Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

1201.

Solve : which combination of spyware programs??

Answer»

On an old Windows 98SE computer with somewhat limited HARDRIVE, memory and processor and so on. What mix of spyware programs would be good for not eating a lot of resources.

I have found the A2Squared on here. And it is definitely in the picture.  So A2Squared and Spybot or A2Sqaured and Adaware, and I will be using Avast for the Anti Virus.

It may have been me, But I thought A2 was better than Adaware on cleaning up this old computer. After running the Adaware until it showed clean I then loaded and UPDATED A2 and it found 367 more infections, including 3 trojans.

Thanks,Fordtruckmaniac...... I would be using a combination of the following:

CCLeaner ..... for general crap removal ( use both cleaner and issues parts)
SpyBot ......... Make sure to use the resident........
Avast ........... For AV scans
A2Squared.... For trojan removal on older machines .

Note Ad-Aware really isnt designed to eradicate trojans .........


dl65  
Quote

Fordtruckmaniac...... I would be using a combination of the following:

CCLeaner ..... for general crap removal ( use both cleaner and issues parts)
SpyBot ......... Make sure to use the resident........
Avast ........... For AV scans
A2Squared.... For trojan removal on older machines .

Note Ad-Aware really isnt designed to eradicate trojans .........


dl65  


dl65,  Looks good to me.

I left out I was using CCleaner too.  

I read this about Adaware in their description of the program, and it got me to thinking about what I noticed:

"Ad-Aware provides protection from KNOWN Spyware including: Data-mining, aggressive advertising, Parasites, Scumware, [highlight]selected traditional Trojans[/highlight], Dialers, Malware, Browser hijackers, and tracking components".

Thanks,If you decide to run Spybot you should also look at the EI Tweaks & Hosts file.
Spybot is a very powerful program in ADVANCED mode, I believe most people only use it as a scanner & don't unlock it's true potential.
(This has been an unpaid text commercial for Spybot S&D)
1202.

Solve : Let's play a little game?

Answer»

Take it from the start  v e r y  s l o W l y.

How do you know you have a virus?

Answer: I know I have a virus because..........................
(You fill in the DOTS) Dilbert...... Quote

Oh, I got a reply from Symantec (SORT of). It's not very helpful:
  Uh , I just WENT through it and it is very SPECIFIC about what to do. Which part didn't you understand?

dl65
1203.

Solve : My mate Lornas Pc?

Answer»

Hey guys, ive just helped my friend Lorna clean out her pc, we got rif of most of the spyware. But there was one thing that i was very weary about that i told her for the moment not to remove. It was something called LOP (http://inetexplorer.mvps.org/data/lop.htm), ive googled it and done some research and found that it is petentionaly a HIGH threat. But when i went onto their website it confused me and im not SURE how to deleate it. Im pretty certain that she installed it with MsnPlus (the sponser program). If i dleleate this LOP via Lavasoft will it casue msn plus to CRASH?!?! Also i would like to note that i really wouldnt want to have to maker her do a Hijackthis log. Thanks

[ch268][ch293]rî[ch347] chriscool9.....  I would suggest using Spybot to remove that nasty .........
Quote

Also i would like to note that i really wouldnt want to have to maker her do a Hijackthis log.
 ......  Do you mind if I ask why you are against using hijackthis ?

dl65  Hey, thanks for reply. I got nothing against HijackThis but its really hard trying to help her over MSN, especialy with her not being the best with Pcs. I just think it would casue alot more problems then it wold solve. Also just out of intrest how some Sby Bot Search and Destroy rather then Ad-aware? Does it do a better job?

[ch268][ch293]rî[ch347]
chriscool9...  Ok ..... Spybot , is far more adept at removing nasties than is Ad-Aware ...... ( I don't mean to imply that ad-aware doesnt work ..... because it finds and removes what it is designed to do)  Spybot does that and a whole lot more .
If both you and your mate use msn messenger ..... why not ask them to click on the "ask for remote assistance" ....click actions and request remote assistance....and you can take control of their pc from your keyboard and their desktop will be on your desktop ....works very well for assisting people who are not too computer literate .

Good luck.

dl65  Hey thanks for all the replies Dl65
Yea i tried using 'Remote Assistance' but it jsut times out with her connection. Ive used it before with others and its very handy. But i always get that little bugwhere my keyboard GETS messed up and then gotta fiddle with it.
Also can i just confirm that directly removing LOP without uninstalling MsnPlus wont casuse msn to crash? Or do i have to completely uninstall msnplus then romove it?!?!?!
Thanks again

[ch268][ch293]rî[ch347]
1204.

Solve : Suddlenly slow internet; AVG, spybot no help?

Answer» HELLO, first of all, thanks in advance for any suggestions. Yesterday, I got into work and my pc started struggling with its internet connection. Everything is significantly a bit slower -- from pages loading to downloads (I attempted to download a new version of iTunes as a test and it took an incredible a amount of TIME).

I have a laptop--a Compaq Presario 2100, AMD Athlon XP2400+, 1.79 GHz, 448 MB RAM--and am running XP. I ran AVG Free and Spybot and turned up nothing out of the ordinary (cleaned up what spybot suggested and there was no differnence). Tried Ad-Aware, too, and at the rate it was going, the full scan would have taken a couple of days.

I'm at my wit's end here and would dearly love to avoid a re-formatting. I'm not too experienced with troubleshooting, tried a System Restore, but nothing changed.

Any help would be greatly apprieciated. Thanks,
Brett

Btw, I didn't install or download anything, or VISIT any sites of the ordinary, that would hint at anything unusual happening.

UPDATE: My laptop's fan is now jumping into overdrive even with just minimal programs running. Something weird is happening here ...BrettMud...... Do you use your laptop in a unusually dusty enviroment ? Perhaps the blades are loaded up with dust and simplly cant keep the machine cool enough .  Does it appear to be running hotter than usual ?
Do you have any temperature monitoring software installed so you could check ?

dl65  
You might want to check your running processes also, now and at a fresh reboot, with Task Manager.sometimes the antispyware programs conflict. all three trying to scan everything and protect everything. try deleating one of them. this happened with me when i had spybot, adware, norton, and defender on my computer.

it might help to disable one of the programs. i purchased spy sweeper and deleted spybot and adware. now my connection speeds are back to normal



tmml Quote
sometimes the antispyware programs conflict. all three trying to scan everything and protect everything. try deleating one of them. this happened with me when i had spybot, adware, norton, and defender on my computer.

it might help to disable one of the programs. i purchased spy sweeper and deleted spybot and adware. now my connection speeds are back to normal



tmml
You should only have 1 Antivirus scanner, 1 firewall, and 1 Antispy scanner running at the same time. Having so many does overwork your processor, hard drive, and entire computer itsself. You should avoid this. Go ahead and turn off all unnessasary protection. (You do not nessasarily need to uninstall it if you are not sure that you want to do that. Just stop it from starting in the options. If you run a scan of your computer with two scans going at once, you can expect it to go slow, it would go faster to scan sepratly)All I can say is that I feel sorry for you. I had the same problem, only on a PC.  And, to make it worse, whenever I tried to download an anti spyware program, the computer would shut down and restart and forget about the download. Finally, one dark and dreary NIGHT, it happened.  Page after page of sites started to appear, one after the other. a-d-a-w-a-r-e or someting like this.  Then, when I tried to email a friend for help, a picture of an ocean liner appeared in the middle of the email page! Apparently an ad for vacations or something, but I'd had it by then.  I shut down the system, and myself until morning. I sent my son out to buy me some virus guards and such.  As soon as I downloaded some type of all purpose guard, and watched in horrification a my 100MB memory went to 238KB, the red light started flashing: virus, virus, can't delete file.
  So I had to reformat and reformat and still don't know what the best protection is to stop this nightmare from reoccuring.  I hope you have better luck than I did
Dr.D Quote
Tried Ad-Aware, too, and at the rate it was going, the full scan would have taken a couple of days.

It sounds like you have a problem that could be helped by running HIJACK This and posting the full log file here. Either zip it up or use several posts to get it all.
Sorry I've taken a little while to respond. Thanks, all, for your helpful suggestions. I ended, finally, by reformatting, and it's taken me a little while to re-download and copy my old software and files ... and get things back up and running. Needless to say, the reformatting worked great and things are back to normal. I suppose it was about time I did so anyway.

This is a great site ... thanks for being so prompt with the help. I'm sure a Hijack This log and step-by-step fix would have helped, but the chugger needed reformatting anyway (2 and a half years without).

All the best,
BA good format and reinstall will fix most Windows problems (for a while anyway).
1205.

Solve : generic.AEL?

Answer»

anybody have info about this supposed trojan horse, besides WHATS avail. on google.What have you LEARNED so far? Are you infected with it?avg said yes once -no other spyware programs find it-for example eido(sp) so i wonder what it is.If it is a true trojan, most spyware programs are inappropriate to find and remove. Try Ewido in safe mode with system restore turned off. You may want to look at A Squared, also.

http://www.emsisoft.com/en/software/free/lanejr.......  generic.AEL     It's a trojan downloader .....and must be removed

To get rid of it , you should have ccleaner and hijackthis installed ...... then run hijackthis and post the logfile here .   Then we can go from there .


dl65  i have both installed. how do i post the log here.Either zip it and attach it or just copy it and post. It will take several posts to get it all, but don't leave ANYTHING out.  logNo nasties in there just junk, perhaps AVG fixed it in the HEAT of the moment. Hi guys , I just had a look and this is what I see that should perhaps be removed ......


O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - (no file)

O3 - Toolbar: hp TOOLKIT - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL    [highlight]I know its related to hp ...but it should go .[/highlight]

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/Coupons.cab

Fed , if your still on have a look at the 03 and 016 ....they are more than questionable ............  Also look at all the toolbars installed ........


dl65  Perhaps the OP collects toolbars & junk. I didn't count. How many toolbars?O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll

I use the Google toolbar just to get the little search window, I find it very handy.

1206.

Solve : PLEASE HELP ME REMOVE WINFIXER MALWARE!!?

Answer»

I HAVE USED ALL OF THE AVAILABLE SOFTWARE TO TRY TO RID MY COMPUTER OF THIS. IT ONLY SEEMS TO BE GETTING WORSE. ANY HELP WOULD BE APPRECIATED. I USE MY COMPUTER FOR BUSINESS AND THE POPUPS ARE DRIVING ME OUT OF MY MIND.You have to Delete a horible amount or crap to get rid of it, here's what they say at nortons

http://www.symantec.com/avcenter/venc/data/winfixer.htmlTHANKS PANBOY,
         I WILL GIVE IT A TRY. I HAVE WENT DOWN THIS ROAD BEFORE TRYING TO USE THE REGISTRY TO RID MY COMPUTER OF THIS GOD=AWFUL PROGRAM, BUT I HAVE BEEN UNSUCCESSFUL TO THIS POINT. ANYWAY THANK YOU VERY MUCH FOR THE REPLY,
RICHARDRAYI LOST HOPE IN TRYING TO REMOVE THIS ITEM. I UNLOADED EVERYTHING OFF OF MY OPERATING SYSTEM AND RELOADED IT AGAIN. IT ONLY TOOK 4 HOURS!!!!! ANYWAY IT APPEARS TO HAVE TAKE CARE OF THE PROBLEM. WINFIXER WAS THE MOST ANNOYING AND MOST DIFFICULT TO REMOVE MALWARE I HAVE EVER RUN ACROSS. I JUST GOES TO SHOW, IT PAYS TO HAVE GOOD ANTIVIRUS/TROJAN/MALWARE SOFTWARE INSTALLED. THANKS FOR YOUR HELP,
RICHARDRAY  
You summed it up well, and a good reinstall removes ALL of the problems, for a while anyway. Sometimes that is quicker also.  I FEEL FOR ANYONE WHO HAS TO TRY TO REMOVE WINFIXER.  I DO NOT UNDERSTAND WHY THE COMPANIES ASSOCIATED WITH THIS MALWARE/ VIRUS ARE NOT PROSECUTED. THE AVERAGE PERSON WHO OWNS A COMPUTER WOULD NOT BE ABLE TO RELOAD EVERYTHING ONTO THEIR OPERATING SYSTEM. WHOEVER CAN COME UP WITH A LEGIT PIECE OF SOFTWARE THAT WILL ACTUALLY REMOVE THIS WILL MAKE TONS OF MONEY. (AT LEAST I WOULD HAVE PAID A FAIR PRICE TO KEEP FROM LOSING  MOST OF THE INFO THAT I LOST) ANYWAY, GOOD LUCK TO THOSE WHO ARE UNFORTUNATE TO COME ACROSS THIS GODFORSAKEN PIECE OF SH*T.
RICHARDRAYI remove winfixer about once or TWICE a WEEK. Usually pretty *censored* easy I find. I didn't get around to looking at your post till you've already nuked it though. All you have to do is run xcleaner then the vundofix. Problem solved. Well usually, if not it may require a little hands on but I've never had too much of a problem with that one.Are you sure it's really removed and you're not just reinfecting yourself. If not, it must be the sites you go to, or inadequate protection, or unsafe practices or all 3.

1207.

Solve : ctfmon.exe trojan?

Answer»

well it just popped up in processes again.

Logfile of HijackThis v1.99.1
Scan saved at 7:32:36 PM, on 6/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NGO ATI Optimized Driver v1.6.4\ATT\atitray.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Corel\WordPerfect Office 2002\Programs\wpwin10.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Allen\Desktop\Downloads and Stuff\HijackThis1991.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://nimrodonline.dhs.org
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\NGO ATI Optimized Driver v1.6.4\ATT\atitray.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exeHave you owned this computer since the last OS clean install?
What I'm SAYING is, could a previous PERSON have had Office installed and since removed it?This baby is due for a good format and reinstall in my opinion!  Wondering if it could be your WordPerfect Office utilising the windows file?

Can you use msconfig>startup to temporarily disable WordPerfect, then use Hijackthis to remove the   O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe entry  , re-boot and see if it comes back for a while?i got this computer brand new from dell and had wordperfect already installed so no i dont think SOMEONE else could have had it on.  i just reformatted the hd about 6 months ago and reinstalled windows.no that didnt work.  its still popping up in processes but its not FOUND in hijack this anymore.Here's your answer to this thing constantly starting up. Open up a command prompt (start -> run -> cmd) type:

CACLS c:\windows\system32\ctfmon.exe /p guest:n
Problem solved. It won't have any permission to run and it won't be able to do so anymore. Also it'll still be there so if you notice any problems you can just reverse it by going back to the command prompt and typing:

cacls c:\windows\system32\ctfmon.exe /p everyone:f
Good luck to ya  alright thanks ill let you know if it doesnt work.

1208.

Solve : winnjj32.dll?

Answer»

Hello,

I have a FILE in Windows\SYSTEM called winnjj32.dll and it APPEARS in my Startup in MS Config as WINNJJ32.

I NEED to remove this file but I am not SURE how as I cannot delete it because it says that it is being used by windows.

Any help will be gratefully recieved.

RobWhy do you need to remove it? What has your research shown you that it is?

1209.

Solve : muliple AV??

Answer»

After searching AROUND, I still haven't found an ANSWER to the question ' is it ssafe to run multiple anti-virus programs. I have heard that you can, and I have also heard that you can't. I'd just like to clarify that.

Thanks,

ViperYou should not have more than one active program loaded. No benefit, and possibility of malfunction.But don't confuse anti-virus with anti-spyware, anti-trojan or anti-anythingelse. Quote

But don't confuse anti-virus with anti-spyware, anti-trojan or anti-anythingelse.

I'm not, I have a computer with both, AVG and Avast AV on them, and I was wondering if I had to REMOVE one.

Viper
You don't have to, but should!well, that sounds good to me, but which one should get rid of?  :-?



ViperYou don't need to remove one of them, just turn one off and use the other.
They both have very good reputations.
The following text was stolen from someone else.  
Quote
 Best Free Anti-Virus Software   Updated  May 3, 2006There are two equal recommendations in this category. First there is AVG Antivirus 7.0 Free Edition. This product [1] has been continuously refined SINCE it was first released in 1991 and now offers SOLID protection capabilities. Additionally, it's relatively small, light on resources, has regular automatic updates and handles email scanning. There is a free and a pro version, the only difference being that the free version has a few non-critical features disabled and has no direct technical support.

Equally effective is the free Avast! scanner [2] though its funky media player style interface is not to everyone's taste. Avast! also required periodic re-registration while AVG does not. However Avast! does not seem to suffer the signature file update problems that plague some AVG users.


I've never encountered an AVG update problem. Quote
well, that sounds good to me, but which one should get rid of?  :-?
Viper

but dont forget, running two AV slows your pc
well I went to run/ msconfig, flipped a coin and chose to keep avast my primary av.

Good choice, 'cause Avast is the best antivirus out there.

Almn
1210.

Solve : When U: Ad/Spyware?

Answer»

I just watched my Dad install Deamon tool's and all was going as normal, but then after the install a SECOND install box poped up,

And i was all like "Oh noes!! dont clicks the buttons!!!"

So my dad went and clicked the button and now i have to get rid of this Crap, any one know what gets rid of "When U Save"?

And also when did deamon get Ad supported?

Ad Aware Works Grand on this one.

But STILL since when is it in Deamon?? Code: [Select]R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = HTTP://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDBVt3B+BXauvnKDJUwswq/dMcegkBgVAuCS/h5upbgAlLs9Kfai0+Ga4Kfp768Yz7ervodYAMy9GREXAIOneYjNsyUxybhS2CGT6AIABYOg/qbtLkz+jMRWocUjGKHiZHIYB7gIev5qVat6qYJAANAvGLXLU1oCSc
O2 - BHO: WhenUSearch HELPER - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Program Files\WhenUSearch\search.dll
O4 - HKLM\..\Run: [WhenUSearch] "C:\Program Files\WhenUSearch\Search.exe"
O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe"
O16 - DPF: ibb_cust - https://ibusinessbanking1.aib.ie/ibb_cust.cab
O16 - DPF: {E2A96175-32D0-4651-B228-B474C2408346} (DacomDownload Control) - http://program.webhard.co.kr/Plus/active_download/DacomDownload.cab
Fix those ones. Also run X-Cleaner. An Ewido scan might be a good idea too. Post another log file if the problems aren't resolved after you've done those.

1211.

Solve : NYB Virus?

Answer»

Lets start out with this:
Each and every one of my computers has something wrong with it. (each and every computer that is mine, and not having to be shared, and this EXCLUDES my good laptop)

Now, I have run across a NEW! wonderful problem.
Almost EVERY floppy disk I have has a messed up boot sector.
If I insert a floppy disk, it will show as if its infected with a virus, however, its not...
[highlight]I would like to make this clear now, I DO NOT HAVE A VIRUS[/highlight]
(as I'm too good for a virus)

All it takes to get this supposed "virus" is the insertion of a Windows 3.0 disk OR DOS 4 disk upon boot.

When I start my computers in safe mode, I get "Your computer may have a virus" from Windows.
(mainly one computer that tells me that)
When I open a floppy disk, AVAST! Says that the disk is infected with a boot sector virus, does not remove the virus, but does not activate it...
When I use my McAfee Emergency Disk, it gives me the "NYB VIRUS" thing as well...
The only possibility of the Windows disks having the virus is if the PREVIOUS owner inserted the Windows 3.0 setup disks while they had the virus...
This virus came out: Jan 15, 1995.
Information about the actual virus is here:
http://vil.nai.com/vil/content/v_880.htm

Why the heck is a Windows 3.0 disk causing all of this to happen?
(if you let me make another post, I will make it so this is a LOT LESS tedious to read.)Oh, and Avast says "Sample of the NYB virus", it doesent just say NYB virus, it says Sample before. Does that make a difference? Quote

The only possibility of the Windows disks having the virus is if the previous owner inserted the Windows 3.0 setup disks while they had the virus...

As Rob SAID, that's how VIRUSES were spread in the good old days!
1212.

Solve : Can't Open Certain Programs?

Answer»

Ok, My friend came over with his pc and asked me to do some work on it.Which was fine I build computers and such for people as a little buisness.So he then asked after I GOT his computer booted for me to put some rom files onto his computer.So of course I agreed.Instead of wasting time installing my isp on his computer I installed his hd into my computer as a slave.So I gave him a ton of files.And when I booted my pc up after he left I NOTICED that I couldn't change certain things on my computer.Like for instance.I was setting up a new ipx connection so I could play a game between me and my g/f.And when I set it up it froze as I finished.So I thought hmmm...Maybe some sort of malware etc. was transferred.So I figured I'd check my msconfig for SOMETHING.Couldn't change anything.So I decided to enter my services.msc...Nothing would close...So I went into my computer...Nothing detected...Thought maybe my hd POWERED off or something stupid...No Dice.It's connected fine and all that good stuff...So I ran multiple scanning progs.Adaware,Spybot,HIjackthis....Did minor work and nothing prevailed.Tried to reboot into safe mode to ruin spybot and such,Except when I log on it gets an error that isn't shown and reboots.Took off all user accounts and did same to no prevail...So I'm curious on to what sort of malware,virus such could cause this...Anything else juist doesn't make sense to me. Your INPUT and knowledge would be greatly appreciated

ThanksWhat are "a ton of ROM files"?

1213.

Solve : AVG against Bitttorent??

Answer»

AVG
Bittorrent (stable)
i just update my AVG this afternoon then few minutes AVG detected that my Bittorent.exe a Virus
this what AVG report

Virus Detected
While Closing File: E:\PROGRAM FILES\bitorrent.exe
Trojan horse PSW.Generic2.AOK

then i click "HEAL"
and then AVG says "object was sucessfully healed"

but later on i cant use anymore bittorrent
so i reinstalled

but when i run again the newly installed Bittorrent im getting same problem

i think this is only a new problem both AVG & Bittorrent
anyone knows how to fix this?what ever i do it really detect it

i get this link
http://forum.grisoft.cz/freeforum/read.php?4,53254,sv=

the link says the same in my problem
[COLOR="Blue"]Virus Detected
While Closing File: E:\Program Files\bitorrent.exe
E:\Program Files\maketorrent.exe
E:\Program Files\choose_language
Trojan horse PSW.Generic2.AOK[/COLOR]

[COLOR="Red"]PSW- a.k.a password stealer[/COLOR]


any idea on this matter?
i think i will try other torrent dl'derAVG had an issue similar to this with a CD Ripping program I used briefly in the past. I never figured that ONE out.

Try an online scan with the suspect bittorrent file installed, either at Panda or Trend Micro's page. Better yet, do both, one at a time.You could also upload the file for multiple scans.
http://virusscan.jotti.org/after i uninstalled the Bittorent i ran:
Ad-aware (result: cleaned)
ZA Anti-Spy(result: cleaned)
AVG(result: cleaned)
Spybot S&D(result: windows firewall override "immunized")

im sure that Bittorrent i got is genuine, coz since ive learn P2p i think i dl'd 4 times the BT from ZP and BT link not from other site
also ive done "exception" from scanning but AVG will detect the system of my pc where some file of BT exist and it will get back to problems

Another AV? not an option for me
but i get another dl'der and its Azurues and i think its ok
and i clean all the files of BT from my pc

as of now im running the BitDefender Online Scan

BTW thanks to all of youWhy is another AV not an option?One properly functioning active antivirus is sufficient for most viruses. More than one causes problems. Each frequently thinks the other's scanning is a virus and this will slow down your system or worse. As to which one to use, that is up to you. Quote

One properly functioning active antivirus is sufficient for most viruses. More than one causes problems. Each frequently thinks the other's scanning is a virus and this will slow down your system or worse. As to which one to use, that is up to you.

Bittorent stable VS. AVG
so i CHOOSE AVG, i dropped  Bitttorent so that nothing pop-up from AVG
i replaced with Azureus and my Opera 9 also can downlod torrent file

ThanksAh, we went different directions there.  I wasn't suggesting that anyone run more then one AV at a time.  I was wondering why he selected AVG and what was stopping him from going with a different set of tools that will allow BT to function properly.
1214.

Solve : WinVirus Pro?

Answer»

Are you doing these repairs in safe mode with system restore turned off?

Do you have a real Windows CD to reinstall if that is necessary?Fair9.......  Did you run Vundo fix ?

Please post a fresh hijackthis log and please include the very top part which SHOWS your OPERATING system .

dl65  Vundo does require 'special' treatment, below is a very helpful link for your viewing pleasure. Don't give up, we like bug hunts.
http://www.bleepingcomputer.com/forums/topic18610.htmlIf you've already ran the vundo fix and are still having problems with that file then this will take care of it for you. Go to start, run and type cmd then press enter. This will bring up a command prompt in which you can type. What you need to type is....

Code: [Select]cacls C:\WINDOWS\system32\gebyx.dll /p guest:n
Then press enter. After you reboot that particular file will no longer run. Post ANOTHER hijack this log afterwards so we can CHECK it and also report any problems that you may still have.

1215.

Solve : deleting virus throguh registry?

Answer»

Infostealer.Metafisher
that's the random trojan i got. i scanned with norton but came up empty. then i tried to manually delete it, but the procedure i followed, well no file similar to that showed up.
Does that mean that if the program is not in my registry, i don't have the virus? captainsmooty.....  You dont have a virus , however you are infected with a trojan........
Heres what I would SUGGEST you try .
If you have system restore , turn it off .
Go to ...... http://www.filehippo.com/download_ewido/   and download the latest version of Ewido ( win 2K and XP )   If you have some other Windows operating system D/L ...... http://www.emsisoft.com/en/software/free/   A-Squared .
reboot into "SAFE" ....and run your anti virus again and see if you can remove it.  If not , run Ewido or A-squared depending on your operating system ....
Delete anything found ........ Reboot back into normal mode and see how things are .... if for any reason it is still there post a hijackthis log file .

Good luck

dl65  
I use Norton antivirus and scanned everything in safe mode, etc. I found no threats. I also used Microsoft Malicious Tool removal and it found NOTHING. I don't even know if the trojan is still there. I dunno where else this thing can be on my computer...

how do i create a highjack this log file also?Did you download and run ewido like dl65 said? If not do that next. If still nothing then here's the link to download hijack this.

http://download.hijackthis.eu/hijackthis_199.zip

Do a scan and save a log file, then just copy and paste into posts. Chances are because of the character restrictions you'll have to post two or three.I ran ediwo and my computer is clean. and this is the log PART 1
I don't see anything wrong... but i can't read this either.....
____
Logfile of HijackThis v1.99.1
Scan saved at 2:46:12 PM, on 6/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\AOL\1148853906\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Natalya\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.animereflections.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sony.com/vaiopeople
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1148853906\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
part 2
____
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate SCHEDULER - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
part 3
___
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.execaptainsmooty...... I see no evidence of the trojan , so I believe you have removed it .......
There are however several entries in your hijackthis log file which you should fix ........

mark for removal , the following :

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE           [highlight]Realtek AC97 Audio - Event Monitor. "Sypware" file used surreptitiously monitor ones actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers[/highlight]

O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP [highlight](file missing)[/highlight]

 O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server ([highlight]file missing)[/highlight]    

  O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server [highlight](file missing)[/highlight]

That's it .......

once they are marked ....click on fix marked ....... and you should be good ....

dl65    


what do i do with the (file missing) just remove it?captainsmooty.......   Yes .... mark them for removal.

dl65  thanks so much!
did anyone tell you, are the smarter man alive???

1216.

Solve : virus compounded by stupidity?

Answer»

Slight crisis. I have effectively destroyed my computer (an Elonex Exentia with xp). I got a virus using msn (stupidity; clicked on legitimate-looking link....I know, I know. I should know better.) Initially the virus gave me lots of adverts. Had I known better, I would have left WELL alone and just dealt with it! Anyway, I then tried to improve matters, using adaware.  After using adaware and turning the computer back on broadband stopped working and the computer said it was unable to renew my ISP address.

Soo, I used [virus programme with red, umbrella logo]. And then THINGS perhaps got a little worse, but certainly didn't improve, so, impetuous as ever, I used LSPFix. And now the computer is NOT happy. It still turns on, and you can still use Word, but iTunes won't load, the internet won't even open, the computer is refusing to do system restore, it can't even OPEN connections, and struggles to open My Computer... can anyone suggest a possible and sensible next course of action? I'm straying towards just reinstalling the whole system, but it does seem horribly drastic. The big question is is there any way of reversing the effects of LSPfix?

Many thanks in advance for any help you might be able to give,
Laura

 laura.taylor.....   Ok , lets see if we can sort this out .......
You are using win XP as an operating system ........
Your machine is infected with something ....what , we don't know .
Quote

Soo, I used [virus programme with red, umbrella logo]

Does this program have a real name ?
Quote
After using adaware and [highlight]turning the computer back [/highlight]on broadband stopped working and the computer said it was unable to renew my ISP address.  
  Do you mean you used system restore ?
If system restore is still turned on ....... Turn it off

Will your machine load up ?   If it does , reboot it into "SAFE Mode" ....... To do this shut the pc down and then restart it ....... just as it begins to startup , repeatedly tap the F8 key ....... you will see a window open that asks you how you want to load windows , choose "SAFE MODE" and press enter ...... let it load , you will see the words SAFE in all four corners of the screen and then your dsktop icons will load.( they will not appear the same as they do in the normal windows desktop....... wait until everything finishes loading , and then do a full system virus scan with your AV ...... delete anything it finds and report back with the results .  Then we will proceed .

dl65  


Might also be a good idea to BOOT into safe mode with networking and see if you can get online there. If you can download Ewido as well as X-Cleaner and run them both there. Make sure you update ewido before running it. Quote
After using adaware and turning the computer back [highlight]on[/highlight], broadband stopped working and the computer said it was unable to renew my ISP address.  
LOL Ye-es. Apologies for lack of sense! I used adaware, then turned it off, then turned it back on...

I didn't use system restore - I'm not that computer literate! Attempted system restore yesterday, but it told me that I didn't have sufficient authority within the system - despite my being down as administrator. Which is another issue.

It will load up. I shall - once I've finished revising Representation and Democracy for the day (life is just too much fun these days!) - try everything you've all very kindly suggested, and shall report back later!

Thanks,
LauraAlas, it's all a bit too complicated. Dad works for a computer firm and has said he's going to take it into work and get them to sort it out. Phew.

Many thanks for all your help, however - you've been LOVELY; apologies for wasting your time!

Laura
it would be nice to know how everthing turns out? what the problem was how they fixed it and stuff
1217.

Solve : McAfee messes up Eudora?

Answer»

Hi, I'm typing from my grandmother's computer. She likes to use Eudora, but her settings keep getting, um... messes up. Instead of*

[email protected]

it reads

Herusername%[email protected]

Thinking it was Eudora, I found the Eudora.ini file, SET it correctly, saved it, and flagged it "read-only". However, the settings STILL change, though the .ini file does not (obviously, I did set it to read-only).  Eudora tech SUPPORT says it's McAfee, and my test rules out Eudora as the culprit. I can't think of any viruses that can do this (she's got me around, and we all know how wonderful McAfee is, so I made *censored* good and sure that she's got SpyBot, SpywareBlaster, a HOSTS file, and the like). AcAffee is, it appears, causing this.

My question is thus, since I'm not familiar with McAfee: Where would I find the settings that control Email?Just in the main part of it, Security Center I think. Just disable the spam filter, it's junk anyways and that's what keeps changing her info. I SEE it all the time. Pain in the *censored* but fairly easy to fix. Disabling the spam filter will usually take care of it.Sorry, that didn't work. :-/Do a complete uninstall of Mcafee then re-install without Spamkiller or just get rid of Mcafee."Yeah, I'd like to!"

--Grandma


I'll see if she wants to do a reinstall, but I'm not sure how McAfee subscription works... if it's like Norton, where you have to Email tech support,  I'll put it off a day or two. But wouldn't disabling McAfee SpamBlock do the job? Quote

...Instead of

[email protected]

it reads

Herusername%[email protected]

My question is thus, since I'm not familiar with McAfee: Where would I find the settings that control Email?

Right-click on the McAfee icon down by the Windows clock (it might look like a shield with a red letter V) and click VirusScan Console in the shortcut menu.

Doc
1218.

Solve : virus scripting-- not to make one?

Answer»

what kind of scripting do virus creators USE? or is there like a virus MAKING PROGRAM out there? im just wondering and i have been wondering this question for a LONG time.It's very involved and we don't discuss such items here. Maybe a Google search will teach you what you want to know?ok thats what i WANTED to know

1219.

Solve : my hijackthis log?

Answer»

Logfile of HijackThis v1.99.1
Scan saved at 10:28:05 PM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\COREL\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\HPHipm11.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Jeremy\LOCALS~1\Temp\Rar$EX00.406\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink ScamBlocker V2 - {15F4D456-5BAA-4076-8486-EECB38CD3E57} - C:\Program Files\EarthLink TotalAccess\Toolbar\EScamBlk.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPuB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program FileO3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - EXTRA context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143520289187
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8D266DE-8A43-44CF-96A1-663DC6B95BE7}: Domain = earthlink.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{B8D266DE-8A43-44CF-96A1-663DC6B95BE7}: NameServer = 207.69.188.185
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccO23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo WIRELESS, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Rather than just posting a log that wasn't requested, please describe ALL problems with the system that you are having. One of the experts will be along to check it.
i was just doing a system check

and it beeen really slow lately, like turtle slow,

i have spybot addware se

norton internet sercurity
all the scans came up clean unlovedwarrior......  
In your running processes , I see ....... C:\WINDOWS\System32\DLA\[highlight]DLACTRLW.EXE[/highlight]   it is produced by Sonic software ....... Everything I find on it refers to it as malware ..........  I would go in and manualy remove it ..... ( dont DELETE it yet , just take it out of the system32 file and save it elsewhere until we're sure .
I would also manaully delete this one ...... C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe  

Now mark for removal the following :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search

 R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll    

 R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l

When the above are marked , click fix checked ..........

By any chance have you recently switched to earthlink as your ISP or downloaded a revision from them ?

Most of the dodgey entries seem to be related to earthlink .

dl65  


Ya those are pretty much all good. Earthlink is a broadband provider as previously stated and Sonic is the burning software that ships on Dell PC's. It's fine too. You're log LOOKS clean to me. If you're concerned about the speed try running Cleanup!. It cleans temp files out of the system and I've seen it clean up over 10 gigs before. It can speed up a PC significantly so maybe give that a shot. Could also try another scanner if you're concerned about spyware. Maybe try Ewido and see if that helps.unlovedwarrior.... So , "you fixed the stuff " ....is the pc running any better or faster ?


dl65  i tried Ewido but my IE closed on me when it was cleaning out the tracking cookies and other things..

yea my computer is running fast then before

 thanks

1220.

Solve : Weird messages......?

Answer»

He all, I recently re-installed XP and inside of 10 minutes I had started getting these weird messages. I had just configured my dialup connection and the only site I had visited was Microsoft's homepage.

These messages open in the task bar as a closable window and are listed in the Task Manager as Applications. They are title "From Messanger to Registry User" (I think that the wording). I know windows has a valid service like this that is rarely USED, but these come on like ads saying that I need to go to either www.regpro32.com or www.msreg.com, and that my registry is corrupted. That makes no sense since I just installed a fresh XP not 15 minutes prior.

I have seen my share of malware but this is a new one to me. Any ideas? My HiJack logs are sqeaky clean, and SpyBot, AdAware, AVG etc turn up nothing either. I don't get this one. I need the help of a vet here.

THANKS,

JamesDid you have SP2 loaded, the firewall on and antivirus in place before you CONNECTED to the Internet? You can be infected within seconds.

A fresh install of any WIndows and a trip to MS update will IMMEDIATELY show Alexa problems with AdAware. That is with NO other sites being visited.No, just SP1. I did in fact pick up Alexa, that is easily spotted with AdAware like you said. This other one is just plain strange. I've just never seen one quite like this before.i have gotten those errors a million times, i just ignore them, and nothing has been wrong with my computer. to make those messages go away go to: control panel, admin tools, services, find messenger, right click goto properties, click stop and set startup type to disabled. no system components depend on messenger being on so dont worry about turning it off, you wont notice anything different about your computer except those *censored* popup things will be gone. forever.Yes Mr. Midian, I did in fact know that but that you for the suggestion. It's the principal of the thing that bothers me. I have dealt with my share of spyware but this one just has me boggles.

Here is one of the messages that I wrote out:

Code: [Select]Message from SUBSYSTEM to ERROR on 7/6/06 8:15:19 AM

YOUR SYSTEM HAS 46 REGISTRY ERRORS!

To fix the erros please do the following:
1. DOWNLOAD Registry Repair from http://www.patchreg.com
2. Install Registry Repair
3. Run Registry Repair
4. Reboot your computer

FAILURE TO REPAIR AN INVALID REGISTRY MAY LEAD TO DATA CORRUPTION!I think you are clearly infected with spyware now as this is NOT a Microsoft warning and they are wanting to sell you a product. This is not part of a normal Microsoft installation. Period.lmao.. i i thought ad bots where annoying... but this is beyond annoying... im glad i installed SP2 before going to any sites...

1221.

Solve : I dont Know Whats Worng Please Read?

Answer»

Alright to start off my computer started acting funny like 3 days ago...it just started to slow down dramaticly so i ran a virus scan and it foung a 1 trojan and deleted it...i also ran a spyware scan and like two were founf but they were deleted..i READ through the boards di what i read turned oof the recovy consle ran that ccleaner and all that...but my computer is still very slow...i have a amd 2000 xp with 256 mb ram windows xp.....and the crazy part it starts off running at 240mb when the computer loads up...someone please helpC:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\VEXPLITE\viritsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\BIGCHR~1\LOCALS~1\Temp\Rar$EX00.156\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' MENUITEM: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139444242665
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsecurity.com/trojanscan/axscan.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Applenino585......  Well , had a QUICK look at your hijackthis logfile and ....... you dont appear to have the latest service pack installed ......... and other than a few unecessary REGISTRY entries, the log looks clean ........

perhaps tell us the following :

1 Did you turn off system restore before running the scans ?

2 What did you use to scan for the viruses ?( I see referances to 2 differant ones )

3 Did you run the virus scans from safe mode ?

4 What trojan scanner did you use ?

Quote

and the crazy part it starts off running at 240mb when the computer loads up...
  what do you mean by this ?


Let us know ,

dl65  
Update WIndows & turn off some of your real time protection.
1222.

Solve : Reoccuring Tracking Cookie?

Answer» [email PROTECTED] ad-aware reconizes it as a critical OBJECT as a TRACKING cookie. this is the 2nd time i have deleted this cookie and i have never been to the site. whats going on?Not all cookies are tracking cookies. If you block all cookies, some web functionality will be blocked to you. For instance, some sites USE a cookie to keep you logged in between visits. This type of cookie just STORES information about your login here that is only accessible by this site and doesn't do anything else (e.g. it does not 'track' you or do anything else you wouldn't want it to do). If you block all cookies, you may not be able to stay logged in here between browser sessions. This applies to most other sites you log in to as well.

Time for some reading:

http://www.worldprivacyforum.org/cookieoptout.html

http://www.post-gazette.com/pg/05195/537851.stm
hey thanks alot for the info. As always you're welcome.
1223.

Solve : System Restore Won't Restore-Gamblock??

Answer»

I tried to run a System Restore to the  first night I got my new PC. It will not let me. Does anybody know if the program Gamblock prevents me from doing a System Restore? I installed the program July 1 but I want to go back to the first night I had my PC. I have " moonpie" and I wanted to see if a restore would help before I go nuk-u-ler! I will post my Hyjack log and any help would be greatly appreacted. You guys are great. I just want to restore my PC...I have not even had it a week!

Thanks, AnnaLogfile of HijackThis v1.99.1
Scan saved at 12:36:42 AM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

RUNNING processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\DISC\DISCover.exe
C:\Program Files\DISC\DiscUpdateMgr.exe
C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DISC\DiscGui.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\system32\lnxspt.exe
C:\windows\system32\winsys.win
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\Web\GamBlockUpdate.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\DISC\DiscStreamHub.exe
C:\HP\KBD\KBD.EXE
c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\HP_Administrator\Desktop\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AlwaysReady POWER Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [LSupport] c:\windows\system32\lnxspt.exe
O4 - HKLM\..\Run: [WinSys] c:\windows\system32\winsys.win
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Updates From HP.lnk = C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\biO15 - Trusted Zone: http://*.trymedia.com (HKLM)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1151697387190
O16 - DPF: {95B5D20C-BD31-4489-8ABF-F8C8BE748463} (ZPA_HRTZ Object) - http://zone.msn.com/bingame/zpagames/zpa_hrtz.cab40641.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeI can't help you with System Restore as that is a girls program but why do you believe you have moonpie?Spysweeper tells me I have "MOONPIE"
it removes it and then it comes back. I think it is picking up Gamblock program
falsly thinking it is Moonpie...I think Gamblock acts like a trojan right?It could be a false positive by Spysweeper, give Ewido a try.
http://[url]http://www.ewido.net/en/[/url]
Moonpie is classed as a remote access trojan or rat, Ewido is very good with trojans.By deleting
O4 - HKLM\..\Run: [LSupport] c:\windows\system32\lnxspt.exe
O4 - HKLM\..\Run: [WinSys] c:\windows\system32\winsys.win
this removed Gamblock and I am able to run restore. Now this brings up a lot of questions for me.
Firts off you don't want people with gambling problems to really know how to take the program off but again,
those lines I deleted wer epicked up by my Spysweeper as a trojan...and with this PC being new, that sort of pisses me off.

Ummmm
Hugsm AnnaGood for you, from what little I've Googled on Gamblock it's supposed to be quite hard to remove or even impossible if there is such a program.
Have you SINCE re-booted, maybe it will come back.fed why do u think system restore is a girls program?Because system restore is for people who have no idea about computers.
In fact system restore can also remove drivers & windows updates thus creating even more havoc for someone who already doesn't know what's going on.
I think the 'If something's wrong try System Restore' mentality is something Microsoft dreamed up as a 'fix anything button'.
Notice how Microsoft only included System Restore in the two girl OSs?
Just my thoughts on it, others will surely disagree. It is EASIER for the uninitiated to do. A real man reformats!  

(or USES a disk image previously saved.)i know how to reformat ive done it serval times myself
disk image??Instead of reinstalling Windows, the drivers, the updates, the programs, etc., which takes HOURS, you can get a full system restore in about 10 minutes. Use i tfor backups, storing an image of just the base system, or with everything loaded as you would have to do in case of a system crash:

http://www.acronis.com/homecomputing/products/trueimage/

Better than System Restore built into Windows by FAR as you can store this on a DVD, extra hard drive, etc.This is a pretty old thread, so you may never see this...  But why didn't you tell me about this Acronic True Image software back when I asked about making a "home-made" XP disk, GX-1?  Wouldn't this be the next best thing?

1224.

Solve : Another Help With Virus Removal?

Answer»

I swear I know this, but my brain has slowly been melting away into nothingness... Have been doing "hardware" work for the last three weeks (painting, floor refinishing, etc.), and so I can't even fathom the answers to the following simple questions.

I run AVG every day, and it always comes back clean.
I run Ad-Aware weekly, and Spybot S&D three times weekly.
I just ran Kaspersky, and it found 8 viruses, 13 infected objects, and three suspicious objects.

Some were in "c:\recycler\nprotect" - which I assume is the NOrton Protected RECYCLE Bin. I removed Norton, so I'm not sure why they're still around, but, anyway...

Most of them are "locked" and were "skipped".

So... What to do? Find them individually and delete them? What's cooking here?

Why am I so dumb all of a sudden?


Soon I will be singing "Bicycle Built for Two"...

Attached is the Kaspersky Report.

Thanks!Run ccleaner, empty the recycle bin, remove all traces of Norton. Be sure and check the web site for Symantec on how to adequately remove the Norton virus.

ccleaner.com

Do all scans in SAFE Mode with System Restore turned off.  AVG should also be set to scan all files which is NOT the default setting.YEAH, I HAD followed all the instructions for removing Norton - I think I SWAPPED the engine in a 64 Ford once in LESS time - which is what is so troubling about it STILL showing up.

And you'll notice some of the "suspicious" files were part of the ccleaner install... Weird.

It's OK, though. Last night while moving some boxes I tripped on the cord for that laptop and pulled it down off a four-foot shelf. The little plastic case that covers the processors popped off, the CD-ROM drive popped out, and, oh, yeah - it won't restart.

Gonna attack THAT in a little bit. I'm sure you'll see my "How do I fix THIS" posts on the hardware boards.

that sucks about your laptop. but i have had trouble like that, just it didnt bug me so much my external drive had some 600+ viruses and such it and the software i was using never picked it up i think all the difffrent software has diffrent classificatiosn of problems like whats supicous on one might be critical on another.I'll bet that external drive had lots of warez and other downloads. Am I right? Frequently those aren't found unless they are specifically unzipped and scanned. You have to point some scanners in the right direction as well, and keep them updated obviously. I have never heard of 600 viruses on any drive, so there was definitely something going on!rjbinney,

You will find a Norton removal tool below...

http://www.mrtech.com/news/messages/4767.html

patio.   8-)

1225.

Solve : Processor Peaks?

Answer»

After d/l Limewire my PC started freezing. I subsequently un-installed but still suffer the same problem.

Ran AVG and Spybot to no avail, reset to a date earlier than d/l, worked well for a little while then re-aserted itself.

Opening Task manager I can see regular peaks of full processor use.

I can obtain a hijackthis log if anyone feels able to assist

Thanks in advance.Any file sharing is a GREAT way to get malware. You are just the latest proof of that. Post it if you want, but you will be back for the same problem later, trust me.  Logfile of HijackThis v1.99.1
Scan saved at 8:20:27 PM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\KService\KService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Paul\My Documents\Downloads\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.bt.yahoo.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [pdfFactory Dispatcher v2] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe" /source=HKLM
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /BACKGROUND
O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Paul\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.toucansurf.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1144695114924
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
This appears clean to everyone then ? Leaves me with a re-install of windows I suppose.  The Hijack experts have not commented yet, but should be along soon. What is using the processor as shown in Task Manager?

Did you try Ewido? What is your antivirus? Did you run all scans in Safe Mode with SYSTEM Restore off?

A good format and reinstall does SOLVE most Windows problems, for a while anyway. Keep that possibility open. Do you have a real Windows CD?All in safe mode, cleared everything using ewido.

Anti-virus=AVG,
results Partition table(MBR)                             Reading error
          Boot sector of disc C:                          Reading error
          C:\WINDOWS\system32\shell32.dll          Change (another exactly the same OK)      

Nothing appears in taskmanager.

Have an original Windows disc.Dapablo ......  What are you using K service for ?

KService.exe  

--------------------------------------------------------------------------------
 
Description:
 KService.exe is background service for Kontiki P2P file sharing program. Whenever it is run, it will use your bandwidth to deliver shared media across the Internet.

I would be removing this .........
[highlight]C:\WINDOWS\kdx\KHost.exe [/highlight]

O4 - HKCU\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe -all

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe

You might also scan with Spybot ....... http://www.tucows.com/preview/310138
Make sure you update it after you install it ........


dl65  




1226.

Solve : Malware 'Spyware Remover'?

Answer»

this is really annoying me, it has changed my homepage to Malware.com or something

i have ran the seemingly useless NORTON Anti Virus 2006 and it could not find anything but when i RUN Windows Defender it finds the spyware attached to the file (as it keeps installing itself then uninstalling its self' but when i click remove, it says error occured, windows defender could not remove this virus

any help?Useless...... Quote

[highlight]this[/highlight] is really annoying me, it has changed my homepage to Malware.com or something  
  Could you please explain what "this is ?

Quote
i have ran the seemingly useless Norton Anti Virus 2006
...... Norton Anti Virus is designed to detect and remove viruses ....... and it does a decent job of that .

Please provide a wee bit more info and we can probably offer a POSSIBLE plan of attack to assist you .

dl65  

Run X-Cleaner, Ewido and then download HIJACK This and post you're logfile here so we can check it over and make SURE it's all good. Also make sure that you update ewido before running it and of course remove everything both X-Cleaner and Ewido find.dont forget to do the scans with ur system restore turned off and in safe mode
1227.

Solve : system32 startup?

Answer»

i had a virus not too LONG ago, and with all the problem (that were fixed) the SYSTEM32 still UPLOAD in startup.
i scan my coputer all the time. what do i do to fix it?

thanx!!I don't understand the problem. What does "the system32 still upload in startup" mean?it MEANS that whenever i start my computer, the flie:system32, is open.
how do i make it stop open in startup?Have a READ here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;170086

1228.

Solve : downloader?

Answer»

C:\WINDOWS\system32\dxt855.dll

norton can't repair it, quarantine it, or access it, and i can't delete it because its a SYSTEM file and "Access is denied"

norton reminds me with unending POPUPS that the file is infected with a downloader and i can't do anything about the virus, or the endless popup REMINDERS, when i click "ok" another one pops RIGHT back up, reminding me AGAIN that i have a downloader virus.

Help?GOOGLE for killbox.exe, so far we haven't found a file it can't delete.

1229.

Solve : Would a virus/worm/trojan horse cause this??

Answer» IVE been working a computer that is having some issues.
  
At first it was giving my niece this error in start up.  "Cant find system.ini. Need to run windows setup again to install the file. Press any key to continue." When any key is hit any and it shuts the computer off.   Never getting into windows98.    I realized I can hit f8 and it started into safe mode.  I ran scandisk.  Now when I shut it down and restarts, it makes me choose what mode I want to start it in.  It wont let me start in normal mode.  I just keep restarting it into safe mode.  

Not really sure what to do next to figure out what is WRONG with it.   Should I just reformate the hard drive. Really didnt want to do that.  Even if I did that if its a virus etc it may not get all of the infected stuff and it may have a reoccurance, right?  

Operating System:Microsoft Windows 98
Maker/Model: HP Pavilion
RAM: 56.0
Hard Drive: 10 gb I think
Anti-virus Agvest-anti virus and also norton 2005.  Agvest was just updated on 7-13 I believe.
Spyware and adware ran on 7-13  
disk frag ran last on 7-11
ScanDisk ran today.
 
Is this a possible virus or trojan horse causing issues?

The recover disk only gives me the option to reformat the hard drive. Im not ready to do that yet.  
Any other suggestions???Do you have the win 98 install disk? You just need to restore the system.ini file, like it says.
No, you shouldn't have to reformat, but reformating the hard disk would get rid of a virus, as well as everything else on your hard drive.

In safe mode run AVAST, and SEE if you find anything



ViperI would backup the data files and then reformat the drive and reload Windows WITHOUT hesitation. Usually agressive and non-thinking disk cleaning causes this rather than malware. What happened just prior to this?Read this article and see if the symptoms add up.  It may save a complete reformating of disk.

http://support.microsoft.com/kb/305671/en-us

From microsoft knowledge base.

Steeve
1230.

Solve : Exploit.MS05-002?

Answer»

Ugh.  

I just ran an AVG SCAN and it turns out I have alot of viruses, although it appears to be the same one (Exploit.MS05-002) listed many times. It was found in my temporary internet files.

Any help?


Remove them. All of them. Do this is Safe Mode with System Restore turned off.  Download Cleanup, INSTALL it then boot into safe mode and run it there. If they're just in the TEMP folder it'll TAKE care of them with no problem. Run AVG afterwards, might wanna pick up Ewido too just in case. Make sure you update before going to safe mode.

1231.

Solve : digvag.dll?

Answer»

I GOT a dll file CALLED digvag.dll and its cuasing me all kinds of mischeif any clue how to GET rid of it?....I've tried everything.How do you know that is the culprit and what is it doing?

Killbox will remove it.

http://www.bleepingcomputer.com/files/killbox.phpyour amazing man, thx for that, my 2 anti virus soft ware kept saying that was the file.  Nortons called it a downloader, it kept creating pop ups.  thanks a million, for that programGlad you are all fixed up.  Killbox? not bad. I do it the old fashion way and delete all keys with it's name. Dangerous, immature, and LUCK.....but it works.

1232.

Solve : Firewalling myself in? All of a sudden...?

Answer»

All of a sudden my Outlook Express can't send messages. I didn't intentionally change any settings.

I use OE 6 with AOL (IMAP, not POP3).

I have discovered that if I turn OFF my firewall (Kerio Personal 2.1.5), the outgoing message GOES through.

This has only started happening in the last 24 hours.

I get the Socket Error 10053 and other error number 0x800CCC0F. Googling that points me to my AV (AVG), but turning Kerio on and off seems to be what gets results. Turning AVG on and off doesn't seem to make a difference.

I have Outlook Express configured in KPF to any protocol, any port, any direction...

System Restore hasn't helped, either.

What's gigging?

what spyware and av do u have??

reply and ill try to help

and some specs on your machine os??unlovedwarrior.....  LOL , please read the post before you start asking questions ........ The poster is using AVG as anti virus and Kerio Personal 2.1.5 as the firewall .  

His issue appears to be with the firewall SETUP ........ outgoing messages are  being blocked .


dl65  
i did read it but i was on my work phone listen to music and iming ppl..

lol

so he just needs to go into the configureation, go to outbond and make outlook unblocked...

or something on those LINES i never used that firewall before.
i use zonealarmRight... But here's the confounding part:

Quote

I have Outlook Express configured in KPF to any protocol, any port, any direction...
So, outbound, inbound, all about the town... It's all allowed. (And MSIMN.EXE, too).

Thinking somehow that had been corrupted, I deleted OE from KPF so it would "catch" it next time it ran and allow me to reconfigure... It did, and it's "allowed"... But it's not happening.
 rjbinney.....  Have you tried uninstalling Kerio and reinstalling it just to be certain the issue isn't with it ?
Another thought , did you get any updates from M/S just before the issue showed up ?

dl65 Quote
Have you tried uninstalling Kerio and reinstalling it just to be certain the issue isn't with it ?
Thought about it, but thought I would do that as a last resort... You know, having to retrain it for everything is gonna be a pain (not as much as not sending mail, but still...)


Quote
Another thought , did you get any updates from M/S just before the issue showed up ?
I DID. But I also used System Restore to roll back past them to see if that would help, and it didn't. I may try rolling back farther?

It's also been suggested that I allow KPF to use Port 587 (the AOL outgoing port) for ALL applications - that it may be confused about where the request hails.

I can't quite figure out how to do that.

I haven't done a reinstall yet, waiting to get Who tickets online - can't jeopardize fouling up the machine!The Who is far more important than configuring a firewall... Tenth row, opening night.


Anyway, the problem seemed to go away for awhile - apparrently on its own as it didn't line up with any of my attempted fixes.

Then it came back.

So I uninstalled KPF (which I really did like) and installed Zone Alarm's free version. So far so good. We'll see...

Thanks all for the help.
1233.

Solve : AVG Free version- set up?

Answer»

Hi everyone,
I am using AVG free VERSION on my home computer and keeping it up to date regularly. I remember reading on the forum a post on how to set up the AVG free version to scan incoming e-mails and out GOING e-mails. But can't seem to locate the post can any one give me the link to that post or some fresh advice will also be appreciated.
That is the default behavior. You can just uninstall it, reboot and install again.
From looking at my copy, what you can do is LAUNCH the Control Center (right-click on the tray icon and select "Launch AVG Control Center").

One of the main options  - in the blocks across your screen - should be "Email SCANNER". It should say "Email scanner is fully functional" at the bottom of the block.

Double-click on that.

From there, you can choose all your different options (in "Configure" and "Properties", natch).

Make sure the "Disable Plug-In" BUTTON (lower right hand of main Email scanner screen) is not grayed out.

1234.

Solve : "Instant Update Reminder"--is this a bug??

Answer»

in response to dl65's email of 6/25 at 7:57 pm:  how can i FIND the url of my home page? thanks dededl65:  one other thing, i use a dial up service from peoplepc but you flagged 2 of their programs for removal.  won't that affect my dial up service?  thanks, dedecan anyone help me w/ the 2 messages I posted on July 3rd?  here they are:

dl65:  one other thing, i use a dial up service from peoplepc but you flagged 2 of their programs for removal.  won't that affect my dial up service?  thanks, dede

in response to dl65's email of 6/25 at 7:57 pm:  how can i find the url of my home page? thanks dede Quote

I highly recommend ewido, great program, very easy to use, completely FREE.
At Major Geeks, CNet, and its own site, it's all 29.95. Is there a free version that I just ain't finding?Free to try, $29.95 to buy. I think it continues to be functional but you would no doubt want to send them some CASH for a good product.Theres 2 Versions of Ewidow now, if you go on to the Girsoft site YOULL see there with AVG Free and Ewido Free

http://free.grisoft.com/doc/1
1235.

Solve : WATCH YOUR INBOX!?

Answer»

Theres another virus going around about Microsoft Updates.

"Microsoft Client

this is the latest version of security update, the "July 2006, Cumulative Patch" update which resolves all known security vulnerabilities affecting MS Internet Explorer, MS Outlook and MS Outlook Express as well as three new vulnerabilities. INSTALL now to continue keeping your computer secure. This update includes the functionality of all previously released patches. "

Heres the message info below:
X-Message-Status: n:0
X-SID-Result: Fail
X-Message-Info: txF49lGdW430dgZ6841w5WSgEOn9tsWccQWVslh 8bJ0=
Received: from smtp.guitar.ocn.ne.jp ([61.207.12.174]) by bay0-mc3-f5.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);
       Tue, 18 Jul 2006 20:59:16 -0700
Received: from hahc (p4253-ipad12fukuokachu.fukuoka.ocn.ne.jp [219.162.113.253])
      by smtp.guitar.ocn.ne.jp (Postfix) with SMTP
      id 4967247F3; Wed, 19 Jul 2006 12:59:07 +0900 (JST)
From: "MS Public Assistance" <>
To: "Client" <[email protected]_msn.com>
SUBJECT: New Security Patch
Mime-Version: 1.0
Content-TYPE: multipart/mixed; boundary="atvzddwlqtjwuu"
Message-Id: <[email protected]>
Date: Wed, 19 Jul 2006 12:59:07 +0900 (JST)
Return-Path: [email protected]
X-OriginalArrivalTime: 19 Jul 2006 03:59:17.0153 (UTC) FILETIME=[B4A53110:01C6AAE7]


Hey... I got that, but most things I get from micrsoft, I just delete anyway. Good thing I don't like microsoft   Quote

Hey... I got that, but most things I get from micrsoft, I just delete anyway. Good thing I don't like microsoft  
Lucky for Microsoft, it wasn't send by Microsoft.
I just noticed your new avatar! I just started watching those Internet cartoons!
Pretty cool.
The point was, it said microsoft, so it had to go
I love the foamy vidoes, it's too bad I have dial-up, that connects at 19.2kps

But anyway, what type of virus is it, jst a worm or something? Quote
The point was, it said microsoft, so it had to go
I love the foamy vidoes, it's too bad I have dial-up, that connects at 19.2kps

But anyway, what type of virus is it, jst a worm or something?

I am not sure. My AV scanner didn't DETECT the attachment, more likely for one or two reasons. Its probably a new virus, and it was not downloaded, yet.

There's another email going around, unfortunately, each time I open it, it downloads a new piece of SPYWARE to my system. I should probably scan right now, actually.

This is better than the time when I had 19+ virus emails...and look who stepped in the danger zone!
the other message going around goes as follows:

Quote
Hi.
I'm afraid I wasn't able to deliver your message to the following addresses:



Undeliverable mail to [email protected]


Message follows:

X-Message-Status: n:0
X-SID-Result: Fail
X-Message-Info: txF49lGdW43oykKuaerLnns8T7tMHlwfQhp75+qy4OY=
Received: from smtp.guitar.ocn.ne.jp ([61.207.12.174]) by bay0-mc9-f9.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.2444);
       Tue, 18 Jul 2006 21:33:12 -0700
Received: from jgac (p4253-ipad12fukuokachu.fukuoka.ocn.ne.jp [219.162.113.253])
      by smtp.guitar.ocn.ne.jp (Postfix) with SMTP
      id 3E447448D; Wed, 19 Jul 2006 13:33:08 +0900 (JST)
From: "" <>
To: " " <[email protected]>
SUBJECT: Undeliverable Message
Mime-Version: 1.0
Content-Type: multipart/alternative;
      boundary="czxszysfe"
Message-Id: <[email protected]>
Date: Wed, 19 Jul 2006 13:33:08 +0900 (JST)
Return-Path: [email protected]
X-OriginalArrivalTime: 19 Jul 2006 04:33:13.0079 (UTC) FILETIME=[7226D870:01C6AAEC]

With attachment name:
ameyzi.exe

and the Microsoft email attachment was titled:
installer664.exe

They're fake senders, unfortunately, so a WHOIS on their IP came up empty. :-/There's a bunch of these going around now!
(I usually get targeted for virus spam) (and spam in general)
I once got over 20 virus emails. My step dad was enthusiastic....

This forum is going slow again. Its getting boring. All this heat wave crap has everyone away from their computers, right?
That's probably what happened to the admin...

And now I am installing MSN Messenger on my step dads computer, hoping he never finds out...

Just LET me get Internet in my room, and it will be all better...thats when u bust out the linux and laugh at the window users unfortunetly im a windows users a work and at home on the family computer
1236.

Solve : I get Virus Alert - maybe Spyquake installed??

Answer»

Re: I have Windows 98, Norton AV program, Zonealarm, (free verson)  ADAWARE, Search and Destroy and Hijackthis

All of a sudde my taskbar has been switched to the top.  In the taskbar, I have  this green circle with a ? in it and then it changes to red with a diagonal line thru it yellow triangle with an ! in it and it continues to blinks and then an irritating yellow box pops up with System Alert: Adware and Spyware and to run a spyware scan to find out the reason, etc. , a red and gray box keeps popping up saying my computer is infected.  Critical System Error,  that detected a virus.   When I click on the icon, it runs a scan and says I have 48 high level risks, etc. and to click here to purchase Spywarequake or something.
 I have run Adaware, Search and Destroy. "Windows Security Center" detected active threats on PC, Security software unable to delete  To clean and block all adware/spyware, you need to download and install ONE of the certified intrusion detection SYSTEMS: System Doctor, Ad Protect, Virus Blast.  
    After I run Adaware and clear things out, Search and Destroy says its clean.  But obviously it's not.  Someone  said I have Spyquake Have a look at the Instant Update Reminder Topic , i think you MIGHT have a similar PROBLEM

1237.

Solve : Disable Norton Protection Center Check?

Answer»

I have Norton SYSTEMWORKS 2006 basic running on a PIII with Win XP Home, 512mb with 80 G &AMP; 40G HDDS.  At bootup, the Norton Protection Center checks all INSTALLED programs.  This delays the completion of bootup.  How can I disable the installed program CHECK without affecting the AntiVirus check at bootup?Is there a manual on the install CD?

1238.

Solve : help required for malware/ highjackthis log?

Answer»

Hello there,

pchelpforum being momentarily shut down and I needing some help, here I am.


I've got some malware CONTAMINATING my pc, I've scanned my pc with ewido but the scan didn't finish, it did suppress about 14 viruses THOUGH.
I here post the log of that aformentionned scan and my latest hijackthis one.

Looking forward to your replies and thanks in advance

yulneversolvethisone.....  Well ...... apart from several 023 enties with files missing ..... there is nothing in your log that appears to be the issue .
However , I dont see any anti virus program installed or running  ........ what are you using for your virus protection .Did you TURN off system restore before running the scans ?
Did you run the scans from the "SAFE" mode ?

dl65  I have bitdefender 9 installed and running.

I ran all the scans in safe mode with sys. restore disabled.

I did a scan with bitdefender and ewido today and they both found trojan.fakealert and trojan.small repectively which are both the same trojan.

My pc is now working pretty well but i've still got this trojan that nothing seems to be able tu suppress.

thanks againEwido is for trojans.

http://www.ewido.net/en/How do you know you still have a trojan?
What is it called?well I know because bitdefender and ewido told me so: the name is trojan.small ALIAS trojan.fakealert

Thx again for your helptrojan.fakealert .........This may be someones idea of a practical joke .........
http://vil.nai.com/vil/content/v_138763.htm


dl65  Do any of the SCANNERS give you a location of the trojan, if not try the Panda online scan.
Online Virus Scan and Spyware Scan
http://www.pandasoftware.com/products/activescan.htm

1239.

Solve : What is pup?

Answer»

What is pup and how do I know if I can TRUST it?
MCAFEE sometimes shows it has found a pup and ASKS if I trust it or not
How do I know?
Any help would be grateful  
Here's a CUTE one for you:


 


Seriously, PUP stands for Potentially Unwanted Program.  Does McAfee identify it by a specific name?  If so, I'd Google that name.  It may be spyware.  Does McAfee give the option of removing it?  Are you using any of the POPULAR spyware removal tools such as Spybot Search & Destroy?

1240.

Solve : Att: CH Authorized Malware Removal Specialists - details and all logs included?

Answer»

Got siteadvisor and can't uninstall AVG TOOLBAR. Have been to the AVG SITE, have searched on how to, the only option it allows in the add-ons management is 'disable'. This is ONE reason I don't like AVG or any program/company that doesn't provide for an easy uninstall. WHat security do you use EF?PERSONALLY I prefer using Avast.

1241.

Solve : games and malware?

Answer»

How likely is it to pick up malware from the Yahoo GAMES free downloads and other free download game PLACES?  I'd APPRECIATE any other advice on  safely getting games.  Where to GET them.   Thx!Yahoo Games is Safe.

Other websites, can't tell without knowing what download/game sites you're going to.

1242.

Solve : daemon hot key,is it bad??

Answer»

found this in stratup list,googled it seems bad,how to get rid of it?  also tried to post log from hijack this but wont let me post log!!!   thanks for your help.log, thanksRunning processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and SETTINGS\robert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\robert\My Documents\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,PROXYSERVER = 117.104.7.10:8080
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /StartUp
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKCU\..\Run: [nodenable] C:\Program Files\eset\nodenable.exe /s
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\robert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B1AFE17-8A7B-4A48-B7E1-42B4CF8CB243}: NameServer = 207.69.188.185,207.69.188.186
O20 - AppInit_DLLs:  C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
END of file - 4186 bytes
So can you directly state the question? I'm not getting this.never mind ill figure it out!  thanks anyway!!!If you haven't figured it out, I've done some research:

I googled it and found this: Hot Key Keybd Daemon. It's basically a keyboard program (From your keyboard software) that's used to detect when a custom button is pressed on your keyboard.

If you want to remove the startup entry download This.
Be careful when editing startup entries as this may damage your computer.

1243.

Solve : Best viruses protection?

Answer»

I am looking for new viruses protection for four computers. I am using Windows Love One now. I just had to reload every thing on my wife's computer because of a viruses. I have used Norton in the past. It didn't work to well. In one year I got three bugs while it was protecting a computer. It is also very annoying.What do you use or THINK is a good one?Throw all your other software out and the window and DOWNLOAD, Avast 4.7.
You can't go wrong, I have had avast for ages now, and it has prevented some many infections i have lost count.

Do yourself and your computer a favor and install Avast.

You can find it here, <affiliate links REMOVED> http://www.avast.com/eng/avast_4_home.html

It's totally free, and there is no scamming crap.
I have that on my old lap top and I have had no problems. Then I don't get on the net with that computer much. Some one on this site recamended it for use with Windows ME because I couldn't find one for ME. It seems today every thing is set up for XP and Vista. Thank you very much for your time and the site.

1244.

Solve : Slow Starting of Each New Program After Boot?

Answer»

After the Windows XP SP3 machine boots, each time a new program is opened, a long delay is experienced before the program starts.  For example, Outlook takes 30+ seconds to start and the volume adjustment control takes 25+ seconds to start.

Once started, the programs can be reopened with normal delay for a period of time.  When computer sits idle for a long period, programs again take a long time to start.

Disk defragmented
Latest Microsoft patches installed
Many unused programs removed
Symantec antivirus - full scan run no issues
Superantispy - no issues except tracking cookies
Malwarebytes - no issues  (trojan vundo removed two weeks ago)
Spybot - run
Ad-aware  - run
Java Updated

Hijacklog file included.

Another item that may be significant, during a reboot icons on desktop appear normally, but during the completion of boot, the desktop returns to 800*600 resolution.  Can then be reset to its normal 1600-1200 resolution manually.

Any help will be appreciate
Bill
-------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:58:24 PM, on 10/24/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Comodo\CBOClean\BOCORE.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\UPSMON\UPSMON.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\VMWARE\VMware Workstation\vmware-tray.exe
C:\WINDOWS\V0230Mon.exe
C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\UPSMON\UPSInt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: ClickCatcher MSIE handler - {16664845-0E00-11D2-8059-000000000000} - C:\Program Files\Common Files\ReGet Shared\Catcher.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {6FB13DD6-4650-4556-AE18-27142F0B5C9F} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java(TM) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\Program Files\ReGetDx\iebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UPSMON] C:\Program Files\UPSMON\UPSMON.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\V0230Mon.exe
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized
O4 - HKLM\..\Run: [BOC-427] C:\PROGRA~1\Comodo\CBOClean\BOC427.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAID Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to R&estricted Zone - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra 'Tools' menuitem: Add to Tr&usted Zone - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - C:\WINDOWS\system32\webzone.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Offline - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - C:\WINDOWS\system32\oline.dll
O9 - Extra button: Favorites Search - {FF925300-80E6-11D4-A15B-FFF9086C1A3C} - C:\PROGRA~1\DzSoft\FAVORI~1\FavSeek.dll
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - http://download.autodesk.com/esd/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: tuvWNGWO - tuvWNGWO.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVP - Unknown owner - C:\temp3\avtemp\avp.exe (file missing)
O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Symantec Network DRIVERS Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 13415 bytes
You have way too many security programs installed.

Uninstall:

  • Zone Alarm
  • Adaware
    • BOClean
    .
    ----------

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    - O2 - BHO: (no name) - {6FB13DD6-4650-4556-AE18-27142F0B5C9F} - (no file)
    - O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    - O20 - Winlogon Notify: tuvWNGWO - tuvWNGWO.dll (file missing)


    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis.

    Run CCleaner and restart the computer.

    ----------

    Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note:  It is important that it is saved directly to your Desktop

    Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
     
    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
Instructions completed, Hijackthis log attached.  Combofix, second log in next post.

Many of the programs seem to have returned to normal open speeds.  Will continue to verify.
The boot problem with screen resolution switching to low resolution remains.

Whoward

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:44:18 PM, on 10/25/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\UPSMON\UPSMON_Service.Exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\Program Files\UPSMON\UPSInt.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\UPSMON\UPSMON.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\SYMANT~1\vptray.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
C:\WINDOWS\V0230Mon.exe
C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: ClickCatcher MSIE handler - {16664845-0E00-11D2-8059-000000000000} - C:\Program Files\Common Files\ReGet Shared\Catcher.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: ReGet Bar - {17939A30-18E2-471E-9D3A-56DD725F1215} - C:\Program Files\ReGetDx\iebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UPSMON] C:\Program Files\UPSMON\UPSMON.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [vmware-tray] C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\V0230Mon.exe
O4 - HKLM\..\Run: [LELA] "C:\Program Files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: RAID Manager.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - (no file)
O9 - Extra button: Favorites Search - {FF925300-80E6-11D4-A15B-FFF9086C1A3C} - C:\PROGRA~1\DzSoft\FAVORI~1\FavSeek.dll
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - http://download.autodesk.com/esd/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVP - Unknown owner - C:\temp3\avtemp\avp.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\hpbpro.exe
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\hpboid.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\WINDOWS\system32\nvsvc32.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: UPSMONService - Unknown owner - C:\Program Files\UPSMON\UPSMON_Service.Exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe

--
End of file - 11668 bytes

----------------------------
ComboFix log?The requested Combofix log included.

Whoward

[Saving space - attachment deleted by admin]Run this online scan.

This scanner requires Internet Explorer

Use the ESET Nod32 Online Scanner

1. Check the box next to YES, I accept the Terms of Use.
2. Click Start
3. When asked, allow the activex control to install
4. Click Start
5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked.
6. Click Scan
7. Wait for the scan to finish
8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here are results of the scan.


Whoward
----------------------------------------------------------
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3557 (20081026)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=30f0ffe08120ed4da5bd1db1d488d48a
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2008-10-27 03:26:09
# local_time=2008-10-26 11:26:09 (-0500, Eastern Daylight Time)
# COUNTRY="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=676390
# found=1
# scan_time=13312
C:\Downloads\test35\The_Ultimate_Troubleshooter\_The_Ultimate_Troubleshooter_v4.45.rar   probably unknown NewHeur_PE virus (deleted)   00000000000000000000000000000000
How is the computer running now?In general, the program is running very well.  The slow starting of programs has been fixed.  A great big thanks to Evilfantasy.

The problem of switching to low resolution at about 80% into the boot process still occurs.

WhowardI'm not sure what to think about the low resolution. You might want to start a new topic in the Windows forum about that.

Final steps.

  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok, concider this item closed.

    Thanks very much for your assiatance.
    1245.

    Solve : I am going to reinstall OS tomorrow;best way to protect my system??

    Answer»

    I am going to reinstall OS tomorrow after facing many problems with malware and virus issues with internet  ( Files are downloading automatically without my concern )

    So, I REQUEST you to suggest steps I have to follow before installing and immediately after installing the OS .

    ( Best antivirus, best firewall,best adware..........etc )

    You can suggest me anything to get rid of these malware issues.
    You can use Windows Firewall if you are USING XP SP2 or higher.

    The first thing you do:
    INSTALL An Antivirus program.
    Either Avast (www.avast.com , my personal favorite)
    Or AVG (http://free.avg.com/)
    You might also grab AVG Antispyware as well

    Second thing:
    Run Windows Update! Set Automatic Updates up as well, your COMPUTER should at some point prompt you with an ADVANCED Windows Update setup, make sure Updates install at a time when your computer is usually on.

    Third Thing:
    Your system, at this point, should be protected to a descent point.
    1246.

    Solve : Threat Protection?

    Answer»

    Tell me that which is the best?Not SURE what may be the best, but there have been a lot of reviews and tests.

    For example:
    http://tech.yahoo.com/blog/null/5244
    http://news.helpero.com/article/The-best-free-antivirus-is_11.html

    http://www.google.com.hk/search?hl=en&q=top+antiviruses&btnG=Google+Search&meta=&aq=f&oq=top+antivirusebullguard is great  is  it not on the list  I've heard from a lot of people that Avira Antivirus is good. Quote

    bullguard is great   is  it not on the list   
    Blackrainbow! Are you HAPPY now?
    very thanks  Norton for me is the best.. Good anti-virus indeed. Quote from: kianaruiz on November 11, 2008, 03:01:24 AM
    Norton for me is the best.. Good anti-virus indeed.
    Many, many many many people will disagree with you here....

    Norton pretty much LOST it since Norton 2003 Antivirus.
    1247.

    Solve : computer infectd here are the logs requested?

    Answer»

    Hello. I am SuperDave's teacher for malware removal.

    These in the ComboFix log show major SYSTEM file infections (you are lucky your computer boots right now):

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    -- Previous Run --

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    -- Previous Run --

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    -- Previous Run --

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    -- Previous Run --

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    -- Previous Run --

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    --------

    c:\windows\system32\userinit.exe . . . is infected!!

    c:\windows\system32\lsass.exe . . . is infected!!

    c:\windows\system32\svchost.exe . . . is infected!!

    c:\windows\system32\spoolsv.exe . . . is infected!!

    c:\windows\explorer.exe . . . is infected!!

    ===================================

    This in the ComboFix log also shows Virut infection:

    ------- Sigcheck -------

    [-] 2009-09-26 . 4DA2350BD3A2A4CADADF36CA84D25636 . 30208 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\lsass.exe
    [-] 2009-09-26 . 36F24DCCBDCDFC9E6E09263841218A6D . 30208 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\lsass.exe
    [-] 2009-09-26 . 36F24DCCBDCDFC9E6E09263841218A6D . 30208 . . [5.1.2600.5512] . . c:\windows\system32\lsass.exe

    [-] 2009-09-26 . 5543AE20C2B5A3F38EE987AE4CFAC169 . 75264 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\spoolsv.exe
    [-] 2009-09-26 . 5543AE20C2B5A3F38EE987AE4CFAC169 . 75264 . . [5.1.2600.5512] . . c:\windows\system32\spoolsv.exe
    [-] 2004-08-04 . 6C181FDA12BBF882019ADB003325A53C . 57856 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\spoolsv.exe

    [-] 2009-09-26 . 83D9FBF4BDFB6B09A80482159B9E24D5 . 519168 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
    [-] 2009-09-26 . 206316CBFC51823A24F720CB20C4540A . 524800 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\winlogon.exe
    [-] 2009-09-26 . 206316CBFC51823A24F720CB20C4540A . 524800 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

    [-] 2009-09-26 . 870CDD8B38CE6EF9B87166A497CA8653 . 31232 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\svchost.exe
    [-] 2009-09-26 . 507D0252EC8ECC0EB99BD33B9600C556 . 31232 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\svchost.exe
    [-] 2009-09-26 . 507D0252EC8ECC0EB99BD33B9600C556 . 31232 . . [5.1.2600.5512] . . c:\windows\system32\svchost.exe

    [-] 2009-09-26 . 4B7E7EC46DE485912CA0CC98F85B1761 . 43008 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\userinit.exe
    [-] 2009-09-26 . 4B7E7EC46DE485912CA0CC98F85B1761 . 43008 . . [5.1.2600.5512] . . c:\windows\system32\userinit.exe

    [-] 2009-09-26 . 8AECD40E1311BBAC619C88DF7F85C06A . 1033728 . . [6.00.2900.5512] . . c:\windows\explorer.exe
    [-] 2009-09-26 . 8AECD40E1311BBAC619C88DF7F85C06A . 1033728 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\explorer.exe
    [-] 2004-08-04 . 143BE67A0947BF55E53A831337AD4747 . 1032192 . . [6.00.2900.2180] . . c:\windows\$NtServicePackUninstall$\explorer.exe

    [-] 2009-09-26 . A9E91CFB9C428BA941E440CC231C1638 . 30720 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\wscntfy.exe
    [-] 2009-09-26 . A9E91CFB9C428BA941E440CC231C1638 . 30720 . . [5.1.2600.5512] . . c:\windows\system32\wscntfy.exe
    [-] 2004-08-04 . 05BC6D5C48C87F8143A3DC2386D0F5FE . 13824 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\wscntfy.exe

    [-] 2009-09-26 . E7F92CD27E2AA05071924369743E563D . 32768 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
    [-] 2009-09-26 . E7F92CD27E2AA05071924369743E563D . 32768 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
    [-] 2004-08-04 . 8A609F260EBBB6CAC35DA8F0121C6B25 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe

    ============================================

    So, either follow my advice here, or just ignore it. If you ignore it, your computer will probably not work in the future, until someone fixes it.

    If we try to fix the computer, the system files will still be damaged, and you will get tons of system errors, which will lead to your computer eventually not booting anymore.

    Thanks!I am in complete agreement with DragonMaster Jay. If your computer is still running, you should take this opportunity to back-up your important files before re-formatting. I've have included some important information about this below.

    Backing up files before formatting

    If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

    Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

    I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.
     
    -) Dr.Web CureIt!
    -) AVG Win32/Virut Removal Tool
    -) Symantwc W32.Virut Removal Tool
    -) McAfee Avert Stinger
    -) Microsoft Windows Malicious Software Removal Tool

    If you do not know how to perform a fresh install, use this website -> www.windowsreinstall.com/

    Very important, do the following immediately or as soon as possible!

    If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.
     
    From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or GROUPS you belong to etc.

    DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.
    ============================
    Here's some additional information which will be useful after you reformat.

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before IMMUNIZING. Spybot - Search & Destroy FAQ

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

    Remember only install ONE firewall

    1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
    2) Online Armor
    3) Agnitum Outpost
    4) PC Tools Firewall Plus

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. SIMPLY put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

    1248.

    Solve : Can a virus(or similar) lead to BSODs??

    Answer»

    Hi,

    Im not sure if any one can help but I would really appreciate it if they can.

    I have searched forums all over the place inc here but not had much luck finding answers.
    A while ago my desktop started acting funny.

    First some basic info, RUNNING vista home ultimate 64, tried to keep os and antivirus updated, Hardware is MSI p7n2 mobo, intel Q9550, 280GTX, 4x2gb CORSAIR DD3 ram, 2x500gb hdd + keyboards/mice/headphones. +antec 900 case, gigabyte 720 watt psu.

    First off it would freeze randomly, when under load and when nothing was running, this would occur both after hours of running and within minutes after of booting up from cold.

    A little while after that as the computer was booting up and during the windows welcome screen only part of the image would display, with areas of black sometimes in bands running horizontally across the screen.
    About this time I also started getting numerous BSODs, some of which were IRQ_NOT_LESS_OR_EQUAL_TO and somthing about a process timed out on secondary processor. there were others but I cont remember what they were.

    The computer used to run most things but it was PRETTY unstable, AVG would crash at start up, firefox, MS office, Archicad, Photoshop would randomly and frequently crash. Some games mostly RTS (dawn of war + similar) would sometimes run but FPS (UT3, ARMA2, Fallout3) would crash as they started up. Strangley ANNO 1404 would run fine.

    I tried backing everything up to external HDDs and reinstalling vista, using this to reformat the HDDs but didnt improve. installed UT3 again and had same issues.

    Computer is now at a repair shop and they have tried some diagnostics but have been unable to replicate the issues, except for UT3 crash! They cant decide if it is hardware or software related.

    Anyway the reason I was WONDERING if this may be a virus is that I am experiencing similar (not identical) simptoms on a laptop that has been plugged into the External HDD, also have now had 2 BSODs. This has been scanned with several antivirus softwares and nothing found tho. Sometimes when starting the laptop will display a black screen after the welcome screen. This lasts for about 10 seconds, but once or twice has not gone and I have had to reboot.

    Any ideas would be great now what might be going on and if it is possible that the laptop has the same issues. Sorry for the length of the post, but its better to be descriptive.


    Again thanks for reading all this and for any help anyone can provide.
    Mykl.Anyone have any ideas? 

    Its still at the shop and they still cant figure it out.

    Im going to go and get it tmw and have another try myself, then maybe take it some where else.

    Thanks in advance,
    Mykl.If you re-formatted the HDD I hardly think that the problem is malware. Re-format starts you out with a clean slate.Thanks Dave,

    That's what I thought but didn't know if there was a way to hide a virus somewhere so it did not get erased.

    I heard from the shop about 2 hours after I posted this. Definitely the mobo they say. I spoke to MSI (Australia) and they said they will fix it under warranty, but I need to pay to get it out and ship it to them. Going to cost about $80. cheaper than I was expecting.

    Does anyone know a good cause for mobos to fail?

    That is the third one that has failed in about a year in different computers at my house. One computer repairer said that it may be to do with minute fluctuations and brownouts from our electricity supplier. Does this sound feasible?

    Thanks again.
    Mykl. Quote from: Mykl on March 12, 2010, 12:17:05 AM

    Hi,

    Im not sure if any one can help but I would really appreciate it if they can.

    I have searched forums all over the place inc here but not had much luck finding answers.
    A while ago my desktop started acting funny.

    First some basic info, running vista home ultimate 64, tried to keep os and antivirus updated, Hardware is MSI p7n2 mobo, intel q9550, 280GTX, 4x2gb Corsair DD3 ram, 2x500gb hdd + keyboards/mice/headphones. +antec 900 case, gigabyte 720 watt psu.

    First off it would freeze randomly, when under load and when nothing was running, this would occur both after hours of running and within minutes after of booting up from cold.

    A little while after that as the computer was booting up and during the windows welcome screen only part of the image would display, with areas of black sometimes in bands running horizontally across the screen.
    About this time I also started getting numerous BSODs, some of which were IRQ_NOT_LESS_OR_EQUAL_TO and somthing about a process timed out on secondary processor. there were others but I cont remember what they were.

    The computer used to run most things but it was pretty unstable, AVG would crash at start up, firefox, MS office, Archicad, Photoshop would randomly and frequently crash. Some games mostly RTS (dawn of war + similar) would sometimes run but FPS (UT3, ARMA2, Fallout3) would crash as they started up. Strangley ANNO 1404 would run fine.

    I tried backing everything up to external HDDs and reinstalling vista, using this to reformat the HDDs but didnt improve. installed UT3 again and had same issues.

    Computer is now at a repair shop and they have tried some diagnostics but have been unable to replicate the issues, except for UT3 crash! They cant decide if it is hardware or software related.

    Anyway the reason I was wondering if this may be a virus is that I am experiencing similar (not identical) simptoms on a laptop that has been plugged into the External HDD, also have now had 2 BSODs. This has been scanned with several antivirus softwares and nothing found tho. Sometimes when starting the laptop will display a black screen after the welcome screen. This lasts for about 10 seconds, but once or twice has not gone and I have had to reboot.

    Any ideas would be great now what might be going on and if it is possible that the laptop has the same issues. Sorry for the length of the post, but its better to be descriptive.


    Again thanks for reading all this and for any help anyone can provide.
    Mykl.
    take out wires out of your case and then clean it and reconnect it properly. Take out your ram and clean it, take out your SMPS connections from MOBO then reattach it.
    Moreover, if this doesn't help reinstall your OS and install Avast Pro.
    1249.

    Solve : my pc does not start up...?

    Answer»

    i want to start up my PC and then i see a flash of a blue screen like bios or something and then then my pc is restarting again over and over again1) It's not the bios you see
    2) Did this just start? If so, what happened between the last time the system started normally and the first time it did not (new hw, sw, virus, error, etc)?
    3) Why are you POSTING in the virus section - do you think it is malware? If so, why?
    4) What OS?
    5) At EXACTLY what POINT do yo see the blue screen flash?i saw a virus error of a trojan  my os is winXP the blue screen is a with lot of codes like this  0x00453001 in a flashWhat do you mean you "saw a virus error of a trojan"? If you want HELP, start providing details. Quote from: Allan on March 22, 2010, 10:11:23 AM

    1) It's not the bios you see
    2) Did this just start? If so, what happened between the last time the system started normally and the first time it did not (new hw, sw, virus, error, etc)?
    3) Why are you posting in the virus section - do you think it is malware? If so, why?
    4) What OS?
    5) At EXACTLY what point do yo see the blue screen flash?

    1) i know but i mean a  screen like bios or something...
    2) 1.i just STARTS my pc and i see the bsod(blue screen of death) before this i had 1 trojan
    3) yes i think
    4) XP
    5) before you log in

    please somebody help !!!!!!!!!!!!!!!
    1250.

    Solve : "Your computer is infected" warning?

    Answer»

    Great Dragon master, bit late now, i'll do this tomorrow and post back......
    ThanksOkey dokey. Quote from: DragonMaster Jay on March 01, 2010, 10:31:50 PM

    Okey dokey.

    OK, DragonMaster, here is the checkup log

     Results of screen317's Security Check version 0.99.1    
     Windows 7  (UAC is enabled)
    ``````````````````````````````
    Antivirus/Firewall Check:

     Windows Firewall Enabled! 
     avast! Free Antivirus   
     WMIC entry does not exist for antivirus; attempting automatic update.
    ``````````````````````````````
    Anti-malware/Other Utilities Check:

     WinPatrol 2009
     SpywareBlaster 4.2   
     CCleaner     
     Java(TM) 6 Update 14 
     Out of date Java installed!
     Adobe Flash Player 10 
    Adobe Reader 9.1
    ``````````````````````````````
    Process Check: 
    objlist.exe by Laurent

     WinPatrol winpatrol.exe
     system32 AvastSvc.exe -?-   
     Alwil Software Avast5 AvastUI.exe 
    ``````````````````````````````
    DNS Vulnerability Check:


    `````````End of Log```````````


    Humm, i'll see about the java update now

    Please read the following information that I have PROVIDED, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay SAFE while browsing, to prevent re-infection.

    Software recommendations

    Firewall
    • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
    • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
    • PC Tools Firewall Plus: free and excellent firewall.
    AntiSpyware
    • SpywareBlaster
      SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
    • Spybot - Search & Destroy.
      Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).
    NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

    Resident Protection help
    A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

    Rogue programs help
    There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Securing your computer
    • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft.  To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.
    Please consider using an alternate browser
    Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

    If you are interested:
    See this page for more info about malware and prevention.Great and thankyou dragonMaster

    Quote
    hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future

    I am used to the host file in XP, clicking on " hpHosts file" would this just replace the host file automatically in windows 7 and also in vistaGo to the download page and grab the Installer for Windows. Download it and install it and it shall do the work for you. Quote from: DragonMaster Jay on March 04, 2010, 12:00:32 PM
    Go to the download page and grab the Installer for Windows. Download it and install it and it shall do the work for you.

    Just one more thing dragonMaster, should i set the DNS client to manual, or keep it started (automatic) just a bit confused over this



    Quote
    Only in extreme SITUATIONS should you disable this service as caching DNS lookups reduces network traffic and makes internet surfing performance faster
    Leave it to manual. Quote from: DragonMaster Jay on March 08, 2010, 02:02:21 PM
    Leave it to manual.

    OK, DragonMaster all done.......Great..

    Another point.
    I have a folder on my c:\drive called  [ 32788R22FWJFW ] it has other folder's in it [EN_US]  [ LICENSE]  and [N_] plus lots of sys,dat,cmd. files  is this RELATED to " combofix "  and is it safe to delete

    To uninstall ComboFix

    • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
    • In the field, type in ComboFix /uninstall


    (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

    • Then, press Enter, or click OK.
    • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
    Hello DragonMaster

    NO windows carn't find " Combofix "  [run]  ( Combofix /Uninstall )

    I think when it was installed , and when i tryed to run it and got the pop-up dialog saying " incompatible OS " i deleted the file on the desktop,  which is PROBABLY the reason it won't uninstall...

    OK. No biggie. Just delete the folders from it.

    That includes that numbered folder, the file C:\combofix.txt, and C:\Qoobox Quote from: DragonMaster Jay on March 12, 2010, 07:25:04 AM
    OK. No biggie. Just delete the folders from it.

    That includes that numbered folder, the file C:\combofix.txt, and C:\Qoobox

    OK dragonMaster, i just deleted the whole folder [ 32788R22FWJFW ]   those other two folder's  are not there,  looks fine anyway.... Quote from: DragonMaster Jay on March 04, 2010, 12:00:32 PM
    Go to the download page and grab the Installer for Windows. Download it and install it and it shall do the work for you.

    Sorry DragonMaster,  How is this updated or can you just leave it like thatYou can leave it like that.

    It updates from time to time, and you can use the same installer over the current install, if you wish to update.