InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2501. |
Solve : Hijacker?? |
|
Answer» Windows XP Media Center Edition, Dell computer... not sure on SPECS, sorry. |
|
| 2502. |
Solve : My icons and task bars have disappeared - here is what hijack gave me ...? |
|
Answer» Windows xp |
|
| 2503. |
Solve : trying to delete undeleteable virus file? |
| Answer» THATS what I THOUGHT had HAPPENED. i HATE it when this HAPPENS. | |
| 2504. |
Solve : Superantispyware not a Win32 Application? |
|
Answer» Hi, |
|
| 2505. |
Solve : Anti-virus/spyware? |
|
Answer» Hello all, |
|
| 2506. |
Solve : Perfect Defender 2009 "Virus Removal" - FAKE DON'T BUY OR DOWNLOAD!? |
|
Answer» This has come to my attention that there is a virus, and whenever your homepage pops up, it says this may be a virused site, and it can be harmful to your computer. You'll also get a popup concerning "Win32.Zafi.B" that it will record keystrokes and take screenshots of your computer, stealing personal information.
If you have purchased it to..."Remove" their virus, then your credit card number is stolen. They make you "purchase" the "Microsoft Gold Certified" program, but, it isn't, and takes your number. Hope this helps, BRQuote from: BatchRocks on February 09, 2009, 12:40:57 PM This has come to my attention that There is avirus, By which you mean you got it?I munged your link. Please DO NOT post links to infected web sites... I suggest using WOT - Web of Trust. WOT is a free Internet SECURITY addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. The site itself isn't harmful, but the download is, and sorry... Was just warning. And, I do use WOT :-). QUOTE from: BC_Programmer on February 09, 2009, 12:45:54 PM Quote from: BatchRocks on February 09, 2009, 12:40:57 PMThis has come to my attention that There is avirus, Yesssssss.....I don't mean to argue it but yes, it is an infected site. It's on multiple security tools black lists. If you can get infected by clicking a link on a site then the whole site is considered infected. We don't want users complaining they clicked a link at CH and got infected Quote from: evilfantasy on February 09, 2009, 01:19:03 PM I don't mean to argue it but yes, it is an infected site. It's on multiple security tools black lists. Oh...Riiiight, Sorry about that! Good thing for helpful Fantasies *WINK*. EDIT : I just posted this to help everyone who has this, as it's been 'out there' since December Eighth. |
|
| 2507. |
Solve : virus after effect? |
|
Answer» yesterday i was hit by virus (worm kido.32), i was able to remove it thru kaspersky but my DRIVE s COULD not be opene by CLICKING it, says no association of files, but can be open thru explorer, what should i do t orestore it bac KTO NORMAL |
|
| 2508. |
Solve : Stuck - Firewall will not allow updates to antivirus software.? |
|
Answer» Download the OTMoveIt3 by OldTimer
Not much else to report. After that post about the worm going about I turned automatic updates for windows on. (I had turned it off PRIOR to trying to trying to fix this machine) There are new updates available; should I install these or wait until this problem is fixed? [attachment deleted by admin]Download Panda Anti-Rootkit.zip * Unzip it and run the PAVARK.exe file. * Tick the box that says In depth scan and follow the on screen instructions. * Let me know the results in your reply. Ok this is interesting. Panda said no rootkits found. Results attached. What next if everything is clean? Still can't update new definitions. [attachment deleted by admin]Try reinstalling the PROGRAMS that won't update.I uninstalled both MBAM and Superantispyware using Revo uninstaller, then downloaded and installed them again. No change, they still refuse to update. I am wondering whether I should try to download AVG Antivirus and see if that will run instead of avast because I have no virus protection. Whats next Evilfantasy?It's worth a try. You should get all Windows Updates also.\ Cleanup and other suggestions. 1. Double click OTMoveIt2.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some GREAT FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before. For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, SPYWARE, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Finally! Something must have kicked the system. Everything seems to be working now with the exception of Avast which seems to have issues. I uninstalled it, but I can't get it totally off my system. It doesn't appear to be causing any trouble however. I downloaded AVG Free instead and it is going fine. Thank you very much for your time Evilfantasy, I really appreciate it |
|
| 2509. |
Solve : Antivirus program for thumb drive?? |
|
Answer» What is the BEST anti-virus program to put on a thumb drive? Would like to check my sister-in-law's computer--after I get MINE cleaned. |
|
| 2510. |
Solve : Killing 'Nircmd.com' what does this mean?? |
|
Answer» Killing 'Nircmd.com' |
|
| 2511. |
Solve : McAfee will not update and some other wierd stuff.? |
|
Answer» I am trying to update my McAfee definitions and it keeps telling me that "one or more items cannot be fixed because of an error". I have run McAFee Virtual technician and it doesn't find any errors. I even redownloaded the program last night. Nothing has fixed it. |
|
| 2512. |
Solve : Check Logs Please? |
|
Answer» HI, COULD I PLEASE have these logs checked: THANKYOU [attachment DELETED by admin]Please check these logs. Thankyou LizD [attachment deleted by admin] |
|
| 2513. |
Solve : Registry help? |
|
Answer» Does anyone have a good recommendation for a free registry cleaner that REPAIRS the files for free, not just scans them? I have a DLL error that prevents me from using the internet and freezes my computer. If anyone has a solution I'd gladly appreciate it.First and most important to know is that any Registry cleaner DO NOT repair the registry. The descriptions are misleading and have caused even 'healthy' computers to not boot back to Windows. NEVER run a registry cleaner on a PC that is having performance issues. You might as well just reformat and reinstall as that's LIKELY what will happen if you do. |
|
| 2514. |
Solve : Cannot access websites such as McAfee, AVG, other antivirus sites? |
|
Answer» Hi, |
|
| 2515. |
Solve : CCleaner question?? |
|
Answer» Of course- fixing the account would still be fixing only half the problem. a reinstall would likely fix all your issues. (aside from introducing the new issue of finding drivers, but that's no problem)I see what you mean, what drivers do you mean BC_Programmer? I see what you mean, what drivers do you mean BC_Programmer? It sure is- and- we can actually provide some help with it too! considering it's even still infected with a keylogger after all this effort by you and EvilFantasy, it's probably best to go with a reformat.Hold up BC_Programmer, I though violence and swearing were not allowed on this site.. . The mere though of formatting this drive sends a chill up my spine.... so lets no go there without SERIOUS consideration. so lets go with a reinstall at the moment OK . Ready to go now so do I need to back up or save anything in particular or just fly with the sheets to the wind?Well I TRIED everything suggested and ended up doing an install of Win XP Pro SP3. It seems that now I have the bad copy with popping, a good copy of XP Pro and another I dont know what it does (not xp but a REPAIR option of some sort). In doing that of course, I thought I lost all my programs, bookmarks, websites, passwords and favourites etc., but as I FOUND out they are all still there on the infected popping copy. Thanks to all with their input and assistance with this. I have a lot of work to do now copying all the bits and pieces over to the new windows XP. Maybe I might actually try and get rid of the pop virus later then.evilfantasy, Thanks for your help. I do have a (perhaps) simple question. All the logs I posted, showed eventually, that the computer was rid of all suspect nasties, correct? So where the Dell does this popping annoyance COME from? |
|
| 2516. |
Solve : anti virus 2008/trojans? |
|
Answer» hi - any advice would be really nice....... the a/v 2008 thing appeared early jan 2009.... we have avg free and spysweeper, after full scans of both problem seemed to have gone. But after on every restart avg was detecting trojans. Followed your suggestions and malwarebytes seems to have stopped it, but not really sure if there isn't anything lingering. operating windows xp logs for superantispyware, malbytes, hijack this and avg log below mucho gracias SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/19/2009 at 03:54 PM Application Version : 4.24.1004 Core Rules Database Version : 3715 Trace Rules Database Version: 1689 Scan type : Complete Scan Total Scan Time : 01:05:32 Memory items scanned : 399 Memory threats detected : 0 Registry items scanned : 7269 Registry threats detected : 0 File items scanned : 94641 File threats detected : 1 Adware.Tracking Cookie D:\Documents and Settings\paul\Cookies\[emailprotected][1].txt Malwarebytes' Anti-Malware 1.33 Database version: 1668 Windows 5.1.2600 Service Pack 3 19/01/2009 18:01:32 mbam-log-2009-01-19 (18-01-32).txt Scan type: Quick Scan Objects scanned: 67197 Time elapsed: 5 MINUTE(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\MSFox (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\ieupdates.exe.tmp (Adware.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\system32\2HKwq8To.exe.a_a (Trojan.Agent) -> Quarantined and deleted successfully. Logfile of TREND Micro HijackThis v2.0.2 Scan SAVED at 13:04:17, on 21/01/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe c:\APPS\HIDSERVICE\HIDSERVICE.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\slserv.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe c:\APPS\Powercinema\Kernel\TV\CLSched.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Apps\Powercinema\PCMService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\PROGRA~1\AVG\AVG8\avgscanx.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe C:\Program Files\AVG\AVG8\avgui.exe C:\Program Files\Webroot\Spy Sweeper\SSU.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\AVG\AVG8\aAvgApi.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe C:\Program Files\Trend Micro\sniper.exe\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://c:\windows\system32\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [Ulead AutoDetector v2] "C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] "C:\WINDOWS\system32\HDAShCut.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SsAAD.exe] "C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE" O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" O4 - HKLM\..\Run: [Alcmtr] "C:\WINDOWS\ALCMTR.EXE" O4 - HKLM\..\Run: [AVG8_TRAY] "C:\PROGRA~1\AVG\AVG8\avgtray.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Add to Windows &Live FAVORITES - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158543252937 O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37960.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{7AB7C708-8D8B-4F8F-9A33-F9D872D8CE86}: NameServer = 212.74.112.66,212.74.112.67 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing) O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (file missing) O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe O23 - Service: Google Update Service (gupdate1c9677be6f19480) (gupdate1c9677be6f19480) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 11689 bytes Resident Shield detection Infection;"Object";"Result";"Detection time";"Object Type";"Process" Trojan horse SHeur2.JZF;"D:\Documents and Settings\paul\Local Settings\Temp\~tmpa.exe";"Moved to Virus Vault";"09/01/2009, 21:06:06";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse SHeur2.JZF;"D:\DOCUME~1\paul\LOCALS~1\Temp\~tmpa.exe";"Healed";"09/01/2009, 21:06:07";"file";"D:\DOCUME~1\paul\LOCALS~1\Temp\yyy5749.exe" Trojan horse Agent.ATAR;"D:\DOCUME~1\paul\LOCALS~1\Temp\~tmpc.exe";"Moved to Virus Vault";"09/01/2009, 21:06:59";"file";"D:\DOCUME~1\paul\LOCALS~1\Temp\yyy5749.exe" Virus found FakeAlert;"D:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\0ZD7VSK5\freescan[1].htm";"Moved to Virus Vault";"09/01/2009, 21:10:04";"file";"C:\Program Files\Internet Explorer\IEXPLORE.EXE" Virus found FakeAlert;"D:\Documents and Settings\paul\Local Settings\Temporary Internet Files\Content.IE5\8T92JFPH\freescan[1].htm";"Moved to Virus Vault";"09/01/2009, 21:11:12";"file";"C:\Program Files\Internet Explorer\IEXPLORE.EXE" Potentially harmful program Fake_AntiSpyware.AAP;"C:\WINDOWS\SYSTEM32\SCUI.CPL";"Deleted";"09/01/2009, 21:14:01";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse SHeur2.KFT;"D:\DOCUME~1\paul\LOCALS~1\Temp\yyy5749.exe";"Moved to Virus Vault";"18/01/2009, 09:17:38";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse Downloader.Agent.ASNF;"C:\WINDOWS\system32\2HKwq8To.exe";"Moved to Virus Vault";"19/01/2009, 11:35:36";"file";"C:\Program Files\Mozilla Firefox\firefox.exe" Trojan horse Downloader.Agent.ASNF;"C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP576\A0118976.exe";"Deleted";"19/01/2009, 11:35:40";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse Small.AYR;"C:\windows\system32\winsystems.dll";"Moved to Virus Vault";"19/01/2009, 12:22:07";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse Small.AYR;"C:\System Volume Information\_restore{B1C538C0-CBA3-4434-A006-53A338B37653}\RP577\A0119032.dll";"Deleted";"19/01/2009, 12:22:11";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse SHeur2.KFT;"D:\Documents and Settings\paul\Local Settings\Temp\yyy5759.exe";"Moved to Virus Vault";"19/01/2009, 12:32:37";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse Downloader.Agent.ASNF;"D:\Documents and Settings\paul\Local Settings\Temp\~tmpb.exe";"Moved to Virus Vault";"19/01/2009, 12:34:49";"file";"C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" Trojan horse Crypt.BHX;"C:\SYSTEM VOLUME INFORMATION\_RESTORE{B1C538C0-CBA3-4434-A006-53A338B37653}\RP575\A0118870.DLL";"Moved to Virus Vault";"19/01/2009, 15:25:46";"file";"C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" |
|
| 2517. |
Solve : Conficker problems..? |
|
Answer» Looks like we got everything.
. The above procedure will:
---------- Download OTMoveIt3 by OldTimer OTMoveIt3.exe and place it on your desktop. (unless you already have it installed) 1. Double click OTMoveIt3.exe to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, ALLOW it access. 4. Click YES at the next PROMPT (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt3 ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before. For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you SAFE from ONLINE scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. ok all done thank you evilfanfasty...Irish eyes are smiling ... I will and have recommended this site to anyone who needs help and support... achiman.. Your welcome. Glad it worked! Safe surfing... |
|
| 2518. |
Solve : help! can't get rid of win32.zafi.b? |
|
Answer» I get the same pop up that everyone else seems to get but no MATTER what way I try to remove it I can't. My broser won't let me open any pages that have downloads on them that I need. I also cannot run my system backup or add/remove programs. I'm completely lost on what to do next I've spent many hours already TRYING to figure this out.Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
|
|
| 2519. |
Solve : Invalid Update Control CTF File on AVG 8? |
|
Answer» it SAID it can up date the update manger saids nvalid Update Control CTF File You need to DELETE all of the .ctf files. See here http://www.winhelponline.com/blog/error-invalid-update-control-ctf-file-when-updating-avg-anti-virus-80/ok Thank You it worked |
|
| 2520. |
Solve : I may have spyware and malware: Please Help!? |
|
Answer» I have a Dell dimension 4300 with a operating system of Windows Me 127.0MB Ram, I also have a Westell 6100 modem provided by Verizon Broadband DSL. I suspect malware and spyware because everytime i log on to my internet explorer 6SP It changes the size of the browser, I also cannot rum some of the programs i used to run. Like MsDos, Certain exe programs, I also cannot use my AIM any more because it connot connect any more. Iknow there is more but i cant think of them right now.
|
|
| 2521. |
Solve : Help! Fatal System Error when trying to rid malware? |
|
Answer» Uninstall McAfee and install one of the free antivirus from the malware removal guide.
Is the problem fixed? Ran that program but when I start up IE I still get the same error. I even tried to go to a few sites thinking maybe it was just slow but it's the same message on every page.Click Here to download IEdll.zip. Save it to your desktop. Right click on IEdll.zip click on Extract all. Go to the extracted files and double click on IEdll.bat Follow the prompts. It will tell you when it is done. When finished restart your computer. How about now?Do I have to register? Because that's all I see is a login/register screen when I press that link.I will attach it here. [attachment deleted by admin]Ran it and followed all the prompts until it finished and closed itself, than I restarted. Came back and IE still doesn't say anything other than: Internet Explorer cannot display the webpage Most likely causes: You are not connected to the Internet. The website is encountering problems. There might be a typing error in the address. What you can try: Diagnose Connection Problems More information This problem can be caused by a variety of issues, including: Internet connectivity has been lost. The website is temporarily unavailable. The Domain Name Server (DNS) is not reachable. The Domain Name Server (DNS) does not have a listing for the website's domain. If this is an HTTPS (secure) address, click Tools, click Internet Options, click Advanced, and check to be sure the SSL and TLS protocols are enabled under the security section. For offline users You can still view subscribed feeds and some recently viewed webpages. To view subscribed feeds Click the Favorites Center button , click Feeds, and then click the feed you want to view. To view recently visited webpages (might not work on all pages) Click Tools , and then click Work Offline. Click the Favorites Center button , click History, and then click the page you want to view. Try this next. Download and run WinSockFix. This is a two step process that will Back up the Registry and Reset the Winsock Stack.
|
|
| 2522. |
Solve : infected computer = slow internet? |
|
Answer» my computer is infected please help my internet goes realy slow here are the logs O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE') ---------- Run Dial-a-fix. Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
Did that help?whats nLite? and am going to try it it took me a long just to load this page http://www.nliteos.com/nlite.html SOMEONE has modified the Windows shell with a program called nLite. could that be a bad thing ? that it runs on nLiteNot if you know what you are doing. You didn't install nLite? Who might have?well a while back close to a year back a friend of mines installed windows, he might have put that program with the software Go to Add/Remove Programs and uninstall it. Then post a new HijackThis log.does not show up in there k did the Dial-a-Fix but same thing .. Here is the new log see if anything changed ? Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 9:54:55 PM, on 1/21/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16762) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe D:\Program Files\Reader 8.0\Reader\Reader_sl.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Oscar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\Tablet.exe D:\Program Files\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\Documents and Settings\Oscar\Desktop\Programs\sniper.exe.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.co.uk/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Oscar\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_03] cmd.exe /c md "%SystemRoot%\System32\dllcache" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_04] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_05] rundll32 advpack.dll,LaunchINFSection nlite.inf,nLiteReg (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nlpo_06] rundll32 advpack.dll,LaunchINFSection nlite.inf,S (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nlpo_02] rundll32 advpack.dll,DelNodeRunDLL32 "%SystemRoot%\System32\dllcache" (User 'NETWORK SERVICE') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{29DBFC70-ADB2-4950-BF32-358273D17553}: NameServer = 4.2.2.1,4.2.2.2 O17 - HKLM\System\CCS\Services\Tcpip\..\{CBFFB94A-B86B-4769-887E-89459223601D}: NameServer = 4.2.2.1,4.2.2.2 O17 - HKLM\System\CS1\Services\Tcpip\..\{29DBFC70-ADB2-4950-BF32-358273D17553}: NameServer = 4.2.2.1,4.2.2.2 O17 - HKLM\System\CS3\Services\Tcpip\..\{29DBFC70-ADB2-4950-BF32-358273D17553}: NameServer = 4.2.2.1,4.2.2.2 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O23 - Service: Adobe LM Service - Adobe SYSTEMS - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file MISSING) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 8750 bytes Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there)
Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nlpo_02"=- "nlpo_03'=- "nlpo_04"=- "nlpo_05"=- "nlpo_06"=- Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. Restart the computer. ---------- Is this your ISP? COLORADOBROOMFIELDLEVEL 3 COMMUNICATIONS INCproblem resolved - goes slow at times but way faster than what i started with, Thank you I would also recommend that you Defrag the computer. You can use the built in Windows Defrag or a faster FREE program. Defraggler is very effective and easy to use. Be sure to clean out temp files and restart the computer just before using this. |
|
| 2523. |
Solve : Silence is NOT golden!? |
|
Answer» Okay, here's the deal. For the last few days, when I start up my comp, I get an error message that's titled "Microsoft visual c++ runtime library," followed by "Runtime error! C:\windows\system32\svchost.exe This application has requested runtime to TERMINATE it in an unusual way." I've read other threads from people who've had this message pop up and it usually seems to affect their internet connection or certain programs. For me, it has somehow disabled my sound. The sound is there when windows starts up (I get that Doo-a-looo-diddy-dooo sound at startup), but after the pop-up comes it's gone. I've tried terminating svchost in tsk manager (the one that takes up 15 ks or so. I went through Administrative Tools-Services and found that my windows audio was stopped, but when I started it, nothing changed.... I take that BACK. Prior to starting it, when I tried to play a file in Window's Media, they all TURNED orange with an exclamation mark. After I started it, it acted as if it was playing but no sound came STILL. I've run ad-aware, spyware terminator, anti-virus and regcure, none of which has obviously helped |
|
| 2524. |
Solve : Re: Viruses and Spyware? |
|
Answer» I have been having trouble with spyawre guard 2008 and following some suggestions have helped. I was asked to post my SCAN logs here. |
|
| 2525. |
Solve : Problems inc. Trojan.Csrssc/Systemc-A? |
|
Answer» I have been having problems recently with my computer running slow and freezing randomly, often my browser will encounter an error and just close (Firefox, Opera and Safari have all done this). I ran a scan with Trend Micro Internet Security and allowed it to clean what it could and also with SUPERAntiSpyware. Yesterday, the Trojan.Csrssc/Systemc-A came up and I followed the SAS instructions to delete it, but it doesn't seem to be working as it was there again today. I don't know if there's a special program to ERASE it? |
|
| 2526. |
Solve : Monitor switching of at start up. ( Virus? )? |
|
Answer» Monitor switching of at START up. |
|
| 2527. |
Solve : hijack scan , brought up a bho file? |
|
Answer» i ran a hijack this scan and CHECKING some files , there is a ( BHO ) file and it doe's not have good reading , should i take it out , or would you LIKE to have a look at the scan , thank youPlease post it here and one of our MALWARE Specialists will have a look.thank you , i managed it |
|
| 2528. |
Solve : Trojan Win32.PEPatch.AO found in Non-bootable PC? |
|
Answer» A FRIEND brought his Dell 2100 (3 1/2 yrs old, XP Home (with SP3, I believe), 512 mb ram, single 80 gb Hd Drv, with Norton AntiVirus installed) to me. The owner assured me that he had noticed no aberrant behavior until YESTERDAY, when it refused to boot. After confirming that it would not boot in either normal or safe mode (it displays the splash screen, then a cursor appears in the center of the screen, and all activity STOPS - in Safe Mode, the screen displays the safe mode indications at the edges of the screen, and the cursor again shows up, but no further activity), I removed the hard drive, and set it up as an external drive to one of my PCs. The drive spun right up, and I had no problems reading it. AVG Free found two instances of a TROJAN - Win32.PEPatch.AO, attached to two familiar files in Windows\System32\, spoolsv.exe and svchost.exe, both dated August 10, 2004. AVG reported that forced removal of this malware would cause the host system to be unstable - which, for whatever it's worth, makes sense to me. |
|
| 2529. |
Solve : FOUND 5ROOTKITS AND DNSCHANGER THANK U EVILFANTASY BUT WHAT NEXT? |
|
Answer» zone firewall(zfw) says at startup everytime that symptom1 |
|
| 2530. |
Solve : Computer Running Slow, Maleware Found, Can't access "My Computer"? |
|
Answer» Hi Guys, |
|
| 2531. |
Solve : Computer sometimes freezes up and is so slow all the time. Please help!? |
|
Answer» Here's my hijackthis log: |
|
| 2532. |
Solve : cannot download anything on the net using IE and Firefox? |
|
Answer» :-[hi everyone, |
|
| 2533. |
Solve : Adware.secondThought infection, plus cannot acces antispyware sites? |
|
Answer» I've GOT a hijacker that redirects me away from Google or Yahoo search results and blocks me from accessing many antivirus and antispyware sites. It won't let me run Spybot, SuperAntiSpyware or Malwarebytes AntiMalware, or update AVG. I've been updating AVG manually by downloading the definitions file, and it reports an Adware.SecondThought infection but seems unable to get rid of it. Logfile of HijackThis v1.98.2 |
|
| 2534. |
Solve : Another case of AVG reporting SHeur2.LVU trojan!? |
|
Answer» Again it repoted in sim.exe, and again i 3 restore points. |
|
| 2535. |
Solve : Fixing My Gateway GT4022!!? |
|
Answer» Hello my name is Karina. I bought Gateway GT4022 with Windows XP comp in 2006. It started acting up ever since I was tricked into installing a virus scanner for vista in April 2008. I deleted that PROGRAM and there was no problems after that. Then, I periodically check my programs on my C drive to delete excess programs and FILES. Suddenly I see about 60-70 windows update that were not there before? So I delete what I could immediately. I assume I made a mistake because now the computer has very big pixels,(which i changed manually) and my log in screen does not show up any more, it takes me DIRECTLY to my desktop. It is small little things that are annoying. My window player does not play. And there is still windows updates on my programs. What should I do? What program virus or anything should I buy? Or is it something as simply as to system restore ( which will not allow me)? PLEASE Help me! |
|
| 2536. |
Solve : IE7??? Malware??? Spyware??? Registry Errors??? HELP!!!? |
|
Answer» I AM FRUSTRATED!!! I have spent a lot of time TRYING to post messages to the "virus and infections" category, as instructed by you. When I leave my "post" to reread instructions, look up info, etc... I CANNOT GET BACK TO IT! GONE! TWICE. |
|
| 2537. |
Solve : Malware Removal Help - logs posted? |
|
Answer» My parents - in their 70s - have been having PC trouble. Their machine is a Sony VAIO running Windows XP. |
|
| 2538. |
Solve : Computer freezing, restarting, BSOD - virus?? |
|
Answer» Hi, |
|
| 2539. |
Solve : Computer freeze while downloading? |
|
Answer» My computer would freeze when i am downloading a large FILE at a fast SPEED (1mb+) over wireless.My event viewer shows nothing. This started happening after installing and uninstalling the new zone alarm. I tried a completely uninstall and then manually deleting the files and registry and i think i got it all. But still freezes during fast wireless downloads. Over ethernet its fine. |
|
| 2540. |
Solve : bad image on all exe files? |
|
Answer» I have a dell Inspiron 600m that is having major issues. When you start the system you first get an error message: |
|
| 2541. |
Solve : My Problem? |
|
Answer» Dell XPS 400 Windows XP |
|
| 2542. |
Solve : Tea Timer instal or not?? |
|
Answer» Hello and thank you for looking at my post. |
|
| 2543. |
Solve : If I BUY the software will it be FASTER??? |
|
Answer» HI, A few months ago you helped me to get rid of a lot of spyware and junk on my computer. (ThankYouThankYouThankYou!) Anyway, I've been using the anti-spyware, malware removal software, and I have AVG anti-virus (all free versions) and it is reallllllllly slow. It literally takes hours to complete the scans! If I go ahead and buy the full versions from the software companies will it run faster? If so, how much faster? I would be upset if I paid for the software and it still took hours to run a complete scan. I have a Dell Dimension 4100 with Intel Pentium III with Windows XP Home Version and my hard drive is only 18.6 GB. Thanks for any advice you can give me! -granny-How much Memory do you have in the PC? How might have to tweak the PC. Plus PIII--Sounds like it might be time to upgrade:)Quote from: NJtech on February 03, 2009, 07:31:12 PM Plus PIII--Sounds like it might be time to upgrade:) Doubtful.You need to upgrade your machine. And, do not scan simultaneously. Quote from: randysilverio on February 03, 2009, 07:38:07 PM You need to upgrade your machine. No... Completely unnecessary. The only reason to upgrade the machine would be if they were a hardcore gamer. 1Ghz is PLENTY for XP, although if it's still operating with the stock 128MB a boost there (to 256+ MB) would probably the most bang for the buck, of an upgrade is considered. But NONE of these posts even address the question- wether they will scan faster if the full version is purchased. The answer is no- But you could try out other fre Anti-virus programs, Avira, Avast, and Nod32 are other reputable free AV programs.I think its time for the p4 http://www.avg.com/faq.num-1230#faq_1230 1230:Setting scan process priority The priority of the scan process defines how fast will the scan run, and how much system resources will it use. In other words, you can set the scan to run as fast as possible while slowing down your computer noticably, or you can choose that you wish the test to run using as little system resources as possible, while prolonging its run time. There are three options for the test priority in AVG: Fast scan = shortest scan time, highest usage of system resources The Fast scan does not leave any time gaps between reading files on the computer, and the scanning runs in multiple threads to utilize even multi-core processors. The Fast scan is recommended when the computer is not used or no other demanding application is running at the same time. Slow scan = LONGEST scan time, lowest usage of system resources The Slow scan leaves time gaps between reading individual files, so that other applications can access the data on the computer with minimal delay. The scanning itself also runs with lower priority, in single thread, and with lower memory demands. Automatic scan = both scan time and generated system load depend on current computer load In the Automatic mode, AVG is adjusting the scan priority and gaps between files based on current system load, thus minimizing the impact of the test on the system, while finishing the test in shortest possible time. The scan priority can be set for both running and scheduled test: Running test Please adjust the slider in the window of currently running test (AVG User Interface -> Computer scanner -> running scan). Scheduled test In Computer scanner, please double-click on the scheduled scan and switch to the tab "How to scan". After setting the priority, please click the "Save" button to store the configuration.Upgrade components to get the antivirus scans to run faster? I understand the reasoning but you can't be serious! Also not everyone can afford to, or even knows how to, buy and replace a HDD or even RAM. @newgranny - No. Buying the software will not increase the scan speeds. The only thing that full versions offer in terms of speed are updates. And I don't FULLY believe that. They all COME from the same server... A few things to consider. Unless you are going to a lot of dangerous web sites, or downloading a bunch or torrents/shady software, you don't need to worry to much about running malware scans every day. Sensible web surfing greatly reduces the need to run full antivirus scans. As long as you have the real-time protection running your usually safe and can only run a full scan once a week or even once a month if you think you are being safe and the computer isn't acting funny. Also before running a scan do a disk clean up and maybe even defragment the disk. Restarting the computer just before starting the scan will also reduce scan times. The fewer things running the better. Do scans when you are away from the computer. agreed. average user doesnt need to do a complete scan that frequently, although even those that do, can set it to scan as they sleep, whatever time that may be. I use a common commercial antivirus it runs quietly in the background and picks up any nasties as they occur-no need to run complete system scans all the time. Well worth the $20 it cost me after rebate on sale every fall. One thing missing from the post, is how much memory is installed-you WANT more than 256mb. Lastly, if there is not much "free space" left on your Hard Drive, this can slow down everything you do, considerably. I can get away with your system no problem. I like the pentium3's. |
|
| 2544. |
Solve : how to get free virus protection? |
|
Answer» this computer is a secondary computer sharing a modem of another computer which is protected with avg free.i tried to load avg on this system but it said i need an upgrade or somethin to get protection. also am i right when they say only one computer PER household?i also tried to load a norton trial one and it said basically the same thing.is there an OLDER VERSION of these versions to cover an xp home EDITION[this is an ex office computer and my dad also refers to it as an windows xp proffessional]can anybody help me?nicoleIt sounds like it isn't a valid copy of Windows. |
|
| 2545. |
Solve : McAfee Virus Scan error: ffff95b@2? |
|
Answer» I tried to scan a newly downloaded .exe file before I opened it. I got the message: The virus definitions database that you are using is 41 months old. There is a chance that VirusScan does not detect some viruses that were found during this time period. uninstall mcafee restart They were just told not to install it.... Some know "better" |
|
| 2546. |
Solve : HELP! Virus/spyware is preventing internet access!? |
|
Answer» The online scanner never FINISHED even after a few DAYS. I EVENTUALLY decided to get Kaspersky because I had no anti-virus scanner ANYWAYS. After scanning with Kaspersky, that Exploit.Java.Gimsh.a was all it found and it was DELETED. |
|
| 2547. |
Solve : The Stubborn Folder? |
|
Answer» Hi all, I have this Image.exe icon that looks like a regular folder-- a little more opened, that pops back everytime I delete it (some kinda virus, right?) in my USB thumb drive. I have a Norton Antivirus 2008 installed and regularly updated (just updated it a few minutes earlier), and all other details may be found in the attached HIJACK This report (renmed it to That One just in case a MALWARE recognizes it) what should I do to get rid of it?
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection. ---------- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE - O4 - HKLM\..\Run: [My App] C:\WINDOWS\system32\Image.exe - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present - O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "Alcmtr"=- "My App"=- Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, ETC) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Hi evilfantasy, you replied me a few hours later but it took me all those days to have a connection and see your post Sorry for that, and thanks a lot for your interest. I've done all you said except for: 1- It took forever (well, 30 minutes) for Flash_Disinfector.exe and my desktop didn't reappear so I pressed ctrl+alt+del and run explorer.exe 2- Didn't have - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present in my Hijack This log. That's all and the Stubborn Folder seems to be no more-- at least for now, and here's my Hijack This and ComboFix reports along with a picture of how the Stubborn Folder looked like. P.S. I think we've met before (of course you've helped me before) thanks again. Is it clean now? [attachment deleted by admin]
Download Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
|
|
| 2548. |
Solve : problem solved (I hope)...logs posted? |
|
Answer» I believe I had a TROJAN? called virtumonde. Lots of pop-ups and my windows update was disabled. I went through your Malware Removal Steps and the SuperAntispyware SEEMED to FIX my PROBLEM but I finished all the steps anyway. An all CLEAR and any other advice would be awesome. Thank you SO much! |
|
| 2549. |
Solve : Dr watson Debug error logs? |
|
Answer» I was online and my volume control popped up, with out clicking on it. Computer locked up. Reboot computer and got error for Dr. Watson debug came up. Searched web and found this forum. Done everything listed, and i am posting logs. hope i posted in right place.
---------- Open HijackThis and SELECT Do a system scan only. Place a check mark next to the following entries: (if there)
Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: [Select]REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run] "pyyjumvvmdpa"=- "Spyware Begone"=- Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry. Make SURE that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is RUNNING. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixOk I done as asked, this is the log i have now for you. Thanks [attachment deleted by admin]
Once downloaded please close ALL open browsers, also save any work because this may require a restart.
----------
---------- How is the computer running now? ,Computer running much better. thanks for help. One more thing if you can help. Dell Dim 4550 Windows xp how do you disable log on to windows screen before computer boots completely up. thanks againGet Rid of the LOGON Screen - http://www.mydigitallife.info/2007/11/11/disable-and-turn-off-windows-xp-login-screen-and-show-traditional-nt-log-on-to-windows-box/ Final steps to help secure your PC. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before. For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a RISKY website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2550. |
Solve : Right Clicking Folder Freezes Computer? |
|
Answer» Hello again, |
|