InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1901. |
Solve : Helper.dll & Helper.sig files.? |
|
Answer» A few weeks ago, my friend opened her computer and this window popped up with helper.dll and helper.sig files showing up. She downloaded a few different malware/spyware/adware programs and ran them, not at the same time of course, and each time her computer seemed to remove those things and work normally.
|
|
| 1902. |
Solve : AOL Virus Protection???? |
|
Answer» I have AOL and recently downloaded their version of McAfee. Since then, I have had nothing but problems. They have helped me fix a couple of problems, but now it is unbearable. I can not open ANY web pages and get the "Microsoft Explorer error" message. I also can not open the MY COMPUTER folder and several other folders. This time, AOL says it is a Microsoft problem. Any suggestions would be greatly appreciated.Advice number 1.... McAfee is a HORRIBLE program... Second... What version of Windows are you using? We might be able to run a system restore... Another thing... When did this happen? |
|
| 1903. |
Solve : Was it a viruses?? |
|
Answer» Last week my wife came and told me that her computer just started down loading an up date and was rebooting. She wasn't on the net. A HALF hour later it was still loading the up date on the reboot screen. After a half hour it was still loading. It said STEP 3 of 3 0 % compleat. Don't turn off computer. A half hour later I turned off the computer and restarted it. It did the same thing. I shut it down once more and started in safe mode, that was the only way to get to files I wonted to save. No luck, it wouldn't let me save any thing to disk. It said that I didn't have the file to run the DVD player. I rebooted the computer and it came up in part safe mode. It didn't say safe mode it just looked like it and nothing would work. No internet, no USB and no DVD. I tried restarting several times, same thing. I got my Son on the phone and he said that it was a viruses that had corrupted some files and that I would have to do a clean install of the OS. I did that and every thing is fine. Can any one tell me if this was a viruses or did I do this by shutting down the computer when I was told not to. On the reinstall of the OS (Vista) I had to down load the up dates and they only took about five or so minutes on the reboot and that was 250 MB of stuff. If it was a viruses it went from working to not working in one hour.There is no way we can just tell a virus by symptoms alone. Thats why we always request logs. No logs, no telling...I understand. I don't know how I could have GOTTEN any logs. I guess that it was best that I just reloaded the OS. Thank you for your time. |
|
| 1904. |
Solve : What can you tell us about TFUN.exe? |
|
Answer» I've GOOGLED it and used "The Process Library'. Everyday COMODO is asking me if I want to allow it to enter. Of course I don't, at the same TIME I can't FIND anything definite about its DEFINITION. Do you know anything about what it is exactly. Spelling with caps is correct. |
|
| 1905. |
Solve : TFUN.exe? |
|
Answer» What is it? I used all your earlier PREFERRED advice like googling it or using the 'Start Process LIBRARY'. The results are varied as much as just useless to explain it's POTENTIAL or veracity. |
|
| 1906. |
Solve : Windows Messenger Popup- Virus?? |
|
Answer» I installed XP Pro yesterday and now I am constantly getting a popup from a Windows Messenger WANTING to redirect me to their URL to fix the problems on my computer and various other things. I have run Spy Sweeper and Spython and also had System Mechanic go thru the registry. I deleted everything that came up but it is still there. I tried running Spy Sweeper in safe mode but it wont because it doesnt load the definitions.Any suggstions on how to fix this? ThanksNot a virus, not adware, not spyware, not crackers. |
|
| 1907. |
Solve : Download.Trojan? |
|
Answer» I just got a "trojan" or "virus" named mmview 101.dll. The PROBLEM is my norton antivirus is unable to quarantine it or delete it. How might I go about removing it.Well... The EASIST way is to take it to a professional and pay about $15 - $30... But, you probably do not want to do that, so you might want to try another antivirus program... |
|
| 1908. |
Solve : is a firewall preventing online shopping?? |
|
Answer» Everytime I TRY to shop online, the error PAGE comes up when I try to add something to my cart or proceed to checkout. Is my ANTIVIRUS making this happen? And if so, how do I DISABLE it so I can spend my cash? Thanks genius. That depends.... What security level is it on, and which FIREWALL do you have? |
|
| 1909. |
Solve : Hacker using proxy! plz help destroyed many site? |
|
Answer» Alright since this is a secruity based forum i thought it best to post this here, |
|
| 1910. |
Solve : help Explorer keeps Refreshing? |
|
Answer» followed the post and attached the logs.
|
|
| 1911. |
Solve : kdony.exe virus? |
|
Answer» Nope, most were just autoit V3 scripts aside from chriscontrol (a remote admin tool). The scripts probably just set it off because of the endless possibilities in functions. OK lets do this. |
|
| 1912. |
Solve : Best FREE antivirus Protection? |
|
Answer» Ok guys I want to know what you guys think is the best free complete antivirus protection software on the market right now? I would RECOMMEND AVG, it can be downloaded here: http://free.avg.com/download?prd=afe Ever since I have downloaded AVG free edition it will not update. It did a couple of times but is this due to the fact thats its free and paying users get priority on updates. No. I am using AVG right now, the latest version and it updates automatically at least once a day. As free user, you don't download at the high speeds that paid users get, but the downloads are quite small so anybody with a decent internet connection won't notice too much. For AVAST, you have to grab a free user code from their website ever 6-7 months and AVIRA has a nag screen which can be disabled but in my experience, the screen still flashes a bit as it's loading. Otherwise, all three are pretty good. Any free AV provider that updates at least once a day and has realtime scanning is good enough at least for me. |
|
| 1913. |
Solve : Is my computer being hacked??? |
|
Answer» Hi, |
|
| 1914. |
Solve : Re: Pop-up porblem? |
|
Answer» Mind telling me which Spyware program you are using? |
|
| 1915. |
Solve : Trojan Isbar.140? |
|
Answer» Has ANYONE ONE got any idea how to get rid of this and is this bad?maggiemay46 ......No trojan is good .......it has to go ....... You didnt mention how you found it ......your anti virus ? .....Try this , go to ........ |
|
| 1916. |
Solve : Odd program? |
|
Answer» When I hit ctrl/alt/delete, there is a program running two times called OYIvasJh.exe. I have searched Google, Dogpile, Altavista, Yahoo, MSN, and can find nothing about it. If I try to end process, it all the sudden starts running (literally) 80+ times, the computer lags for a few mins, then its back to running 2 times. I have run McAfee, F-Prot, Trend Micro and Zone Alarm updated anti-viruses, they have all come up with nothing. I have run Adaware and Xoftspy and they too CAME up with nothing. |
|
| 1917. |
Solve : helpctr.exe nightmare? |
|
Answer» hi |
|
| 1918. |
Solve : Please Help me-Urgent? |
|
Answer» I am trying to figure out what is wrong with my friend's computer. Basically, it went to a black background all of a sudden yesterday (said something about how the computer is infected or something). And now, it keeps restarting. I tried to run it in the mode that was last used that worked (I forgot the technical title for it), and that didn't work. Then I tried restore it and that didn't work. So now I am in safe mode and I don't know what to do next. Oh, and last week I did some checking around about it's previous symptoms (like shutting down with a particular message) and I read that it may have had a virus (a worm from what I read, but I really don't know). And now it is doing this. Anyway, this friend of mine really needs her computer being in graduate school and all) so if you could help we would really appreciate it. Thanks, and have a GREAT DAY (night)...Loki292......I believe you said the pc will boot up in safe mode .....( thats good ) So here's what I would try ..... |
|
| 1919. |
Solve : help me get this off plz!!!!!? |
|
Answer» ive got some crap on my computer plz help me get it off ive got PANDA and it keeps saying thay it nuteralized these VIRUSES (i get 5+ a day) plz help!!!! |
|
| 1920. |
Solve : panda-keeps reporting? |
|
Answer» hi...ummm...well i built my own computer and the man that helped me build it told me that panda anti virus was a good system and its been saying that its neturalized all these virusus about 5 a day. ive run the panda scan, the ad-aware scan, and the spy-bot search & destroy. But my computer is STILL getting all this stuff! i opened my history on internet explorer 1 day and now every time i go on it says its not responding. ive even ran every thing in SAFE mode but its still not helping!!! |
|
| 1921. |
Solve : explorer redirect program? |
|
Answer» hi there,could you please HELP me?an uninvited program has put itself on my desktop.the name is:SPLASH ral welcome.aspx.http://j.2004cms.com/redirect/chck.asp?... how do i SAFELY get rid of it?thanks to any who reply.Download an antispyware program... TRY Microsoft AntiSpyware... |
|
| 1922. |
Solve : brutally attacked? |
|
Answer» i GOT trojans ,spyware , adware, worms you name it.drivin me nuts. |
|
| 1923. |
Solve : slow loading? |
|
Answer» I wonder if someone can help me? What the PROBLEM is i am on bt fastest broadband and its takes a while for the pages to load its very slow. any idea what my problem is?Spyware! Download this program, and it will help... http://www.microsoft.com/athome/security/spyware/software/default.mspx .... HOWEVER, you need to have Windows XP or 2000 to install the software... Do you have XP or 2000? |
|
| 1924. |
Solve : A general Question ?? |
|
Answer» Hello everyone, how are all of you? |
|
| 1925. |
Solve : Please help me, I've got a Trojan.Downloader!? |
|
Answer» I ran a virus scan on my computer and found out I have been infected with Trojan.Downloader.1466. I can't find any information on it. If anyone could tell me about it I would be very grateful. I would also like to know if there is any way to get rid of it for very cheap(free). Maybe you could tell me if I can do it myself. Thank you in advance. |
|
| 1926. |
Solve : computer won't turn on after running av? |
|
Answer» Sooooooo, |
|
| 1927. |
Solve : Dangerous Situation! Help me please.? |
|
Answer» Apparently, I've had a hidden trojan for 2 years that has been downloading more and more trojans, spyware, adware, and malware. I've yet to get to the bottom of it, but it is now getting out of hand. I have ran MS AntiSpyware and have come to find out |
|
| 1928. |
Solve : Browser Shutdowns(Firefox & IE)? |
|
Answer» Recently when I try to download Windows Updates, Quicken Updates, or load anything into Windows Media Player or Real Player my browser shuts completely down. It does not matter if it's IE of Firefox. |
|
| 1929. |
Solve : Home Page Settings? |
|
Answer» marblesmells.....Glad to hear things are back to normal.....sometimes those hijackers can be very tough to CLEAN up .....particularly when so much as one entry is MISSED or overlooked ........( which is what happened ) |
|
| 1930. |
Solve : problem plzzz help me? |
|
Answer» there is SOMETHING on my computer and it keeps trying to change my password on aol, it also jus loads web pages up and clicks on things itself |
|
| 1931. |
Solve : Virus? Spyware?? |
|
Answer» I've been experiencing some unusual computer problems as of recently, and maybe someone here can help me pin-point what's wrong. I USE Mozilla Firefox and I've never had much trouble with spyware/ads, but I generally like to SCAN with Ad-Aware as a precaution, because you really can't be too safe. Well, suddenly I can't run Ad-Aware anymore. When I try to, I get this odd error message which appears to be written in German. I don't speak the language and I have an english version of the program. Fehler beim Lesen von memof I got this back Quote Error when reading memof error when inserting a RichEdit goal Best just re-install it.I already said that I had tried that, it didn't work. :-/Problem solved! I searched Google about that bizarre German error message and found out someone else had the same problem. It turned out that, for whatever reason, I was missing riched20.dll and riched32.dll from my /system folder. Once I installed those two files, both programs began functioning properly again. If anyone else ever has this problem, go here: http://www.lavasoftsupport.com/index.php?showtopic=60851 |
|
| 1932. |
Solve : MSN Hack?? |
|
Answer» I was recently hacked on MSN, I found the site(i think) however, it does not stay in my history, I recently managed to get rid of "Searchbar" and this person was supposed to be helping me. He typed something in MSN and my CD drive opened. Then he restarted my computer. I can not block people in the message window(not the contacts part). I believe I was stupid and accepted a .exe file from him. I clicked open on it, then when nothing happened I immediatly deleted it. I found files on my HD called "Fastfun"(deleted them) and there was a shortcut to the CD drive, I think that was it but now without my permission I unknowingly send messages to people telling them to go to a website to hack people on msn. I want this to stop, I am running Spybot now. I ran Norton and it found nothing. Also, when I clicked on the oringinal .exe file ZoneAlarm asked if systray.exe could act as a server. I clicked no, and MSN would not work, so I enabled it. I do not know if this is the (Virus, Trojan w/e it is) or not. I have re-installed MSN and do not know what to do. |
|
| 1933. |
Solve : Free Antivirus Software? |
|
Answer» Hey I was wondering is there any free antivirus software out there? If so what's the best? I need some antivirus software but I don't have any money. AVG is free for personal use and PRETTY good. Go to www.grisoft.com or click here. http://free.grisoft.com/freeweb.php/doc/2/Check out http://www.Majorgeeks.com. Tons of freeware and shareware, including some good anti-spy, add, and virus programs.The message lives on! ok alHi I have been using AVG Free for about 12 months and have just switched over their Professional Whcih cost money but the free version stood me well for the 12 months, the only snag is you need to update it manually where as the professional is automatically done. Ojas Hi |
|
| 1934. |
Solve : Can a virus "survive" a deleted partitio? |
|
Answer» My son had a virus that I couldn't remove so I reinstalled XP by deleteing the existing NTFS PARTITION and creating a new NTFS partition. ...Could a virus have survived the deltion/creation of the partition? If so, how do I completely clean the drive?... No, but a virus can infect you after you re-installed WinXP but prior to performing the live update. When reinstalling Windows, it's best to physically disconnect from your hi-speed modem. Boot to Safe Mode and then clean the drive. Carl Aderhold.......Well , if you couldnt reach Norton to do a update.......the virus ( if thats what it is , is still present ) ......Did AVG .....identify it and TELL you where it is residing ? I ALSO notice that you don't have SP2 installed .......is there any reason for that ? I just noticed Computer Commando posted as well.........do as he suggests. Let us know dl65 Hi Sometimes the only a format will get rid of a virus you use your operating disk to format. But be aware you will all data on the disk as you start fresh and will need to reload all your programes including your motherboard drivers as well. Formatting wipes the disk clean.Carl: Was it a boot sector virus? I'm not 100% sure, but it may be that this type of virus may survive a partition deletion because the malicious code is within the hard drive's boot sector & not on the partition. Boot sector viruses are usually (but not always) transmitted via infected floppy disks. It may be a good idea to throw out any floppy disks that were used with the comupter before the virus was removed. Something to think about, Doc DocIt can be held in winxp sfp[system file protection ......folder]...........i would save data to disk/website/ and scan for bugs..and re-format the whole lot.....the eraser program may help you....and stop your son from DOWNLOAD p2p programs the biggest cause of problems..one of them......? |
|
| 1935. |
Solve : Search Engine results want me to buy something? |
|
Answer» I have recently had a rash of spy ware, adware etc... |
|
| 1936. |
Solve : C: drive files gone, cannot boot!? |
|
Answer» My husband's PC has WIN98 and was working fine. I scan with NAV daily and do weekly scans for spyware. During a recent NAV scan, the PC froze and when rebooted, it cannot find the system disk. |
|
| 1937. |
Solve : windows 98 problem? |
|
Answer» Hi all: |
|
| 1938. |
Solve : help me, i deleted something?? |
|
Answer» My computers antivirus ran out so last night I searched for something free. I downloaded AVG and it found 42 trojan horses. I quarantined them, and deleted some, but now Internet explorer doesn't work RIGHT, say one page will come up, then the next page will say page cannot be displayed. then it will work next TIME. I tried to restore what I deleted to it's original location, but IE still doesn't work right. I am running windows xp. Any help about this will be appreciated, Oh, I also tried to go back to a previous date but that didn't help.Can you delete the trojans that you put into Quarantine? [glb]Flame[/glb]hey, this is what I ended up doing, any help woudl be appreciated... OK, let me start at the beginning. I downloaded adaware to try to get rid of spyware, it kept locking up, so I went to their website to FOLLOW their directions. After I followed them and ran adaware in safe mode, when I restarted my computer, there was nothing but the desktop picture, no icons, no taskbar. Well, eventually, I realized it had to do with the profile, there were 2 profiles, one was mine, one was administrator. I deleted the profile that was mine, (b/c the icons were coming up in safe mode under admin) but it wouldn't auto. logon as admin. I deleted my old profile and created a new one. Everything worked fine until I tried to connect to the internet. I have bellsouth dsl. It connects, like say if I go to ajc.com the site comes up, but it won't let me log in to anything, my credit union site home page comes up but anything I try to login to comes up as page cannot be displayed. I have reconfigured my modem and conections, reset settings to default, restored to a previous date, and nothing is working. I have a feeling it has something to do with the corrupted files in teh other profie taht I deleted. Any suggestions? Aside from reformatting the whole thing? Any help would be appreciated, and you can also email me at [emailprotected]Also, I meant to tell you that I had downloaded taht free firewall, zonealarm, when I uninstalled zonealarm, it started working again, that's when I decided to get rid of the spyware..... and messed up I uninstalled avg, and zonealarm, and put norton internet security, but today I deleted internet secirity and reinstalled avg, where it found 10 trojans, and deleted them... I don't have afirewall on there at all (but one does come with xp, but I think i have diabled it) so, explorer should be working right, unless with the avg and spybot I ran today deleted something I needed to make it run? jdchambers98......So , after reading your lenghty post , I am not sure if your pc is able to connect to and surf the Net ........ I find it a bit scarey that you were infected with 42 trojans and you say Norton saw none of them ........thats really odd. While Norton is primarily a anti virus app .....it will usually identify a lot of trojans ...even if it isnt able to remove them . Is your pc virus free now ? If you wish to rid yourself of spyware ......you might want to D/L Antispyware Beta ...........get it at http://www.microsoft.com/athome/security/spyware/software/default.mspx ....This app does a very good job on spyware . Let us know your status. dl65 It does connect and is surfing, actually I am using it now, but something taht has to do with logging in it won't let me do. If I go to walmart.com, I can surf around the site, but when it comes to login, or register, the page cannot be displayed, same with the credit union, can't login, and ajc.com.... I have checked my security settings... It looks like I will have to reformet, does anyone know where instructions are on saving the things you want when you reformat? Like, saving your files...? Or any suggestions before I do that? |
|
| 1939. |
Solve : windows\system32\lfoqehw.exe??? |
|
Answer» Each time I run MCAFFE it shows that i have a potentially unwanted program . windows\system32\lfoqehw.exe. I can't delete it or QUARANTINE it. How do I GET rid of it.Boot to SAFE mode and try it. |
|
| 1940. |
Solve : PLEASE help... imwireup.exe error? |
|
Answer» Everytime I log into windows I get a pop-up saying that imwireup.exe cannot run because commcoss.dll isn't found. I don't get how why I have that... I've tried running ad-aware and search&destroy but nothing has helped. I've also searched google and ASKED people but no one seems to know how to get rid of it! I don't know what to do... I don't know much about computers at all and I'm really scared. Please, someone help. Hi Jensie |
|
| 1941. |
Solve : Trojan Horse BackDoor.Small.28.BL? |
|
Answer» how can i GET rid of it????????Yesterday my AVG (antivirus) PUT up a similar WARNING too. |
|
| 1942. |
Solve : cant find old antivirus uninstaller? |
|
Answer» i just upgraded from win 98se to winxppro.now im trying to install newer norton antivirus.but first i need to uninstall my older antivirus.i LOOKED all over the computer add /remove programs ect.i cant find the uninstaller anywhere.it WONT LET me install the new untill i uninstall the old.please help.What about in the programs menu? Start -> All Programs -> Norton .... No uninstaller there? Also, this is more risky, but.... If you go into your C: drive, go to Program Files -> SYMANTEC or Norton , and find your software that you want to uninstall... Next, look in the folders (in norton) for uninstall.exe ... |
|
| 1943. |
Solve : I am sending huge ammounts of data? |
|
Answer» without any browser open huge ammounts of data is pumping out of my computer when connected to internet. WHY! |
|
| 1944. |
Solve : Router shows unauthorized adress under DHCP list? |
|
Answer» Here's something that I noticed today.. [1] Use MAC address filtering. [2]Turn off SSID broadcast [3]Don't advertise your router to the world. [4]Limit the number of IP addresses available to the actual number needed by your network 1. This can be done for the two machines not regulated by me, since those are, as you can see, detected in the list (Blackened out by me, though) how do I find out my own MAC adress? 2. What is SSID broadcast be and how do I find out where to disable that? - SSID SEEMS to be related to wireless networks. (Our network is not wireless) 3. Advertise in what way? I am blocking WAN Ping 4. Done. Limited the pool to use 3 adresses and making the lease time forever. Does that suffice for point 4?You can find your MAC address by using the ipconfig utility. SSID is for wireless. I assumed wireless capability. If the router has wireless capability, even if you are not using it, it still broadcasts SSID unless the wireless is disabled completely or SSID is disabled.The router has no wireless capabilities. Once I obtained the MAC adress for the other PC on the network I can disable all other MAC adresses that try to connect. What reason could there be that the Router does not show all the computers connected to more than 99% of the time? I disabeled the MAC adress for the IP that is 'connected' but it is still there.. Why is it there?Is that not your ISP IP address?The IP is not immediately released. You can release it from the particular machine, or reboot the router. The ISP's IP address should show up in the routing table but not in the DHCP clients table.After trying to decrease the IP pool Internet would no longer work on all PC's, I have tried assigning each PC an IP adress rather than having the PC's OBTAIN an IP Adress manually, but this would not work either. Since I haven't got the room to experiment all I want with this, I have kept the standard I reset the router BACK to the factory settings after complications arose (A bug they never bothered fixing, but I always manage to run into). This removed the IP adress that wasn't supposed to be where it was. Guess the problem could be considered 'solved'.... Be it in a way I had non quite expected. Or wanted. And, no I doubt it is the IP adress of my ISP. My ISP is not located in America..Quote ...some kind of Computer Science Corporation in my DHCP list does! CSC has been in the computer business for almost 50 years , http://www.csc.com/aboutus/history.shtml IP's assigned in ORDER, so, low number = 1st ones involved with ARPAnet (now DARPA), precursor to WorldWideWeb. Why it's on your client list makes no sense, just delete it. |
|
| 1945. |
Solve : Isrvs? |
|
Answer» I have some sort of hijacker and I have no clue how to get rid of it. It has gotten so bad that I am barely ABLE to do anything in the regular mode b/c it is running so slow so if there is anyway I can fix it in safe mode that would be awesome |
|
| 1946. |
Solve : 123mania? |
|
Answer» how can i GET RID of it? I have "the CLEANER" but its still there.hmsam......Here's all the info you should REQUIRE to remove it ...... http://www.doxdesk.com/parasite/123Mania.html |
|
| 1947. |
Solve : Help on Anti-Spyware...? |
|
Answer» What are good programs that are free that protects your computer from worms, trogans, etc and also scans your computer...... I can't use Antispyware Beta because I found out that my computer had a phoney microsoft ID Key...... I need HELP Go to the top page in this forum Computer Viruses and Spyware and look at the top post named "PLEASE read this first" |
|
| 1948. |
Solve : have antiexe in partition running xp can't FDISK? |
|
Answer» I'v been trying to recover from Antiexe virus in boot :you are SUPPOSE to be able to run FDISK/MBR but I can't GET this dog to HUNT any hints out there . for some reason I can not change dirs and make my system stay in that dir I can change the directory on C: but it will just bounce back to A: |
|
| 1949. |
Solve : System shutdown problem - NT Authority\system? |
|
Answer» Sir HELP Me i don't know how to solve this!! the PROBLEM was encounter is WINDOWS XP- lsass.exe 60second System SHUTDOWN Problem lsass ... thanks!!!I would run the MS blaster removal tool.........if not there is this>>http://support.microsoft.com/default.aspx?scid=kb;EN-US;q267578 |
|
| 1950. |
Solve : Downloader-yh trojan? |
|
Answer» R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/ O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\Program Files\SlipStream Web Accelerator\PBHelper.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [Zone Labs Client] "C:\Utilities\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [Ad-watch] "C:\Utilities\Lavasoft\Ad-aware 6\Ad-watch.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [Free Download Manager] C:\Utilities\Free Download Manager\fdm.exe -autorun O4 - Startup: ERUNT AutoBackup.lnk = C:\Utilities\ERUNT\AUTOBACK.EXE O4 - Global Startup: SlipStream.lnk = C:\Program Files\SlipStream Web Accelerator\slipaccel.exe O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Utilities\Free Download Manager\dlall.htm O8 - Extra context menu item: Download by Free Download Manager - file://C:\Utilities\Free Download Manager\dllink.htm O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Utilities\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Utilities\Free Download Manager\dlpage.htm O9 - Extra BUTTON: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - C:\UTILIT~1\CACHEM~1\CachemanXP.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Utilities\Executive Software\Diskeeper\DkService.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Here is first PART of report: RUNNING processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Utilities\Executive Software\Diskeeper\DkService.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\runservice.exe c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\MsPMSPSv.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Utilities\Zone Labs\ZoneAlarm\zlclient.exe C:\Utilities\Lavasoft\Ad-aware 6\Ad-watch.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Utilities\Free Download Manager\fdm.exe C:\Program Files\SlipStream Web Accelerator\slipaccel.exe C:\Program Files\InterMute\SpySubtract\SpySub.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe D:\New Downloads\hijackthis\HijackThis.exe Everything was done as you requested and was clean except MS mentioned Warez but opted to ignore it. Keeping Temp Int Files folder open to see when i286.exe pops up and what triggered it. We'll get it thanks again. Snerd....looking better , but I see an entry I either missed or overlooked the first time ..... Run hijackthis again and mark for removal..... O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file) Something else ......make SURE there's nothing in your recycle bin .........before you reboot The Warez entry you choose to ignore my be the culperit......Warez sites are bad for viruses and trojans. let us know how you make out dl65 Bin was empty and am gonna remove that file .... A friend gave me a small note all it said was ewido.com and after a long time...... -------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 8:54:04 PM, 4/11/2005 + Report-Checksum: 886A8083 + Date of database: 4/12/2005 + Version of scan engine: v3.0 + Duration: 30 min + Scanned Files: 103332 + Speed: 56.14 Files/Second + Infected files: 7 + Removed files: 4 + Files put in quarantine: 4 + Files that could not be opened: 0 + Files that could not be cleaned: 3 + Binder: Yes + Crypter: Yes + Archives: Yes + Scanned items: C:\ D:\ E:\ F:\ C:\ D:\ E:\ F:\ + Scan result: C:\WINDOWS\system32\sypeitb.dll -> TrojanDownloader.Qoologic.i -> Cleaned with backup C:\WINDOWS\system32\wmconfig.cpl -> TrojanDropper.Win32.Small.wc -> Cleaned with backup C:\WINDOWS\system32\Wsiibw.exe -> Spyware.DealHelper.ac -> Cleaned with backup C:\WINDOWS\unadbeh.exe -> TrojanDropper.Win32.Small.wc -> Cleaned with backup C:\WINDOWS\system32\sypeitb.dll -> TrojanDownloader.Qoologic.i -> Error during cleaning C:\WINDOWS\system32\wmconfig.cpl -> TrojanDropper.Win32.Small.wc -> Error during cleaning C:\WINDOWS\unadbeh.exe -> TrojanDropper.Win32.Small.wc -> Error during cleaning ::Report End What do you think?Snerd........Go to each of the following locations and see if you can manually remove them....... Reboot into Safe and then remove them . C:\WINDOWS\system32\sypeitb.dll -> TrojanDownloader.Qoologic.i -> Error during cleaning C:\WINDOWS\system32\wmconfig.cpl -> TrojanDropper.Win32.Small.wc -> Error during cleaning C:\WINDOWS\unadbeh.exe -> TrojanDropper.Win32.Small.wc -> Error during cleaning let us know, dl65 I think we got it - if you re-read the ewido report it seems to say that it got them on second try. I checked and could find nothing but I will run ewido again to be sure. Read that Trojan Hunter found and cleaned that file so I TRIED it. Beautiful program, fast and easy to use. I like it when they immediately update before scan but it found nothing. Now all I have to do is to try and figure out why my folders keep switching back to icon view from list view. You are great, I cannot thank you enough and I will be back to read and learn.Snerd....I have had my items change on occassion from list to icon ......but I think it may be just a glitch in windows ......If you find out otherwise ...let us know . Glad to hear your issue is resolved . dl65 |
|