InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3301. |
Solve : Advertising? |
|
Answer» i have xp sp2. |
|
| 3302. |
Solve : Win32:OnLineGames trojan? |
|
Answer» I have a trojan on my windows me computer & I need help getting it off. My Avast antivirus will not quaranteen it either.
To keep your operating system up to date, visit here monthly: And to keep your system clean, run these free spyware scanners weekly: And be aware of what emails you open and websites you visit. To learn more about how to protect yourself while on the INTERNET read this article by Tony KLEIN: So how did I get infected in the first place? ----------------------------------- I suggest you visit the various sites and make sure these programs are compatible with your computer. Also, you should get CCleaner (without Yahoo! toolbar) and clean up with it at least once a week. We have a free guide HERE. And if all else fails, you can download HijackThis and post a log for us to look at. This will sometimes tell us if there is something lurking around on your computer.avg anti-spyware and/or superantispyware should fix the problem just remember to scan in safe mode with system restore turned offDue to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3303. |
Solve : 108search? |
|
Answer» HI. recently i my firefox203.WOULD not appear,yet opera and ie7 did,all scaners showed nothing- avast, avg, avg root, xsoft se ,adaware se, virgin pc guard,and symetec 108 search assitant remover found nothing.then SPYWARE TERMINATER found 108search,and attika somthing .after 2 scans it removed them and order was restored.can you tell me why i keep getting these infections as i dont KNOW where there coming from. Thanks for your time contrex....Do I DETECT sarcasm? This is a free forum, where the motto "you get what you pay for" was never more true. A fuller answer is that you are going to websites which infect your PC with adware, either without you permission, or because you have been clicking "yes" when asked if you want to install various search bars, etc. It might be that you have suffered a "browser hijack", in which case there is a program called "Hijack This!" which maybe you should run... http://www.spywareinfo.com/~merijn/programs.php By the way, I WONDER if you meant to type "180search" and not "108search"? Go to Add/Remove programs and uninstall 180 Solutions if it is there. Check here http://www.symantec.com/security_response/writeup.jsp?docid=2004-061516-5303-99 These may be helpful. Unexplained computer behavior may be caused by deceptive software http://support.microsoft.com/?id=827315 Download Ad-aware SE and scan your PC for the presence of spyware: http://www.download.com/3000-2144-1...page&tag=button Symantec Security Check http://security.symantec.com/sscv6/...id=ie&venid=sym Microsoft Windows AntiSpyware http://www.microsoft.com/downloads/...&displaylang=en 3 Simple Steps to Help Ensure the Protection of Your PC http://www.microsoft.com/athome/sec...ct/default.mspx Why do you say detecting sacsim not at all more so now. Thanks for your time on this one,contrex..........spybot search and destroy and superantispyware tooAs this issue appears to be resolved, I am closing this topic. If you are the original poster and you would LIKE this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3304. |
Solve : New Computer.? |
|
Answer» HI all, ive just built myself a new computer, its pretty flash and im pretty happy with it. My problem is, i keep contracting spyware and stuff in large amounts. im running adaware, avast, spybot search and destroy. its to the point where if i do an adaware SCAN each hour im almost guaranteed to have picked up some more. i have no idea what is causing it. ive posted a hijack this log below, appreciate any help i can get. I have no idea what it is that is attracting so much spyware to my computer, im not downloading or anything. Thanks. |
|
| 3305. |
Solve : Help Help Help ! my Computer is ill? |
|
Answer» Quote from: HELPER on May 24, 2007, 03:01:50 PM hmm, then what was i thinking of? At this point we don't know. As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you REQUIRE help, PLEASE start a New Topic with information about your computer and your problem. |
|
| 3306. |
Solve : how many viruses has your computer gotten?? |
|
Answer» What i meant was popular sites like addictinggames.com or somethingoh then most LIKELY not.. just TRACKING cookiesYou could get one of Sierra's games. They're free, good, and don't have viruses. |
|
| 3307. |
Solve : unknown virus - HELP!!!? |
|
Answer» Remember everyone ... below is the link to the "first fix" for flash drive infections. Save yourselves a whole lot of grief ..... |
|
| 3308. |
Solve : How to remove the virus? |
|
Answer» I recently got this use computer, It has no Virus protection at all. I just got done upgrading it to window vista home. I having install any virus protection yet. Some how my friend downloaded something on the net and now my computer is affective by a virus. My computer keeps showing: "RESTART and log off, restart and log off" repeated when I log in. How do I fix this problem. Can anyone help.look at my signature and see which of those programs will run in vista.. run scans in safe modeLike unlovedwarrior said, CHECK out some of those programs and see which ones you can GET to work in Vista. I suggest AVG Free. Update it and scan with it in Safe Mode. Let it clean whatever it wants and when it's done, restart your computer and POST a HijackThis log.thanks guys I will TRY this.Ccleaner will work, superantispyware will, i think the AVGs also will work not sure about the adaware and spybotQuote from: thaokou on May 29, 2007, 12:01:04 PM Some how my friend downloaded something on the net and now my computer is affective by a virus. The answer to "somehow" is that you were on the internet at all with no virus protection on a Windows computer. That's all it takes. You may want to print this and save it for future reference. |
|
| 3309. |
Solve : MSN Virus [RESOLVED]? |
|
Answer» SORRY for the delay in an update, i'm afraid that the PC is running so *censored* comparatively well that i keep forgetting that i even had a problem! All of the leud pop-ups are gone, speed is good and it doesn't keep asking me to download questionable virus protectors. Here's the latest Hijack This file. Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 15:57:55, on 27/05/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\alpsfsvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\runservice.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\AIM\aim.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe C:\WINDOWS\system32\sistray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Dan\My Documents\Dan's Music\Wavetune Themes\HiJackThis_v2.exe --->--> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer Provided By Wanadoo R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\WINDOWS\system32\WSBar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll O4 - HKLM\..\Run: [AOL_Demo] "C:\Applications\Tool\AOL Demo\DSGDemo.exe" O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [SiSRaid] "C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [SiSPower] "Rundll32.exe" SiSPower.dll,ModeAgent O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Search with Wanadoo - res://C:\WINDOWS\system32\WSBar.dll/VSearch.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.pcservicecall.co.uk O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab O16 - DPF: {15AC034D-14DF-4AF8-9D02-29E1F56A8235} (Virgin Digital MusicNet Class) - http://www.virgindigital.co.uk/activeX/VirginWMA.cab O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1} (king.com) - http://games.king.com/ctl/kingcomie.cab O16 - DPF: {47CEF84E-92D8-4C4A-86D7-CB982889DCC0} (Oberon Media Network Optimizer) - http://mp1.mplay.oberon-media.com/client/flashnet.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game11.zylom.com/activex/zylomgamesplayer.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94 O17 - HKLM\System\CS1\Services\Tcpip\..\{42674042-8611-4CE1-B2CB-6CA1A71C299A}: NameServer = 195.92.195.95 195.92.195.94 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: COMPONENT Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: - C:\WINDOWS\system32\alpsfsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 8644 bytes You're right Matt, about the AllPro Soft thing, never heard of it and never intended to download it. With regards to the king.com files, i presume they'll forever be there because other people who use this computer play games on king.com . Well, your log looks a lot better. Our efforts appear to have been successful. I wouldn't worry too much about the King.com entry. Some people say to remove it, but it shouldn't be harmful. If you don't recognize AlProSoft, then go ahead and fix this entry... O23 - Service: AlProSoft Support Service (AlProSoftSupSvc) - TODO: <Company name> - C:\WINDOWS\system32\alpsfsvc.exe Then reboot in Safe Mode and use Add/Remove Programs to uninstall any mention of AlProSoft Support Service. Then (with hidden files and folders revealed) delete: C:\WINDOWS\system32\alpsfsvc.exe Let me know if you have any trouble. Other than that, your log looks clean to me. And I'm glad to hear that things are running better. You have some good anti-malware programs, so I don't think I need to give you a lecture on that. I would suggest getting AdAware, though. It would also be a good idea to have SpywareBlaster, which will help make your internet browsing a bit safer. I don't spot a firewall on your computer, so you should look into getting one. There are plenty of good free options, such as Kerio Personal Firewall and ZONEALARM. To learn more about how to protect yourself while on the internet, read this article by Tony Klein: So how did I get infected in the first place?.Awesome, thankyou V E R Y much for helping me through that stuff, same thanks go to oddjob. I REALLY appreciate the help. What i would ask quickly though, with regards to firewalls - i've been using Avast's firewall for some time, is that adequate protection - because i've tried Zone Alarm and it's completely annoying.As far as I know, Avast! doesn't have a firewall... It comes with Network Shield, which has some features of a firewall, but it's not a full-fledged firewall. If ZoneAlarm doesn't suit you, there are others such as Kerio (mentioned above), Comodo, Jetico, or Ashampoo (avoid giving them your e-mail). And although I'm not fond of Symantec, there's also Sygate.Right, i'm on Comodo. I was going to ask, are Window's Firewalls not adequate then? It's just, having security programs gets me concerned about everything. I end up monitoring them for ages just to see what actually happens, and then these particular firewalls need you to allow all sorts of programs to connect, which is just alot of hassle for the less computer literates in my HOUSEHOLD. I always thought a firewall was just that ... a device that prevented hackers and bad things from getting onto your PC, never knew they were this sophisticated.the reason is so that if you do get infected the bad program cant send info back to the creator Quote from: Gliff on May 29, 2007, 03:52:40 PM Right, i'm on Comodo. I was going to ask, are Window's Firewalls not adequate then? It's just, having security programs gets me concerned about everything. I end up monitoring them for ages just to see what actually happens, and then these particular firewalls need you to allow all sorts of programs to connect, which is just alot of hassle for the less computer literates in my household. I always thought a firewall was just that ... a device that prevented hackers and bad things from getting onto your PC, never knew they were this sophisticated.Windows Firewall is better than nothing, but it's always a good idea to have something with better protection and more features. I know it seems like a bit of a hassle at first, but once you get used to it, it won't feel so bothersome. And besides, if you ask me, it's worth the protection.Actually, since installing yesterday and a bit of accepting needed to allow certain programs to connect to the internet, Comodo is a nice program. Quiet, but it does the job. Thanks for all of your advice, if anyone i know gets computer problems, i will no doubt direct them here! The help has been fantastic, and i appreciate it to no extent. Thanks!You're very welcome, Gliff. I'm just glad I was able to help you out. As this issue appears to be resolved, I am closing this topic. If you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3310. |
Solve : Viruses and Trojans? |
|
Answer» Windows XP SP2, IE-7why the poll?? |
|
| 3311. |
Solve : Pc wont work without virus [RESOLVED]? |
|
Answer» Before i do anything i how do i find out my ISP Dont want to delete incase it is mine.You don't know your ISP? Who do you send your payments to? Ha. |
|
| 3312. |
Solve : uniblue pack? |
|
Answer» I have just downloaded uniblue pack , it comes with SPY eraser regisrty booster and speed me up , i just wanted to know what people think of the programs in general , some 1st class opions would be cool. Well, it appears to be legit, but I've never used it. All I can say is that I personally wouldn't trust it. But that's just me.Yh it seems ok it picked up tons of errors on its error fixing tool like over 1500 haha , it said it fixed them all , theres also a spyware blocker on my taskbar now which is very cool , its posted all over torrent sites , with tons of seeds , so it has to be good..The first search i did for it guaranteed me i'd find chicks in New York... |
|
| 3313. |
Solve : wired mouse actions, is a virus the problem? / RESOLVED? |
|
Answer» well i noticed that the other day my mouse started to click randomly very fast but then stoped. Today however it has been non stop eg i went to click firefox icon and 99 windows will pop up so my pc will just crash and then when i try to get task manager up it minamize automaticly. So i though i could have been a virus so i scanned using avast, came up with nothing so try bt yahoo spyware scan nothing there, then it was really pissing me off so i went and tried ad-ware and then spyware doctor and bother did not fix the problem. I have just tried system restore as a last resort but no luck there, any on got an idea of what is going on?
As for your log, I see no suspicious entries. But I would like to quickly address a couple of things... 1. You have both Avast! and AVG. It's good to have plenty of protection, but make sure you're not running both of these programs at once, as that can cause problems. 2. To add to your arsenal, I would like to suggest AdAware SE Personal, AVG Anti-Spyware (not the same as anti-virus), and Spybot - Search & Destroy. Again, like anti-virus programs, don't run all of these at once. 3. Your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. It would be a good idea to update AVG and scan with it in Safe Mode, but from what I see, I don't suspect a virus. This is likely a hardware issue and like patio says, you should try testing out a different mouse on your computer. And test your current mouse on a different computer if you can. Don't mind this post; it's just a bit of general maintenance.Thanks alot, I ran all the programs you suggested and changed my mouse over just to be sure and so far its been ok Awesome, glad to hear it. If you have anymore troubles, just let us know.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3314. |
Solve : General Maintenance? |
|
Answer» I was curious about it, but who am I to question the powers that be.yes, congrats again to ALL new mods (sorry ... I didn't realise Chris wasn't the only one). It's not just me then.To move posts from the FAQ section because of how the template for that section is currently setup it's a little different, but it is possible. Click the Modify link, select Additional Options, and then CHECK the box to "Move this topic." The Off Topic section needs a lot of work. I initially LIKED the wiki STYLE template but every day am finding something else that needs to be fixed or changed with it. May just convert it back to the users default template again.Chris figured another way before we knew about that - copy the move topic link and replace it with the topic number. Very ingenious. The wiki template looks nice but there are a few problems with it. Perhaps the normal template may be a good idea.Quote from: Calum on May 28, 2007, 04:00:16 AM The wiki template looks nice but there are a few problems with it.I 2nd that. But I do like how the FAQ is organized by CATEGORIES now though, if we could have them organized in categories and with the normal template I think that would be good.I agree. Use the normal, friendlier template and keep the categories to help with organization.Ok. Now using default template.Thanks. |
|
| 3315. |
Solve : Bootable CD Antivirus, Virus Scan suggestions???? |
|
Answer» Hello, I have looked around for a Bootable CD with Virus Scan capabilities and havent found anything yet. I tried to create a Bart PE Bootable CD with Norton AV, but it doesnt work. |
|
| 3316. |
Solve : Norton Antivirus 2006? |
|
Answer» I'm running Windows XP and Internet Explorer browser. My question is Yeah ... I was forgetting that one. So much to remember, so few active brain cells.... Ha, don't worry, we all have this problem from time to time. Don't mind this post; it's just a bit of general maintenance.i like the new hat what site did u get norton off of? |
|
| 3317. |
Solve : Norton AntiVirus 2007 issue? |
|
Answer» I'm running Windows XP and Internet Explorer browser. I constantly experiance a small pop-up from Symantec in the lower right of my screen stating: "A recent attempt on your computer has been blocked". When I check for details I usually find that it has flagged the same incident repeatedly until another occurs. Furthermore, there is really very little to do about such incidents if they are being blocked, thus the pop-up becomes very annoying. It will occur no matter where I am at (on any page) but sometimes will appear only on the desk top. I know this because I've moved the page slightly to observe that corner of the desk top screen. My question is; how do I disable it? I've addressed the issue to Symantec Tech Support but I cannot seem to get them to fully understand the nature of my problem. Any suggestions? Sorry for the late REPLY, however...if you paid for the product, you might as well get what you paid for... Here is the answer to your annoying pop-up...BTW...I've been using Norton products for years...with no issues. So if you've already decided to uninstall it...then just disregard. Another BTW...you won't find a lot of Norton fans at this site... Your answer: 1) Open your Norton product. 2) Open Settings. 3) Click Intrusion Detection and then click Configure. 4) Remove the checkmark from "NOTIFY me when Intrusin Prevention blocks connections". 5) Click the OK button and CLOSE all Norton product windows. You won't receive those nasty blocked connection alerts anymore. I know, I know...too little...too late.lol.... theres also got to be a norton and/or macfee fan.... lol jk i think dl65 uses norton tooAnd I use McAfee and am quite pleased with it. I do admit it has its flaws, of course, but it has served me very well in the time I've had it. Quote
Saviour: I find no "Intrusion Detection" to click after I open "Settings". Can you tell me what options are available in your Norton Antivirus 2007...apparently I'm using Norton Internet Security 2007 and got the two confused...my bad... Open your product and look for the Options link....it's there somewhere on the first page you see when the program opens. Look for and select Antivirus alerts. Just disable the alerts and save your settings. If worse comes to worse...you can tell me what you see and I'll walk you through it.Quote from: The Saviour on June 07, 2007, 05:57:58 PM Can you tell me what options are available in your Norton Antivirus 2007...apparently I'm using Norton Internet Security 2007 and got the two confused...my bad... Saviour: Sorry, I had to leave yesterday before I COULD respond. Anyway, this is it ... Norton Protection Center options> OPTIONS: General Settings> Norton status settings> (check box) Show protection status on Windows Taskbar Windows Security Center alert settings> (check box) Show messages from Windows Security Center OPTIONS: Advanced Settings> Windows alert settings> (check box) Show Windows Automatic Update Alert That's it .......Is this just Norton AntiVirus 2007 or Norton Internet Security 2007? |
|
| 3318. |
Solve : Why rag Norton?? |
|
Answer» Not sure if this should be posted here or in Off Topic: There is a reason NORTON is known as the Norton virus, and there is an entire FAQ article dedicated to its removal. No offense, Calum... I was just wondering why there is such a dislike for Norton products here. I use them all the time and see no issues...other than the fact they are a resource hog. With the right amount of RAM, this is no longer an issue.I got Norton. It's easy to use and very effective. I dunno why people don't like it...Norton is certainly better than nothing, but in my experience (as well as the experience of many others), its success in detecting and removing malware has been somewhat subpar. I've seen a significantly higher success rate with free programs like AVG. AVG isn't perfect, of course, but it does the job just as well (if not better) for a much more reasonable price. Besides, I'm not fond of anything that makes it so difficult for you to remove it...just like a virus (which is where I believe the term comes from). Of course, it's all simply a matter of opinion. Oh, and I see you've beaten my highscore at Simon... You do REALIZE this won't be tolerated, right?Quote Oh, and I see you've beaten my highscore at Simon... You do realize this won't be tolerated, right? Uh-oh...Personally, I hated Norton when I used it. It really did slow the old PC down (I say old, it's more than adequate for XP - Sempron 2400+, 512Mb RAM). It also did not uninstall correctly, and there are still odd traces popping up over 18 months later. I also found that there were several viruses on that computer which Norton had failed to detect. Just my personal experience, but I found it to be one of the worst programs I've ever used. That keeps me from recommending it to anybody else. Oh, and no offence taken. But the comment quoted was in response to advice to buy Norton to get RID of one Trojan, which I thought was pretty poor when free software COULD do the job.Quote But the comment quoted was in response to advice to buy Norton to get rid of one Trojan, which I thought was pretty poor when free software could do the job. Point taken... and a good point I might add.Steve this is off topic but,I like the Personal Text you added to your signature. Robert "Treat others the way you'd like to be treated..."I've actually had more problem with McAfee than with Norton. But then, I've been using Norton almost ever since Ken Norton wrote the the original utilities. That was long before SYMANTEC bought them out.Glad you mentioned Ken Norton.Remember The 'Ali''virus? Norton didn't have a cure for that. Cassius Marcellus Clay, Jr. --->No wonder he changed his name.I have got by fine so far, with AVG. It's a great program and pretty cheap to be so free. Never used Norton so,I can't comment on it. Great to have you back Saviour. We can sure use your expertise.I hate Norton. I used to use it, but after having to reformat and reinstall my system like 3 times I gave up on it. Now I use Kaspersky. It's never given me any problems. Another thing about Norton, it came with this computer which i just bought. My old computer has the printer on it and it took me like 3 days to figure out why I couldn't print anything or get file sharing to work. Turned out Notron was blocking my network without telling me. I know I should have tried disabling Norton to see if it was the problem, but I couldn't find the pause protection button. I uninstalled it and everything worked fine. Norton sucks. |
|
| 3319. |
Solve : Firewall for vista? |
|
Answer» Quote from: patio on JUNE 04, 2007, 07:37:55 PM Ranked second in the latest comprehensive leak/block test i read...have you tried it? ? Never tried it... I initially used Symantec products...Norton Internet Security to be exact...have tried Trend Micro, Zone Alarm, Windows Live OneCare, etc., etc. I've always returned to NIS. Currently using NIS 2007 and LOVE it. It's been good to me, but you know as well as I...it depends on who you ask.patio so far i like it but it keeps asking the same stuff over and over again even if i allow prementlyQuote from: unlovedwarrior on June 05, 2007, 08:11:14 AM patio so far i like it but it keeps asking the same stuff over and over again even if i allow premently Then somethings amiss...if you need to PM me with DETAILS feel free to do so.i sure willunlovedwarrior Are trying it with vista or xp Skybluexp... |
|
| 3320. |
Solve : I have difficulty downloading updates. help? |
|
Answer» why is it that i can connect to the internet via wifi yet my AVG antivirus and avg anti-spyware could not connect to the UPDATE servers? i wrote them, they did not respond yet. is it in my settings? or is my server hindering me from doing this? thank you.i have just downloaded the updates manually (and not via the avg icon) but i could not open the file because it is in the *.bin format. can you suggest what free downloadable program i could effectively use? thank you.How long has this been happening? It's possible that the servers were just down when you tried; it happens fairly often (just now HAPPENED to me). If you would LIKE to update AVG Anti-Virus manually, update just like you normally would. But this time, click on Folder instead of Internet and navigate to the .bin file you downloaded. |
|
| 3321. |
Solve : W32.Shodi Removal? |
|
Answer» This one might be a little tricky, but we're gonna try to get this thing. 1. Download an emergency copy of SAV32CLI. On an uninfected Windows computer, run this file to extract the contents into a SAV32CLI folder on a medium that can be write-protected. Add any RELEVANT IDEs to this folder and write-protect the disk (on a CD/R or CD/RW close the session).If you can, I'd like for you to give this a try and then report back to me.CBMatt, Thanks for looking into this for me. I did get a scan done by Kaspersky and part one is posted below. Before I try what you suggested earlier can you look at it and let me know if that is still the way you want me to proceed? Part 1 ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Wednesday, May 30, 2007 11:20:21 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 30/05/2007 Kaspersky Anti-Virus database records: 333967 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 59401 Number of viruses found: 2 Number of infected objects: 98 / 0 Number of suspicious objects: 0 Duration of the scan process: 00:46:34 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\518d3b3fd6ce0222481939caa95e41a2_6ee841b4-6103-4ce6-830e-ecb66b9670bfObject is lockedskipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5aa7b1f9b4952b0a5b2915b14b8e038a_6ee841b4-6103-4ce6-830e-ecb66b9670bfObject is lockedskipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7346f0ad2f7269d43adc1db49e1d210f_6ee841b4-6103-4ce6-830e-ecb66b9670bfObject is lockedskipped C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d3745e1e9bd1e7182ebd85b5b1efa2b2_6ee841b4-6103-4ce6-830e-ecb66b9670bfObject is lockedskipped C:\Documents and Settings\All Users\Application Data\Prevx\PXSetup.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\All Users\Application Data\QSLLPSVCShareObject is lockedskipped C:\Documents and Settings\ChWalker\Application Data\Microsoft\Outlook\CWalker.srsObject is lockedskipped C:\Documents and Settings\ChWalker\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.673.0-static.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Cookies\index.datObject is lockedskipped C:\Documents and Settings\ChWalker\Desktop\Home\Generals\Command & Conquer\generals.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Desktop\Home\Programs\CnC3_Demo.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Desktop\Home\Programs\Programs\MySpaceIM_Setup.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Desktop\Home\Programs\Programs\spybotsd14.exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Local Settings\Application Data\Microsoft\Feeds Cache\index.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Application Data\Microsoft\Windows\UsrClass.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOGObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\History\History.IE5\index.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\History\History.IE5\MSHist012007053020070531\index.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Temp\~DF4184.tmpObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Temp\~DF4189.tmpObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Temporary Internet Files\Content.IE5\index.datObject is lockedskipped C:\Documents and Settings\ChWalker\Local Settings\Temporary Internet Files\Content.IE5\L21H2XHD\HijackThis[1].exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\Local Settings\Temporary Internet Files\Content.IE5\SAHFBVXK\avg75free_472a1024[1].exeInfected: Virus.Win32.Shodi.iskipped C:\Documents and Settings\ChWalker\NTUSER.DATObject is lockedskipped C:\Documents and Settings\ChWalker\ntuser.dat.LOGObject is lockedskipped C:\Documents and Settings\LocalService\Cookies\index.datObject is lockedskipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.datObject is lockedskipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOGObject is lockedskipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.datObject is lockedskipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.datObject is lockedskipped C:\Documents and Settings\LocalService\NTUSER.DATObject is lockedskipped C:\Documents and Settings\LocalService\ntuser.dat.LOGObject is lockedskipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.datObject is lockedskipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOGObject is lockedskipped C:\Documents and Settings\NetworkService\NTUSER.DATObject is lockedskipped C:\Documents and Settings\NetworkService\ntuser.dat.LOGObject is lockedskipped C:\Program Files\Adobe\Acrobat 5.0\Acrobat\Acrobat.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\AeXNSAgent.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXAPedit.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXAuditPls.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXCustInv.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXExchPls.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXInvSoln.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXMachInv.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXNSInvCollector.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXRunControl.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\AeXSNPlus.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{01B54EB5-3679-4C73-9E10-E169D5A5EC59}\cache\SNData2.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{5C599BF5-AC69-4DFE-9262-AF2418FEFEA1}\cache\TaskSynchronization.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{5C599BF5-AC69-4DFE-9262-AF2418FEFEA1}\cache\UnInstallSynchAgent.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{5C599BF5-AC69-4DFE-9262-AF2418FEFEA1}\cache\UpgradeSynchAgent.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{B7B543B5-3679-4D73-9E1F-E162D5A59C53}\cache\AeXMSIAgent.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Software Delivery\{B7B543B5-3679-4D73-9E1F-E162D5A59C53}\cache\AeXNSInvCollector.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Altiris Agent\Task Synchronization\UnInstallSynchAgent.exeInfected: Virus.Win32.Shodi.iskipped Part 2 of kaspersky scan C:\Program Files\Altiris\Carbon Copy\client.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Altiris\Carbon Copy\shellker.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Citrix\ICA Client\ssoncom.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Citrix\ICA Client\ssonsvr.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Adobe\Web\AOM.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Microsoft Shared\MSInfo\msinfo32.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Microsoft Shared\PhotoEd\PHOTOED.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Microsoft Shared\Speech\sapisvr.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Real\Update_OB\realsched.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Dell\NicConfigSvc\NICCONFIGSVC.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Dell\QuickSet\Quickset.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\icwconn2.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\icwrmind.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\icwtutor.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\inetwiz.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\Connection Wizard\isignup.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Internet Explorer\iedw.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Microsoft Office\Office10\EXCEL.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Microsoft Office\Office10\MSACCESS.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Movie Maker\moviemk.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\NetMeeting\cb32.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\NetMeeting\conf.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\NetMeeting\wb32.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Outlook Express\msimn.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Outlook Express\oemig50.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Outlook Express\setup50.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Outlook Express\wab.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Outlook Express\wabmig.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\RealVNC\VNC4\winvnc4.exeInfected: not-a-virus:RemoteAdmin.Win32.WinVNC.4skipped C:\Program Files\RealVNC\VNC4\wm_hooks.dllInfected: not-a-virus:RemoteAdmin.Win32.WinVNC.4skipped C:\Program Files\SlySoft\AnyDVD\AnyDVD.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Express Labeler\stax.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\dlaunin.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\ssdiag.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\tfswcmd.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\tfswctrl.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\RecordNow! Plus\Launch.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\RecordNow! Plus\LeaderReg.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Sonic\Sonic Solutions Product CD\RecordNow! Plus\RecordNow.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\LSETUP.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\LUALL.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\LuComServer.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\LUInit.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\NDETECT.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Symantec\LiveUpdate\SymantecRootInstaller.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Terminal Services Client\CONMAN.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Terminal Services Client\MSTSC.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Terminal Services Client\setup\SETUP.EXEInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Trend Micro\OfficeScan Client\ConnLog\Conn_20070530.logObject is lockedskipped C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\AdpBrowser.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\DelDelay.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\delfolder.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\DoShutDown.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\gtny.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\setspath.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\tranplug.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\WebCyberCoach\b_Dell\WCC_Wipe.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows Media Player\migrate.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows Media Player\mplayer2.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows Media Player\setup_wm.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows Media Player\wmplayer.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows NT\Accessories\wordpad.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows NT\dialer.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Windows NT\Pinball\pinball.exeInfected: Virus.Win32.Shodi.iskipped C:\Program Files\Yahoo!\Messenger\YahooMessenger.exeInfected: Virus.Win32.Shodi.iskipped C:\System Volume Information\MountPointManagerRemoteDatabaseObject is lockedskipped C:\WINDOWS\CSC\00000001Object is lockedskipped C:\WINDOWS\Debug\Netlogon.logObject is lockedskipped C:\WINDOWS\Debug\PASSWD.LOGObject is lockedskipped C:\WINDOWS\SchedLgU.TxtObject is lockedskipped C:\WINDOWS\SoftwareDistribution\EventCache\{F2A8DBC0-47EA-41F1-9FAF-D7C595B9864C}.binObject is lockedskipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.logObject is lockedskipped C:\WINDOWS\Sti_Trace.logObject is lockedskipped C:\WINDOWS\system32\CatRoot2\edb.logObject is lockedskipped C:\WINDOWS\system32\CatRoot2\tmp.edbObject is lockedskipped C:\WINDOWS\system32\config\AppEvent.EvtObject is lockedskipped C:\WINDOWS\system32\config\DEFAULTObject is lockedskipped C:\WINDOWS\system32\config\default.LOGObject is lockedskipped C:\WINDOWS\system32\config\Internet.evtObject is lockedskipped C:\WINDOWS\system32\config\SAMObject is lockedskipped C:\WINDOWS\system32\config\SAM.LOGObject is lockedskipped C:\WINDOWS\system32\config\SecEvent.EvtObject is lockedskipped C:\WINDOWS\system32\config\SECURITYObject is lockedskipped C:\WINDOWS\system32\config\SECURITY.LOGObject is lockedskipped C:\WINDOWS\system32\config\SOFTWAREObject is lockedskipped C:\WINDOWS\system32\config\software.LOGObject is lockedskipped C:\WINDOWS\system32\config\SysEvent.EvtObject is lockedskipped C:\WINDOWS\system32\config\SYSTEMObject is lockedskipped C:\WINDOWS\system32\config\system.LOGObject is lockedskipped C:\WINDOWS\system32\h323log.txtObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTRObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAPObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VERObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAPObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAPObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATAObject is lockedskipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAPObject is lockedskipped C:\WINDOWS\wiadebug.logObject is lockedskipped C:\WINDOWS\wiaservc.logObject is lockedskipped C:\WINDOWS\WindowsUpdate.logObject is lockedskipped Scan process completed. Unfortunately, info on your version of this particular infection appears to be hard to come by and that is the only fix I have been able to find. At the moment, I don't know of any alternatives, aside from a reformat. But give me a moment to consult another member and ask for his input... In the meantime... Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls. Given your current situation, the program might not work, but give it a couple of tries. It's worth.Here is the combofix log part 1 "ChWalker" - 2007-05-30 18:58:12 Service Pack 2 ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\ChWalker\Desktop\Home\Programs\" (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) "C:\WINDOWS\system32\drivers\fad.sys" ((((((((((((((((((((((((((((((( Files Created from 2007-04-28 to 2007-05-30 )))))))))))))))))))))))))))))))))) 2007-05-30 09:38d--------C:\WINDOWS\system32\Kaspersky Lab 2007-05-30 05:450--a------C:\WINDOWS\USR_Shohdi_Photo_USR.exe 2007-05-28 11:05d--------C:\DOCUME~1\ChWalker\APPLIC~1\Prevx 2007-05-28 11:04d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Prevx 2007-05-28 10:5777,312--a------C:\WINDOWS\ua2.dll 2007-05-27 16:52d--------C:\Program Files\WebCyberCoach 2007-05-27 16:39d--h-----C:\DOCUME~1\ChWalker\APPLIC~1\GTek 2007-05-27 16:39d--h-----C:\DOCUME~1\ALLUSE~1\APPLIC~1\GTek 2007-05-27 16:387,882--a------C:\WINDOWS\system32\GTKCMOS.sys 2007-05-27 16:387,626--a------C:\WINDOWS\system32\GPCIEnum.sys 2007-05-27 16:387,168--a------C:\WINDOWS\system32\DLPT64.sys 2007-05-27 16:386,977--a------C:\WINDOWS\system32\DDMI2.sys 2007-05-27 16:386,656--a------C:\WINDOWS\system32\DLPT2.sys 2007-05-27 16:385,632--a------C:\WINDOWS\system32\GPCIEn64.sys 2007-05-27 16:385,120--a------C:\WINDOWS\system32\GTKCMO64.sys 2007-05-27 16:384,608--a------C:\WINDOWS\system32\DDMI64.sys 2007-05-25 15:0883,168--a------C:\WINDOWS\system32\S32EVNT1.DLL 2007-05-25 15:0882,832--a------C:\WINDOWS\system32\drivers\SYMEVENT.SYS 2007-05-25 15:08d--------C:\Program Files\Symantec AntiVirus 2007-05-25 15:08d--------C:\Program Files\Symantec 2007-05-25 15:08d--------C:\Program Files\Common Files\Symantec Shared 2007-05-25 15:08d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec 2007-05-19 16:12d--------C:\DOCUME~1\ChWalker\APPLIC~1\HP 2007-05-19 07:17d--------C:\DOCUME~1\LOCALS~1\APPLIC~1\HP 2007-05-19 07:15d--------C:\Program Files\Common Files\HP 2007-05-19 07:14d--------C:\Program Files\Hewlett-Packard 2007-05-19 07:13d--------C:\Program Files\Common Files\Hewlett-Packard 2007-05-19 07:1294,208--a------C:\WINDOWS\system32\HPZipt12.dll 2007-05-19 07:1269,632--a------C:\WINDOWS\system32\HPZipm12.exe 2007-05-19 07:1265,536--a------C:\WINDOWS\system32\HPZinw12.exe 2007-05-19 07:1257,344--a------C:\WINDOWS\system32\HPZisn12.dll 2007-05-19 07:12278,584--a------C:\WINDOWS\system32\HPZidr12.dll 2007-05-19 07:12204,800--a------C:\WINDOWS\system32\HPZipr12.dll 2007-05-19 07:1049,664-ra------C:\WINDOWS\system32\drivers\HPZid412.sys 2007-05-19 07:1016,496-ra------C:\WINDOWS\system32\drivers\HPZipr12.sys 2007-05-19 07:10118,727--a------C:\WINDOWS\hpoins09.dat 2007-05-19 07:09827,392-ra------C:\WINDOWS\system32\hpotiop2.dll 2007-05-19 07:0977,824-ra------C:\WINDOWS\system32\HPZIDS01.dll 2007-05-19 07:09659,456-ra------C:\WINDOWS\system32\hpowiax2.dll 2007-05-19 07:0938,400--a------C:\WINDOWS\system32\hpz3l054.dll 2007-05-19 07:09254,026-ra------C:\WINDOWS\system32\hpovst09.dll 2007-05-19 07:0915,104--a------C:\WINDOWS\system32\drivers\usbscan.sys 2007-05-19 06:41d--------C:\Program Files\HP 2007-05-19 06:2825,856--a------C:\WINDOWS\system32\drivers\usbprint.sys 2007-05-03 05:14374,784--a------C:\WINDOWS\3dg32.dll 2007-05-03 05:13876,066--a------C:\WINDOWS\system32\3dreng.dll 2007-05-03 05:1371,680--a------C:\WINDOWS\system32\3dr.dll 2007-05-03 05:13479,744--a------C:\WINDOWS\system32\3dr332.dll 2007-05-03 05:1338,400--a------C:\WINDOWS\system32\3dr32.dll 2007-05-03 05:13278,528--a------C:\WINDOWS\system32\3drrgb.dll 2007-05-03 05:13278,528--a------C:\WINDOWS\system32\3drbgr.dll 2007-05-03 05:13274,944--a------C:\WINDOWS\system32\3drargb.dll 2007-05-03 05:13274,944--a------C:\WINDOWS\system32\3dr565.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3drrgba.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3drbgra.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3drabgr.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3dr664.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3dr655.dll 2007-05-03 05:13274,432--a------C:\WINDOWS\system32\3dr555.dll 2007-05-03 05:1322,016--a------C:\WINDOWS\system32\3drsys.dll 2007-04-28 16:5738,229--a------C:\WINDOWS\system32\drivers\StMp3Rec.sys 2007-04-10 22:08d--------C:\Program Files\QuickTime (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-05-30 13:30:41--------d-----wC:\Program Files\Terminal Services Client 2007-05-30 10:49:34--------d-----wC:\Program Files\Common Files\SureThing Shared 2007-05-29 07:36:40--------d-----wC:\Program Files\Sonic 2007-05-28 03:05:43--------d-----wC:\Program Files\MySpace 2007-05-27 09:07:00--------d-----wC:\Program Files\IrfanView 2007-05-27 09:05:38--------d-----wC:\Program Files\Digital Line Detect 2007-05-27 05:56:25--------d-----wC:\Program Files\Movie Maker 2007-05-25 13:21:45--------d-----wC:\Program Files\Xvid 2007-05-25 13:21:31--------d-----wC:\Program Files\Windows NT 2007-05-25 13:21:16--------d-----wC:\Program Files\Windows Media Connect 2 2007-05-25 13:21:09--------d-----wC:\Program Files\Volo View Express 2007-05-25 13:19:04--------d-----wC:\Program Files\Sierra On-Line 2007-05-25 13:15:07--------d-----wC:\Program Files\NetZero 2007-05-25 13:14:56--------d-----wC:\Program Files\NetWaiting 2007-05-25 13:14:30--------d-----wC:\Program Files\MSN Messenger 2007-05-25 13:14:02--------d-----wC:\Program Files\Modem Helper 2007-05-25 13:11:56--------d-----wC:\Program Files\Messenger 2007-05-25 12:59:50--------d-----wC:\Program Files\CCleaner 2007-05-25 12:59:28--------d-----wC:\Program Files\Apple Software Update 2007-05-25 12:59:27--------d-----wC:\Program Files\Apoint 2007-05-24 13:38:29--------d-----wC:\DOCUME~1\ChWalker\APPLIC~1\Skype 2007-05-19 06:08:48--------d-----wC:\DOCUME~1\ChWalker\APPLIC~1\IGN_DLM 2007-04-28 13:59:26--------d-----wC:\DOCUME~1\ChWalker\APPLIC~1\Apple Computer 2007-04-18 16:12:232,854,400----a-wC:\WINDOWS\system32\msi.dll 2007-04-12 12:18:41--------d-----wC:\DOCUME~1\ChWalker\APPLIC~1\LimeWire 2007-04-03 19:53:13--------d--h--wC:\Program Files\InstallShield Installation Information 2007-03-30 17:30:03--------d-----wC:\DOCUME~1\ChWalker\APPLIC~1\Command & Conquer 3 Tiberium Wars Demo 2007-03-30 17:04:07--------d-----wC:\Program Files\Electronic Arts 2007-03-22 22:58:54262,144----a-wC:\WINDOWS\system32\default_user_class.dat 2007-03-17 13:43:01292,864----a-wC:\WINDOWS\system32\winsrv.dll 2007-03-08 15:36:28577,536----a-wC:\WINDOWS\system32\user32.dll 2007-03-08 15:36:2840,960----a-wC:\WINDOWS\system32\mf3216.dll 2007-03-08 15:36:28281,600----a-wC:\WINDOWS\system32\gdi32.dll 2007-03-08 13:47:481,843,584----a-wC:\WINDOWS\system32\win32k.sys part 2 of combo fix log (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2006-10-26 11:28] {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx [2001-03-02 14:02] {55EA1964-F5E4-4D6A-B9B2-125B37655FCB}=C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll [2006-01-10 12:09] {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}=C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 17:29] {5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06 03:05] {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 06:25] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Dell QuickSet"="C:\Program Files\Dell\QuickSet\Quickset.usr" [] "AeXAgentLogon"="C:\Program Files\Altiris\Altiris Agent\AeXAgentActivate.exe" [2007-05-27 17:36] "OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2007-05-27 17:41] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-27 17:37] "QuickTime Task"="C:\Program Files\QuickTime\qttask.usr -atboottime" [] "PrevxOne"="C:\Program Files\Prevx1\PXConsole.exe" [] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce] "WIAWizardMenu"=RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "RunStartupScriptSync"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "RunLogonScriptSync"=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoWelcomeScreen"=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "ForceStartMenuLogOff"=1 (0x1) "NoTaskGrouping"=1 (0x1) "NoWelcomeScreen"=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"= AMINIT.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "wwSecSvc"=2 (0x2) "iPodService"=3 (0x3) HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs* [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1cf7bc02-071b-11dc-a703-0014a54bb7e3}] AutoRun\command- E:\Installer.exe Contents of the 'Scheduled Tasks' folder 2007-04-25 01:29:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job ******************************************************************** catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-05-30 19:00:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ******************************************************************** Completion time: 2007-05-30 19:01:52 C:\ComboFix-quarantined-files.txt ... 2007-05-30 19:01 --- E O F --- Quote [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]Have you messed with your registry to make changes to your computer? Download The Avenger by Swandog46, and save it to your Desktop.
Quote Files to delete:
I know you're having problems with executables, but see if you can manage to scan with TrojanHunter, AVG Anti-Spyware, and SUPERAntiSpyware. It's a longshot, I know, but it could really help.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3322. |
Solve : Virus of sum sort???? |
|
Answer» 2007-05-01 12:12d--------C:\Documents and Settings\Administrator\Shared im running avg 7 and adaware se and avg keep coming up with unwanted files so far here is wat followsDo these files still show up in your scans or were they removed? You may want to give SDFix a try. Download it and save it to your desktop. Then... 1. Open the extracted SDFix folder and double click RunThis.bat to start the script. 2. Type Y to begin the cleanup process. 3. It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot. 4. Press any Key and it will restart the PC. 5. When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to END the script and load your desktop icons. 6. Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt (Report.txt will also be copied to Clipboard ready for posting back on the forum). Post back with this log along with the results of your scans.no those files have been removed and i did that new avg thing and it came up with no problems found. here is the sdfix log file. SDFix: Version 1.85 Run by Administrator - Wed 30/05/2007 - 21:39:58.92 Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting... Normal Mode: Checking Files: Below files will be copied to Backups folder then removed: C:\-59809~1 - Deleted Removing Temp Files... ADS Check: Checking if ADS is attached to system32 Folder C:\WINDOWS\system32 No streams found. Checking if ADS is attached to svchost.exe C:\WINDOWS\system32\svchost.exe No streams found. Final Check: REMAINING Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\BearShare\\BearShare.exe"="C:\\Program Files\\BearShare\\BearShare.exe:*:Enabled:BearShare" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files: --------------- Backups Folder: - C:\SDFix\backups\backups.zip Checking For Files with Hidden Attributes: C:\Documents and Settings\Administrator\Desktop\BACKUP!!!!!!!!!!!!!!\backup\Downloads\Epic.Movie.DVDSCR.XviD-NEPTUNE.[www.torrentfive.com]\Sample\Thumbs.db C:\Documents and Settings\Administrator\Desktop\BACKUP!!!!!!!!!!!!!!\backup\back up stuff\Installs\Microsoft Office Xp Pro (Word, Excel, Powerpoint, Outlook, Access, Frontpage)\MSDE2000\SQLRESLD.DLL C:\Documents and Settings\Administrator\Desktop\BACKUP!!!!!!!!!!!!!!\Everything & Anything I Have On My Computer (All Sorted So Dont *censored* It Up!!)\Downloads & Install Files\Messenger Plus! - Setup.exe C:\Documents and Settings\Administrator\Desktop\BACKUP!!!!!!!!!!!!!!\Everything & Anything I Have On My Computer (All Sorted So Dont *censored* It Up!!)\Downloads & Install Files\setup msn 6.1.exe C:\Documents and Settings\Administrator\Desktop\BACKUP!!!!!!!!!!!!!!\Everything & Anything I Have On My Computer (All Sorted So Dont *censored* It Up!!)\Downloads & Install Files\vnc-4.0-x86_win32.exe C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp C:\WINDOWS\system32\config\default.tmp.LOG C:\WINDOWS\system32\config\SAM.tmp.LOG C:\WINDOWS\system32\config\SECURITY.tmp.LOG C:\WINDOWS\system32\config\software.tmp.LOG C:\WINDOWS\system32\config\system.tmp.LOG Finished i will let you know if it rebbots again. thanks so much for your help. ur a legend!!!!!!!!!!!!!!!!!!! I'm glad I could be of some help. I'll keep my fingers crossed and hope the reboots have STOPPED. After all of this work, you should be clean now, so if the reboots persist, it might be related to a hardware issue.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3323. |
Solve : This thing has to have super powers.? |
|
Answer» Be on the look out for this trojan that is not the usual pain in the neck. After running my usual Norton System Scan, I was informed of a High risk trojan that is resistant to removal. The name I was given is: |
|
| 3324. |
Solve : Viral Infection!t? |
|
Answer» My computer has been raided by viruses! |
|
| 3325. |
Solve : ProductId? |
|
Answer» virus vbscript solow deleted my productID erm.... i got 3 pc, 1 sp3 "pirate"1 vista and 1 sp2 If it is in fact Genuine contact the Mothership by phone and they will walk you through it. Takes about 5 minutes...Quote from: insertusername on May 26, 2007, 05:34:49 AM erm.... i got 3 pc, 1 sp3 "pirate"1 vista and 1 sp2 K, but as you have 2 pirated copies (at least) I don't think it hurt too bad. Don't mind this post; it's just a bit of general maintenance.Due to lack of feedback, I am closing this topic. If you are the original poster and you would LIKE this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you REQUIRE help, please start a New Topic with information about your computer and your problem. |
|
| 3326. |
Solve : trojan dropper? |
|
Answer» hi, a few days ago a dowloaded a free trial of AVG. when it was done with setup, it restarted and froze at log in screen. i restart my comp. and it freezes at log in screen when it says starting up. I have left it over night at that screen and have tried rebooting numerous times. I went into safe mode and ran AVG. it found 2 trojan dropper's and lots of tracking cookies. AVG "HEALED" the trojans but did not delete them. so i manualy deleted them. i ran the scan and nothing came up. so i then tried booting normaly and it still freezes. looking through some of the forums, i tried hijack this. |
|
| 3327. |
Solve : Hard Disk Fill Up? |
|
Answer» My Lacie backup hard disk drive has free space of 200GB but i can copy/transfer a file of 10GB to it. What should I do? Is it a kind of virus called worms? Which software should I use? HelpI dont understand the question. What do you mean you can transfer 10GB to it? |
|
| 3328. |
Solve : web page jumping? |
|
Answer» can anyone help? when I click on a link from agoogle search it does not go to that link but jumps to something all together different.It certainly sounds like your browser has been hijacked... |
|
| 3329. |
Solve : Can Firewall Restrict Threats and viruses to enter in System..??? |
|
Answer» I wish to the Firewall for restrict the Viruses and Threats to ENTER in my System ... |
|
| 3330. |
Solve : how are viruses quarantined?? |
|
Answer» i know this is probably an odd and not so popular topic, but how do they quarantine viruses with protection software? also why would that method not be implemented into the ''latest and GREATEST'' operating systems... that would make things a lot simpler, and you can't say microsoft doesn't have the know how to make an un-rivalled antivirus protection program...furthermore, if these were implemented into OSs then wouldn't there also be an easy way to just update the virus protection. that saves everybody the trouble of using programs such as norton.. *shudders*Protection programs quarantine an infection by moving it to a folder where it is disabled and remains inactive so it can't cause harm. In many cases, the file is renamed. It's technically still an infected file, but it is rendered harmless. Many programs also allow you to monitor activity of quarantined FILES to ensure they stay that way. |
|
| 3331. |
Solve : pctatletail carnt remove it? |
|
Answer» Hello,i have a new dell xps 210,vista primium.It has PCTATLETAIL, Thanks,CBMatt no i got it myself about 2 weeks agoWith all due respect, If you installed it as you would have us believe, then you will know how to remove it. dl65 No offense, but to the Original Poster: You don't have to create new lines randomly in your post, it doesn't look nice and makes it harder to read ('word wrap' will automatically move words to new lines). Excessive unnecessary capital letters don't help either.To answer the question, if the program a monitoring program as Chris states. Such as a keylogger, then it will act like a virus and 'hide' itself so others are unaware of it's presence. I think there is a special keystroke combination to expose the main screen, where from there you can remove it. If this does not work an alternative could be to boot into safe mode, and remove it's program folder, (may not be 'PC Tattletale', in order to hide) and in NORMAL mode remove its entry using hijack this or CCleaner to fix invalid entries? Also Google the name and try find a method to remove it manually, if the above is not correct. TNXThis page says PC Tattletale can be removed as following. Though it recommends scanning with Spyware Doctor 5. PCTattletale Manual Removal: Warning: The following instructions are only for advanced computer users. We recommend you to backup your system registry or create a System RESTORE Point before any risky step. We offers no warranty of any kind to manual operators. For common users we recommend to remove MALWARES using anti-spyware tools, such as PestPatrol, Spyware Doctor, BPS Spyware&Adware Remover, ... To uninstall PCTattletale: 1. Terminate the processes in TaskManager: msn6mngr.exe Netlogon.exe svchost.exe Wincmd.exe WinLoad.exe WinSysMngr.exe PCTT.exe 2. Click Start > Run. Type REGSVR32 -u . Then click OK. Replace with following: %SystemRoot%\explorer32\chattext.dll %SystemRoot%\MSN32.dll 3. Click Start > Run. Type regedit. Then click OK. Navigate to and delete the subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Explorer HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Welcome HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E8AC9B0E9894094189EA59912D1CCA3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\39E9F6C570B40D842A0953B8A8C07ADB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\51799C1F87136324485141E00C6A942F HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\535AAC914F48699489B746B6ADD9165A HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D77628069B703345B8F64FB8EE22104 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\830EE956C56E84D45A51DD1CDC6E26A3 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91E6512C39B0465449BA5314D057905E HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A45B49DECD972DF4892DD152ACF2E0E1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C12F23E87949C614289082A5A0B1BFCD HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6D6E8663969C4142A4CDE91F63BDD38 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information\{0FFA260F-8A4D-4906-B572-6028A18DE3D5} Navigate to the subkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, delete the values: "(default)" = "", "WinLoad" = "%System%\Winload.exe" 4. Remove these files in Explorer: %SystemRoot%\Instructions.htm %SystemRoot%\KbdMonitor.exp %SystemRoot%\KbdMonitor.lib %SystemRoot%\mscomct2.ocx %SystemRoot%\mscomctl.ocx %SystemRoot%\msinet.ocx %SystemRoot%\MSN32.dll %SystemRoot%\mswinsck.ocx %SystemRoot%\PCTT.exe %SystemRoot%\tabctl32.ocx %SystemRoot%\UninstallPCTT.exe %SystemRoot%\Unzip32.dll %SystemRoot%\WinLoad.exe %SystemRoot%\xwebpic10.ocx %SystemRoot%\zip32.dll 5. Remove the directory in Explorer: %SystemRoot%\explorer32\ %ProgramFiles%\Common Files\InstallShield\Driver\7\Intel 32\ Hi, thankyou all for your advice i will try to remove it myself if there is no program to remove it... With all due respect dl65, i dont see were i said i installed it myself so how could i remove it???Quote from: paul420 on June 27, 2007, 10:59:42 PM Thanks,CBMatt no i got it myself about 2 weeks agoThis made it sound like you installed the program yourself. I thought the same at first. I had to read it a couple of times to realize that you were talking about your computer. Like I said before, this program has to be manually installed, so if you didn't install it and you're the only user, then someone has possibly been snooping around without your knowledge. In any case, if you continue to have trouble removing it, let us know.Thanks CBMatt,im gona ask my cousin when he gets home from collage at weekend to go into the registry. cheers....... |
|
| 3332. |
Solve : HJTL..pc running massively slow? |
|
Answer» I'm back again, this time it's for a friends pc. I ran the AVG anti-spyware & ant-virus in safe mode ont his comp also. I removed the things it has found & was wondering what I Should remove from this pc. For the record the help here as been great, really appriciate it. |
|
| 3333. |
Solve : isbro.hk? |
|
Answer» I have been having really bad problems with two pcs lately and i posted a thread on the hardware section called "a challenge for you".
Download a self-extracting copy of HijackThis from here ……. http://downloads.malwareremoval.com/hijackthis_sfx.exe Save it to your Desktop. Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder …… C:\Program Files\HijackThis Go to this folder and run the hijackthis.exe file. From the menu click on "Do a system scan and save a logfile". ******************* Rehide your Hidden Files & Folders by carrying out the reverse operation to that described at the start of this post. Copy and paste both the Superantispyware scan report and the HJT logfile to this thread. More specific removal instructions will follow for any malware revealed. OJ SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 06/26/2007 at 10:18 AM Application Version : 3.8.1002 Core Rules Database Version : 3260 Trace Rules Database Version: 1271 Scan type : Complete Scan Total Scan Time : 11:18:13 Memory items scanned : 386 Memory threats detected : 0 Registry items scanned : 4175 Registry threats detected : 0 File items scanned : 15754 File threats detected : 26 Adware.Tracking Cookie C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][1].txt C:\Documents and Settings\Owner\Cookies\[emailprotected][2].txt Adware.Starware C:\Documents and Settings\Owner\Application Data\Starware\Manager C:\Documents and Settings\Owner\Application Data\StarwareLogfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 12:31, on 2007-06-26 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\SiteAdvisor\6066\SAService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe C:\Program Files\SiteAdvisor\6066\SiteAdv.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Outlook Express\msimn.exe C:\Documents and Settings\Owner\Desktop\programs\HiJackThis_v2.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.co.uk R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.co.uk R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll O3 - Toolbar: Wanadoo - {8B68564D-53FD-4293-B80C-993A9F3988EE} - C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Search with Wanadoo - res://C:\PROGRA~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk O17 - HKLM\System\CCS\Services\Tcpip\..\{3CA4FF57-4204-4483-87DA-0CA825A2C31C}: NameServer = 195.92.195.94 195.92.195.95 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe -- End of file - 5245 byteswhen i ran superantispyware, i had several windows popping up asking to insert a disk into drive d (cd) with the options try again, continue and cancel. It happened when it was scanning the registry. Since deleting the nasties, it has booted up ok, no problems. Thanks so much for your help. Do you think this could've been the problem with the other pc? Only problem with the other one is that you cant boot it atall, not even to safe mode.oddjob is right about this being a phishing site. As long as you didn't download any attachments, you should be fine, but you might want to search for an ecard.exe file on your computer, just in case. Download CCleaner (install without Yahoo! toolbar) and configure it according to this guide. Use this to clean out your Temp and TIF, as well as invalid registry entries. I see that you don't have Java installed. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. As for your logs, I don't see anything malicious. AVG AS got rid of the Starware Toolbar, which is fortunate, but I don't know how much damage just a toolbar could've been doing. You say things are running fine now, though? I'm not too sure what you can do about your other computer if it's not booting up. That sounds like more of a hardware problem. I'll take a look at your other thread to see what kind suggestions have been made. You could try slaving the hard drive to your working computer and then scanning it with AVG Anti-Virus, AVG Anti-Spyware, and SUPERAntiSpyware. However, keep in mind that if the drive is infected, there's a possibility of it spreading.Alright, I just read through your other thread... Slaving a hard drive is fairly simple. First, open up the faulty non-booting computer and disconnect the hard drive. Pay attention to the cable connected to it. Open up your working computer and there should be a cage/slot that your drive will fit in. Remember that cable I mentioned? There should be a couple just like it in the working computer; use one to connect it to the drive. Then you'll need to jumper the drive and set it as a SLAVE. There should be diagrams on the drive that explain how to do this. Use tweezers to reposition the tiny plastic jumper. Here are some helpful references/guides that will likely explain it better... http://www.ehow.com/how_6030_install-second-hard.html http://www.ehow.com/how_6031_change-master-slave-designation.html http://www.pcguide.com/byop/byop_SettingHardDriveJumpers.htm If DONE correctly, when you boot up the computer, it should detect the new hardware and the slaved drive will show up in My Computer. You will then be able to use the virus/spyware scanners to scan this second drive.Thank! Will do that and let you know result. Added the faulty c drive to my daughters pc as a slave. There was no slot for a second drive so i had to remove the cd drive and put it in there. went to bios to ensure it was on autodetect which it was. Booted up ok but very very slow. went into "my computer" and it had the broken drive there as "d drive" but i was unable to open it, it stopped reponding. I tried to scan the broken drive using superantispyware but although i set it to scan the slave, it just scanned the other drive. I then opened word to try and open up a document from the slave but i had the error message telling me that my slave was in a different format. I then realised that the file system for my daughters pc was fat32 and the file system on the slave was ntfs. I then converted the file system on the working c drive to ntfs. I am still having same problem though. I am unable to access the slave. Device manager tells me that the slave is working but the error messages in event viewer keep saying "bad block on drive d". Any ideas on how i can get my data off the faulty drive? Is there any alterations i can make in the bios?As this now seems to be a hardware problem and not a spyware problem, is it better to continue my posts on my original thread in the hw section?Given the current situation...yes, I do believe this would probably be better-suited for your other thread. My hardware knowledge only extends so far and at this point, I'm not comfortable giving you further advice here when there is the potential to lose your data. Simply attempting to slave the drive shouldn't have caused any damage, but changing the format might not have been the best thing to do. I can't say for sure if this might've had any adverse effects. If you can manage to get the drive to boot, come back here and I'll help you with cleaning it out if necessary. In the meantime, I'll keep an eye on your other thread.I changed the format on the working drive (my daughters),, not the faulty one. Have taken drive back out now and my daughters pc up and running fine. Will continue the hardware problems on the other thread now. Thankyou for all your help. Alright, gotcha. Well, good luck on getting this all worked out. I know how frustrating it can be when you're worried about losing data.And if it brings about a regular backup routine...all the better. See the new posts in that thread. |
|
| 3334. |
Solve : Encrypted print on some pages? |
|
Answer» Suddenly I am pulling up pages on internet and half the print is encrypted and the REST is not. |
|
| 3335. |
Solve : Could This Be a Virus? |
|
Answer» I am noticing RANDOM problems with my PC. When I play World of Warcraft, It will half of the time Crash saying that there is a missing file. Sometimes, other random programs will crash(MSN, Firefox, anything else) will also crash. Now I am using Norton 2007, and I also scanned on Housecall, and they both said that my PC is all good. I also use Spybot, Adaware, CCleaner to grab EVERYTHING else. |
|
| 3336. |
Solve : computer virus? |
|
Answer» sister called and stated when she turn on computer a MESSAGE APPEARED (virus detected in system) how do u remove a virus? what do i TELL her? computer 4 months old. (help)We would need some info like what program is giving this message, the exact error message, the virus if named, and what type of virus and spyware protection is loaded. |
|
| 3337. |
Solve : Can't delete files without replication!? |
|
Answer» Only problem is it appears impossible to highlight the first documentt without opening it so I can't get to the point where I'm scrolling down and HIGHLIGHTING all the docs that i want to delete! When the computer starts tap F8 several times BEFORE you get to the Windows splash screen. THat will get you into safe mode. Try all of your scans while there and then delete the files as usual. Did you do this?Hi, yes I did do this but it still didn't allow me to delete the files. Continued to get the ERROR message cannot delete file, cannot read from the source file or disk'. Did allow me to delte individually by going into docs on from the Start menu, but can only do this one doc at a time and there are tens of copies of each doc (SEE recent posts about being unable to highlight multiple docs).There are certainly issues that need to be addressed. Did you ever determine that you are free from malware? If so, how?I've scanned with MCafee and Panda. My latest McAfee scan reveals only 1 cookie. I did run Panda also (free scan) and that revealed 47 spyware but I assumed that the scan would also have removed them. I tried to buy Panda Virus scan but discovered that it was incompatible with McAfee when I tried to download it and I didn't want to remove McAfee as it provides the core of the protection for my computer(!). Hoever, I recently realised that I have been receiving pop ups WARNING of a 'potentially unauthorised registry change' which were I think to do with spyware and giving me the choice of allowing the change or blocking it. When I looked at it seemed to be from Microsoft so I allowed it. I don't think I should have done this - I scrolled to the bottom of a recent pop up and realised that McAfee were advising a block if I was not expecting the change. Is there a way forward? I really appreciate your continuing help.How about [highlight]starting in safe mode[/highlight] then selecting [highlight]double click to open single click to select[/highlight] then try to select them all?OK, I'll give it a try.Panda will only remove viruses for free, spyware, trojans & worms are in the realm of Ewido/AVG Online Scan for free removal.Hi, i dont know much about it but what if its trying to read the documents off of the cd? i mean its worth a shot to put the cd in and try deleting them, if its looking for a source with the files on it. just a thought tho.You mean off the CD or off of "My Documents"? If it's the former, it's impossible without a CD-RW. If it's the latter -- it's been tried. Trust us on this, a burned disc should not be automatically trying to write to the hard drive.I seemed to have solved it. The AVG clean appears to have done the trick and I have purchased the antispyware which is compatible with mcAfee. The thousands of docs have been deleted (the scan revealed 50 items of malware). Fingers crosssed and thanks VERY much for all your help.50 pieces? Wow, another reason not to go with McAfee. I mean no offense to you, but honestly, 50? That's a lot. Quote I seemed to have solved it. The AVG clean appears to have done the trick and I[highlight] have purchased the antispyware which is compatible with mcAfee[/highlight]. The thousands of docs have been deleted (the scan revealed 50 items of malware). Fingers crosssed and thanks VERY much for all your help. Easy, Dilbert. Lesson not learned yet. By the way, Fed posted the solution over a week ago. Quote Panda Activescan |
|
| 3338. |
Solve : dmserver.exe? |
|
Answer» Ive found this program RUNNING on my computer under svchost.exe , and it seem to me that there were tomany programs running under svchost its USING more than 20 megs of ram. i think ill just delete the program and see what happens How about a HJT log?Well panda didn't pick up ant thing that i didn't expect, and it showed Wget as a hacker tool. and a few tracking cookies Any way Ive attached my hijack this log, i didn't notice any thing very strange in it.Still run Ewido/AVG.For some strange reason when I run the online Ewido Scan IE closes half way trough, with no error message, it just diesDownload the Ewido/AVG Antispyware free program, install it, update it & run it in safe mode. See if that turns anything up. You could look at Autoruns from www.sysinternals.com too. Let it load then set the view to 'hide signed microsoft entries', hit the refresh button & see what you can. |
|
| 3339. |
Solve : HJT log...Need help? |
|
Answer» My pc and net are running slow, so I ran spy/adware & virus scanners and found soy/adware & viruses. I ran HJT & PandaScan for another forum at www.techsupportforum.com but they would not help at all. I would greatly appiciate it if some one could tell me what to remove for the HJT log & tell me waht to do for the viruses. Here are my logs. |
|
| 3340. |
Solve : found 4 keyloggers with Spyware Doctor / RESOLVED? |
|
Answer» I use Windows XP. |
|
| 3341. |
Solve : Hourglass and Internet connection? |
|
Answer» You need to FIND out what program or malware is trying to access the internet, Hijackthis will show you the likely suspects. |
|
| 3342. |
Solve : Internet Connection Username being hijacked? |
|
Answer» SFC is System File Checker. You can run it from the command line or under the tools tabs in system information. If this doesn't find the problem try running the Internet Explorer Repair Tool.You winsock may have been damaged by your VIRUS removal. This is kind of common. |
|
| 3343. |
Solve : Zone firewall? |
|
Answer» hello |
|
| 3344. |
Solve : Spyware Terminator troubles? |
|
Answer» After installing the latest updates in Spyware Terminator today it stopped some other security working. ie AVG Anti Virus, Spyware Blaster, RemoveIt. (I never tried the others I have INSTALLED) Note on SpywareTerminator: We originally listed Spyware Terminator on this page out of concerns that Crawler, the company behind the product, had established CONNECTIONS with IBIS, a well known adware distributor responsible for such adware programs as Wintools, Websearch, & Huntbar. Although we FOUND no problems in our initial testing with Spyware Terminator, and while the vendor itself announced that it was exiting the adware business (1), we decided out of caution to impose a three month probation period before we would consider re-testing and, if warranted, de-listing the the product from the Rogue/Suspect list. During that three month probation period we monitored the behavior of IBIS and Crawler. At the end of the three month probation period we re-tested Spyware Terminator, again finding no problems serious enough to justify listing the program on this page. As the vendor involved has not been involved in the distribution of adware for many months, and as the program itself exhibits no problems serious enough to warrant MENTION on this page, we have decided to de-list Spyware Terminator from the Rogue/Suspect list and can no longer regard the program to be "rogue/suspect." From Spyware Warrior...not exactly a glowing endorsement. Glad you got it solved. patio. 8-) |
|
| 3345. |
Solve : Appropriate antivirus software? |
|
Answer» My current protection ARSENAL: |
|
| 3346. |
Solve : weird problem...? |
|
Answer» not really crippling (anymore), but I have this weird virus that permanently disabled my SYSTEM Restore and doesn't let me right-click in Windows Exporer or on the desktop...ALSO killed my Search function after a while...there were other PROBLEMS at first, but they disappeared after about a day... |
|
| 3347. |
Solve : Symantec Firewall/VPN 100 Appliance? |
|
Answer» Hello, |
|
| 3348. |
Solve : spyware killer pro? |
|
Answer» Me and my Dad decided to take a free 30 day trial of spyware killer pro from cosmi. We are both running win xp pro, I.E, and both have avg, zone alarm, ewido, spybot and a2. My Dad downloaded spywarekiller pro first and it detected about 7 adware/dialers ETC. We were quite shocked as all scans from the other spyware removers showed pc to be clean. After installing it, his homepage had been changed to msn.com but we thought nothing of it. |
|
| 3349. |
Solve : what in the #?? |
|
Answer» did a search tonight on my PC & found the following notepad document FILED under: |
|
| 3350. |
Solve : AVG scan what is this?? |
|
Answer» You guys have been so much HELP with my last question. There are many valid reasons for those files to show changed, a Windows update, file system check that replaced them if corrupted, and others. As long as AVG doesn't say they are infected it is ok. If it continues to show changed, delete the FOLLOWING file(s) in the C:\ directory and AVG will create a new one(s)... dl65 thanks..I think Quote from: DeeC on April 25, 2007, 08:15:15 PM thanks..I thinkYou think? Is there a problem? He just gave you the information you asked for.Yea, I guess I didn't realize they sign their posts with an eye roll. Thought he was being sarcastic.DeeC ...... LOL ........ I always sign my posts with my username and the If I wanted to be sarcastic, you would know........ dl65 Quote from: DeeC on April 26, 2007, 11:24:40 AM Yea, I guess I didn't realize they sign their posts with an eye roll.Ah, sorry for giving you the third-degree then. I actually thought the same of dl65 the first time I came here. Heh.Ok Ok, no picking on the newbie...LOL Quote from: dl65 on April 26, 2007, 12:42:44 PM DeeC ...... LOL ........ I always sign my posts with my username and the Yes and it's not the first time DL's smilie has caused that problem. |
|