted. but I'm sure my cmd file is infected with something, I'm guessing a polymorphetic virus, because my antivirus didn't find anything on it, yet it's not working properly, also, the file size grew by 2 MBs, it's usually about 379kb. I can't run any commands in it, not even cd\ I was wondering if any one can help me attempt to trace the person that did this, I'd like to find out who did this, i do realize that they most likely covered their tracks nicely, I'd still like to attempt.


right now I'm running P.H.L.A.K, Professional Hackers LINUX Assult Kit, for an OPERATING system, I'm running it off of the cd
Ok, I replaced the cmd file from phlak with a backup a made a while ago. I'm back in windows and angry. I'm still wondering ways to track the person that hacked my tower, he(or she) will PAYAm sorry but you cant doing nothing but either report hacker IP address
http://www.reportahacker.com/reporting/reportahacker/index.phpYeah, that figures...I suggest you get some real time protection for that computer.Like a firewall to start.

1200.

Solve : An infection?

Answer»

Hey there.
Recently I was foolish enough to download what I thought was a legitimate installer, only to discover it brought with it a good BUNDLE of viruses and adware. My first move was to disable my INTERNET connection to prevent it spreading or downloading more things onto my computer. Next I ran Spybot Search and Destroy, AdAware-SE and my Norton Antivirus SEARCHES to cleanse my computer. I also installed Avast virus protection and had it run its system startup scan and a completly thorough scan for viruses. When I thought everything was removed I enabled my internet connection again, and was given numerate popups from Avast telling me I had viruses and adware found. I followed the "suggested action" of moving everything to the "chest". Now what move shall I take next? What has "moving to chest" actually done? Are all threats now dealt with and I can have piece of mind? Presumably my computer is still infected, what shall I do next to get it sorted out?

Also I can no longer open Windows Task Manager with CTR + ALT + DEL and opening it with run taskmgr.exe tells me the file is already in use, despite it not being open. Also I have a new program installed on my computer called toolbar888 which I cannot remove without closing internet explorer first. However internet explorer is not even open at the time. Any ideas with these two problems at all?

Any help appreciated, I know I've been a silly boy  
Brom Bromley-UK.......  The first thing you should do , is turn off your system restore ( if you have that option available to you........ ( you DIDNT mention the O/S )  . Next reboot into safe MODE and run your Anti virus from safe mode ...... Once you are finished , reboot back into normal and see how things are .

dl65  Sorry, I'm on Windows. Thanks, ill give this a shot.