Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3351.

Solve : Help! I seem to have an email worm?

Answer»

It is now AVG Anti-Spyware...

Still HIGHLY RECOMMENDED and still Free.

patio. 8-)I was asking the OP what happened to Ewido because Ewido should have fixed his problem.
I called it Ewido because I feared he got it confused with AVG Antivirus.OOoops sorry 'bout that.

3352.

Solve : Major computer problems, spyware, trojans the works?

Answer»

As you are new, you should browse the forums and see that AVG Free, SPYBOT, AdAware and CCleaner are frequently recommended. They are all free.This is an EXAMPLE of someone posting a question to a thread UNrelated to the original issues.

tracypatzold > please help US by starting your own new TOPICS for discussion when you visit a site. Do not piggy back on another member's topic unless your POSTS are directly related to the thread's discussions.

Thanks.


OJ

3353.

Solve : Help!What`s going on??

Answer»

I received email from someone I don`t know telling me to "stop sending them this crap". I never sent them anything. This was through my yahoo mail.Is someone using my yahoo ID (and password)? Am I a part of a SPAM-bot network? How can I tell?
My anti-spyware and anti-virus are up to date and show nothing unusual. I have used a rootkit revealer to see if something might be hidden. This is also a fresh clean install of winxp pro
It bothers me that someone would use my id to annoy other people-how do I stop it besides changing my password?.either it is SPAM or maybe they mis-typed the email address they were intending to send it to which intern made the email come to you.Or you gave the password to someone ELSE, or you have been hacked, or you are a zombie mailer, or your brother's playing tricks on you.

There are others POSSIBLE as well.ummm... I think ill go for one of the things GX said

3354.

Solve : Need help recovering from Smitfraud.C?

Answer»

Hello, I'm NEW to the board, so please forgive me if I'm posting erroneous information, while leaving out the important stuff.

Yesterday I was hijacked by Smitfraud and 40 other spywares. I ran Antivir, it had 5 detections, I removed them, and then Antivir stopped functioning. Then the computer BEGAN restarting all the time. I entered Safe Mode, found that Antivir still doesn't work, and ran Spybot and Ad-Aware. The found and removed many things, though they could not remove one entry of Smitfraud.C, specifically winsys2f.dll. I rebooted Safe Mode several times, ran Spybot and Ad-Adaware each time, and now each has no detections. I cannot find winsys2f.dll anywhere. I have folder oprions set to 'show hidden files' and unchecked 'hide protected operating system files.' I edited the registry so I was able to turn off System Restore. I tried reinstalling Antivir in Safe Mode with Networking, but it will not activate or function. When I start Windows normally, there are multiple errors and it is unusable or I get BSOD. It is also telling me I do not have a genuine copy of Windows (I don't know if I do or not, but I wasn't getting that message before.)

Any help resolving this would be appreciated, just let me know what to do or what else to post.

Here is my system, which was built from scratch (not by me) and includes no recovery disc:

Windows XP Professional Version 2002, SP 2
Intel Pentium III, 938 MHz, 512 MB of RAM

I don't know what other hardware to post, or where to find that information.

Here is my HijackThis log taken during Safe Mode (I can't run it in normal mode):

Logfile of HijackThis v1.99.1
Scan saved at 4:36:19 PM, on 1/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Kenneth E. McConnell\Desktop\Programs\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Protection Bar - {0D045BAA-4BD3-4C94-BE8B-21536BD6BD9F} - C:\Program Files\VideosCodec\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [wdokbye.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Kenneth E. McConnell\Local Settings\Application Data\wdokbye.dll",bpzgoi
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [sysinter] C:\WINDOWS\system32\adirss.exe
O4 - HKLM\..\Run: [sdfghjgewaertyutrew.exe] C:\WINDOWS\system32\sdfghjgewaertyutrew.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Cliprex_WhenUSave_Installer] C:\Program Files\Cliprex_WhenUSave_Installer\Cliprex_WhenUSave_Installer.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\KENNET~1.MCC\LOCALS~1\Temp\spchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERHer ya go
http://www.bleepingcomputer.com/forums/topic17258.html
http://wiki.castlecops.com/Malware_Removal:_SpyAxe_Removal
http://www.spywareremove.com/removeSmitfraud.html
http://www.anti-spyware-101.com/remove-smitfraud/
Spybot Search and DESTROY will handle that. If you use IE, you can use Spybot's immunize function to prevent a recurrence. Will also prevent a lot of other spyware.Spybot couldn't remove all instances of Smitfraud.C, only some of them. Now I'm also having trouble with adirss.exe.

Logfile of HijackThis v1.99.1
Scan saved at 10:46:27 PM, on 1/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\adirss.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Documents and Settings\Kenneth E. McConnell\Desktop\Programs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O4 - HKLM\..\Run: [wdokbye.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Kenneth E. McConnell\Local Settings\Application Data\wdokbye.dll",bpzgoi
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Cliprex_WhenUSave_Installer] C:\Program Files\Cliprex_WhenUSave_Installer\Cliprex_WhenUSave_Installer.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\KENNET~1.MCC\LOCALS~1\Temp\spchost.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\ProgramYeah, doing some google research on removing smitfraud would be a start.......otherwise

www.pc-tools.com

Spyware Doctor is a beast and will tell you if there is more to pick up. For me, it got rid of the worst spyware you can imagine. As long it is not a virus (doesn't look like it) Spyware Doctor will cover ya.

When you run into an "issue" I'm sure you will run into and need assistance regarding Spyware Doctor, PM me, and I will relieve you of your pain.

Be nice forum mods please I don't think more spyware removers are going to help. Spybot and Windows Defender already failed, in both safe and normal modes. Since I didn't get a recovery disc with this computer, I don't have any option now but to format the C drive and buy a new copy of XP. I just hope that the malware hasn't infected the BIOS or will otherwise survive the reformat, or I'll be wasting more money. My machine's pretty much an expensive boat anchor as is, and that's pretty depressing.Hi there.
Ok well so you can have the most efficient help i recommend posting the full HJT log file. By default the forum only allows so many characters. Take as many posts as it takes to post the full log.

ChrisQuote

I don't think more spyware removers are going to help. Spybot and Windows Defender already failed, in both safe and normal modes. Since I didn't get a recovery disc with this computer, I don't have any option now but to format the C drive and buy a new copy of XP. I just hope that the malware hasn't infected the BIOS or will otherwise survive the reformat, or I'll be wasting more money. My machine's pretty much an expensive boat anchor as is, and that's pretty depressing.
Smitfraud is not your average infection, it requires specially made tools to remove.
http://www.spywareremove.com/removeSmitfraud.html
Download that program and FOLLOW its instructions.
Do not ignor this post like you did my last one or your problem will NEVER be solved.
No regular spyware remover program can completely remove smitfraud.
smitfruad will get it just google it.. make sure you dl it from a good site

http://www.google.com/search?hl=en&q=smitfraud&btnG=Google+SearchThanks for the help. everyone!

I tried Smitfraudfix, and that seemed to work on that one.

However, I had several other INFECTIONS I couldn't get rid of. I couldn't run Panda AV, install ANY programs, or burn any discs. Yikes!

My computer was custom built, with no recovery/installation disc. So, tonight I made a bootable disk on an uninfected computer and ran FDISK on my infected one. I bought a new copy of XP at BestBuy and am installing that now.

So far, so good.

I lost some data and programs, but no biggie.

That's a good tip about POSTING THE COMPLETE HIJACK LOGS. I hadn't noticed that mine were getting the ends clipped off!

D'Oh!

Cheers.
3355.

Solve : PWS- LSP Trojan?

Answer»

I've searched for how to get rid of this. McAfee can't clean/quarantine or delete it. And it doesn't allow me to access the internet.

McAfee says it is a trojan located in C:\WINDOWS\system32\u.dll

What do I do to get rid of it?

And yes that's all the information I have about it.What were you using for protection besides McAfee?DLoad; install; update and run AVG Anti-Spyware and let it fix all it finds...It blocks internet access. At least I haven't been able to go to any website.I don't ahve anything other than McAfee.That was your first mistake.Then I will learn from my mistake. But I can't until this is gone.Have someone DLoad and burn AVG Anti-Spyware to a CD...

While they are at it also have them grab :

Spybot S & D
AdAware
CCleaner

All these are FREE which means you should have them and use them frequently to keep your machine in tip top shape...Alphamale .... after installation make sure you boot the infected computer into safe mode before running the fixes with the tools patio advises.


OJOkay, I did a system restore and was able tot get online to download AVG. It got rid of the trojan. But, now I can't get online, I tried system restore a few more times but I still can't get online. I just get " LIMITED or no connectivity".
I uninstalled the driver and re- installed it, and still nothing.

What do I do now?Anyone think this could've been NewDotNet (or something similar) by any chance?

This may be a longshot, but...

Alphamale,
Download LSPFix with another computer and put it on your own. Go AHEAD and double-click on it. Check the I know what I'm doing button. You will SEE two panels. If there is any file LISTED in the Remove panel on the right-side, leave it as is and just click Finish>>, then reboot your computer and you should now have access to the internet. If nothing is listed under the Remove panel, do not do anything; just close the program.

If this doesn't help you, an HJT log may be in order, as there could still be something causing trouble. Thank you. I'll try it.It worked! Thank you very much.I'm quite pleased to hear that it worked. Be sure to keep up with your regular scans and if anymore problems arise, stop by and we'll help you out.

I'm suspicious of whatever infection you had. Scan again to see if anything else comes up. If you get that same trojan again, post back and we'll instruct you further.

EDIT: Funny, I just saw your other post. It's far too late for me to review your log right now, but by the time you come back on, someone will have likely taken a look at it. If not, I'll see what I can find.

3356.

Solve : Spam- Xarvester?

Answer»

I have a virus named Spam- Xarvester. McAfee can't do a thing about it and AVG can't find it. It keeps trying to send an email and McAfee blocks it, but it just keeps trying over and over. McAfee was also messed up somehow, whenever I boot, a window pops up saying that components of ActiveShield are missing.

McAfee says that the virus is in the C:/windows32\cp1041.dll or something like that.

Can I download something or manually do something to get rid of it?

No website has anything on this. None that I have found anyway.Alphamale ........ According to what Google found, I WOULD be posting a hijackthis LOGFILE here for us to look at and then a solution may be found.
Get hijackthis at .... http://www.majorgeeks.com/download3155.html


dl65 Logfile of HijackThis v1.99.1
Scan saved at 8:21:10 PM, on 4/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgamsvr.exe
C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgupsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\LxrSII1s.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgcc.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Toshiba Games\Penguins!\help\GameCode\Programs\WordWeb\wweb32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\eHome\ehmsas.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\svchost.exe
c:\program files\mcafee.com\shared\mghtml.exe
C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgwb.dat
C:\Program Files\Toshiba Games\Penguins!\help\GameCode\Programs\Mozilla Firefox\firefox.exe
C:\Program Files\Toshiba Games\Penguins!\help\GameCode\Programs\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstart
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: SMS Server.lnk = C:\Program Files\Rosetta Stone\SMS\server.exe
O4 - Startup: WordWeb.lnk = C:\Program Files\Toshiba Games\Penguins!\help\GameCode\Programs\WordWeb\wweb32.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15-3.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by19fd.bay19.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, INC - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\TOSHIB~1\PENGUI~1\help\GameCode\avgupsvc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Lexar Secure II (LxrSII1s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrSII1s.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PcdSptiSvr - Sony Cooporation - C:\Program Files\Sony\mylo Utility\PcdSptiSvr.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe

3357.

Solve : Icesword 1.20 ??

Answer»

I saw ICESWORD 1.20 on Major Geeks. They say, "IceSword is an effective tool against rootkits". Does anyone have an OPINION about it? Is it worth downloading?
pantherman..... Any blurbs I have READ suggest that it's ok ........ The D/L is only 2.1 mb ...... so if you have broadband , /dl it and test drive it ........

DL65 Thanks dl65, I will give it a try.

3358.

Solve : logex problem?

Answer»

i have this logex text document that CREATE itself in my c: after i surf any websites.
it contains the website that i surf and keeps on overwriting itself.
c: is not my windows drive but its a drive i created from the same harddisk.
sometimes when i on my IE, it shows the 'page cannot be displayed' screen.
i have the registered version of spyware doctor and using avg trial version.
no scanned RESULTS were shown on both software.

anyone know how i can remove this logex file ?Run both of the following online SCANS first.
Ewido/AVG Online Scan
Panda Activescan

Search your computer for 'logex' and tell us ANYTHING that turns up.

Post a hijackthis log so we can see what's running on your computer.

3359.

Solve : X-HIV Infects Internet!!!?

Answer»

Ya guys have you ever heard about the SoBig virus?
Well this, the X-HIV virus is more dangerous than that!!!
SoBig infected me 4 years ago, and it took me half a year away to FIX my computer, because it was the administrator of my server!!! Now X-HIV infected me and my server is rulied!!! None of my computers turns on and some of them are 'killed'!!!ummm well ill tell you that bill gates doesnt care, NORTON barely works to be begin with same with Macfee, AVG or Avast will problably do the job before the othere TWO.

do you have any info on the virus?

unlovedwarriorNooo! NOT TEH INTERNETS!

If I may be so frank, I don't think any of the above will fix it. However If you have a problem, if no ONE else can help, and if you can find them, maybe you can hire the A-Team

For future reference; there SEEMS to be no such thing as the X-hiv virus. Not according to Google, anywayYou might need Magic Johnson. Only he can stop X-HIV.

3360.

Solve : Malware alert?

Answer» SOMEDAY...HOPEFULLY LATER in my LIFE
3361.

Solve : HELP! I don't know what this is!?

Answer»

I keep getting a pop up message (actually 2 similiar mssg.) - it says Messenger Service in the top corner and in the box it says:

Message from Local System to user on (date & time)
CRITICAL ERROR MESSAGE! Registry Damaged & Corrupted
To fix this proplem:
Open IE & type www.registrycleanerxp.com
Once you load the web page, close this message window
After you install the cleaner program you will not receive any more reminders or popups like this. Visit www. registrycleaner.com immediately!

The other message says (same messenger service box)
Message from Registry to Cleaner
Stop! Registry Cleaner Recommended
To download & scan computer for registry error:
1. Visit www. registrycleaner.com
2. Download & install Registry Cleaner
3. Scan computer for any possible errors
4. Register to complete scan corrections
5. Registry cleaner can improve system performance & stability issues.

I get this pop up constantly (like every minute or two). I have re-formatted my hard drive & reinstalled my operating system and a minute after windows starts up, I get the pop up again. If I unplug my ETHERNET cord from my modem (I have comcast high speed internet), I don't get the message. I even plugged in a different computer to my modem and BAM! it got the pop up too! I've tried anti-virus protection, firewall, spyware/adware scans nothing gets rid of it. Somebody please help me. I don't know what else to do!

Thank you in advance for any suggestions. These are what's known as rogue programs...they SAY your machine is infected and want you to spend your hard earned cash for a fix that literally does nothing...

DLoad and run a little script called "Shoot the Messenger"

This enables you to turn off the messenger service and this garbage will go away.what protections do you have as well?I found the Shoot the Messenger website and I tried to download it and I am unable to. The DOWNLOADING screen comes up, but the progress meter doesn't show anything and then after a while I get an error saying it was unable to download and it timed out. ?

As far as protection, I have McAfree Virus Scan, personal firewall and I have a pop up blocker running.

get avg anti-spyware spybot search and destroy adaware se personel free run the scans in safe mode w/ system restore off

and tell us how things are goingIf you have to run 'shoot the messenger' you're not running the latest service pack on whatever OS you use. What OS are you using? if your using xp you should be able to go to control panel -> administrative tools -> services
a list of services will open in a window then find Messenger right click on it select properties and then a box will open up in the drop down list startup type: in the middle of the box select disabled
click apply and these messages should go awayQuote from: srksrk on April 23, 2007, 11:00:38 PM

I found the Shoot the Messenger website and I tried to download it and I am unable to.

What site was this?Quote from: srksrk on April 23, 2007, 11:00:38 PM
I found the Shoot the Messenger website and I tried to download it and I am unable to. The downloading screen comes up, but the progress meter doesn't show anything and then after a while I get an error saying it was unable to download and it timed out. ?

As far as protection, I have McAfree Virus Scan, personal firewall and I have a pop up blocker running.



It's a tiny DLoad and probably finished before you blinked...where do your downloads go to ? ?if your using xp you should be able to go to control panel -> administrative tools -> services
a list of services will open in a window then find Messenger right click on it select properties and then a box will open up in the drop down list startup type: in the middle of the box select disabled
click apply and these messages should go away


THIS WORKED! Thank you, Thank you, Thank you! to everyone for there advice. This is a great site.
3362.

Solve : About:Blank virus web windows close automatically?

Answer»

Hello,

I think I have the About:Blank virus. When I try to open a new window or click on a new link About:Blank Micro" will appear for a very quick second. When I click on a link the new window will open and the old window will close and be gone. My back button will not work.

A little background information. I thought I had the Bravesentry virus and was cleaning this when this about:blank thing STARTED to happen.

I have run a Hijackthis and looked at the log file but do not see about:blank on it.

I'm stumped.

any help would be apprecitaed.

Brentino
PS: I know I already have a thread but, this is a better spot.

this is the log file:

Logfile of HijackThis v1.99.1
Scan saved at 5:39:56 PM, on 12/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Winferno\SIEPIE\SIEPulse.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Consumer INPUT Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInput.exe
C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInputUa.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\FrontierNet\FrontierNet DSL Attendant\app\TangoService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
C:\PROGRA~1\FRONTI~1\FRONTI~1\app\TangoManager.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.frontiernet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/yme/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\FRONTI~1\FRONTI~1\app\TANGOM~1.EXE
O4 - HKLM\..\Run: [ViewMgr] C:\Program FThis is an incomplete logfile. You will need several posts to include it all. It should go all the way to 023.

Run your scans in safe mode with system restore off. Then use the online scanner at www.trendmicro.com THEN run Hijack This and post the logfile as described for analysis.Hello,

Thank you for your help.

I started my computer in safe mode and tried to run the virus scan at trendmicro.com. My internet closed down on three separate occasions. So, I ran the virus scan in normal start up mode. It FOUND one "infection" ADW_spysherif.AB which I cleaned.

I am attaching my HiJack this log. If that doesn't work I will repost and add what I need to.


Thank you so much for your help.

Well, that didn't work, let's try this:

Logfile of HijackThis v1.99.1
Scan saved at 7:30:30 PM, on 12/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Winferno\SIEPIE\SIEPulse.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInput.exe
C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInputUa.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee\MSC\mctskshd.exe
C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\FrontierNet\FrontierNet DSL Attendant\app\TangoService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\FRONTI~1\FRONTI~1\app\TangoManager.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.frontiernet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/yme/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [TangoManager] C:\PROGRA~1\FRONTI~1\FRONTI~1\app\TANGOM~1.EXE
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr_.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bmore of my log:

O4 - HKLM\..\Run: [SIE2004] "C:\Program Files\Winferno\SIEPIE\SIEPulse.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
O4 - HKLM\..\Run: [ymetray] "C:\Program Files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe" -preload
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [MISAggregator] C:\PROGRA~1\McAfee\MCAFEE~3\MisAgg.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Consumer Input Rewarded with MyPoints, Consumer Input] C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInput.exe
O4 - HKCU\..\Run: [Consumer Input Rewarded with MyPoints, Consumer Input Update] C:\Program Files\Consumer Input Rewarded with MyPoints, Consumer Input\ConsumerInputRewardedwithMyPoints,ConsumerInputUa.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\Regclean.exe" -startminimize
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Private IE - {644B7837-F1E9-4dba-853C-7E304F51968B} - "C:\Program Files\Winferno\SIEPIE\PrivateIE.exe" (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: (no name) - {B9030549-F0EA-40a7-8E3C-62A9FB0812D0} - "C:\Program Files\Winferno\SIEPIE\PrivateIE.exe" (file missing)
O9 - Extra 'Tools' menuitem: Private IE - {B9030549-F0EA-40a7-8E3C-62A9FB0812D0} - "C:\Program Files\Winferno\SIEPIE\PrivateIE.exe" (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.mypoints.com
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v44/scrabblecubes/scrabblecubes.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {18C3FD15-74F6-4280-9C98-3590C966B7B8} (SkillGam Control) - http://www.worldwinner.com/games/v46/skillgam/skillgam.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} (FunGamesLoader Object) - http://www.worldwinner.com/games/v46/shared/FunGamesLoader.cab
O16 - DPF: {2C153C75-8476-434B-B3C3-57B63A3D1939} (Brickout Control) - http://www.worldwinner.comore of my log again:

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) - http://www.worldwinner.com/games/v49/bjattack/bjattack.cab
O16 - DPF: {5EE92643-21CE-4949-903F-39439DCC3944} (Shapetris Control) - http://www.worldwinner.com/games/v42/shape/shape.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://amiuptodate.mcafee.com/vsc/bin/2,0,0,0/McUpdatePortal.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v45/bejeweled/bejeweled.cab
O16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) - http://www.worldwinner.com/games/v47/blockwerx/blockwerx.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com.edgesuite.net/panel/maple/dcainst.cab
O16 - DPF: {94299420-321F-4FF9-A247-62A23EBB640B} (WordMojo Control) - http://www.worldwinner.com/games/v45/wordmojo/wordmojo.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinner.com/games/v55/cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinner.com/games/v45/sol/sol.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D8D7672-93FF-417E-9024-C16AD141C50C} (Haunted Control) - http://www.worldwinner.com/games/v49/haunted/haunted.cab
O16 - DPF: {A91FB93D-7561-4524-8484-5C27C8FA8D42} (WwLuxor Control) - http://www.worldwinner.com/games/v48/luxor/luxor.cab
O16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) - http://www.worldwinner.com/games/v64/swapit/swapit.cab
O16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) - http://www.worldwinner.com/games/v40/hangman/hangman.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BB637307-92FA-47EC-B3F7-6969078673CC} (Royal Control) - http://www.worldwinner.com/games/v44/royal/royal.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) - http://www.worldwinner.com/games/v42/paint/paint.cab
O16 - DPF: {E12EB891-D000-421B-A8ED-EDE1BDCA14A0} (GolfSol Control) - http://www.worldwinner.com/games/v42/golfsol/golfsol.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) - http://www.worldwinner.com/games/v46/wwspades/wwspades.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4902/mcfscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee Log Manager (McLogManagerService) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mclogsrv.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task SCHEDULER (McTskshd.exe) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mctskshd.exe
O23 - Service: McAfee User Manager (mcusrmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcusrmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\FrontierNet\FrontierNet DSL Attendant\app\TangoService.exe

That is it: Thank you so much for your help!!!Ok try this, download CWShredder, download AboutBuster, and download Adaware, install them and run them. Hope that helps 8-).You have entries for Ewido, MacAfee, Spyware Blaster, Panda and much more. Have you run ALL of your scanners in safe mode with system restore turned off? Try that and then the Panda online scanner again.

Why do you have Tango on there?

3363.

Solve : trojan removal?

Answer»

Hi.

This is a follow-up to my post about an occasionally slow computer.

Thanks to the good advice I got in that thread, I discovered a BackWeb problem and deleted it, a Ptsnoop problem and deleted it, and I’ve downloaded a-squared’s HiJackFree and it’s found Trojan.Zapchas.ac in my explorer.exe. The instructions for removing the trojan are, to me anyway, a bit vague. How do I delete the trojan and keep the NECESSARY exe?

BryonA-squared should be able to get rid of it...what instructions did you recieve ? ?

patio. 8-)The help page says that when one has fully determined that something is bad, then use the kill function off to the left. I can clearly see that, but it doesn't tell me how to get rid of just the trojan while keeping the original exe my computer needs.Ewido/AVG Online ScanFed, the Ewido scan looks great, but I can't get it to run through either my IE or Firefox. I should have mentioned again that I'm running Windows 98 SE. Perhaps the OS is too old for the scan.

BryonYep, you need W2K or XP to run it. What original .exe are you worried about ? ?

There is a non-destructive method of re-installing Win98 without losing your data just in case...I'm either not being clear about my problem or I don't really understand my problem. Probably the latter.

HiJackFree tells me that I've got the Zapchas.ac in the explorer.exe file, the one that runs the graphic interface for Windows 98 SE. My question is how to get rid of the trojan while keeping the graphic interface. I used HiJack's quarantine procedure to see about removing the trojan and I lost my toolbar at the bottom of the page. I quickly undid the quarantine so I could navigate again. So how does one get rid of the trojan but not the useful aspects of explorer.exe? Or do I need to have a spare explorer.exe ready to run?

(I've read that Zapchas often creates a second explorer.exe in the system folder, and that the original is in the Windows folder. There's only one explorer.exe on my HD.)

ALSO, the HiJackFree online analysis tells me I've got a dozen other trojans or worms or adware in addition to the one it mentions in the main process scanner. Spybot, Ad-Aware Lite and Spyware DOCTOR don't see any of them (which, I know, doesn't mean they're not there). What route do I take with the conflicting information?

3364.

Solve : tracking blog guests?

Answer»

is it POSSIBLE to track people who visit your blog (any way at all)? And how dangerous can those sorts of viruses be?

recently I started visiting a few and wound up with a virus called stauscheck/statfind, or something like that - I forgot.

It was out of PLACE (from my usual viruses) so I looked it up and it turned out to be a blog monitoring tool that tracks IP numbers, telling the site owner how often the number visits. Apparently, it monitors the guest's COOKIES as his web page loads the site, sending the info back to the site owner so he/she knows how you found them.

the thing is, I know the people I visited, and I don't feel very COMFORTABLE knowing they might be able to see what I'm doing online.

As we al know, viruses are 100% illegal. All I can tell you is buy great protection. If you need help finding one, start a new topic asking for opinions. Because this topic has the potential of becoming a "how to create a virus" or "how to insert a virus" thread, I will be locking it. This thread may or may not stay locked, depending on admin decision.

3365.

Solve : Malware wiped 5.3 and spydare?

Answer»

Help me. I have two computers that is infected with spyware. The first one has malware wiped 5.3 and spydare. I think they are the same program. Spydare flashs a circle with a red line through it over a question mark. Click on the flashing question mark and it take you to a site that wants to scan your computer and pay to buy the program. Yet can not uninstall either program. I know it is a scam/id theft program.

I ran pest patrol. The spyware prevents pest patrol to update its files and scan the computer.

I have Windows XP home and I.E. Explorer 7 on the computer.

Thanks.


I suggest you print this out to help you follow my advice.

***********************

Make sure you have exposed all Hidden Files & Folders.

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the CHECKBOX labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.

***********************

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from TIME to time].

*******************

Rehide protected system files & folders by doing the reverse operation to that listed at the start of this post.


*******************

Lastly, download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and PASTE both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow.



OJ



Info on the program you mentioned...

MalWare Wiped:

AGGRESSIVE, deceptive advertising; uses flawed, inadequate detection scheme; same app as AdwareDelete, AntiVirus Gold, SpyAxe, SpyFalcon, SpyLocked, Spyware Sheriff, SpywareStrike, TitanShield AntiSpyware, & VirusBlast [A: 12-28-05 / U: 12-26-06]


I would certainly STAY away.

And keep the issues in the same thread so those helping do not get confused...
3366.

Solve : has encountered a problem??

Answer»

when i try to open a program, ill GET errors mostly saying something has encountered a problem and needs to close, if i try to open it 2-3 times it'll keep saying that. then the 4th time it'll finally open. i also get alot of those dwtson.exe errors. i tried to get rid of watson, but it keeps coming back. any suggestions on how to resolve this?cgts18...... Wow with all the info you have provided , it's hard to know where to START ......... How about this ...........
What OPERATING system are you using ?
Is it current with all the latest updates ?
When did this start ?
Is it always the same program that results in this error message ?
Could you please list one of the Dr Watson error messages ?


dl65 xp pro, not registered, not current with updates, few weeks,(ive had it for months) the instruction at "0x7c882fc4" referenced memory at "0x7c882fc4". the memory could not be written. click ok to terminate the prog.
my firewall also keeps popping up alot, most of the time it says a "helkern attack" was detected.
but when i try to open alot of progs or firefox, it usually just says "" has encountered a problem and needs to close.cgts18 ...... helkernis a nasty worm ......... Your firewall should be able to hold it at bay.

As far as the other errors...... a format would probably sort THINGS out , but in the meantime what about posting a hijackthis log and we can see whats running in there .

dl65
Logfile of HijackThis v1.99.1
Scan saved at 7:09:10 AM, on 1/15/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\1141165206\ee\AOLSoftware.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Defender Pro\Defender Pro Firewall\KAVPF.exe
C:\Program Files\Labtec Wireless Desktop\MagicKey.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Labtec Wireless Desktop\MulMouse.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Labtec Wireless Desktop\OSD.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Nero\Nero 7\Nero Home\NeroHome.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.766\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: OsbornTech Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Defender Pro Firewall.lnk = C:\Program Files\Defender Pro\Defender Pro Firewall\KAVPF.exe
O4 - Global Startup: Enable Labtec Wireless Desktop.lnk = C:\Program Files\Labtec Wireless Desktop\MagicKey.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll (file missing)
O9 - Extra 'Tools' menuitem: Popup Blocker - {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - C:\Program Files\DefenderPro AntiSpy\PopupBlocker\PopupBlocker.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {141EF9AD-3A5F-24EE-949A-7F2330411A0B} - http://85.255.113.214/1/gdnUS2218.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by22fd.bay22.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: hubbsi - {7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885} - C:\WINDOWS\system32\vwlummc.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
---------not sure if thats what you meant> thats all i can fit.

3367.

Solve : Big problem with 'generic.dk'?

Answer»

Recently I've been getting notices by my Macafee that I my 'C:\windows\system32\crunner' file is infected with a 'generic.dk' Trojan. I try to delete/quarantine/clean it but apparently its 'write protected'. I specifically scanned the 'crunner' file with Lavasoft adware se and it revealed 6 viruses and I cleaned them all, but I still receive the notices about the Trojan. Is there anyway to GET rid of this WITHOUT completely reformatting my hard drive?Download Trojanhunter 4 from here ...

http://www.misec.net/

***************

If you are on Windows 2000 or XP ....

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.


Install both programs and update them to the latest definitions.

Do NOT use them yet.


Now boot to safe MODE. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system SCAN with each program and let them fix what they want to.

REMEMBER TO SAVE THE SCAN REPORTS and also remember where you saved them.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > AVGAS is a good program to use as an “on DEMAND” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

In your next post please include the scan reports from both programs.


Please let us know if anything has improved for you. Is McAfee still reporting any problems?


OJ

3368.

Solve : can't delete virus... please help!?

Answer»

i have a virus (TROJ_CONHOOK.AA) located in C:\WINDOWS\system32.icwiew.dll, and security program (trend micro pc-cillin) says that it needs to be manually deleted. I don't know very MUCH about things like this, and I'm not sure if the file it's located in (icwiew.dll) is important or not, but each time i attempt to delete it, it says that it is being used by another program or person. even when i close all the PROGRAMS on my computer, halt internet traffic, ect. the message still comes up. i need to know how to delete icwiew.dll, or clean out the virus if this file is too important to delete. please help! thank you. echinococcosis...... First of all , it's a trojan ....... So if your using win XP , the first thing to do is to turn off system restore on all drives. Go to the control panel and click on the [highlight]system icon [/highlight] ( make sure you have the control panel set to display the classic view ....... When the system properties BOX opens ....click the [highlight]System restore tab [/highlight]( up top ) when the new window opens , put a check mark in the box in front of "turn off system restore on all drives" then click apply and ok and close up the control panel and exit . Now reboot your machine into "SAFE mode" ..... Once it shuts down ,and just as it starts to reboot, repeatedly tap the F8 key until you are offered various options to start ....select SAFE mode .........
once it finishes loading , go into C drive / programs / windows ......... then scroll down to the system32 folder ....... open it and go down to [highlight]icwiew.dll[/highlight] right click it and select delete and it should delete. Now run a scan with your anti virus program , it should now be clean. Assuming it is , reboot back into Normal and you should be good to go.

dl65 If you then still cannot get rid of it, read-up here. 8-)DLoad, update and run the FOLLOWING:

Ewido
Stinger
Aswclnr

Do this in Safe Mode with system restore turned as per Dusty's instructions above...

patio. 8-)thanks for the advice. dl65, i tried that but it didn't work. same with those programs you suggested patio. fffreak, i went to the link and tried many of the options it gave. i finally found one that worked: i downloaded a program that allowed me to see the specific process that was using the file and end it. the process was called winlogon.exe, and my computer said it was critical but i ended it anyway. the screen went blue and said something about a fatal error, but then when i restarted it everything was normal. icwiew.dll has dissapeared... no idea where it went, but i never actually deleted it manually. i went to run and typed winlogon.exe again, and now it's back under processes. so the virus is gone, but i'm a bit worried that i may have messed something up by ending winlogon.exe. i know i must sound like such an idiot when it comes to computers. i mean, i know the internet inside out and i can use all the graphic design and photo editing programs but when it comes to figuring out all of this internal working stuff i'm really at a loss. so do you think that by ending (and restarting) winlogon.exe, i destroyed some important files or something? and if so, what should i do?You didn't do anything, all you did was end that process which is your logon application into windows, when you rebooted everything went back to normal.Quote

DLoad, update and run the following:

Ewido
Stinger
Aswclnr

Do this in Safe Mode with system restore turned as per Dusty's instructions above...

patio. 8-)

I'm somewhat suprised these tools didn't handle your issue...Those tools can't remove pebcak errors. Gotcha...

3369.

Solve : Possible Downloader time bomb problem?

Answer»

Hi everyone, I am new to this forum so hello. I think I have the Downloader.Trojan on my computer and have run both Norton and AVG to try and seek it out, no luck. I got this message in AVG

Warning: Action failed for registry value HKLM\SOFTWARE\Classes\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}:409: creating registry value....
Access is denied. (5)

Does any ONE know enough about the registry to tell me what this is. I don't like changing the registry so I can help it I had rather find it in the folder hierachie If I can and zap it. Thanks in advance if you have any ideas. DThe message means AVG was not allowed access to that portion of the registry.
This doesn't neccessarily mean you are infected...why do you suspect this ? ?

Can you list any other protection programs you have ? ?About a week ago I got a pop up message from Norton saying that Downloader had been detected and it couldn't fix it. I took evasive action but probably didn't stop its' download. Nothing it happening with my computer "yet" but I feel like it is a time bomb waiting to explode. Perhaps it is just paranoia because I am working on an important project. Thanksdownload and install avg antispyware FREE (if you dont already) and spybot search and destroy

update them turn system restore off and reboot into safe mode do the scans and post the avg antspyware log here

also get hijackthis and do a scan and save log and post the log here (the log can take several posts)


unlovedwarriorSorry for the delay, had to go out of town and get hijackthis


Logfile of HijackThis v1.97.7
Scan saved at 1:42:48 PM, on 4/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\vssvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\Dennis\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.dcc.edu"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\m5cwi299.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\m5cwi299.slt\prefs.js)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll (file missing)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O15 - Trusted Zone: http://faculty-web.dcc.edu
O15 - Trusted Zone: http://www.dcc.edu
O15 - Trusted Zone: http://*.fiberartsstudio.com
O15 - Trusted Zone: http://www.macromedia.com

1) This is not a complete log...it may take a few posts to get it all due to the Forum limitations on post length...this is normal.

2) Update and run all your scans once more

3) Re- install Hijack this into it's own directory ...name it HJ1 or something you choose. It shouldn't be run from a Temp directory.

4) Update and run all your scans once more

5) Answer Quote

Can you list any other protection programs you have ? ?
thisthe log will go to 23 itll take two or more post..I think the virus has done something to the original POSTER. At least it wasn't the aliens this time... Maybe due to the use of an out of date version of HJT and the fact that it's in a temporary location, hmm...??


OJ
3370.

Solve : Ran AVG and this is what I got...?

Answer»

Hello, obviously I'm new here..Hello. Ok, so here is my prob.

I have two computers in the house (networked together)
I have seperate issues that i think now have merged into
the new one. Today while I turned on the computer I got a
really long message, the jist of it said:
System user 32 DLL was relocated.....etc.

Now, this has never happend before and I have no clue that all this
means. I close it out and decide to SCAN with my AVG.
When done my results had no threats or virus found but in
the Virus Results tab it shows this: C:\Windows\system32\user32.dll

Now, this has happend on my other computer when I ran my AVG as well.
My other computer, which is faily old has been running really slow.
But this is the first time that the new computer has had the
same problem.

If anyone knows what i'm talking about I thank you for the help.plz post more info on computers and post hijack this logSure, I need to find out how to do that and I will get back, Im really new to this. Thanks so much.


EDIT: Im using a HP Pavilion with Microsoft XP 2002http://www.merijn.org/files/hijackthis.zip do the scan and save log and post the results back here it will take multiple posts


and lets do one computer at a time kSo I ran a patch download with help from HP today on the other computer.
It seemed to work. I asked them if I should run the same on this one,
they said to try it. It's still being sluggish and slow, i'm sure that
it's just because this one is just old.
Pentium 2 Windows XP I have about 3.35 gb Free.


Logfile of HijackThis v1.99.1
Scan saved at 4:54:10 PM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VIEWPOINT\Common\ViewpointService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dani\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.38/WinSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040105/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152152383138
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeHi

This log is more or less clean. Just one thing to raise on the program Viewpoint.

It's a monitoring program. Some say remove it others don't bother. Me? I say remove it. Your choice.

If you want to remove it do this ...

Go to Control Panel - Add/Remove programs and remove:

Viewpoint

Rescan with Hijack This, close all browser windows except HijackThis (including this one), put a check/tick mark beside this entry IF it's still present and click “fix checked” ....

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe


Next locate and remove this folder from your Program Files folder....

C:\Program Files\Viewpoint

....IF it's still there.


I'm assuming you didn't post the HJT log for the other machine as you believe it's fine. That's OK but, if I were you, I would post a log from that computer too so we can check all it well.

As to the sluggishness you may be RIGHT. Running Windows XP on a Pentium 2 isn't really a problem but the hard drive space and RAM may be.

You need to keep around 15% of your hard drive free so check that 3.35 gb fits the bill there.

Also you will need (preferably) at LEAST 512MB of RAM for XP. More if you can get it but that will depend on the capacity and specs of your motherboard.

Lastly, you should give both computers a good "spring clean" to make sure they are uncluttered by old browsing data, prefetch files etc. Run both these programs on both your machines...


First Ccleaner. Get it here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/

Scan both computers with it on the default options and clean the drives.


Second download Ewido/AVG Anti Spyware from here and install on both computers….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot each computer to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it in case there is trouble and you need to post it in the forums for someone to look at.

Reboot back to normal mode and use the computers as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

Reboot back to normal mode and use the computers as you would usually do.


Hope this helps out. Let us know how things are going now.


OJ
Thanks OJ, Apparentlly on my first computer I don't have enough RAM
anymore. I seem to have enough space, but that's what I was told.

I'm still getting the same infected file on the new computer. I will
post the log file here in a while. I'm running a scan now.
Thanks again.

Ok here is the second computer file:

Logfile of HijackThis v1.99.1
Scan saved at 2:05:08 PM, on 4/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
C:\Documents and Settings\HP_Owner\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1173913335437
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

Sorry about the delay here, DeeC. We are rather busy. If you are still having trouble would you please post a fresh HJT log and an update on current problems.

Thanks.


OJ

3371.

Solve : Unregistered Version of Softdefender?

Answer»

Help!

Everytime I open .rar or .zip files on my PC, a pop-up message is shown and reads "This program is protected by unregistered version of SoftDefender This message will not appear on programs protected by a REGISTERED verson of Softdefender."

Can I delete Softdefender from my PC instead? Can I get rid of this Softdefender without purchasing the Registered Softdefender which costs a whopping $69.00? How can I open my .rar and .zip files normally again?Ken...... I WOULD start by uninstalling "Softdefender" by using the Add/remove function in the control panel........ once it says it has been removed .....check in the program folder on C: drive to be sure there arent any leftover bits still there . Then do a search of the registry looking for Softdefender and delete any entries FOUND ........ In lieu of going into the registry , you might d/l CCleaner from ..... http://www.filehippo.com/download_ccleaner/ install it and run both the CLEANER and issues .

As far as opening rar and zip files , how did you open them prior to this , with winrar or winzip?


DL65 Thanks dl65... i tried WINRAR and WINZIP on the files. I haven't found Softdefender in Add/ Remove Programs list but i haven't looked in the registry. How do you get in the registry anyway? If this doesn't work, I would readily declare Softdefender as a virus!!! hehehe

3372.

Solve : Hijack This Entries?

Answer»

i did a Hijack This scan, and i came up with a few entries that were previously not there. they are as follows...

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


O9 - Extra BUTTON: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O11 - Options group: [INTERNATIONAL] International*


(an added note, i use firefox, and my homepage has always been google.ca, i would just like to know if i can delete these entries. i also believe that these entries have been added since i upgraded to the NEWEST IE.)

i would like to know if i could safetly delete all these entries.nevermind, i just set up a system RESTORE point and deleted all of them. so far, NOTHING has happened.good to here

3373.

Solve : cpvfeed popups?

Answer»

I'm having trouble with lots of irritating IE popups (though I use Mozilla), most of them being sourced to url.cpvfeed.com

I run Ad-Aware, Spybot, AVG, BitDefender, Windows Defender, AOL Security Centre and WinPatrol, yet so FAR the problem persists.

I've looked around on other forums for SOLUTIONS, but most of the problem-details other people are showing in their Hijackthis LOG don't seem to be appearing in mine, so I'm rather befuddled really.


This is my Hijackthis log:


Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:47:15, on 08/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\1147445736\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Common Files\AOL\1147445736\ee\AOLSoftware.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\AOL\1147445736\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
C:\Program Files\WinPatrol\winpatrol.exe
C:\Program Files\AVG\avgas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Ashampoo\AntiSpyWareGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ashampoo\AntiSpyWareControl.exe
C:\Program Files\Common Files\AOL\1147445736\ee\aolsoftware.exe
C:\Program Files\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Softwin\BitDefender8\bdswitch.exe
C:\Program Files\Softwin\BitDefender8\bdnagent.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Softwin\BitDefender8\bdmcon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla\firefox.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\Documents and Settings\HP_Owner\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1147445736\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [AOLSPScheduler] C:\Program Files\Common Files\AOL\1147445736\ee\services\safetyCore\ver210_5_4_1\AOLSP Scheduler.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG\avgas.exe" /minimized
O4 - HKLM\..\Run: [Ashampoo AntiSpyWare Guard] C:\Program Files\Ashampoo\AntiSpyWareGuard.exe
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender8\bdmcon.exe"
O4 - HKLM\..\Run: [BDNewsAgent] "C:\Program Files\Softwin\BitDefender8\bdnagent.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Ashampoo AntiSpyWare Taskplaner] "C:\Program Files\Ashampoo\AntiSpyWareControl.exe" -TRAY
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-GB ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Gmail Notifier.lnk = C:\Program Files\Gmail Notifier\gnotify.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl CLASS) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1175961852171
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AOL Antivirus Update Service (aolavupd) - AOL LLC - C:\Program Files\Common Files\AOL\1147445736\ee\services\safetyCore\ver210_5_4_1\aolavupd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG\guard.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: McAfee McShield (McShield) - Unknown owner - C:\PROGRA~1\mcafee.com\ANTIVI~2\mcshield.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - Unknown owner - C:\Program Files\mcafee.com\personal firewall\MPFService.exe (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 5490 bytes





If anyone at all could help me, I'd be so grateful. Thanks so much!Sorry for the delay. We are busy.

If you are still having problems please post a fresh HJT log and brief details of ongoing issues.


OJ

3374.

Solve : Web Browser Hijack?

Answer» Logfile of HijackThis v1.99.1
Scan saved at 3:07:54 PM, on 07/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Ray\zoftwares\comphope\hijackthis_sfx\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QCWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to MICROSOFT Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {342999A3-728D-4DF6-BB81-CDD1A743096A} (MRActivXUI Class) - http://66.35.195.125/webcomp/ver5.4.4.0/wbaxuiph544.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab55708.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O18 - Protocol: bt2 - {1730B77B-F429-498F-9B15-4514D83C8294} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL (file missing)
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - C:\PROGRA~1\BT2Net\BT2PLU~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
O23 - Service: ACU Configuration Service (ACS) - UNKNOWN owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I asked you to give us an update on how the computer is operating now. You don't say but I guess it's OK now. Right?


OJThe computer is running fine except that I notice the boot time has increased. Well, i guess its because I have installed many anti-virus stuffs. I tried to find "Softomate" entries in the Registry but couldn't find any. The Ad-Aware ALWAYS finds this Softomate thing & MRU Lists.

Here is the log file of Ad-Aware:

MRU List Object Recognized!
Location: : C:\Documents and Settings\SZR\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : C:\Documents and Settings\SZR\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru
Description : list of recent documents opened by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\office\11.0\common\open find\microsoft office word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\windows media\wmsdk\general
Description : windows media sdk

Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Softomate Toolbar Object Recognized!
Type : RegValue
Data :
TAC Rating : 9
Category : Data Miner
Comment : "{01E69986-A054-4C52-ABE8-EF63DF1C5211}"
Rootkey : HKEY_USERS
Object : S-1-5-21-2575881574-1178726471-879617933-1005\software\microsoft\internet explorer\toolbar\webbrowser
Value : {01E69986-A054-4C52-ABE8-EF63DF1C5211}

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 18


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 18


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : [emailprotected][2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:[emailprotected]/
Expires : 02-04-2008 2:03:30 PM
LastSync : Hits:6
UseCount : 0
Hits : 6

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 19



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 19


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
149 entries scanned.
New critical objects:0
Objects found so far: 19Clean your system out with Ccleaner then run AdAware again. Post the AdAware new log.


OJDone the CcCleaner & scanned again with Ad-Aware, pls find the log below:

Ad-Aware SE Build 1.06r1

Logfile Created on:April 7, 2007 6:16:12 PM
Using definitions file:SE1R164 02.04.2007
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):2 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

07-04-2007 6:16:13 PM - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : C:\Documents and Settings\Administrator\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : S-1-5-21-2575881574-1178726471-879617933-500\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
149 entries scanned.
New critical objects:0
Objects found so far: 2




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2

6:31:28 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:15:15.196
Objects scanned:155431
Objects identified:0
Objects ignored:0
New critical objects:0
Sorry for the delay. Looking better.

How are things now? Are you OK? Got any ongoing problems?

Let us KNOW and give details on lingering issues.


OJ
3375.

Solve : prob with viruses?

Answer»

I have AVG anti virus, and it found 3 viruses and 2 trojans, but it only got rid of 2 of them. why DIDNT it do anything to the othersScan in safe mode with system restore turned off.Get AVG Anti-Spyware too.You probably have AVG CONFIGURED to move virii to the virus vault...have you CHECKED the vault ? ?how do you turn of SYSTEM RESTORE anyway?GOOGLE found this in .84 seconds:

http://support.microsoft.com/kb/310405

3376.

Solve : Strange Sounds?

Answer»

My Girlfriends Laptop got some viruses that i CANT remove, one of them is a "Drivecleaner" virus, that Popps up now and then telling her to registrer cause her computer is under a risk.
When i click the abort button, a drivecleaner site opens in IE, when i exit the window a new message apears with the same message, when i exit that window it stops...for a while, after a while it comes BACK again.
She Got Norton Anti Virus, and it cant find the Virus. I culd maybe manange to find it and delete it, but when im first here it would have been nice to get some help with that one too.

The Biggest Problem is that her computer play off a soundtrack, sounds cinda like voices that talk in a high speed, and it plays again and again for a minute or so. then it stops, and come back after a while. This sound apears no mather if she got anything running or not. And it can apear while the screensaver is on.
I really dont have any idea why this sound apears, and only answer must be a virus or something. Any ideas how to get this to stop??Your AV software won't pickup drivecleaner because it's not a virus, use RogueRemover from
http://www.malwarebytes.org/corporate.php
I'm not too SURE about her squeaky voice.Well, ive been looking some more on it, and it wasend Drivecleaner, sry m8, it was Errorsafe
And both Errorsafe and those sounds seems to have something with IE to do, cause when the sound apeared i mananged to stop it with using the tasklist to abort Iexplorer.
The Errorsafe seems to open in Iexplorer too, the first poppup window says internett explorer, it looks just like the normal errorsafe poppups, guess ya all had some of those.
Her Default browser is Firefox, so it seems like that if i can uninstall IE i might get it to stop. I alltso tought about upgrading to IE 7.0 or something, but was cinda short on time this time. Any ideas?

If You want any screenshoots or something just let me know, and sry about my bad english Quote

Your AV software won't pickup drivecleaner because it's not a virus, use RogueRemover from
http://www.malwarebytes.org/corporate.php
I'm not too sure about her squeaky voice.
[highlight]RogueRemover will fix errorsafe too.[/highlight]Cheers m8, ill check it out, but still need some help with the strange sound tracks.
Seems to be 3-4 diferent sound tracks that comes, all running in IE.
Anyone at least know what folders this file must be in and what cinda file it must be? its no visual program running, the tasklist just say Iexplorer. and it comes when nothing is running tooWell, Rogueremover 1.09 dident find the errorsafe program :-/ :-?That's strange, errorsafe is on the rogueremover target list.
Are you sure you have got errorsafe, how do you know?yeah, i SAW it on the list.
She got errorsafe cause the massage tells her to download errorsafe, and it opens a window with the errorsafe download site.I was hoping RogueRemover would be the 'easy' button for you... I guess not.
It looks like ErrorSafe is a Vundo variant so you will have to run vundo fix.

http://www.bleepingcomputer.com/forums/topic18610.html

Let US know how it goes. havent tried it yet... but found something about the strange sounds, i were looking for some drum tabs on my computer when i heard one of the same sounds that she has.
i was on http://www.911tabs.com/tabs/k/kiss/guitar_tabs/strutter_guitar_tab.htm and then i heard it. and i found out it was some short movie down on the site that plays a girl that dances some dating site or somthing. and when i use the taskist to exit iexplorer the sound stops on my girlfriends computer. i culd not find the link of the site cause smart me had to click away and when i tried again some times later i only get a smilie window down there, followed that to http://smiley.smileycentral.com/download/index.jhtml?partner=ZNxmk142&nsrc=az2&click_hash=115sNHl&ref=http%3A//www.911tabs.com/bands/m/index4.html

ill see if i can dig something else uphere's a tip...

minimize your volume or disable your sound system first while fixing the problem so that you won't get irritated with the sound. What program does the soundtrack use to play itself? whatever program it is (Winamp,Musicmatch, etc.) remove that program and re-install it. If you don't have the isntaller for it then remove all the sound tracks from list and reboot, then scan the drive where you stored your playable tracks.

This happened to my cousin's PC, he just removed the player and re-installed it, quick and easy.Well, the sounds play from iexplorer (internett explorer) so theres no playlist, and it comes when it wants too, no mather if your doing somthing or not. dont need to click somthing, it just comes. Dont mather if you dont run any programs (itunes, IE, firefox etc).
3377.

Solve : Storm Worm hits computers around the world?

Answer»

[highlight]** f..y...i... **[/highlight]

Fri Jan 19, 2007 8:53 AM ET



HELSINKI (Reuters) - Computer virus writers ATTACKED thousands of computers on Friday USING an unusually topical email citing RAGING European storms, a security company said.

The virus, which the company named[highlight] "Storm Worm," was emailed [/highlight]to hundreds of thousands of addresses globally with the subject line "[highlight]230 dead as storm batters Europe[/highlight]."

An attached file contained so-called MALWARE that can infiltrate computer systems.

"What makes this exceptional is the timely NATURE of the attack," Mikko Hypponen, head of research at Finnish data security firm F-Secure, told Reuters. . Hypponen said thousands of computers, most in private use, had been affected.

He said most users would not notice the malware, or trojan, which creates a back door to the computer that can be exploited later to steal data or to use the computer to post spam.

3378.

Solve : spyware that i can get rid of?

Answer»

hi everyone i posted a question in the windows xp topic
and was instructed to scan in safe mode with spybot s and d
and rogue remover witch i have done but i STILL GET pop ups
and after i scan again spybot keeps coming up with this
Smitfraud-c.toolbar888

could anyone tell me how to get rid of this and its annoying pop upsFirst do everything here .....

http://www.bleepingcomputer.com/forums/topic17258.html


If that doesn't fix your problem post a HJT log to this thread and more specific advice will follow.


OJhi oddjobBeen on my hols hols??? its nice to see you backQuote from: unlovedwarrior on April 20, 2007, 09:28:24 AM

hols??? its nice to see you back
Ditto. I've been wondering when you'd FINALLY come back, oddjob.Quote from: unlovedwarrior on April 20, 2007, 09:28:24 AM
hols??? its nice to see you back

Holidays. my bad raptorThanks everyone.

Meanwhile ... back at the ranch .... how's it going, 2jzlux? Any improvement in the last three DAYS?


OJQuote from: unlovedwarrior on April 22, 2007, 09:50:30 PM
my bad raptor

Don't worry about it.
3379.

Solve : Physically Installed Keylogger??

Answer»

There's always the option of starting to re-write a resume'...i wouldn't stay in an uncomfortable situation for long myself.

The us vs. them mentality can't be good for productivity and maybe someone needs to volunteer the idea that Management and STAFF need to sit down and address these ISSUES out in the open.

After all there STILL remains the possibility that Management might not be aware of this scenario...

Best of Luck.

patio. 8-)Quote

So I understand you have no interest in giving me guidance, GX1, because you would RATHER jump to conclusions about how people are only trying to get around the fortress that IT has created...

I thought we were trying to look at this in DIFFERENT lights to fully explore the situation, and I was telling you how it worked in my corporation. Yours may or may not be different.

I think you were the one that jumped to conclusions about me.
3380.

Solve : f virus is this?What virus is this??

Answer»

What kind oI don't exactly know...can't SEE it from here.I can't understand the QUESTION from here. It COULD be the 1/2 sentence virus...a nasty ONE !He should rem

3381.

Solve : viruses - found on webpages?

Answer»

Has anyone gone to a site that gives you a virus when you go on it (one of the pictures or something has a virus in it, and is automatically downloaded into Temporary Internet Files)?

I went on one recently: Code: [Select]www.guildwarsize.com
Don't go it, it gave me a virus. (By the way, it was advertised by a forum member, guildwarsize)Don't post it as a link then Dark Blade, It's really tempting to click it I didn't mean to post it as a link.
I didn't PUT it in hyperlink, it just did it automatically.

I'll fix it, then.


BTW, you're the only person to actually LOOK at this post, so no-ones in any danger.

Edit: Turned WEB link into code, so it doesn't link to the virus siteI actually CLICKED it without reading your post because usually when i see a link, i click it and look at the post while it loads. I closed it when i saw:
Quote

a site that gives you a virus when you go on it

I don't think it affected my computer.....Well, it did on mine. Do you have AVG (7.5 Free) on your PC?No I've got Norton, works for me.As I've said in numerous posts, AVG is way better than Norton. But I suppose if that does it for you...

Well, you probably have a Trojan Horse on your computer now, because with AVG, it shows a pop-up as soon as you have a virus. With Norton, you'll probably have to search.With norton, it pops up too.I haven't used it for so long, I've forgotten.

Maybe AVG is more up to date?What was the name of this virus/trojan/bug/dream?Trojan Horse Downloader. Small. 58. AW

It's in my AVG Virus Vault.

I'm goin offline now, so I won't reply until late tomorow.Quote from: Fed on April 19, 2007, 04:23:56 AM
What was the name of this virus/trojan/bug/dream?
Dream? I new they could intrude in your dreams......its not uncommon for this form of infectionYes, but I don't like the FACT that a link to this site is in SOMEONE's signature...Quote from: Dark Blade on April 20, 2007, 12:32:58 AM
Yes, but I don't like the fact that a link to this site is in someone's signature...
That's not good, advertising a virus.
3382.

Solve : I can’t access anything in Windows 98 Normal Mode?

Answer»

My friend is using Windows 98 and she opened an email in AOL from 1nc048.com but didn't click on any links. She deleted the email and signed off of the internet. Later, when she went to sign back on to the internet, she realized she couldn’t access anything on her desktop. We restored the registery to an earlier point and that didn't do anything. What can we do to fix this problem :-/ Thanks weyesup..... Are you able to reboot into the safe mode ? If you can , go there and then do a full virus scan and see if anything shows up .


DL65 Thanks for your reply, yes she can boot in safe mode and she ran adaware and spybot, but she doesn't seem to have a virus checker. I was trying to look in the autoexec.bat file and the config.sys to see if there was anything STRANGE going on, but she doesn't even have much there to question. KINDA reaching out to help her from one coast to the other by phone. Any other suggestions? :-/If you can do safe mode with networking there is an online scanner at www.trendmicro.com

If not, you can download the latest AVG Free, burn it to a CD and run it in safe mode on the affected machine. It won't be up to the minute with the latest definitions, but it will probably be enough to rule a virus problem in or out.

http://free.grisoft.com/freeweb.php/doc/2/ Thanks, I will pass it along. Hope it works. You can also, if there is a virus, and if it runs on startup, just click start, run, then type msconfig, goto the startup tab, and uncheck an unwanted program. Thanks, it is WORKING a little better now. She can access the internet, she has downloaded the virus cheker SUGGESTED and is running and running the virus checker, ad aware and spybot. Little by little she is getting closer to working normally. Thank you all so much for your help.
List all the protection programs she has currently...

Perhaps we can add a few to her arsenal.


There is no one tool that will do it all.

3383.

Solve : Sys32.lsb-unco??

Answer»

RemoveIt when scanning tells me I have the malware Sys32.lsb-unco. But then freezes (Just RemoveIt. Everything else is okay.) and I cannot click on "fix". Or rather do, but nothing happens. I then have to close via TASK Manager. None of the other security below finds this problem and putting it into a search engine did not come up with anything. Is this a false warning or is there something I should do to find and remove this maleware? If so what please?

Win XP Proffessional
AVG ANTI virus
AVG anti spyware
Cyberhawk
Spyware Guard
Spybot
Spyware Blaster
A Squared
AdAware
BlackLight
CCleaner
RemoveIt
Advance Windows Care
1. Start/run, type msconfig, click OK. Under the startup tab, look for it or anything RELATED to it and diasable.
2. Look in the prefetch folder and delete it or anything related.
3. Disable SYSTEM restore.
4. Boot to safe mode and rerun the scans. If the problem is detected and repaired, reboot normally. Re-enable system restore if desired.
NOTE: It might be a good idea to disconnect from the internet while doing this.Thanks. Problem solved!Thank you for responding BACK to let us know.

3384.

Solve : My computer Freezes after i put a 2nd cd in.?

Answer»

I just bought a game today but i recently had my happy FEELINGS go down when every TIME it asks me to insert the 2nd CD my COMPUTER hums like its working and continues to hum.
But nothing happens it freezes i cant move the mouse or nothing


So i constantly have to restart my computer from the switch button every time i try and its not my anti-virus software that scanning the CD because i turned it off. [AVG,ZoneLabs]


Do you think it may be some virus?gl0rious...... Some questions ....... Does you machine match or better the requirements for the game ?
Is the game a store bought legal game or some copy ?
Why would you have your anti virus turned off and your firewall ?


dl65 When i got to can you run it i am only missing one componet which is my GRAPHICS card :-/ but it SAYS that i just need a certin kind. But i have that certain kind but i guess not the same version.

And yes it i is legaly purchased game.
And i thought that would help if i turned it off during the installation becuase last time i installed a game
it wouldnt run becuase of my software.

[Even though i may not meet the req. i ran company of heores which uses the same req.]What game and what are your system specs ? ?

3385.

Solve : open office org 2.2?

Answer»

I RECENTLY installed open office org 2.2. Now, every time I open a document, my firewall program tells me that office org is trying to access the internet. Why would that be? Maybe to check for UPDATES, or to register itself.
Allow it access and see what it does, it's likely it wants you to register.alot of programs do to check for updates and what not


Calum beat meHe's pretty quick lately...since Miss Cleo dumped him he has more time.i guessQuote from: patio on April 18, 2007, 05:08:22 PM

He's pretty quick lately...since Miss Cleo dumped him he has more time.
. . . Miss Cleo?
Wasn't that in another thread?
I don't think I was eve involved, wasn't it CBMatt?
I vaguely recall seeing SOMETHING like that anyway . . .I was married to Miss Cleo. And she didn't dump me...I dumped her before she had a chance. Raptor dated her for awhile, but I'm not sure exactly how that one turned out.Sorry Calum...but it seems like everyone has been friends with her ...i just lost track.

not me cuz im UNLOVED We're going off-topic again...

tekkite07, is your problem solved? If it is, then no-one should REALLY NEED to post anything more here.
3386.

Solve : Internet Connection Trouble?

Answer»

I have a SONY VAIO with Pentium 4, 1022.3MB, 3.20GHz... Im using AOL for firewall, virus protection and whatnot. i dunno what else you may need to know about my comp but anyway...

Ive been playing DAOC lately and recently during gameplay my internet connection fails and I get kicked off the game. I have comcast cable and the lights on the box never blink-out (which usually means the signal is gone.) Sometimes when i try to access this game or other online programs AOL boots up trying to connect. Is AOL jacking up my comp? Ive run virus protection and things like that trying to clean my comp but nothing has worked so far. Any ideas?

Also, if AOL is the source than i am willing to delete it. *censored*, maybe ill delete it anyway. The only thing i dont have that AOL provides is a firewall. Is the Windows XP firewall good? or are there any free ones anyone is aware of that i could use? Thx

I know this could be considered a "Game" topic but in case this is a virus i just decided to post here.Also, ive been trying to speed up my comp since ive been having these troubles lately and one tip i see is to limit the amount of startup programs. When i hit ctrl+alt+del, view the task manager, and look at the running processes i have 52 of them going on without any programs running. Can i remove those? if so, how do i know which ones to remove? thx.Update: After READING some of the suggestions on other posts, this is what ive done...

Removed:
All AOL programs and protections
All Norton Programs

Added:
AVG-virus
Prevx 1
CCleaner
Spybot
Windows XP Firewall

I Ran all of those and that seemed to speed things up abit (espescially removing AOL) but anyways...now i have a new problem.

WHen i restart/reboot my comp, a message comes up before windows EVEN opens. THis is the msg:

"Pri Master Hard Disk: S.M.A.R.T. Status BAD, Backup and Replace
Press to Run Setup"

I push F2 and get the boot-up-menu-thingy ( dunno what its called) where i can choose at the top MAIN, Advanced, Power, Boot, or Exit.
I viewd each option but just went into exit where i could either Exit and Save Changes, Exit and Discard changes, or just Discard changes.
Exitting while saveing changes brought me back to that error screen at the beginning, however exiting and discarding allowed me to get back on to my computer, where everything was seemingly back to normal.

Everytime i restart my comp i get that error, and must go to exit and discard changes before continuing bootup.That HDD is getting ready to fail....backup your important stuff immediately and use it as little as possible til you can replace it.

patio. 8-)

p.s. This may be the source of your other issues as well...grrrreeaattt...all that work to get my system to run faster and the hard drive dies. time to take it to Best Buy to get it replaced then....sigh

Thanks for the help patio You're more than WELCOME...but before HANDING it off to the Geek Squad make darn sure to backup ALL important stuff...Data disappears at Best Buy !

3387.

Solve : Help! Can't get rid of virus...?

Answer»

Hi, for some time now I have had a virus called "W32/Downloader.AOKZ" that has infected a file called "ldcore.dll" in system32 of Windows. I am alerted by my virus program but it cannot delete it. I have tried to manually delete it using Windows Explorer but an error message comes up when I try to do so, saying that it is used by another program. I am running a virus program called Freedom.

My problem is that I don't want to install another virus program, because last time I installed Norton and I had to reinstall my Windows because something happened. So, how do I get rid of this virus? Is it necassary to install another virus program? Do i uninstall the one I have now?stevengerrard ...... W32/Downloader.AOKZ ....looks like a trojan as opposed to a virus .....

so , If you are using XP ....... turn off your system restore , and then reboot into safe mode and run a full scan with your anti - virus scanner .........
See if it deletes it from there , if it won't post a hijackthis log .
Please explain what you mean by [highlight]I tried to remove it manually using Windows exporer .[/highlight]

dl65 What I mean is that I open My Computer, then the WINDOWS folder, then system32, and finally I try to delete the infected file by right-clicking and then delete.

So, I restart in safe mode and then run my anti-virus program?I would use the Ewido/AVG Online Scan but if you just want to delete the file then Google for Killbox.Fed, I used Killbox to try and delete the file and it STILL wouldn't delete. I also did that online AVG scan from the link you gave me and it didn't delete the trojan.


I have no clue as to how to get rid of this thing, does anyone KNOW how to?I feel for uDid the online scan detect the 'virus'?
What scanner do you use on this computer?
Did you explore ALL the deletion options in KillBox?Quote

I feel for u

Thank you, that helps.

Quote
Did the online scan detect the 'virus'?
What scanner do you use on this computer?
Did you explore ALL the deletion options in KillBox?

The online scan detected the infection and supposedly removed it. When I restarted my computer my current virus program [highlight]Freedom[/highlight] (link below) found it again. http://www.freedom.net/viruscenter/onlineviruscheck.html

I did explore all options in KillBox and it still wouldn't delete.stevengerrard..... Would you please post a hijackthis log here for us to see ........ Get it at ..... http://www.majorgeeks.com/download3155.html d/L it and then run a scan and save the log file and post it here .


dl65 Ok, this is what I came up with...


Logfile of HijackThis v1.99.1
Scan saved at 6:23:15 PM, on 1/22/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Plugins\Plugins\E12C95FCBD1240FEAE314D89676CA6F8\LieDetector.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype\Plugins\Plugins\DF206D97847745E7983C822C45EE3038\ringjack.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Documents and Settings\*******\Desktop\HijackThis.exe

O1 - Hosts: 104.42.43.68 securityresponse.symantec.com
O1 - Hosts: 147.196.204.190 symantec.com
O1 - Hosts: 6.99.74.0 www.sophos.com
O1 - Hosts: 151.132.211.218 sophos.com
O1 - Hosts: 131.167.148.110 www.mcafee.com
O1 - Hosts: 181.239.186.187 mcafee.com
O1 - Hosts: 221.242.203.31 liveupdate.symantecliveupdate.com
O1 - Hosts: 207.50.6.202 www.viruslist.com
O1 - Hosts: 234.119.36.14 viruslist.com
O1 - Hosts: 13.129.37.131 viruslist.com
O1 - Hosts: 220.50.134.116 f-secure.com
O1 - Hosts: 240.63.147.10 www.f-secure.com
O1 - Hosts: 132.139.154.159 kaspersky.com
O1 - Hosts: 213.38.81.70 kaspersky-labs.com
O1 - Hosts: 232.26.160.89 www.avp.com
O1 - Hosts: 165.140.164.31 www.kaspersky.com
O1 - Hosts: 51.93.34.104 avp.com
O1 - Hosts: 111.172.48.51 www.networkassociates.com
O1 - Hosts: 103.151.107.151 networkassociates.com
O1 - Hosts: 194.4.88.180 www.ca.com
O1 - Hosts: 104.186.219.78 ca.com
O1 - Hosts: 102.200.113.70 mast.mcafee.com
O1 - Hosts: 86.86.123.61 my-etrust.com
O1 - Hosts: 212.96.206.109 www.my-etrust.com
O1 - Hosts: 178.159.238.26 download.mcafee.com
O1 - Hosts: 139.113.12.26 dispatch.mcafee.com
O1 - Hosts: 218.143.48.103 secure.nai.com
O1 - Hosts: 177.129.187.50 nai.com
O1 - Hosts: 78.253.155.82 www.nai.com
O1 - Hosts: 1.165.210.184 update.symantec.com
O1 - Hosts: 75.96.202.153 updates.symantec.com
O1 - Hosts: 12.187.245.254 us.mcafee.com
O1 - Hosts: 178.13.70.9 liveupdate.symantec.com
O1 - Hosts: 201.193.7.105 customer.symantec.com
O1 - Hosts: 195.148.252.133 rads.mcafee.com
O1 - Hosts: 250.168.9.60 trendmicro.com
O1 - Hosts: 165.34.16.39 www.trendmicro.com
O1 - Hosts: 215.205.95.2 www.grisoft.com
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O3 - TOOLBAR: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: RESEARCH - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://threats.freedom.net/viruscenter/onlineviruscheck/cabs/cssweb.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: winsock32 (winsock32.exe) - UNKNOWN owner - C:\WINDOWS\winsock32.exe (file missing)

I didn't find a great deal of info on Freedom AV at the security sites i frequent other than it uses the F-Prot engine...have you considered some of the other Free choices such as AVG and or Avast ? ?

However post a log as dl65 suggested. There's more than one way to skin a baddie...stevengerrard........ ok .......
Here's what I see from your log........
For some reason,you do not have SP2 installed and as far as I can see you dont have SP1 either ....... If this is the case , your machine is extremely vulnerable to nasty attacks.
Do you have all the other applicable windows updates installed ?
At the time your hijackthis scan was taken, there didn't appear to be any active anti - virus scanner running ......... I thought you had freedom installed or is it only active when you are online ?
Your firewall also seems to be non active as well.

Now then on to what must be fixed using hijackthis ........

Mark for removal the following:
O1 - Hosts: 104.42.43.68 securityresponse.symantec.com

O1 - Hosts: 147.196.204.190 symantec.com

O1 - Hosts: 6.99.74.0 www.sophos.com

O1 - Hosts: 151.132.211.218 sophos.com

O1 - Hosts: 131.167.148.110 www.mcafee.com

O1 - Hosts: 181.239.186.187 mcafee.com

O1 - Hosts: 221.242.203.31 liveupdate.symantecliveupdate.com

O1 - Hosts: 207.50.6.202 www.viruslist.com

O1 - Hosts: 234.119.36.14 viruslist.com

O1 - Hosts: 13.129.37.131 viruslist.com

O1 - Hosts: 220.50.134.116 f-secure.com

O1 - Hosts: 240.63.147.10 www.f-secure.com

O1 - Hosts: 132.139.154.159 kaspersky.com

O1 - Hosts: 213.38.81.70 kaspersky-labs.com

O1 - Hosts: 232.26.160.89 www.avp.com

O1 - Hosts: 165.140.164.31 www.kaspersky.com

O1 - Hosts: 51.93.34.104 avp.com

O1 - Hosts: 111.172.48.51 www.networkassociates.com

O1 - Hosts: 103.151.107.151 networkassociates.com

O1 - Hosts: 194.4.88.180 www.ca.com

O1 - Hosts: 104.186.219.78 ca.com

O1 - Hosts: 102.200.113.70 mast.mcafee.com

O1 - Hosts: 86.86.123.61 my-etrust.com

O1 - Hosts: 212.96.206.109 www.my-etrust.com

O1 - Hosts: 178.159.238.26 download.mcafee.com

O1 - Hosts: 139.113.12.26 dispatch.mcafee.com

O1 - Hosts: 218.143.48.103 secure.nai.com

O1 - Hosts: 177.129.187.50 nai.com

O1 - Hosts: 78.253.155.82 www.nai.com

O1 - Hosts: 1.165.210.184 update.symantec.com

O1 - Hosts: 75.96.202.153 updates.symantec.com

O1 - Hosts: 12.187.245.254 us.mcafee.com

O1 - Hosts: 178.13.70.9 liveupdate.symantec.com

O1 - Hosts: 201.193.7.105 customer.symantec.com

O1 - Hosts: 195.148.252.133 rads.mcafee.com

O1 - Hosts: 250.168.9.60 trendmicro.com

O1 - Hosts: 165.34.16.39 www.trendmicro.com

O1 - Hosts: 215.205.95.2 www.grisoft.com

O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll [highlight]there it is.[/highlight]

put a check mark in the box in front of each of these entries and then click FIX MARKED

Now reboot your machine and post a new hijackthis log.

dl65
3388.

Solve : a virus that mimics my folder?

Answer»

What KIND of virus is this?

everytime I open a folder, a batch file called "ghost" shows up and mimics the name of the folder that i just opened. I scan my drives using my
symantec antivirus but it only quarantines them. Then after i open a folder, again a mimic of the folder pops up. I think its slowing down my PC. And its spreading everytime I open a folder.

can anybody help me?It's very possible that is actually NORTON Ghost running in the background...check on your version of the Symantec protection package that is installed and report back....

But i agree something isn't running properly.

patio. 8-)I tried Symantic Anti-Virus before. But i found out that everytime it detects viruses they just quarantine instead of delete.

Try replace your Anti-Virus with AVG Anti-Virus free Edition http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10596553.html?tag=lst-4-1


Maybe this can solve your problem...Also you might want to scan the file named Ghost with virustotal.com, its a Multiengine Virus Scanner this will tell you if its a virus or not.

Al969Ken.......Quote

I scan my drives using my
symantec antivirus but it only quarantines them.
It's quite possible that you can change the option of QUARANTINING to delete in the settings...in Norton.
BTW , is your Symantec program new or have you been using it for a while ?
Does it have Ghost included ?

Please let us know

dl65 MEANWHILE he has gone missing...Abducted by ALIENS? That seems to happen a lot around here. Abducted by the "Ghost"...

3389.

Solve : adware in Symantec after scan?

Answer»
I ran a full scan of my Norton Anti-virus and found, not a virus, but an Adware.
File name: rwhedlwz.exe, threat name: Adware.Hotbar and at risk.
I downloaded the removal tool from Norton Symantec " Fxhotbar.exe"
I ran the tool, but after a few second, I get an error message. It is also
impossible to close the window of the message error by clicking on the off
and the X, to close the window. I have to go to the task MANAGER and click
on end task.
How can I remove the Adware?
regards,
PS: Here is the error message:
Microsoft VisualC++ Runtime Library
Runtime Error!
Program: C:\Documents and sett...
R6034
A application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
Note: I suppose I would have to contact symantec, but they are very slow to answer, so I didn't.
Open up Add/Remove Programs and uninstall Hotbar. Then download CCleaner (install without Yahoo! toolbar) and have it fix your registry entries with the Issues feature. If that doesn't fix the problem, you can go here for more information.

For future reference, you may want to do your scans in Safe Mode, as that makes it easier for malware to be detected and removed.

As I'm sure many would agree, Norton isn't the best scanner out there, so I would suggest getting AVG Anti-Spyware, updating it, and doing a full scan in Safe Mode. If you decide that you like this program better, we can help you with disabling/removing Norton properly.Another exorcism Chris ? ?

Let me know. I've got my holy water...Hi Chris,
I went to Add/Remove programs to look for Hotbar, but couldn't fint it.
What should I do then?
Best Regards,Continue with the rest of the suggestion (CCleaner and AVG). After those scans are COMPLETE, if you still think you're infected, you can download HijackThis (save it in a folder where you can easily find it) and post a log here (which might take a couple of posts). If you're still infected, we can use the log to help you remove the malware manually.You might have to remove Hotbar manually. Use Spybot S&D and Adaware SE to scan in Safe Mode and then just use the Windows search function to search for remaining Hotbar files. You may also need to do the same for the registry, although that is slightly dangerous if you go on a deleting spree. Hi Raptor,
How do you scan in Safe Mode?Quote
The ignorant person does not know enough to know that he does not know.
He that knows not and knows not that he knows not, he is a fool, shum him.
He that knows not and knows that he knows not, he is teachable, teach him.
He that knows and knows that he knows, he is wise, follow him.
Tap F8 before Windows boots, choose safe mode from the list. I ran the ZoneAlarm Anti-spyware, the CCleaner, and the Spybot S & D.
After all that, I did a full scan with Norton Anti-Virus and...presto...a clean
bill of health. The Adware.Hotbar was gone.
I like the CCleaner and will keep it on my PC. Thanks Chris.
I also like the spybot S & D . Thanks, Raptor.
Thank you very much for your help.You're very welcome. If you continue to have any problems, let us know.See you around, Darts. Here Ya Go...

DLoad the tool below...

Norton Removal Tool

Do not run it yet.

1) DLoad and install ERUNT and have it make a backup of your registry...
2) Use Add Remove Programs first and un-install Norton...
3) From Windows Explorer search for any folders named Norton and Symantec and delete them...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next instance of Norton. Continue til you have reached the end of the registry...
5) Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6) Now run the Norton Removal tool you DLoaded...
7) Empty the recycle bin...
8.) Go to My Computer and RIGHT clik the C: drive and select Properties and run disk cleanup...
9) Re-boot and run disk defrag....

There you're done !



patio. Chris... a little sprinkle please ? ?*sprinkle*

Be gone, Norton, be gone!
Leave this poor user alone so they may find better protection!
The power of Chris compells you!
3390.

Solve : trojan back door program?

Answer»

ok, let take some time to explain from begining,,,
last week i help a friend of my brother reformat a pc, when he come to me with his CPU, he told me to backup his data first. he told me that his cd writer not working so he can't do a backup. so what i do is i backup his data to my portable hard drive( i know this is stupid and i'll never do it again )
after i completed install windows for his pc. i copy the backup to his pc, and i delete the backup file in my portable hard drive. then i connect the portable hard drive to my pc without doing antivirus scan. the next day y AVG antivirus alert me virus thread found in my pc. at that moment i'm not taking serius about the alert because it ALREADY heal by AVG. and i found that my system run normally.
ok, untill this stage, my system using windows 2K sp4. AVG 7.5 free adition. 40 gb IDE seagate as system hard drive, 160gb SATA seagate as data storage hard drive. 40 gb portable usb hard drive. others detail i think not important here.

last sunday my friend ask me to help him test a sound card problem.creative sound blaster X-Fi, (this is ANOTHER issue, creative forum have thousand of topic regarding it.) because of this, i get a 20gb maxtor hard drive(emty and clean) plug in my system as primary master(my 40gb seagate go to slave) install win xp sp2, ( X-Fi run good on xp sp2, according creative tech guy),install sound card driver and everything needed.
after this, my problem comming, AVG antivirus keep pop up saying that trojan thread found, (in internet temporary folder, file name "DUP5.exe", "c.exe", "w.exe" and many more), i disable system restore, go to safe mode scan all drive with AVG antivirus, and it did found and heal it. reboot and start normal to windows, virus still found again, and my pc very slow. press CTR+ALT+DEL , go to task manager, performance, my cpu usage is 100%, my system didn't running any application at that moment.

help me guy and girl , please, don't tell me to clean out all the drive. i don't care the 20gb maxtor, 40gb seagate or 40gb usb drive, what i care is the 160gb SATA drive. appreciate for any suggestion . Thanks!pcfool...... ok ........ You say that you have run AVG in safe mode and it removed some bad stuff ....... good
But the machine is still not running very good ..... Probably there are still some nasties on it .........

Hopefully you still have system restore turned off .........

Next d/l and install ( if you don't already have them ).........
ccleaner .... http://www.filehippo.com/download_ccleaner/
Ewido/AVG antispyware ....... http://free.grisoft.com/doc/20/lng/us/tpl/v5
Hijackthis ....... http://www.majorgeeks.com/download3155.html

once these are D/L and installed .........
Run ccleaner from normal mode ....... ( run both the cleaner and the issues ) remove what ever is found .
Next ......reboot into SAFE mode....... and run AVG antispyware ..... remove anything found .
Run AVG anti virus ....as well ...... then run a hijackthis scan and save the logfile ......
Reboot back into normal mode and post the hijackthis log here .

dl65

thanks for your reply, i'll try this after work, i in my office now.sorry for late reply, i take out the xp sp2, use back win 2k
here's my hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 3:31:24 AM, on 1/25/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\userinit.exe
C:\WINNT\Explorer.EXE
C:\unzipped\hijackthis\HijackThis.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: @msdxmLC.dll,[emailprotected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: RELATED - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1167445052687
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\system32\CTsvcCDA.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

pcfool........
Quote

sorry for late reply, i take out the xp sp2, use back win 2k


? why would you remove XP/SP2 ? that makes no sense ...... What are you not telling us ?

So , does that mean you reformatted the drive and did a clean install of 2K ?


dl65 Quote
i take out the xp sp2, use back win 2k
pcfool ---->pcgenius Quote
pcfool........
Quote
sorry for late reply, i take out the xp sp2, use back win 2k


? why would you remove XP/SP2 ? that makes no sense ...... What are you not telling us ?

So , does that mean you reformatted the drive and did a clean install of 2K ?


dl65
why i take out the xp sp2? because i install xp sp2 purposely for sound blaster X-Fi testing(as i mention in first post, this is another issue). i'm not reformat my hard drive, my original OS is win 2k, i swap the hard disk to slave, put a 20Gb HD as master and install xp.( is not a legal copy so cannot update.)
i just remove the 20Gb HD, put back my 40GB HD with win 2k as master.Quote
Quote
i take out the xp sp2, use back win 2k
pcfool ---->pcgenius
why you say like that? :-?cuz win 2k is better in some ways then xp.

unlovedwarriorQuote
( is not a legal copy so cannot update.)

This is what free winds up getting you...Only for pirated software though . . . free usually gets you equal or better for other things, like antivirus (think AVG vs. Norton)
Or Linux vs. Windows (in some people's opinion)
Just my random thoughts.Quote
[highlight]cuz win 2k is better in some ways then xp[/highlight].

unlovedwarrior


agree Quote
Only for pirated software though . . . free usually gets you equal or better for other things, like antivirus (think AVG vs. Norton)
Or Linux vs. Windows (in some people's opinion)
Just my random thoughts.

Did you want to discuss semantics...or Symantec's ? ? ?
3391.

Solve : Help - My computer's restarting on its own.?

Answer»

Well, tho all of your fans may be working it may still be to much heat. have you checked the temperature?
If you dont know how to do this you have to restart your computer and press (default: DEL) to enter the setup, then you shuld look for the PChealth option. This option is usual found in the list that apear when you press del but if not it shuld be under some of the other things in the list, just try your way there, if you cant find it then let me know and ill see what i can do.

I have experienced many computers with this problem that actually just had a lach of cooling. You got a powerfull computer and it requires alott of cooling.
If your computer is too hot this may be solved in several ways:

1) limit its air supply, yeah you heard me ;P if you got some openings placed too close to the fan that blows the cold air in, it may be that much if this air goes out of that opening. And yes, i have seen a computer that had this problem and we solved it with some paper and tape. By closing one opening placed on the right side of the fan (seen from behind the PC) with some paper we solved the problem.

2) Get more Fans, and make shure the airstream goes trough the computer, and not just out in the middle, some fans pulling the air out is good too.

3) What you shuld do if your getting tired is to called the ones you bought the computer off and tell em that they gave your computer too little cooling. but if you build it yourself, then skrew that

4) WATER cooling system is your last option, if that dont do the trick, nothing ever will.

well, it might be a lach of power as said above too, how much is your power supply on now?Hello,

Thanks for your responses.

I can’t really just borrow a Power Supply from anyone, but if no easier possibilities arise I’ll send the computer back to the shop to get my Power Supply tested or replaced.

PC Wizard 2006 gives me these temps:
Processor Temp: 21C
GPU Temp: 46C
GPU Ambient: 41C

I’m not sure about limiting the air like that, but I didn’t build my PC myself, I bought it from Tigerdirect, so I assume the fans were thought out by professionals, but in any case, I have 2 fans on the inside, not by openings, 1 fan on the facing side, by an opening, and 1 big fan in the back, by an opening, 4 in all, 2 by openings, 2 not. If you have a suggestion for which of the two openings I should cover based on that info, I’ll try that.

As for adding fans or water cooling, I’ll ask the shop about that if I can’t get a simpler solution DETERMINED first.

As for how much my Power Supply is on now, how do I check that?

Any further help would be great.
ThanksYour temps are fine. See Post #12...

patio. 8-)

MrMark, i know you're trying to assist but suggesting a water cooled solution is PROBABLY not a good place to start... that's quite drastic and not economical for most average users.

ok, then...
well, got to agree there, tempatures is fine
hmm... well, just got to keep trying to find out what it is m8, ill let you know if i get any idea what i it might be.download and run CPU-Z(its free)
http://www.majorgeeks.com/download425.html
Have a look at the Vcore voltage, run a virus scan or somthing to get the processor busy then check the Vcore voltage and watch for large fluctuations. It will be 1.XXX volts (mines 1.376volts, your's will be slighty different depending on the model), the third decimal can vary, even the second decimal a TINY bit, but if the first decimal is jumping around your power supply is junk and is not providing stable enough voltage to keep the cpu happy.
Another program to try is SPEEDFAN (its free)
http://www.majorgeeks.com/download.php?det=337
Run it and check the +12v reading, Speedfan is a little inaccurate so dont be alarmed when you see 11.4volts on the +12v line, but be very worried if it reads in the 10 to 9volt range for the +12volt.
Pay no attention to the -12v reading its not used anymore.my computer does that too email me at [emailprotected] if you can help me. :-?It's best to start your own thread so it recieves the proper attention...

You should also edit out your e-mail addy unless you are interested in *censored* or fake Rolex watches...

BTW Welcome Aboard.Special offers from Nigeria are coming your way even as we speak....have you tried to use the windows cd to repair windows? heart about someone that solved the same problem that way
just boot from the cd and choose to repair windowsHello,

It’s been a while since I posted about this rebooting issue my computer had, but I thought I should return and let you know what it seems the problem and solution turned out to be, after I got it fixed at a computer shop, in case it helps people who end up experiencing the same issue or are helping others with the same issue.

It seems the fix to the rebooting issue was two things:
1) The computer has to be plugged directly into a wall outlet, not through one of those multiple-plug thingies. (just the main computer plug, not necessarily the monitor plug or anything else that needs plugging-in)
2) I’m guessing this was the more important one: Using an Aerosol can (from Wal-mart or something), which blows air, shut the computer down and then blow out the dust in the ‘heat sinks,’ which are the lines behind the fans that look like this: |||||||||| but remember that the dust will fly out everywhere. Blow out the dust anywhere else you can, but these ‘heat sinks’ are crucial, as well as any other areas that look like |||||||||, such as by the video card. Do not use a normal vacuum for cleaning dust, as you may mess something up, just the Aerosol can.

Hope this helps anyone, and thanks again to everyone who tried to help me.Glad you are all fixed up and thanx for posting back.

Stop by anytime...

3392.

Solve : Google Redirect. (hijack)?

Answer»

Hey everyone.

Pretty much i just have that google hijack thing where you type something into google, go into one of the search results and it automatically redirects you to an advertising site. I have no idea about how to get rid of it. Ive downloaded a bunch of anti-spyware programs but they dont help.

Thanks for any help.Try CWShredder it may help. Also post a hijackthis log.

8-)fffreakLogfile of HijackThis v1.99.1
Scan saved at 12:14:40 PM, on 1/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Analog DEVICES\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Dc\LOCALS~1\Temp\Rar$EX00.031\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - OPTIONS group: [INTERNATIONAL] International*
O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://www.tenebril.com/assets/activeX/SpywareScannerV2.ocx
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by125fd.bay125.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - SERVICE: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Also read here and look for spyware and antivirus programs in the security part. Did you try the CWShredder?Um yeah i tried CWshredder and it didnt work. Why did you want me to post the hijackthis log? what can you tell me from seeing that log?Well it might show where the problem is, but I didn't see it. Did you try any of the software from the page that I told you? Just one more question, have you tried Adaware?yeah thanks that worked.divcraft.... After looking at your log file..... I'm wondering Why you don't have any anti-virus installed ?

Next ..... I'm seeing you running some sort of antispyware called [highlight]Spyware[/highlight] [highlight]bot[/highlight]........ [highlight]It is a roque program and [/highlight][highlight]should be removed ASAP [/highlight]........... It is not part of Spybot Search and Destroy ( which is very good) Use Add/remove in the control panel to remove it.

Next use hijackthis to fix the following entries.......

O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)

O16 - DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} (TenebrilSpywareScanner Control) - http://www.tenebril.com/assets/activeX/SpywareScannerV2.ocx
[highlight]do you know and trust this entry ? if not mark it for removal[/highlight]

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

ok ...once you have marked the ones to remove ....click on fix checked ......


Then before you do anything else .......... go and D/L the free version of AVG anti-virus ............ You have AVG antispyware .....that's not a Anti virus program.

Once you get AVG and the latest updates , reboot into safe mode and run a complete anti virus scan with AVG.

Report back with the findings .

dl65 Hi divcraft

Couple of other things.

These two entries are leftovers of an infection and should be fixed with HJT .....

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =



Also Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
OJ
Ok thanks for the help guys. i did what you asked and everything seems to be runnig in order now. If i have any further problems i will contact you. thanks.Glad to know all is well.

If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html


If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/


Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.


OJdivcraft....... Glad to hear that things are running ok......... However you still have no AV running ......... So you know , AVG antispyware 7.5 is not a full time active ...anti virus application. As the name implies, it is designed for spyware ........... Get the AVG free Anti Virus as well and then you will have AV
protection.


dl65
3393.

Solve : Reinstall virus.?

Answer»

Hello,again. i have cleaned my pc now to factory settings. i have done some SCANS with avg virus,avg spy,spyware terminater+virus,and virgin pc guard.
Now i WANT to reinstall the progams i have(as you do) How can i safely scan the disc and install them INCASE a virus is hidden in a program i LIKE?
I have disabled autorun-autostart......i hope this is the right forum.....

Thanks for your time......
By scanning the programs with a REPUTABLE virus scanner before installing them. Hi,
Thanks for your time Raptor.It's O.K to ask what those reputable programs may be, Paul.

3394.

Solve : Question about AVG Free?

Answer»

Is AVG Free edition a good choice for an older COMPUTER. I have windows ME and use a dial-up modem..Will AVG overwhelm my system and make it slower?? Currently using ETrust INTERNET Security.no it should not it might even speed it up a bit because it is less resource intensive than most other antiviruses out there ulWarrior is correct...i have it running on my testbench machine that has 4 flavors of Windows on it including ME...

You might want to contact a friend that is on high speed and have them DLoad it and burn it to CD or throw it on a thumb drive...while they are there tell them to also grab AVG Anti-Spyware which is a different program ( formerly Ewido and also free ) and a good compliment to AVG Free.

Quote from: Alabaster Box on April 12, 2007, 10:09:20 AM

Is AVG Free edition a good choice for an older computer. I have windows ME and use a dial-up modem..Will AVG overwhelm my system and make it slower?? Currently using ETrust Internet Security.

I use it on every Windows system I maintain. It only slows down noticably when it's scanning. Quote from: Raptor on April 14, 2007, 08:30:50 AM
Quote from: Alabaster Box on April 12, 2007, 10:09:20 AM
Is AVG Free edition a good choice for an older computer. I have windows ME and use a dial-up modem..Will AVG overwhelm my system and make it slower?? Currently using ETrust Internet Security.

I use it on every Windows system I maintain. It only slows down noticably when it's scanning.

Although it will take longer, AVG can be set to SCAN without using as many resources. When you do this, you hardly even notice that it's running.I set mine up to update at 4AM and scan at 5AM so i don't notice at all...Psht, those are my peak usage hours.Quote from: CBMatt on April 15, 2007, 02:35:48 AM
Psht, those are my peak usage hours.

Same here. Quote from: CBMatt on April 14, 2007, 08:39:16 AM
Although it will take longer, AVG can be set to scan without using as many resources. When you do this, you hardly even notice that it's running.
Can you provide some details on that?Quote from: soybean on April 15, 2007, 07:12:26 AM
Quote from: CBMatt on April 14, 2007, 08:39:16 AM
Although it will take longer, AVG can be set to scan without using as many resources. When you do this, you hardly even notice that it's running.
Can you provide some details on that?

When you install AVG 7.5 it'll ask you what kind of scanning modus you want. Either LOW system resource usage and slower scanning or the opposite of that. Thank you, Raptor, you saved me about five or ten minutes of trying to remember how to set that up. Heh.Quote from: CBMatt on April 15, 2007, 08:31:53 AM
Thank you, Raptor, you saved me about five or ten minutes of trying to remember how to set that up. Heh.

I tried to do it from within AVG Free, but couldn't find what I was LOOKING for.
3395.

Solve : unwanted ads!?

Answer»

Windows with advertisements telling me to fix my register going to some sites like www.key32.com, www.regupdate.net, www.clean32.com and others, appears every time. I run AVG free, Hijakthis, cCleaner, Ewido, unsuccessfully. Please:is it any way to identifie this "program" and delete it??[size=14][/size]Do your scans in safe mode with system restore turned off and don't play with the fonts and colors. It makes your posts difficult to read. This is not the time for individuality. Can you post a screen SHOT of the ads?
Turn off the Windows Messenger Service if it's running.Problem was Windows Messenger Service Once disabled, ads stoped
ThanksQuote

Do your scans in safe mode with system restore turned off and don't play with the fonts and colors. It makes your posts difficult to read. This is not the time for individuality.
OK. But why have so many OPTIONS?...
In case people want to change the colours.
It makes some things hard to read, but some colours serve to emphasize things or can be USEFUL in other ways.A good result for you, now go and update your WIndows OS. try hostsercure too to help with future ad problems



unlovedwarriorQuote
try hostsercure too to help with future ad problems



unlovedwarrior


THis COULD have used some color, perhaps.Quote
THis could have used some color, perhaps.
And a lot of PROOF reading.maybe english never was my strong point in school and it still isnt (yes english is my native language just cant write it very well)
3396.

Solve : Sites popup with login prompts, shouldnt be there?

Answer»

Hi

Your REPLY in post #12 indicates a problem with hardware, typically a network card or video card & driver but it may be difficult to track down.

Apart from the java issue I mentioned the log is OK. (I did notice your comment that the virustotal scan came up clean).

Have you updated any drivers recently? Are you still getting the same browsing pop up trouble you had in your first post?


OJNope, pretty sure I haven't done any driver updating or anything like that.

As for the browsing popup trouble, yeh, still got that stupid login prompt.Despite having already removed TrustIn Contextual it may still be causing a problem behind the scenes. Let's look at it.

Read through this fix and put it into action.......

http://www.bleepingcomputer.com/forums/topic54501.html#fix

If this fixes the pop up ... just let us know.


If NOT ... Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].


Next post a fresh HJT log here with the AVGAS scan report and another update on how things are going.



OJWell things have changed themselves a bit. I don't get the login prompt on any of the websites anymore. Now I just get a Problem Loading Page - Connection was Reset problem on those specific sites.

Unfortunately, bleepingcomputer is one of those websites that gets that error, so I can't really go and read the instructions.
Also, I now get the Blue Screen of Death everytime I come back from a hibernation.

I don't really want to do anything else until I try that bleepingcomputer thing that you mentioned. So I dunno, I guess you could repost it here or something.First follow these instructions (if possible)....

Print out these instructions as we will need to close every window that is open later in the fix.

Download SmitRem.exe from here to your Desktop …..

http://www.downloads.subratam.org/smitRem.exe


Double-click the smitRem.exe and it will extract the files to a smitRem folder on your Desktop. Do not run it yet.

Download FixTC.reg to your desktop by right clicking on the following link and then selecting Save Link As or Save File as, DEPENDING on your browser.

http://download.bleepingcomputer.com/reg/FixTC.reg

Confirm that the file FixTC.reg now resides on your desktop as we will need it later.

Reboot to safe mode.

Log on to your user account.

Open the smitfraud folder then double click the RunThis.bat file to start the tool.
The scan log is saved here … log C:\smitfiles.txt

***************

Now the “copied” fix instructions from Bleeping Computer, as you suggested ….


1. Click on the Start Menu
2. Click on the Control Panel option.
3. Double-click on the Add or Remove Programs icon.
4. Look again for any/all of the following entries and double-click on each of them. Follow the prompts to uninstall the programs, but do not allow it to reboot the computer if it asks. If after you uninstall a PARTICULAR entry below it still remains, double-click on the entry again to remove it.

Trust Cleaner
TrustIn Bar
TrustIn Contextual Ads
Trustin Popups
TrustIn Search Assistant
Trust Cleaner Promo


5. When it has completed uninstalling you can close Add or Remove Programs and your Control Panel.

6. Go to your desktop and double click on the FixTC.reg file that you downloaded earlier. When it asks if you would like to merge the information, press the Yes button and then the OK button.

7. DELETE the following files and folders (Do not be concerned if a folder or file does not exist):

C:\Program Files\TrustIn Popups
C:\Program Files\TrustIn Bar
C:\Program Files\TrustIn Contextual
C:\Program Files\TrustIn Popups
C:\Program Files\TrustIn Search
%Temp%\wschtm35.dll
%Temp%\srsvc.exe
C:\WINDOWS\local.html
C:\WINDOWS\SYSTEM32\tisa.dll
C:\WINDOWS\SYSTEM32\lut.dat
C:\WINDOWS\SYSTEM32\tisa.cnf
C:\WINDOWS\SYSTEM32\ticads.exe
C:\WINDOWS\SYSTEM32\tctool.exe
C:\WINDOWS\SYSTEM32\ticont.dll
C:\WINDOWS\SYSTEM32\tpopup.exe
C:\WINDOWS\SYSTEM32\tconini.dat
C:\WINDOWS\SYSTEM32\lcch.dat
C:\WINDOWS\onlineshopping.ico
C:\WINDOWS\removeadware.ico
C:\WINDOWS\sexpersonals.ico
C:\WINDOWS\local.html
C:\WINDOWS\SYSTEM32\tu.exe
C:\WINDOWS\SYSTEM32\ttu.exe
C:\WINDOWS\se_spoof.dll
C:\WINDOWS\inetloader.dll
C:\Windows\mxd.exe
C:\Windows\tse.exe
C:\Windows\trustinbar.exe
C:\Windows\ads.js
C:\WINDOWS\videoslots.ico

8. Delete these icons from your Desktop:

Online Shopping.url
Remove Adware.url
Sex Personals.url
Video Slots.url


9. Close all open Windows.
10. Reboot your computer back to normal mode.
11. Download the ATF-Cleaner to your desktop from the following link:

http://www.atribune.org/ccount/click.php?id=1

When it is download to your desktop, double-click on the program to run it. Select the box labeled Select All and then press the Empty Select button. When it is done you can close the program.

***************

Perform an onlinescan with Panda ......

http://www.pandasoftware.com/products/activescan.htm

1. Once you are on the Panda SITE click the Scan your PC button
2. A new window will open...click the Check Now button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It may take a few minutes)
10. When download is complete, click on Local Disks to start the scan

Your computer should now be free of the Trust Cleaner infection.

***************

Please "copy/paste" the contents of the log C:\smitfiles.txt and a fresh HijackThis log.


Please tell us how the computer is operating now.


OJ

3397.

Solve : 0x7c901010  error?

Answer»

I'm FACING a problem while go to i banking website.
the ERROR message 0x7c901010 always appeare and close my window auto.
below attach the file on that message screenshot and HIJACK log file.

is that a viruses/malware in my pc?
or that is IE problem?
I am running win XP SP2 , IE 7.0.

PS: how did u guys post the hijack log file here?i got a limitation.Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept LicenseAgreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
When done please post a fresh HJT scan report and an update on how your computer is operating now.


NOTE >> to post the log here, without zipping it, just "copy & paste" the scan report in a post to this thread.


OJ
May I ask, why did you post exactly the same thing twice?

EDIT: Oh I see, you DELETED it.

8-)fffreak
NOTE >> to post the log here, without zipping it, just "copy & paste" the scan report in a post to this thread.

I can't post all the log here, only up to 09..lines...
the rest cannot paste due to limitation...5500 Max charactersTry splitting the log report up and post it in sections over several posts. That should work.


OJQuote
EDIT: Oh I see, you deleted it.
YEs ... the first post appeared not to go so I posted again then, as you noticed, deleted the duplicate.

Sorry if I confused anyone!!

Cheers.


OJoh thanks...problem solvedHi only_lonely .... do you mean your original problem is now fixed? Hope so.


OJoh yeah..original problem solve..
is java problem...*censored*...i downloaded many anti spy software.This isn't the first nor will it be the last thread that has me confused.Quote
This isn't the first nor will it be the last thread that has me confused.
Me too for a while.

I think the OP is saying they downladed many antispyware programs, in a effort to keep malware at bay, but it didn't work because they were still using an out of date java (which allowed malware in).

I think.

Maybe.BTW oddjob, Welcome Aboard !

Where did you do your Hijack log studies ? ?

Good to have another helping hand...

patio. 8-)
3398.

Solve : Malware virus??

Answer»

HI,CAN YOU HELP PLEASE.
TWO DAYS AGO I FOUND Trojan-Downloader.Win32.Murlo.fa
USING- XOSTSPY SE- BUT WHEN I TURN PC ON, THE NEXT DAY ITS STILL
THERE.I HAVE CLEARED THE RESTORE POINTS AND SCANED AGAIN, BUT IT STIL COMES BACK?? ANY HELP APPRECIATED. (or will i have to reboot from factory disc)The page I link to contains information about this PARTICULAR malware, and a download to a program that should remove it.

http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan-Downloader.Win32.Murlo.fa&threatid=119349Clearing the restore points doesn't always do it...

Follow the advice above for removal.

Then turn off system restore, dis-connect from the web, re-boot into safe mode and run all your scans.

When you post back with results please list all the protection programs you currently have...

and fix that capslock key...Thankyou both for your time phoenix910 and patio.
And quick repley. I will let you know how it gose..

CHEERS.........Thanks for fixing the Caps Lock key too. Hi, Phoenix910 and patio. i ran counterspy nothing found.
I done all the things you sugested and scaned in safe mode.
After this post i will use the disc and wipe pc clean....

Here is the list of scanners i used, First i was with telewest blueyonder, now it has been taken over by virgin ,i use the pc guard full services.
(see there homepage) Then i use..spybot ,adaware se,xoftspy se, avg,kazaabegone,hijack this,ccleaner,avast,MULTI virus cleaner,spyware terminater,
and xoftspy.............thanks

Dump telewest blue yonder...other than that you have a decent package.

You might want to add AVG Anti-Spyware ( formerly Ewido ) also free; it looks at variants AVG AV might miss such as newer Trojans and keyloggers.

The real-time scanner times out after 30 days but don't worry you don't need it. Other than that it remains fully functional.

Let us know how it goes...
Thanks for your time Patio, I have just FINISHED pc reinstall from disc,I only got to put
all my programs on and updates you know.
thanks again............It wouldn't hurt to add Spyware Blaster[/ur] and [url=http://www.siteadvisor.com]SiteAdvisor to your list. That'll help protect you while surfing.

3399.

Solve : Safe Browser?

Answer»

Quote

The biggest risk is just being human - everyone makes mistakes, and some are more prone to make them than others.
Indeed. One of the best security tools is common sense ....

http://info.org.il/irrelevant/may02-smilepop-soapbox4.swf
Thanks Patio. I will GET on to Orange and ask. I am using Firefox now and will see how things go with it.Quote
I use QUITE a few of those, and some others.
I agree though, it is getting more than ridiculous, the amount of protection needed to stay safe (I know there's no such thing as totally safe, I mean reasonably safe) on the internet and maintain Windows.
The biggest risk is just being human - everyone makes mistakes, and some are more prone to make them than others.
It must be nice to be so used to using LINUX that you're [highlight]AMAZED [/highlight]by Windows' faults and the amount of security needed.
I might even get there one day.

Actually I am not amazed with that. I am amazed at the quantity of programs needed to safely be online with that. I do use some basic programs on my Windows boxes - Spybot, CCleaner, and AVG. I have never had any issues they could not resolve, but I may be more selective in my SITES and habits than others.
3400.

Solve : Is my internet deleting software enough??

Answer»

I am currently running WinClear on my OFFICE computer. We do use a server here but I am not sure whether everything is recorded.

I am not using my computer for any ILLICIT material but i just want to secure my personal emails and internet banking details etc. I just don't like the idea of people snooping.

Can someone help out a relative computer NOOB?

Any help is appreciated!I wouldn't be doing my personal banking on any other MACHINE than my own...as to e-mails i have nothing to hide.You should COUNT on everything being monitored and act accordingly.