InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2651. |
Solve : Need help removing RedGirl Trojan? |
|
Answer» I am running Windows XP and have completed the Malware Removal Guide protocol. I am using the up-to-date free versions of AVG, Malwarebytes, and SuperAntiSpyware. |
|
| 2652. |
Solve : what is wiaup.exe ?? |
|
Answer» this showed up in my RUNNING proceses, i CHECKED with previx and its under review,so i thought i WOULD check here. i use anvir task manager and it says its from microsoft but it could be fake. any help would be cool!!! also here is a screen shot! Files with the NAME WIAUP.EXE have been seen to have the following Vendor, Product and Version Information in the FILE header:thank you for the info, i like knowing what is running on my system and this thing was driving me nuts , i could not find any info on it . so thanks again for your time!! |
|
| 2653. |
Solve : backdoor trojan? |
|
Answer» i think my pc was invaded by a backdoor trojan. i followed the instructions from evilfantasy and am attaching the txt files. i really appreciate your help with this. |
|
| 2654. |
Solve : Slow and Sluggish? |
|
Answer» My machine has been SLOW and sluggish lately and my CPU Usage had been running consistently at about 50% or higher all the time. After I ran through all your steps it's now running at 1-4% Usage. Here are the requested logs.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you KEEP from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you very much for the help, it's appreciated. |
|
| 2655. |
Solve : Need a overview to see if I'm ok? |
|
Answer» Hey Everyone, thanks for your help in advance. |
|
| 2656. |
Solve : New Laptop, what should I protect it with?? |
|
Answer» To keep it as clean as possible? Firewall, anti virus, spyware. Which ones? Please |
|
| 2657. |
Solve : hope i did this right? |
|
Answer» followed the post and attached the logs. added the registry scan . |
|
| 2658. |
Solve : Weird behaviour? |
|
Answer» Ill get logs my computer just started freaking out. |
|
| 2659. |
Solve : Hijack this log.....? |
|
Answer» Attn: Broni: |
|
| 2660. |
Solve : repetative trojan cleaned but not removed?? |
|
Answer» Hi, |
|
| 2661. |
Solve : Infected Computer Help? |
|
Answer» Pretty sure my computer is infected. Have had odd behavior for a week or so & I just noticed a different log in on a newsgroup account that I use. This pretty much started after I let someone use my computer while I was away. If one of you kind EXPERTS could check out my logs (hopefully I did them OK) it would be GREATLY appreciated. |
|
| 2662. |
Solve : Hijacked Search Engine - With a Twist? |
|
Answer» HI Guys, i have an issue with the other halfs laptop and im pulling my hair out... Basically what happens it that when ever you search for anything in google it brings up the kind of links you would expect but when you click them they alternate off to other search engines or porn sites... i tried going to microsoft pages and they are blocked, they go to a 404 error with a Search @hand header on the page... this i get the impression is normal but this is the twist... When you try to follow the outlined steps here with the Malwarebytes and SUPERAntispyware it wont let you update them so you are left with what it came with (49 day out of date according to SUPERAntispyware) - im unsure runnin them will make much difference as she as only had it for a day or so i have run the usual spybot etc but come up with nothing found at all i have run ccleaner for other items that outlined in posts with the same issue but no matching files, i have CHECKED things on process explorer too but to no avail. here is the Hijack this log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:00:55, on 19/11/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\eHome\ehmsas.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\AVG\AVG8\aAvgApi.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\SearchProtocolHost.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=2057 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300" O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdoxx.exe] C:\WINDOWS\system32\kdoxx.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu ITEM: &Search - ?p=ZJfox000 O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O9 - Extra BUTTON: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371030.cab O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.broadbandassist.com/bbdesktop/PreQual/files/MotivePreQual.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{88B86558-FBE7-47CE-9689-D1506820D6D2}: NameServer = 85.255.112.155;85.255.112.135 O17 - HKLM\System\CCS\Services\Tcpip\..\{D1F7B376-88AD-4792-A1F5-9194007E542E}: NameServer = 85.255.112.155;85.255.112.135 O17 - HKLM\System\CS1\Services\Tcpip\..\{88B86558-FBE7-47CE-9689-D1506820D6D2}: NameServer = 85.255.112.155;85.255.112.135 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe -- End of file - 8930 bytes Any help would be great on this Although the virus definitions are outdated, try scanning with MBAM and SAS anyway. This is a fairly common type of virus, so the programs may be able to detect it. When you run the scans, post the logs here along with a new HijackThis log. |
|
| 2663. |
Solve : Task Manager was disabled?? |
|
Answer» I can't bring up task manager, I get a message saying that it was disabled by the administrator. I'm the ADMIN on the computer and the only one that uses it. How can I turn it back on? I was told in ANOTHER thread that it was MALWARE but when I scanned for my computer it was CLEAN. BTW I'm using Windows XP.Have a LOOK here: Have a look here: Thank you! Method 2 worked for me.Good job. oops! Sorry it was method 3 that worked.Ok thanks. Did the others not work?Quote from: Carbon Dudeoxide on November 19, 2008, 12:00:19 AM Ok thanks. Did the others not work? Method 1 didn't work, I tried #2 from a suggestion on the other thread and had no luck. Method 4 didn't apply since I don't have XP Pro.All right. |
|
| 2664. |
Solve : Computer dialing whenever it desires...? |
|
Answer» Ok, started a new post and here are my log files. I do have another question but don't know if you are into Linux but I have it installed on another computer. The only think I haven't got working is my dial up modem. Any thoughts? SORRY, but I'm a NOVICE at best when it comes to Linux. I've only toyed around with it on a few occasions and don't yet comprehend how everything works. If you'd like assistance, I suggest heading over to our Linux section. They should have better luck at helping you or at least pointing you in the right direction.Ok, thanks for you have done for me. I'm curious, where are you located? I am in Southern Oregon. JohnI currently live in Bakersfield, CA. |
|
| 2665. |
Solve : rootkit virus? |
|
Answer» i have a virus which my avg cannot deal with along with my anti spyware. my os is xp and any help much appreciated. i have attached my logs. |
|
| 2666. |
Solve : Virus? Can't get past my desktop into any programs? |
|
Answer» I am USING Windows Vista on a Compaq Presario C700 Laptop. dir C:\WINDOWS /a h > win.txtWith Notepad still open, go to File > Save As. Click on the arrow next to Save As Type and select all files. Name the file scan.bat and place it on your infected computer's desktop. Double-click on the file and in only a few seconds, three Notepad files should appear on your desktop: win.txt, sys32.txt, and pf.txt. Attach these files in your next post (you will have to use a flashdrive to transfer them to your working computer). To attach files...while on the Post reply page of the forum, click on Additional Options underneath the text box. You will then see an option to attach files. If this works, it will take me a long time to go through all of the information to sort out infections. It could take me at least a day to find them. And I won't be able to find infections in all areas of your computer, but I can find what's lurking in the most popular spots. With any luck, we might be able to disable whatever's locking up your computer so we can perform normal scans. If my suggestions don't work, then you may be stuck with options #1-4. Another possibility to consider is that this might not be an infection. Many infections don't work in Safe Mode, so it's possible that we're dealing with a hardware problem here. However, I have been dealing with several infections this week that do work in Safe Mode, so it's hard to say what this culprit is right now. |
|
| 2667. |
Solve : The DNS Problem. Does it matter?? |
|
Answer» Maybe this is not the right place to post this, but I think it does matter. Do you? |
|
| 2668. |
Solve : Virus Eradication help? |
|
Answer» Hello, This is my first time posting on this site. |
|
| 2669. |
Solve : Mcafee? |
|
Answer» I have mcafee on my laptop which is running vista. Is just having mcafee enough or do i need more stuff ?listen MCAFFE is a realy bad antivirus to start out with. it collides with windows witch is slowes it down and ALSO the quarentiner SUCKS i gave windows live onecare its good but not as good as avg |
|
| 2670. |
Solve : BV:Malware-gen please help!? |
|
Answer» Ok so I've been fighting this BV:Malware-gen thing since Thursday evening and so far it keeps coming up when I do an avast! scan. I just went through all of the Malware Removal Steps that are posted on this site and the viruses are still coming up on the scan! please help me! ATTACHED are the logs for the SuperAntispyware, Malwarebytes' Anti-Malware, and HijackThis SCANS that I just did. Please try and run these virus and malware programs in safe mode for better results.Please, do not advice on security issues, if you don't know what you're talking about.If you going to MAKE a comment that I don't know what I'm talking about why don't you explain the reason for it and why its not effective? I have found safe mode to be very effective.Simply because, some malwares won't show up in Safe Mode. Some antimalware programs, like Superantispyware, are specially designed to run in Safe Mode, but most of them are designed to be run in Normal Mode. Safe Mode is used only, when computer is not operable in Normal Mode.Ok I finally was able to take care of the problem so thank you to all who replied.Thank you for keeping us updated, silent_dreamer. I'm glad you were able to find a solution. If you end up needing further assist, feel free to come back. And I'm sorry, Broni, but I'm going to have to side with lostcoast on this one. There's no reason for malware scans to be any less effective in Safe Mode. In fact, the general consensus is that they're usually more effective in Safe Mode. While in Normal Mode, some infections can hide themselves from scanners or even disable them. But in Safe Mode, this is less likely to be an issue.Hmm...that's something totally new to me. I think, you'll have to ask evilfantasy to re-write all his instructions, so from now on, we run all scans in Safe Mode. I thought, that scans are to be run in Safe Mode, only id Normal Mode is not operable, but what do I know? I think, we're gonna awake to a big surprise, when after cleaning all infections in Safe Mode, we restart in Normal Mode, and....what?....more bad guys showing up? Do you have any source, CHRIS, showing, that all antimalware scans should be run in Safe Mode?Well, for the sake of convenience, we usually don't have users run their scans in Safe Mode unless we think there's a reason to do so. For instance, if a certain infection can't be removed, running a scan in Safe Mode will normally take care of it (unless it's a very stubborn infection). Most of the time, a Normal Mode scan should suffice. But when a virus is causing problems and disabling software, the symptoms are usually worse in Normal Mode, right? Their more dormant state in Safe Mode makes them more susceptible and allows the antivirus to sneak up on them. Unfortunately, I don't have any "official" sources; this is all from experience and what I was taught at G2G. So, I'm not aware of any articles and I'm honestly not even sure where to look for any. But if you look around online and in forums, you can find plenty of people who agree with what I've said here: http://www.aarp.org/learntech/computers/howto/better_safe_mode.html http://soundbytes.org/phpBB2/viewtopic.php?t=11788&sid=a7afa9da08138bfe1966e8be52732913 http://wiki.castlecops.com/AntiVirus_Comparison (near the bottom) One thing: not all scans should be run in Safe Mode. Some programs such as ComboFix, some versions of BitDefender, and certain anti-rootkits won't work in this mode.So, I assume, the whole argument was about nothing... |
|
| 2671. |
Solve : Spyware and trojans and scripts. OH MY!? |
|
Answer» My computer has started to slow down and Avira anti-virus has detected several scripts and trojans in the past few days. I have downloaded and run the programs promoted on this site and then I removed anything they came up with. I just wanted to post logs and have you guys CHECK if I missed anything. |
|
| 2672. |
Solve : windows explorer problem? |
|
Answer» I had been having a problem with Windows Explorer. I would be browsing through files, and about 5-6 seconds into it, it would tell me that it had an error and needed to be closed...I followed the steps you GUYS provided, and I think everything is working now...anyway here's the logs that I got out of SuperAntiSpyware and Anti-Malware and HijackThis...let me know if you see anything else - THANKS! |
|
| 2673. |
Solve : laptop infected? |
|
Answer» Hi my gateway laptop is infected I did all of the scans needed also I RAN ccleaner here's my logs |
|
| 2674. |
Solve : **STILL HAVING PROBLEMS, PLEASE HELP!!**? |
|
Answer» Piece of crap still won't work. Can't do anything in safe mode. The minute I try to type something in that line after I hit run the piece of crap freezes up. Now what? Sorry, I've just been at this about 12-16 hours a day for the last 2 weeks, and I'm ready to give up. This things been a total pile of junk since I got it, I should have sued the idiot that sold it to me.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. |
|
| 2675. |
Solve : blocking ads? |
|
Answer» What is the best way to block ads from the internet? I have Internet Explorer and I WANT to block any type of ads |
|
| 2676. |
Solve : Cannot open any program from desktop icons or open files from jump drive...VIRUS? |
|
Answer» And here is my most recent hijackthis log and I ran it while the Roxio Media Manager was trying to install in hopes hijackthis would give you something to work with.... |
|
| 2677. |
Solve : Weird "Welcome Screen" Freeze? |
|
Answer» HEY everyone. I've had my laptop for about a year. Sometimes, when I would type in my password to log into my desktop, it would freeze at the Welcome Screen for a bit, then once I get to my desktop, its just a black screen with my MOUSE. When I first got it, it only happened once every 2-3 weeks. Now, it happens more than once every week. I am able to use Task Manager while on this black screen, but my desktop ITEMS don't load. It starts after I type in my password, then I have to wait a much longer AMOUNT of time for it to load to my desktop than normal Normal would be about 10 seconds. The weird freezing would be about 3minutes. Is something wrong inside? Or what? I'm completely stumped. Thanks in advance. - ZainAnyone there? i had a similar problem :S, i noticed that my internet was loading slow, so I reset the computer to run scans in safe mode, but then my desktop stopped loading and got frozen at the welcome screen, using XP plz help Sweeet, IM not alone! I just don't get how some days it would load perfectly fast, and on some days it would load SOOO slow, and the welcome screen would take forever to get on the desktop. But once it gets on the desktop, i have to wait like..another 10minutes for it to load. When I restart it a couple of times, it gets back to normal. |
|
| 2678. |
Solve : Could you check my logs and see if everything is clear on my system?? |
|
Answer» I have had problems with my computer since buying it from a friend. I do have System Suite 8 (Avanquest) security software and it has (I thought!) removed alot of spyware, adware, and a couple of Trojans that were apparently already on it! But within the past month I started recieving notification of Port Scan attempts from my firewall; they were all blocked. A couple of weeks ago my husband was on the computer and when I logged on the next day their was this Spyware threat balloon that kept popping up on my task bar, the desktop background had been changed (saying spyware threat had been detected on my computer and to click link for full system scan, which I DID NOT do!) Also kept getting these windows popping up on my desktop saying WinSec Alert: Trojan Found or Spyware found and would give various names of these Viruses. Also anytime I would go online a pop up would re-route me to a (bogus) WinSec Update site, trying to get me 2 download and/or buy their product. I of course did NONE of the REQUESTS, but I could NOT get rid of this crap on my computer; ran full virus & spyware scans with System Suite, and even downloaded Windows Live one care and ran full scan with it several times (it picked up a couple of things and supposedly quarentined them). No luck until today that is, I found your site and did all of the steps recommended by "Evil". My computer background is back to normal, no more annoying balloons, pop-ups etc. I just want to make sure that everything really is "Clean". Here are the logs as requested, if there is anything else I need to do to ensure that my computer is FINALLY clean and clear please let me know. You have already been so much help, all I can say is THANK YOU , THANK YOU, THANK YOU!! |
|
| 2679. |
Solve : Search engine virus? |
|
Answer» It is a little small, but I've seen smaller. It's not NECESSARILY the size I was worried about...GMER LOGS are just a bit of a PAIN to read in most cases. Thankfully, yours appears to be pretty ordinary. |
|
| 2680. |
Solve : CAN someone delete this please?? |
|
Answer» Hi, I tried to delete it, but it says I can't delete my own post. I am receiving help on ANOTHER site, and would like to remove my request for help here.... just not sure how..... Thank you, Tina Hello, Thank you in advance to anyone willing to help with my problem, you are greatly appreciated. Okay, so I left for an hour last night, came home, and the boyfriend says,"Fix the computer, will ya? Something happened"....... I don't know what happened, but our computer is SO messed up. My Superantispy wont work, firefox wont work, most of internet explorer wont work, except for this page (compuethope), ironically, after TRYING for a long time to open ANY page that may help.... .um... hijack this won't analyze to the internet... I've restarted in safe mode, (and all the different types of safe modes) and tried the programs again, same problem. Here's the hijack log thing I just ran, Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:25:00 AM, on 12/3/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) BOOT mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\WINDOWS\system32\NMSSvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe O4 - HKLM\..\Run: [PDF Complete] "C:\Program Files\PDF Complete\pdfsty.exe" O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe O4 - HKLM\..\Run: [LayoutM] KLayMgr.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ZipCD\EASYCD~1\CreateCD\CreateCD.exe -r O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ZipCD\directcd.exe O4 - HKLM\..\Run: [vxbqxzzypdpjtuc] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\epeuasanumnthe.dll" O4 - HKLM\..\Run: [{90BF8224-CD63-4081-A4C7-EF9A2CF6596F}] "C:\Documents and Settings\All Users\Application Data\065E7536.exe" O4 - HKLM\..\Run: [vhostcheck] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tornew.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Documents and Settings\Administrator\Desktop\Stuff from old coumpter\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Cognac] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\~tmpb.exe O4 - HKCU\..\Run: [MSFox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\yyy14529.exe O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe O4 - HKCU\..\Run: [winhpdrv] "C:\Documents and Settings\Administrator\Application Data\Google\xtgoj6119471.exe" O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} (TPIR Control) - http://www.worldwinner.com/games/v50/tpir/tpir.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224903219390 O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - http://www.worldwinner.com/games/v44/golfsol/golfsol.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support PACKAGE) - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: xyutae.dll,avgrsstx.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\Shared\hpqwmi.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) NMS (NMSSvc) - Intel CORPORATION - C:\WINDOWS\system32\NMSSvc.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- End of file - 7672 bytes I hope that I'm able to keep in contact with you, as my computer is SO instable hey Im no pro but I did get the superantispyware running by right clicking on the shortcut on the desktop and using the "find target" button and then running the application file directly. It started right up. Check my subject for other info i have found so far.Thanks for informing us that you are getting help elsewhere. I will lock the topic now. |
|
| 2681. |
Solve : I followed the steps but they are not working. Different computer It's dell wind? |
|
Answer» Yeah I can check around for a disk. Thanks for all your help. |
|
| 2682. |
Solve : Computer infected with Vundo virus help!? |
|
Answer» Hello i have the vundo virus on my computer and i cannot do anything my antivirus is SAYING everything is malicious activity on any program i click on and that it is the vundo.gen virus . Please help... i can do scans in safemode and that is all. Regular mode is unusable. Vundofix finds nothing. Spybot finds something and trys to remove but is unsuccessful. Malware bytes finds a couple of things says successful but rescan and infections are back. i tried deleting the registries that i found from another site and ending the process in winlogin and deleting file in safe mode to no success. This was a couple of days ago that i tried all this. |
|
| 2683. |
Solve : Logs for following malware removal steps? |
|
Answer» Please can someone look at my logs, not sure if I got rid of all virus. I've run through the malware removal steps and here are my logs for superanti spyware/malwarebytes anti-malware/HJT |
|
| 2684. |
Solve : Spybot Junk? |
|
Answer» When I run spybot it picks up something called right click media or something then I get rid of it but when I run it again its still there.Quote called right click media or somethingThank you for telling us what it is. Now we know how to deal with it....... What is the exact item called?Its called right media I dont think its doing anything from what I see but then again. It just stays.It's just a cookie most likely.I have adaware an it didnt find it. Have the latest defs so it should have caught it if it was.http://en.wikipedia.org/wiki/Right_Media It's nothing to worry about. You pick up cookies on every web site you visit. Cookies are not dangerous. See here. http://www.computer-juice.com/forums/f53/true-story-about-cookies-7542/I now that its just that it wont go awayPost a Hijackthis LOG.it shows up on both of these machines. Try an use as much detail as possible I fear these kind of programs like crap cleaner with out nowing what I'm doing. [Saving space - attachment deleted by admin]Black Pc Uninstall AVG Anti-Spyware. It is no longer supported so is actually doing no good. Turn OFF TeaTimer. Disable Spybot's TeaTimer While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes. Please disable TeaTimer for now until you are clean. 1. Right click Spybot in the System Tray (looks like a calendar with a PADLOCK symbol). Choose Exit Spybot S&D Resident 2. Run Spybot S&D 3. Go to the Mode menu, and make sure Advanced Mode is selected. 4. On the left hand side, choose Tools > Resident uncheck Resident TeaTimer and OK any prompt and Restart your computer. Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it. If TeaTimer will not turn off then uninstall Spybot until we are done cleaning. ---------- Download Malwarebytes' Anti-Malware (MBAM)
Malwarebytes' Anti-Malware 1.30 Database version: 1387 Windows 5.1.2600 Service Pack 2 11/12/2008 7:15:13 AM mbam-log-2008-11-12 (07-15-13).txt Scan type: Quick Scan Objects scanned: 18092 Time elapsed: 5 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) So everything is okay then? |
|
| 2685. |
Solve : UFE's Unidentifed exeuctetables (SP?) Found on My PC! HELP?? |
|
Answer» hi there folks |
|
| 2686. |
Solve : ...same trojan as you folks...? |
|
Answer» I've been dealing with this crappy virus since Friday. :'(Kept my McAfee from updating but I couldn't download any other security packs or even get to any ANY security sites or any link remotely involved in security! I googled the virus traits and the SEARCH lead me here. I read the posts and followed the instructions for all the malware and security downloads. I put them on a flashdrive (from another computer since I couldn't even use any links you folks posted here), LOADED them, and followed all the instruction for scanning. After turning off the TSS.... whatever.... thing, and re-starting my computer, IMMEDIATELY my AVG picked up a Trojan (TDSSXNAQ. ???DLL) and a second scan with the Malware picked up 4 more, including the BACKDOOR! |
|
| 2687. |
Solve : hijack this file? |
|
Answer» Scan with Panda ActiveScan
[Saving space - attachment deleted by admin] |
|
| 2688. |
Solve : BSOD [Blue Screen of Death] :(? |
|
Answer» Hey everyone. the laptop is about 3 years old. it could be a fault with the battery; not sure about life expectancies, but the battery supplies power whenever it is inside the laptop; even when the AC is plugged in and the battery is charged. If the battery is giving out the wrong voltages/too much, etc, you could suffer memory errors and reduced battery life.Also, can you try reseating the RAM.My adapter and battery are like..compatible with each other, so I dont think its getting too much or too little. and if by reseating, you mean taking out the RAM cards and putting them back in, i already tried it several times. Sometimes it would work, sometimes it wouldnt. and i just figured out that sometimes, even if i dont move my computer, the blue screen comes up and i have to restart my computer. once i restart it, nothing appears. its just a black screen , once i press the power button. EDIT 1: I have also realized that when the blue screen comes up, it says "A problem has been detected and windows has been shut down to prevent loss to your computer. PAGE_FAULT_IN_NONPAGED_AREA" Then it says: if you have not seen this before, just restart your computer Check to make sure that newly installed hardware or software is in right. [i have no newly installed items, for the past month] then it says that if it continues, disable or remove any new installed hardware or software, disable BIOS memory options like...caching and shadowing. I dont want to disable any BIOS things, and I dont have any newly installed stuff. What should I do? The only thing that i thought about was that this problem could be due to my RAM cards. Since only 502MB out of 1gig RAM got detected, maybe thats whats messing up the computer, and making all those blue screens come up. Im not sure at all though. Thanks in advance - Zain what I meant was the battery could be going; since all power when the battery is in the laptop goes through the battery, the effect will be felt regardless of wether the AC is connected. Do you have to reboot to GET the laptop to recognize it's RAM when your just on AC with no battery?Yes. Only 502 MB out of 1024MB gets recognized , even with just the adapter and no battery. I also realized that if my computer only detects 502MB , it doesnt give the blue screen. It only happens when it fully detects all the RAM. I tried it with battery, and without , and yet it still recognizes only half my RAM. Just a side note, if you want to add me on msn for convenience, its: [emailprotected] thanks [Was someone trying to reply just a few seconds ago?]is it a dell? if so go to http://en.community.dell.com/blogs/direct2dell/archive/2007/06/25/17311.aspx?PageIndex=3 that my help you the "bad seed" file is PCD5SRVC.pkms FYINope, its a Toshiba x( Still having problemmsssok maybe the ram hence the page file bsodsounds like your laptop has two sticks installed, and one of them is AWOL, OR, in need of reseating. if you can access the RAM (my toshiba has a screw holding on a plate with the RAM beneath that, easily accessible with a philips), first, try reseating both modules. If you still have the same symptoms, it's possible the RAM stick in the higher numbered socket is going/gone. How do you know which one is the "Bad one"? WELL, as you have it now, it sounds like the higher numbered socket has some bad RAM, as I said in my last paragraph. If for some reason they aren't labelled, however, you can isolate the bad stick by having one inserted at a time; the good one will consistently be detected as 512, the other will either not boot at all or result in an error message most of the time. BTW, I feel your ram problem and the BSOD are closely related. wether it's related to your reduced battery life, perhaps; the bad stick could be somehow drawing more then it should (short circuit?) or something; just conjecturing on my part, though.That's similar to what i was thinking. I'll try out the different sticks, and see if the computer boots with 1 each time. Brb. |
|
| 2689. |
Solve : LOL OMFG, stupid chain email? |
|
Answer» Ha, i got a laugh reading this crap in a chain email sent to me. |
|
| 2690. |
Solve : Reg: ntoskrnl.exe blocking applications? |
|
Answer» HELLO all, am usig symantec ENDPOINT protection 11.0 for antivirus but after installation it SHOWING below notification ... i unchecked firwall but it still showining the same message.... i also CHECKED boot.ini file whether any thirdparty kernal is the reason for this message but its not... because of this am unable to open some webportals.... so i uninstalled symantec and checked all are working and am able to access those websites also.... could any one please help on this..... ""TRAFFIC HAS BEEN BLOCKED FROM THIS APPLICATION NT. KERNEL & SYSTEM (ntoskrnl.exe)"" thanks & regardsis this your infector or one of these? infector/http://vil.nai.com/vil/content/v_147447.htm/ search results/http://search.mcafee.com/search?q=ntoskrnl&site=us_site.Virus&num=10&entqr=0&output=xml_no_dtd&sort=date%3AD%3AL%3Ad1&getFields=description&ie=UTF-8&client=default_frontend_us&ud=1&oe=UTF-8&proxystylesheet=default_frontend_us®ion=us&partialfields=&getfields=description&filter=0 tell me witch oneno, the problem has been resolved... i tryed by putting ntoskrnl.exe in "Centrilized Exception " option on symantec... now its working FINE... thanks for your support...thats what were here for |
|
| 2691. |
Solve : Hallmark Virus? |
|
Answer» I have recieved a message from a former work collegue REGARDING a so called "Hallmark card" virus. Actually it is a virus, the card comes as an attachment and includes a trojan. True, these postcard viruses do exist (psiloveyou for example), but they certainly don't erase the ZERO sector as the e-mail implies. The majority of them are no more than mere annoyances. |
|
| 2692. |
Solve : what the best anti virus?? |
|
Answer» whats the BEST anti-virus please post the LINK to download |
|
| 2693. |
Solve : Desktop infected with Virus, Please Help (logs included)? |
|
Answer» Hi,
Open the SDFix folder and double click RunThis.bat to start the script.
Below is my log: SDfix SDFix: Version 1.231 Run by David on 13/12/2008 at 04:08 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-13 04:13:54 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:86486ada "s2"=dword:11da2437 "h0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools\" "h0"=dword:00000000 "khjeh"=hex:a0,29,82,9a,c5,63,6f,ec,ae,3b,cf,23,b7,08,1f,98,ef,66,f3,72,e8,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,19,47,61,3a,36,a3,aa,58,79,2c,a7,34,67,f4,07,56,2f,.. "khjeh"=hex:3d,48,39,f0,90,26,5c,0f,14,db,ee,72,17,e6,4a,69,05,1f,a1,56,9a,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:cf,dd,13,65,09,6d,d0,91,e0,8f,98,ef,10,f2,51,e4,02,01,bd,5f,88,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools\" "h0"=dword:00000000 "khjeh"=hex:a0,29,82,9a,c5,63,6f,ec,ae,3b,cf,23,b7,08,1f,98,ef,66,f3,72,e8,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,19,47,61,3a,36,a3,aa,58,79,2c,a7,34,67,f4,07,56,2f,.. "khjeh"=hex:3d,48,39,f0,90,26,5c,0f,14,db,ee,72,17,e6,4a,69,05,1f,a1,56,9a,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:cf,dd,13,65,09,6d,d0,91,e0,8f,98,ef,10,f2,51,e4,02,01,bd,5f,88,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "p0"="C:\Program Files\DAEMON Tools\" "h0"=dword:00000000 "khjeh"=hex:a0,29,82,9a,c5,63,6f,ec,ae,3b,cf,23,b7,08,1f,98,ef,66,f3,72,e8,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001] "a0"=hex:20,01,00,00,19,47,61,3a,36,a3,aa,58,79,2c,a7,34,67,f4,07,56,2f,.. "khjeh"=hex:3d,48,39,f0,90,26,5c,0f,14,db,ee,72,17,e6,4a,69,05,1f,a1,56,9a,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40] "khjeh"=hex:f5,06,a9,58,da,59,3c,e8,4a,f8,18,6e,60,29,1a,2a,f1,5e,ce,db,1f,.. scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts] "hQ\37w\xe8d2?? ?(?T?r?u?e?T?y?p?e?)?"="avbbv.ttf" "hQ\37w\xe8d2\xf8f8N\xf4f5 ?(?T?r?u?e?T?y?p?e?)"="avbfv.ttf" "hQ\37wO\xe9a5??(?T?r?u?e?T?y?p?e?)"="avbkv.ttf" "hQ\37w\xe8d2\16f? ?(?T?r?u?e?T?y?p?e?)"="avbmv.ttf" "hQ\37w9??(?T?r?u?e?T?y?p?e?)?"="avbnv.ttf" "hQ\37w\xe8d2\23W? ?(?T?r?u?e?T?y?p?e?)"="avbyv.ttf" "hQ\37w\xf472\23W? ?(?T?r?u?e?T?y?p?e?)"="avdyv.ttf" "hQ\37wGW\16f? ?(?T?r?u?e?T?y?p?e?)??"="avemv.ttf" "hQ\37w\xf8f8N\xf4f5? ?(?T?r?u?e?T?y?p?e?)"="avfv.ttf" "hQ\37w0}\xf8f8N\xf4f5 ?(?T?r?u?e?T?y?p?e?)??"="avfv___0.ttf" "hQ\37w!|\xe8d2? ?(?T?r?u?e?T?y?p?e?)"="avgbbbv.ttf" "hQ\37w!|\xe8d2\16f ?(?T?r?u?e?T?y?p?e?)??"="avgbbmv.ttf" "hQ\37w!|-Nwi ?(?T?r?u?e?T?y?p?e?)?"="avgbkv.ttf" "hQ\37w!|-N\xf8f8N ?(?T?r?u?e?T?y?p?e?)?"="avgbmfv.ttf" "hQ\37w!|0}? ?(?T?r?u?e?T?y?p?e?)??"="avgbtbv.ttf" "hQ\37w!|0}\xf8f8N ?(?T?r?u?e?T?y?p?e?)?"="avgbtfv.ttf" "hQ\37wAm ?(?T?r?u?e?T?y?p?e?)"="avhlv.ttf" "hQ\37w\xebe4?? ?(?T?r?u?e?T?y?p?e?)?"="aviv.ttf" "hQ\37wwi??(?T?r?u?e?T?y?p?e?)??"="avkv.ttf" "hQ\37w???(?T?r?u?e?T?y?p?e?)"="avlv.ttf" "hQ\37w-N???(?T?r?u?e?T?y?p?e?)"="avlv___0.ttf" "hQ\37w-N?? ?(?T?r?u?e?T?y?p?e?)"="avmbv.ttf" "hQ\37w-N\16f? ?(?T?r?u?e?T?y?p?e?)??"="avmmv.ttf" "hQ\37w-N0}?? ?(?T?r?u?e?T?y?p?e?)"="avmtbv.ttf" "hQ\37w-N0}\xf8f8N\xf4f5 ?(?T?r?u?e?T?y?p?e?)??"="avmtfv.ttf" "hQ\37w-N0}\23W? ?(?T?r?u?e?T?y?p?e?)??"="avmtyv.ttf" "hQ\37w-N\23W? ?(?T?r?u?e?T?y?p?e?)??"="avmyv.ttf" "hQ\37w-N\16f ?(?T?r?u?e?T?y?p?e?)??"="avnmmv.ttf" "hQ\37w0}\16f ?(?T?r?u?e?T?y?p?e?)??"="avntmv.ttf" "hQ\37w掫S? ?(?T?r?u?e?T?y?p?e?)"="avov.ttf" "hQ\37w\31j\xe827wi??(?T?r?u?e?T?y?p?e?)"="avpkv.ttf" "hQ\37wwm1X? ?(?T?r?u?e?T?y?p?e?)??"="avpopv.ttf" "hQ\37w\31j\xe8270}\16f ?(?T?r?u?e?T?y?p?e?)??"="avptmv.ttf" "hQ\37wyr?? ?(?T?r?u?e?T?y?p?e?)"="avsbv.ttf" "hQ\37wyr\16f? ?(?T?r?u?e?T?y?p?e?)??"="avsmv.ttf" "hQ\37w?yr? ?(?T?r?u?e?T?y?p?e?)"="avssbv.ttf" "hQ\37w?yr\16f ?(?T?r?u?e?T?y?p?e?)??"="avssmv.ttf" "hQ\37wL\xf399f ?(?T?r?u?e?T?y?p?e?)??"="avsv.ttf" "hQ\37wyr\23W? ?(?T?r?u?e?T?y?p?e?)??"="avsyv.ttf" "hQ\37w0}?? ?(?T?r?u?e?T?y?p?e?)"="avtbv.ttf" "hQ\37w0}???(?T?r?u?e?T?y?p?e?)"="avtlv.ttf" "hQ\37w0}\16f? ?(?T?r?u?e?T?y?p?e?)??"="avtmv.ttf" "hQ\37w0}\23W? ?(?T?r?u?e?T?y?p?e?)??"="avtyv.ttf" "hQ\37w\23W??(?T?r?u?e?T?y?p?e?)"="avynv.ttf" "?Am?? ?&? ??Am??(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfftll7.ttc" "?艡? ?&? ??艡?(?P?)? ?(?T?r?u?e?T?y?p?e?)??"="dfftsm9.ttc" "?\20U?? ?&? ??\20U??(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dffttl8.ttc" "??\xf4f5? ?&? ???\xf4f5?(?P?)? ?(?T?r?u?e?T?y?p?e?)??"="dfftys7.ttc" "?0}?? ?&? ??0}??(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_b3.ttc" "?7Q0}? ?&? ??7Q0}?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_c3.ttc" "?7Q-N? ?&? ??7Q-N?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_c5.ttc" "?7Q\xe8d2? ?&? ??7Q\xe8d2?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_c7.ttc" "?7Q?? ?&? ??7Q??(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_c8.ttc" "?\xebe4?? ?&? ??\xebe4??(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_g7.ttc" "?\21\sY\xf28bW[W?3? ?&? ??\21\sY\xf28bW[W?3?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_h3.ttc" "?\21\sY\xf28bW[W?5? ?&? ??\21\sY\xf28bW[W?5?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_h5.ttc" "?\21\sY\xf28bW[W?7? ?&? ??\21\sY\xf28bW[W?7?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_h7.ttc" "?掫S? ?&? ??掫S?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_i5.ttc" "?7Qwi??&? ??7Qwi??P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_j5.ttc" "?7Q\xf4f5 ?&? ??7Q\xf4f5(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_n3.ttc" "?7Q-N\xf4f5 ?&? ??7Q-N\xf4f5(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_n5.ttc" "?7Q\xe8d2\xf4f5 ?&? ??7Q\xe8d2\xf4f5(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_n7.ttc" "??\23W? ?&? ???\23W?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_r9.ttc" "?O?x? ?&? ??O?x?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_w7.ttc" "?7Q\xe8d2\23W ?&? ??7Q\xe8d2\23W(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfft_y7.ttc" "?7Qyr\23W ?&? ??7Qyr\23W(?P?)? ?(?T?r?u?e?T?y?p?e?)??"="dfft_y8.ttc" "?&v?? ?&? ??&v??(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfft_z3.ttc" "?7Q-N? ?(?T?r?u?e?T?y?p?e?)??"="dflihm.ttf" "?i_6^? ?&? ??i_6^?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfttcd7.ttc" "?wm1X?W?1?2? ?&? ??wm1X?W?1?2?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dftthbc.ttc" "?Am+? ?&? ??Am+?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfttlx3.ttc" "?AmI\xf101??&? ??AmI\xf101??P?)? ?(?T?r?u?e?T?y?p?e?)"="dfttly3.ttc" "?tW[? ?&? ??tW[?(?P?)? ?(?T?r?u?e?T?y?p?e?)"="dfttmo9.ttc" "?\3^\1N? ?&? ??\3^\1N?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfttpdc.ttc" "?\3Z\3Z? ?&? ??\3Z\3Z?(?P?)? ?(?T?r?u?e?T?y?p?e?)?"="dfttww5.ttc" "?-N?? ?(?T?r?u?e?T?y?p?e?)??"="dftt_b5.ttf" "?\xe8d2?? ?(?T?r?u?e?T?y?p?e?)"="dftt_b7.ttf" "?\xf8f8N\xf4f5? ?(?T?r?u?e?T?y?p?e?)??"="dftt_f5.ttf" "?-Nwi? ?(?T?r?u?e?T?y?p?e?)?"="dftt_k5.ttf" "??? ?(?T?r?u?e?T?y?p?e?)"="dftt_l5.ttf" "?-N\16f? ?(?T?r?u?e?T?y?p?e?)?"="dftt_m5.ttf" "?\xe8d2\16f? ?(?T?r?u?e?T?y?p?e?)??"="dftt_m7.ttf" "?0}\23W? ?(?T?r?u?e?T?y?p?e?)?"="dftt_r3.ttf" "?\xe8d2\23W? ?(?T?r?u?e?T?y?p?e?)??"="dftt_r7.ttf" scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client" "C:\\Data\\4.Games\\Starcraft\\StarCraft.exe"="C:\\Data\\4.Games\\Starcraft\\StarCraft.exe:*:Enabled:Starcraft" "C:\\WINDOWS\\system32\\muzapp.exe"="C:\\WINDOWS\\system32\\muzapp.exe:*:Enabled:MUZ AOD APP player" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus" "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB" "C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"="C:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe:*:Enabled:Hellgate: London" "C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\GGclient.exe"="C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\GGclient.exe:*:Enabled:GG E-Sports Platform Client" "C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\Garena.exe"="C:\\Program Files\\Ocean Technologies & Media\\GG E-Sports Platform\\Garena.exe:*:Enabled:Garena" "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA" "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent" "C:\\Data\\4.Games\\Warcraft III\\war3.exe"="C:\\Data\\4.Games\\Warcraft III\\war3.exe:*:Enabled:Warcraft III" "C:\\Program Files\\eREAD6.0\\eREAD6.0\\eREAD_Cookcase.exe"="C:\\Program Files\\eREAD6.0\\eREAD6.0\\eREAD_Cookcase.exe:*:Enabled:eREAD 6.0" "C:\\Program Files\\Rhapsody\\rhapsody.exe"="C:\\Program Files\\Rhapsody\\rhapsody.exe:*:Enabled:Rhapsody" "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) " "C:\\Data\\4.Games\\Age of Empires II\\empires2.exe"="C:\\Data\\4.Games\\Age of Empires II\\empires2.exe:*:Enabled:Age of Empires II" "C:\\Data\\4.Games\\Age of Empires II\\age2_x1.exe"="C:\\Data\\4.Games\\Age of Empires II\\age2_x1.exe:*:Enabled:Age of Empires II Expansion" "C:\\Program Files\\QvodPlayer\\QvodTerminal.exe"="C:\\Program Files\\QvodPlayer\\QvodTerminal.exe:*:Enabled:QVOD" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "C:\\WINDOWS\\system32\\spoolsv.exe"="C:\\WINDOWS\\system32\\spoolsv.exe:*:Enabled:spoolsv" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files : Files with Hidden Attributes : Sun 21 Jan 2007 211 A.SHR --- "C:\BOOT.BAK" Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\advcheck.dll" Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\Tools.dll" Sun 21 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Sun 18 Sep 2005 788,568 A..H. --- "C:\Program Files\Online Services\Canada\KOL\client.exe" Wed 17 Aug 2005 13,459,528 A..H. --- "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\nsb-install-8-0.exe" Wed 17 Aug 2005 233,472 A..H. --- "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\webutil8.exe" Wed 17 Aug 2005 389,120 A..H. --- "C:\Program Files\Online Services\NetscapeOnline\Netscape Tech\WinsockFix.exe" Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\ACST4.DLL" Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLFIREWALLMGR.DLL" Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\AOLINSTALLERFW.DLL" Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90\INSTPH.DLL" Wed 14 Dec 2005 200,704 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\ACST4.DLL" Tue 22 Nov 2005 81,920 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLFIREWALLMGR.DLL" Tue 22 Nov 2005 73,728 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\AOLINSTALLERFW.DLL" Wed 14 Dec 2005 88,064 A..H. --- "C:\Program Files\Online Services\Aol\United States\AOL90E\INSTPH.DLL" Sun 18 Sep 2005 77,824 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\acs\AcsInstN.dll" Sun 18 Sep 2005 6,961,146 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\acs\acsnet.zip" Sun 18 Sep 2005 3,058,888 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\acs\acssetup.exe" Sun 18 Sep 2005 307,289 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\asp\aspcheck.dll" Sun 18 Sep 2005 7,083,361 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\asp\aspsetup.exe" Wed 21 Sep 2005 1,960,296 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\autoit\autoit-v3.zip" Sun 18 Sep 2005 550,488 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\deskbar\deskbr.exe" Sun 18 Sep 2005 553,984 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\flash\FlashAX.exe" Sun 18 Sep 2005 2,242,759 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\fw\nisale.exe" Sun 18 Sep 2005 24,064 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\fw\NISChk.dll" Sun 18 Sep 2005 57,344 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\ocp\ocpchk.dll" Sun 18 Sep 2005 748,728 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\ocp\ocpinst.exe" Sun 18 Sep 2005 7,515,304 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\qt\qt.exe" Sun 18 Sep 2005 86,016 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\qt\QTInsInf.dll" Sun 18 Sep 2005 45,056 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\rp\RealChk.dll" Sun 18 Sep 2005 5,111,296 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\rp\RealPl8.EXE" Sun 18 Sep 2005 4,378,673 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\rp\real_upd.exe" Sun 18 Sep 2005 360,448 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\rp\rp9codec.exe" Sun 18 Sep 2005 40,960 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\sysinfo\SiNdInst.dll" Sun 18 Sep 2005 473,736 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\sysinfo\SinfInst.exe" Sun 18 Sep 2005 12,288 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\tb\tbinst.dll" Sun 18 Sep 2005 516,032 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\tb\tbsetup.exe" Sun 18 Sep 2005 597,080 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\toolbar\toolbr.exe" Sun 18 Sep 2005 590,688 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\tpspd\TSsetup.exe" Sun 18 Sep 2005 57,344 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\tpspd\tsverchk.dll" Sun 18 Sep 2005 49,152 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\AOLVPChk.dll" Sun 18 Sep 2005 61,440 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\VPPrePop.exe" Sun 18 Sep 2005 3,858,056 A..H. --- "C:\Program Files\Online Services\Canada\KOL\comps\vwpt\Vwpt.exe" Sun 19 Feb 2006 24,576 A..H. --- "C:\Documents and Settings\David\My Documents\Documents2\1. School\Portfolio\Core\~WRL0001.tmp" Finished! Okay, things appear to be in order. And for future reference, Media Center was the correct choice. Recovery Console is to be used when you have serious computer problems. Now that you are done with these tools, go ahead and remove them. Now...I don't see an active virus scanner on your computer. It's very important to have one, so you should look into getting one such as AVG or Avast. You also need a decent firewall. Good ones to consider are Comodo, ZoneAlarm, and Kerio Sunbelt. Find one you like, disconnect from the internet, disable Windows Firewall, and install your new firewall and restart. Do the above and you'll be good to go!Hey, Thanks! You really helped me out. I appreciate it alot! I'll definitely recommend you if my friends have any trouble. Keep up the good work! I'll download the active antivirus and firewall right now. Hopefully I WONT get another virus haha Thanks again!You're very welcome. Just these programs up and running and it will significantly decrease your chance of getting infected again. |
|
| 2694. |
Solve : Search Engine Reroute Virus? |
|
Answer» I have a virus that reroutes every link I click to different websites. I've tried the malware mailcious websites information the administrators posted. Something is blocking my computer from downloading and/or using MBAM and SuperAntiSpyware AVG (AVG won't update) but I've completed everything else. |
|
| 2695. |
Solve : one remaining issue with trojan.vundo removal? |
|
Answer» thank you so much for this resource-- |
|
| 2696. |
Solve : BSOD. Rootkits. Trojan.? |
|
Answer» I have run into a bit of a snag trying to revive my computer that keeps getting a BSOD ~20 seconds after windows startup.
Open the SDFix folder and double-click RunThis.bat to start the script.
|
|
| 2697. |
Solve : I am requesting assistance in cleaning up my computer? |
|
Answer» Hello,
Open the SDFix folder and double click RunThis.bat to start the script.
Thank you for your assistance. It's nice to have a guru assisting me. I have run SDFix and attached the report.txt file. Let me know what to do next. Philip [Saving space - attachment deleted by admin]I'm happy to help, Philip. The next thing you want to do is copy the text within the code box below... Code: [Select]Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys] Paste that text into a Notepad file and then go to File > Save As. In the Save As Type section, select All Files and then save this to your desktop as tds.reg Double-click on the file to run it and when prompted, select Yes. Once you have done that, follow the below steps so I can get an additional log... Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop CLOSE any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. For Windows XP Systems install the Recovery Console: - If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes. - If for some reason your Internet is not working click No. - If you are not using Windows XP, you will not be prompted. - When prompted to accept the EULA click OK. - Accept MICROSOFT's EULA (Click Yes). - When you are told that the RC is installed correctly click YES to continue scanning for malware. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.CBMatt, I hope I did this right. The logs are attached. Philip [Saving space - attachment deleted by admin]Much better! How are things running now? There are just a couple more things you should take care of... Download OTCleanIt.exe and save it to your Desktop.
You'll also want to clean out your System Restore. This is to remove any infected files that have been backed up by Windows. Please follow these steps... 1. Go to Start > Programs > Accessories > System Tools > System Restore 2. Click on System Restore Settings. 3. Check Turn off System Restore and click OK. 4. Restart your computer. 5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK. 6. Create a new restore point and close the program. System Restore will now be active again. If you would like to learn more about System Restore, go here.CBMatt, Please accept my sincerest thanks. Is there anything else I need to do? Regards, Philip Patrick Everything looks good, Philip. You are good to go! |
|
| 2698. |
Solve : Do I have a virus/malware/spyware problem?? |
|
Answer» Hi all, |
|
| 2699. |
Solve : 3 logs....? |
|
Answer» updated... but IE will not open now...I'm running out of ideas here. Do you have a freind that has the same OS as you to borrow their install disk from? Windows XP Home Edition
here's the log... btw, E drive is my pin usb drive that i've been transferring files with... Process.exe;C:\SDFix\apps;Tool.Prockill;; A0052117.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP790;Trojan.Proxy.4472;Deleted.; cf2332.exe\327882R2FWJFW\psexec.cfexe;E:\cf2332.exe;Program.PsExec.171;; cf2332.exe;E:\;Archive contains infected objects;Moved.; SxxxxxDxxxxxFxxIxxX.exe\SDFix\apps\Process.exe;E:\SxxxxxDxxxxxFxxIxxX.exe;Tool.Prockill;; SxxxxxDxxxxxFxxIxxX.exe;E:\;Archive contains infected objects;Moved.; That didn't find anything new. I think you need to find a friend to borrow an install disk from and do a repair install. http://www.michaelstevenstech.com/XPrepairinstall.htm#RI I've suggested everything I know to this point. |
|
| 2700. |
Solve : Virus from program or outside source?? |
|
Answer» I have uninstalled Acentive's Internet Optimizer(Active Speed) recently and ran Malwarebytes anti-malware, the scan came up with some pretty interesting results Malwarebytes' Anti-Malware 1.30 As you can see at the bottom, there's three files infected all either in Ascentive's folder or the dll in the system32 folder. Could this be from Ascentive's ActiveSpeed or from an outside source?This is considered a rogue program that is often used to scam people. MBAM flagged the files as malicious because although they don't necessarily harm your computer, they are part of a program with malicious intent.so Acsentive's Active Speed is actually harming and not helping like it says?Use Site Advisor. It won't protect your computer but will help you in knowing what the web site you are visiting is really all about. http://www.siteadvisor.com/ ascentive.com Site Advisor Review. Quote Well-respected security researchers have analyzed the software available from this site and found that it offers little or no security protection and may use deceptive sales tactics. http://www.spywarewarrior.com/rogue_anti-spyware.htmthanks Evil, CB. It was kinda fishy, ActiveSpeed and i'm glad i didnt pay for them to just screw up my system. And also thanks for the link for SiteAdvisor. INSTALLED it and works great Unfortunately, there are many programs like this that exist only to scam people out of money. Thankfully, you managed to not get caught up in it! |
|