Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3401.

Solve : NEEEED HEELP PLEEASE!!!!?

Answer»

I am running windows XP and I have a virus but I don't know how to fix it. When I go to boot it it will go to the Windows XP loading screen and then the screen goes blank and it's almost like it goes into standby mode. I can't get the screen to come back on or ANYTHING without shutting it off with the power BUTTON. I have already done a SYSTEM recovery and when I was all done with it it did the same exact thing. Please tell me how to fix this somebody!!!! Thanks!tdelong08......
Quote

I am running windows XP and I have a virus but I don't know how to fix it.
You know because ................... ?

Do you have a anti virus running ?

You should NEVER use system restore to fix this sort of issue ...if thats the problem.

dl65 Virus near the bottom of the LIST of possibilities.have you tried making sure your video card is in all the way?

and the computer is clear of dust
unlovedwarrior
3402.

Solve : Is this virus real??

Answer»

I just got this email from a family member, and i cant tell if this is b.s. or not. ANYONE heard anything about this?


> BETTER SAFE THAN SORRY. READ AND HEED.
> This has been verified with-
> Snopes and it is REAL.
> PLEASE INFORM EVERYONE
> Emails with pictures of Osama Bin-Laden hanged are being
> sent and the
> moment that you open these emails your computer will
> crash and you will
> not be able to fix it!
> If you get an email along the lines of "Osama Bin Laden
> Captured"
> or "Osama Hanged" don't open the attachment.
> This e-mail is being distributed through countries
> around the globe, but
> mainly in the US and Israel
> Be considerate & send this warning to whomever you know.
> PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND
> CONTACTS:
> You should be alert during the next days:
> Do not open any message with an attached file called
> "Invitation" regardless of who sent it.
> It is a virus that opens an Olympic Torch which "burns"
> the whole hard
> disc C of your computer.
> This virus will be received from someone who has your
> e-mail address in
> his/her contact list, that is why you should send this
> e-mail to all
> your contacts.
> It is better to receive this message 25 times than to
> receive the virus
> and open it.
> If you receive a mail called "invitation", though sent
> by a friend, do
> not open it and shut down your computer immediately.
> This is the worst virus announced by CNN, it has been
> classified by
> Microsoft as the most destructive virus ever.
> This virus was discovered by McAfee yesterday, and there
> is no repair
> YET for this kind of virus.
> This virus simply destroys the Zero Sector of the Hard
> Disc, where the
> vital INFORMATION is kept.
> SEND THIS E-MAIL TO EVERYONE YOU KNOWwhat antivirus do you have and does it have a email scanner??

and have you contacted this family member to see if they sent it to you and if they had have any problems with the pics??From Snopes website, originally posted in 2004:

http://www.snopes.com/computer/virus/osama.asp


Here are some other similar stories from Google 5 minutes ago:

http://urbanlegends.about.com/library/bl_osama_virus.htm

http://www.hoax-slayer.com/bin-laden-captured.html

http://www.joewein.net/hoax/hoax-osama-virus.htm


(NOTE: The example letter at the bottom of this page should sound vaguely familiar to you.)


Here's something from Trend Micro in 2006

http://www.trendmicro.com/vinfo/hoaxes/hoaxDetails.asp?HName=Osama+Bin+Laden+Virus+Warning+Hoax


so there might be a virus attached to the e-mail warning me about viruses from emails? *censored* i HATE computers.

so i guess its a good thing i opened it from my work computer.not reallyQuote from: Medman on April 11, 2007, 10:57:40 PM

so there might be a virus attached to the e-mail warning me about viruses from emails? d**n i hate computers.

It's hardly the computer's fault.

Quote
so i guess its a good thing i opened it from my work computer.

It would not be if it were an infected file AND they did not have the means to protect their system.
3403.

Solve : Fun with trojans...?

Answer»

Thanks a lot for your help, both of you! I really appreciate it. And thanks for the links. I'll be sure to take the time to read EVERYTHING and soak it all up. I'll also definitely keep AVG. It's a bit more user-friendly than McAfee and seems to do a better job of finding malware.

As for the problem with my default SOUNDS...my guess would be that one of those files was affecting my default sounds somehow. Whatever it was, it's resolved now, so I'll just be HAPPY with knowing that I don't have to worry about it anymore. HEH. Thanks again! I'd be LOST without you guys.Glad to be of help.

3404.

Solve : More spyware/adware etc.?

Answer»

So prety much i accidently clicked on some link and i pick up some spyware or addware or whatever. Its just a little thing in the corner of my screen saying "system alert! You need to PURCHASE some software" ... i Think its called like Active X torjan or something..

Anyway if anyone can see the problem please tell me....

Heres my HijackThis! Log:

Logfile of HijackThis v1.99.1
Scan saved at 3:45:11 PM, on 4/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\David\LOCALS~1\Temp\Rar$EX00.672\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://myplace.westnet.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [Smapp] "C:\Program Files\Analog Devices\SoundMAX\Smtray.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n028p/EN/install/gtdownlr.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

If I were you, I would just do a full system scan with Ad-Aware, and this should clean anything up. Also check the Start>Programs>Startup menu, and check the programs that start at boot up using Start>Run "msconfig". Yeah i cant see it ANYWHERE in the startup options...Also ive tried to scan my computer with like 10 different anti-spyware programs including ad-aware but none of them can pick it up.

Any more help would be nice. thanksAlright, check all your installed programs. It might have actually installed itself. Tell us what Spyware/Adware programs you have tried. And one personal favourite of mine is Trend Micro Internet Security 2007. I would advise you buy it, but until you do, I am not sure if they OFFER a trial or not, but if they do, get that. In some cases they also offer online scanning. I can't spot anything in particular from a quick glance at your log, but as I said, tell us what you've tried already.Sorry but i deleted them all so i cant remember what they were...but i remember the second i got it and it was when i was on Utorrent...i click some link accidently and some weird website open...so yeah i defenatly got i from a website, not an anti spyware program...No, I wasn't saying you got them from the anti-spyware program, I was wanting to know which anti-spyware programs you have tried so I could suggest ones that you hadn't tried that I've used before.Quote from: divcraft on April 08, 2007, 05:04:13 AM

Sorry but i deleted them all so i cant remember what they were...but i remember the second i got it and it was when i was on Utorrent...i click some link accidently and some weird website open...

Clicking is never an accident. You have to aim the mouse and press the button.

Just for grins, download update and run Spybot and CCleaner in SAFE MODE with SYSTEM RESTORE TURNED off.
3405.

Solve : Incredimail install - installed itself?

Answer»

OS is Win98SE
Computer in question is used by more than one person.


I have heard of Incredimail, but only from a friend that USES it for email. It sounded like just another email client. True?


A couple of days ago, an icon appeared on the desktop,
"Complete Incredimail Installation".

Deleted it. Crossed fingers.

It reappeared the next day.

One of the users of the computer is elderly. In her email, I found a forwarded email from another elderly friend, with mention of Incredimail, and a big ol' "Click here" button.
She uses a web interface for accessing email. Using IE v.6
No need to press and ask. I can make a reasonable assumption that it was clicked, and somehow it downloaded and installed an installation program.

I started looking around.

Found it in C:\Windows\Temp\ImInstaller\IncrediMail
An executable, a .cab file and a text file or two.

I have not deleted that stuff yet.

Because it reappears, I looked some more.
Rebooted, and there it was.... again.

Using the Search function in regedit, I found it a few times.


HKEY_LOCAL_MACHINE\Software\ImInstaller
name=IncrediMail_iver data={a hex number here}


HKEY_LOCAL_MACHINE\Software\ImInstaller\IncrediMail
name=Root
data=www5l.incredimail.com/contents/setup/2007032901/downloader_nu

name=ScriptUrl
data=www5l.incredimail.com/contents/setup/2007032901/downloader_nu/setupscript.xml



HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
zzz_ImInstaller_IncrediMail
C:\WINDOWS\TEMP\ImInstaller\IncrediMail\INCREDIMAIL_INSTALL[1].EXE -startup -product IncrediMail -cluster 2



Questions:

1.) What do you think happened?


2.) What would you do?
This is the bottom line, main question.
I am curious about some things while we are at it though.


3.) At first I thought it would be ok to delete the files in the temp dir .
Wouldn't that cause some sort of burp at boot time though? ... since
apparently the registry entries are looking for them.

4.) Would it be ok to delete those registry entries with regedit?
In other words, would the combination of deleting the files in the
temp dir and deleting those keys, be the proper fix?

5.) Other than politely advising not to click on things found in emails, is
there any other preventative action I can take?



Any and all comments/thought/ideas greatly appreciated.

Need more info regarding the system, ask and I'll get it.


Thanks





This may not answer every question you may have, but I hope you find it useful...I Googled it and found the following for complete removal. IncrediMail does not provide this info in their Support SECTION:

http://www.oeupdates.com/Uninstall-remove-IncrediMail.html


The above link also refers to a Microsoft KnowledgeBase document:

http://support.microsoft.com/default.aspx?scid=kb;en-us;297069


Good luck...Quote from: Saviour on April 09, 2007, 07:30:55 PM

This may not answer every question you may have, but I hope you find it useful...I Googled it and found the following for complete removal.

You Googled Incredimail?

Quote
IncrediMail does not provide this info in their Support section:

http://www.oeupdates.com/Uninstall-remove-IncrediMail.html


You misunderstand. The link you provided is about uninstalling Incredimail.
Incredimail is not installed.

Quote
The above link also refers to a Microsoft KnowledgeBase document:

http://support.microsoft.com/default.aspx?scid=kb;en-us;297069


This page looks to be the same. The keys there are not the same as the ones I mentioned.


Thanks anyway.




Quote
You Googled Incredimail?

Nope...I Googled "Completely Remove IncrediMail", because I've run across this sort of problem before on someone else's computer.

I know you stated IncrediMail is not installed, but it seems the Installer wants to run every time you boot.

IncrediMail's support page will only tell you how to uninstall it using Control Panel, but doesn't assist with the issue you seem to be experiencing.


Sorry I couldn't help. Good luck!I suggest you follow your 4) above. Also check msconfig for the starup entry.1) Delete the install files you found.

2) Delete the reg entries you listed.

3) Restart regedit (not the machine) and type incredimail in the search field...F3 takes you to the next listing until you reach the end of the registry.Delete any other incredimail keys that are found.

Re-boot and run CCleaner and you should be good to GO...Quote from: Saviour on April 10, 2007, 02:01:52 PM
Quote
You Googled Incredimail?

Nope...I Googled "Completely Remove IncrediMail",

This is not Incredimail. It is an installer for Incredimail.

Quote
because I've run across this sort of problem before on someone else's computer.

You have? Great!
But.... you forgot to describe what you did to fix it. ....or, you couldn't fix it?
.... or.... what?


Quote
I know you stated IncrediMail is not installed,

Right.

Quote
but it seems the Installer wants to run every time you boot.

Right.

Quote
IncrediMail's support page will only tell you how to uninstall it using Control Panel, but doesn't assist with the issue you seem to be experiencing.

Right.


Quote
Sorry I couldn't help. Good luck!


Ok.
Thanks for wishing me luck.




Quote from: 2k_dummy on April 10, 2007, 03:55:47 PM
I suggest you follow your 4) above.

I see another post that says the same thing. That's two positive votes for that method.
I needed some reassurance that I was on the right track, before I did any deleting in the registry.
Thanks.


Quote
Also check msconfig for the starup entry.

Did that first. Forgot to mention it. Sorry.


Quote from: WillyW on April 11, 2007, 10:50:45 AM
Quote from: Saviour on April 10, 2007, 02:01:52 PM
Quote
You Googled Incredimail?

Nope...I Googled "Completely Remove IncrediMail",

This is not Incredimail. It is an installer for Incredimail.

Quote
because I've run across this sort of problem before on someone else's computer.

You have? Great!
But.... you forgot to describe what you did to fix it. ....or, you couldn't fix it?
.... or.... what?


Quote
I know you stated IncrediMail is not installed,

Right.

Quote
but it seems the Installer wants to run every time you boot.

Right.

Quote
IncrediMail's support page will only tell you how to uninstall it using Control Panel, but doesn't assist with the issue you seem to be experiencing.

Right.


Quote
Sorry I couldn't help. Good luck!


Ok.
Thanks for wishing me luck.

WillyW,

To be perfectly honest...it was a while ago, when I happened upon this problem so, I can't remember in detail what it was I did (at that time) to remove it. One thing I am SURE of is that you will need to edit the registry in order to fix this problem and you have received a couple of replies recommending this relative to your initial post.

I realize IncrediMail is not installed and that it is the "Installer" that continually wants to run.

One thing I will recommend, though...it is called Process Scanner and you can use it to scan your PC for processes that should or should not be running on your PC. I find it to be a very useful tool and you can obtain more information about it at the following URL:

http://www.processlibrary.com/

Additional links:

About Process Library
Process Scanner

I hope you find the above information helpful and find a solution to removing the IncrediMail Installer from this computer.Quote from: patio on April 11, 2007, 03:20:51 AM
1) Delete the install files you found.

Done.

Quote
2) Delete the reg entries you listed.

Done

Quote
3) Restart regedit (not the machine) and type incredimail in the search field...F3 takes you to the next listing until you reach the end of the registry.Delete any other incredimail keys that are found.

[That's how I found them the first time. Therefore, at that time, what I posted was all of them. ]

Exited Regedit.
Ran Rededit, searched, found none.

Done.


Quote
Re-boot and run CCleaner and you should be good to go...

Machine rebooted fine.
CCleaner - 'issues' search, right? - found a few things. Some had nothing to do with this topic.
Found one that did.
"obsolete software key" "ImInstaller"
Found it with Regedit and deleted it too.

Rebooted.
Ran CCleaner again, and searched with Regedit again. Found nothing that looked like it had to do with this.

For now, I think it is good. You think?

Patio and 2k_dummy: Thanks for your on target instructions on solving this issue. Quote from: Saviour on April 11, 2007, 11:19:37 AM

To be perfectly honest...it was a while ago, when I happened upon this problem so, I can't remember in detail what it was I did (at that time) to remove it.

Ok. Makes sense.


Quote
I realize IncrediMail is not installed and that it is the "Installer" that continually wants to run.

? You did? Naturally, I had concluded that you were confused.
Why you would direct me to things that are not the problem that I described then, if it was not in error .... I don't know now. It is a tad bit obfuscating.
No matter now though.

Thanks for trying, I guess.


Quote
I hope you find the above information helpful and find a solution to removing the IncrediMail Installer from this computer.

Yep - I think I got some good advice.

3406.

Solve : I dont know if this is a virus..?

Answer»

I constantly get disk cleanup MESSAGES saying my hard drive is full, and whenever I get this, I can't STREAM media, and it gets really annoying because this happens about 10 times a day. I have plenty of space on my hard drive though, so my hard drive is never full, but the messages keep coming up. Anyone know what's WRONG?can we get more info on your computer os when did this start HAPPENING what changes have you made hardware software or none what protections do you have anti-virus anti- spyware etc


unlovedwarriorI'm using Win98SE, I have made no hardware changes, and this just started happening a few days ago. I have AVG, but that program is useless because it never detects any viruses. But i don't even know if this is a virus yet.Do you update AVG regularly? All I can SUGGEST at the moment is posting a HijackThis log for everyone to take a look at. Other suggestions should come along shortly.and see about downloading A squared freeQuote

I have AVG, but that program is useless because it never detects any viruses. But i don't even know if this is a virus yet.

This in no way determines that AVG is useless...

When is the last time you ran disk cleanup, defrag and dskchk on that drive ? ?

Post the HDD size and amount of free space as Explorer sees it.Too many theories, so few facts.
3407.

Solve : ISU bloack URL?

Answer»

I facing problem while accessing certain website.the web page redirect to this page:

Access to the requested URL is not allowed!
Please, fill out the form below if you believe the requested page should not be blocked:
Please, send other sites you feel should be blocked using the following form:

This page was generated by cache3.jed.isu.net.sa on Fri, 02 Feb 2007 20:21:06 GMT

is that my internet settings problems?or malware again?
Is this your PC?
Are you the administrator?
Is it on a network?
What sites cause problems?what protections do you have?

unlovedwarrioryes,it is my PC.
i have symantec antivirus.just run the hijack,this is the log

Logfile of HijackThis v1.99.1
Scan saved at 1:29:11 AM, on 2/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT CORPORATION\BlueSoleil\BTNtService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\NORTON AntiVirus\navapsvc.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Iomega HotBurn\Autolaunch.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\SOFTWARE\HijackThisA.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.138.64.143:80
R3 - URLSearchHook: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Kwyshell MidpX - {EBE9E2B5-B526-48BC-AD46-687263EDCB0E} - C:\Program Files\Kwyshell\MidpX\JadInvoker\MidpInvoker.dll
O3 - Toolbar: Yahoo! Toolbar BETA - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime TASK] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global STARTUP: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: D.S.Lite - {F8475519-8412-4D40-A46E-692D9D04DF7F} - C:\SOFTWARE\DSLite2.07.45\DSLite2\DSLite.exe
O9 - Extra 'Tools' menuitem: &D.S.Lite - {F8475519-8412-4D40-A46E-692D9D04DF7F} - C:\SOFTWARE\DSLite2.07.45\DSLite2\DSLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netmarble.com/web/nmstarter/NMStarter23.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061023/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://webmail.ges.com.sg/iNotes6W.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/activex/EPUWALControl_v1-0-3-18.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1143464234390
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1143465193171
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/41/install/gtdownde.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by111fd.bay111.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Norton AntiVirus Auto PROTECT Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

this is the screenshot
The log is clean.

You had a problem with java a few days ago. I believe that was fixed.

I do not know where you are but all I can say about that message is that the Saudi Arabia government censors the internet/web usage of people in that country. This error mesage comes up occassionally but only rarely and only for people in that country.

Are you in Saudi Arabia?no...i am in singapore...never meet that problem before.
and my live messenger also cannot sign in since that...Sounds to me like something my schools filters would say when trying to access a blocked site...Quote

Sounds to me like something my schools filters would say when trying to access a blocked site...
Same here, which is why I asked if they owned the machine and were the admin.it seems is malware..
juz now dl avg ..n scan
found a lots of malware...after clean ..it solve the problemQuote
it seems is malware..
juz now dl avg ..n scan
found a lots of malware...after clean ..it solve the problem


That's good. I'm glad you fixed your computer. Although now if I ever get a virus or suspect of one, i'd be in Safe Mode by now and scanning...Same here, glad you're fixed up and thanks for posting back.
As suggested, it may be an idea to run the scans again in Safe Mode, just to be sure.
Follow this guide to help you clean any remnants.
3408.

Solve : vbs/psyme?

Answer» WOW............i really have no idea what a hijack log is or how u guys run it or whatever but some help gettin RID of this virus/trojan would be awesome
also have eploit anlfile.c...and another EXPLOIT bo.jen...........awesome stuff......................HELPWe are gonna NEED a lot more info on your system, OS what happened prior to this and SPECIFIC error messages before we can assist...

There are no generic fixes.
3409.

Solve : Hmmm...AOL spyware...sorta.?

Answer»

Well, I have this free firewall called 'Comodo', it's won countless awards from a magazine called "PC World"...anyway, I have AIM installed on my computer.


So, I go onto aim after the 2 week of having a newer version, and my firewall pops up, and says a program called Viewmger wants to connect to the internet, and I hit no for now, and close aim.


I researched the program, and it's KINDA like spyware to me, but not so much....anyway, it installs onto your computer with a few products, so if you INSTALL something by Toyota, it will install ViewManager (And other products, like America Online). ViewManager will look into the sites that you view on Internet Explorer. Therefore, if you always click/search for games and game cheats, next time you open aim, it will shoot ads at you that relate to what you have recently been looking at!


It's just something new I found out..


Do you guys consider this spyware? (I wish I knew how to make this a poll.)
Malware? Spyware? Bad? All open to debate. Foistware would be a better DESCRIPTION.

"VIEWPOINT Manager" is AUTOMATIC updates for ViewPoint products such as ViewPoint Media Player (as bundled with AOL, AOL Instant Messenger, Compuserve, etc)

Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".


More information ......

http://www.liutilities.com/products/wintaskspro/processlibrary/viewmgr/


(PS ... I wouldn't want it).


OJ

3410.

Solve : Desktop Icons not responding?

Answer»

Hi. I'm running Windows ME on a PC. Yesterday after the regular AVG Free scan on start up which revealed nothing, I went to connect to broadband using the desktop icon and the result was all the icons disappeared and the screen background went white. Clicking on any icon produces the same effect.

I can only access programs on the toolbar which do not include my internet connection! If I try to access anything via "start" and the pop up menu the screen just changes colour as above.

I have run AVG again from toolbar with nil result.

Your help would be appreciated. Peter EdwardI'm going to suggest a hopefully simple fix first ... have you tried to System Restore to take you back to a time before this latest problem? I'm hesitant here as your problem suggests you may not even be able to get to SR.


OJThanks for your reply. You were right to be hesitant, I can't access System Restore. Cheers, Peter Edward.Try right click > Toolbars > Address. After that then Right click > Lock the Taskbar and make sure you move the address bar so you can type in it. After that type in Control Panel, and the control panel should come up and you might be able to navigate to SR from there. Anyway, thats just a GUESS, I doubt it will work =\.


Good luck...Hi Peter

If none the above comments help you should boot into safe mode (if you can) and CARRY out some basic troubleshooting from there.

This MS article may help (it save me repeating everything) .....

http://support.microsoft.com/kb/273738

I'm trying to keep my suggestions at a "low intrusion" level at the moment to see if we can fix things without getting too drastic.

Please post back and let us know how you're getting on.


OJThanks, I will try your suggestion in safe mode but before I do I am now getting strange error messages such as "Dkservice has caused an error in DKSERVICE.exe. Dkservice will now close. If you continue to experience problems try restarting your computer."

There is a similar one under the banner 'Rnapp"

Do I have a virus or a worm?

Peter EdwardDKSERVICE.exe is installed with Executive Software Diskeeper. Is this something you know about and have installed?

If it is legit then you may like to consider reinstalling this .exe file from a program disk.

I can find very little on Rnapp and nothing in English. You may be right suspecting an infection but, without being able to get online, it may be difficult to sort this out.

I am guessing you have access to a computer online (OTHERWISE you wouldn't be posting this) so I suggest you try this.


Using a computer that can get online download Ewido/AVG Anti Spyware from here to a disk ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it on the suspect computer.

Do NOT use it yet.


Boot the infected computer to safe mode.


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

Now try rebooting the suspect computer into normal mode and using it as you would usually do.


Post back and let us know how you get on. Any improvement?


OJThanks Oddjob. I have just tried the AVG Spyware but unfortunately it is only for Windows 2000 and upwards. I am sure that Ewido is the same.

I am on Windows ME and so is my spare computer.

Where can we go from here? Peter Edward

PS Trying to connect with Contol Panel did not work because it COMES up over the Desktop and clicking on the appropriate icon within causes the same problem with the scree.nYes, I overlooked the application of Ewido/AVG AS on W2000 and up.

If you upgraded from Windows 98 or 98SE, before you upgraded to Windows ME, to locate the option Hide Icons when the desktop is viewed as a Web page, right click on your blank desktop ... click on Active Desktop>click Show desktop Items? Does that help?

And what are your thoughts on DKSERVICE.exe and Executive Software Diskeeper?

Have you investigated any of the MS troubleshooting help in my post #5?The computer was installed with Windows ME. Have tried using Active Desktop etc. though to no effect.

The computer came with Executive Software Diskeeper preinstalled. I don't have the CD but I am sure it is legit. because it has been working without problems.

I have read through all the info. on the MS site but I cannot find anything relevant to my problem.

Incidentally, regarding the warning messages, I misread one which should read "RNAAPP". Apologies for that.

Others coming up are "DRAGDIAG" and "EXPLORER" with the same message re. error, closing and restarting computer.

I managed to run NOD and A-Squared last night from the toolbar. Both gave a negative result.

I await hearing back from you. Peter Edward.Hi Peter

On post #1 you mentioned you couldn't get this machine to go online. Maybe this is at the heart of your trouble.

On RNAAPP.......

http://www.modemhelp.net/newsletter/dun/combatrnaapp.shtml

On DRAGDIAG ....

http://www.liutilities.com/products/wintaskspro/processlibrary/dragdiag/


Both seem to be related on some way to your internet connection ...the dialup and/or modem.

(Don't touch EXLPORER at this stage).


I'm starting think there's no malware infection but rather a possible hardware/software foul up at the bottom of all this.


Have you tried bootng to safe mode?

Choose "Last Known Good Configuration" option. Windows makes a copy of the current configuration after a successful boot and flags it as “good.” This copy isn’t really a backup but more of a list that contains information about the system’s settings. If your system fails to boot after a configuration change you can use the Last Known Good Configuration setting. This replaces the current configuration settings with those from the last known good file,which should allow Windows to boot normally.


Is there any way you could try re-installing your modem/software? Maybe reinstalling that would kick start/fix RNAAPP & DRAGDIAG.

Excuse short reply. Being SUNDAY I have much to do elsewhere.

If anyone else has any sugesstions .... please free to add them.

Let us know how you get on, Peter.


OJ


Thanks Oddjob, using your last suggestion first, the screen is now stable. However, the reinstallation will not progress beyond installing new drivers. The computer then freezes and has done so the six times that I have tried.

On reboot the error messages are in order of appearance:-

DKSERVICE
RPCSS
DRAGDIAG

Can you move me on from here and many thanks for your interest in my problem. Regards, Peter EdwardReinstalling drivers should not usually cause this much trouble.

DKSERVICE > To be honest I have never seen anyone with this program before. I know nothing about it. As Executive Software Diskeeper came preinstalled the organisation you bought it from should have given you the master program installation disk. Have you tried uninstalling the program entirely, rebooting then reinstalling form scratch? If so what happended?

If not ... can you try this without the program causing any damage anywhere?

RPCSS
DRAGDIAG
> I guess from what you say that, although the desktop is now working as it should, you still you can't get online with this computer.

Similarly to ESD, have you tried uninstalling the modem entirely, rebooting then reinstalling from scratch?

Problematic modems happen to many people (me included) and this rectified the problem.

Remember that, when you install a modem from scratch, you do it exactly in accordance with the manufacturer's instructions. I Know this may sound daft but it is particularly relevant with modems more than other progrqams, I believe.

For example, if you have an external modem connected by USB, you must be careful at which point during the installation process you connect the USB cable to your tower.

Try this and post back again. Please also update us on what you can now do on this computer
and what you can't.

Good luck.


OJ

3411.

Solve : Cannot Connect to Internet or Restart Comp!?

Answer»

I accidentally clicked a bad link and it infected my computer. I can't restore, internet does not work, and it does not RESTART. Here are the logs. Please help me!

Logfile of HijackThis v1.99.1

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\ad-aware.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1A31E9A2-72D9-BCC1-3DB8-0B9EC0657E30} - C:\WINDOWS\system32\unlsvce.dll
O2 - BHO: OwlforceB - {3E1500AC-87A5-416b-A211-82E848649DA9} - C:\PROGRA~1\OfB\OWLFOR~1.DLL
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [PPMemCheck] C:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: ImageTune.lnk = C:\Program Files\Portrait Displays\ImageTune\dthtml.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra CONTEXT menu item: Download using LeechGet - file://C:\Program Files\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Program Files\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Parse with LeechGet - file://C:\Program Files\LeechGet 2004\\Parser.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2812814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/1501...
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/c...
O16 - DPF: {4FE89055-5300-469E-AFAD-DEB3181EDE76} (PearsonAsstX Control) - http://www.mathxl.com/applets/Pears...
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuit...
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/1501...
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: Winmsc - ms3d2a43d1.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Portrait Displays\ImageTune\dtsslsrv.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Portrait Displays\ImageTune\DTSRVC.exe (file missing)
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RadClock - Unknown owner - C:\WINDOWS\system32\RadClock.exe (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - Unknown owner - C:\WINDOWS\wanmpsvc.exe (file missing)
O23 - Service: Windows Management Instrument Driver Includes (WMIDriverInc) - Unknown owner - C:\WINDOWS\wmiprvse.exe (file missing)
O23 - Service: WUSB54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe" "WUSB54Gv4.exe (file missing)

SmitFraudFix v2.137

Scan done at 12:25:31.46, Tue 01/30/2007
Run from C:\Documents and Settings\Cody\Desktop\New Folder\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\

C:\secure32.html FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\autosys.exe FOUND !
C:\WINDOWS\system32\ctpmon.exe FOUND !
C:\WINDOWS\system32\RegistryCleanerSetup.exe FOUND !
C:\WINDOWS\system32\zlbw.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Cody


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Cody\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»»


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32

huy32 detected, use a Rootkit scanner

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

Did you do any virus or spyware scans? That is a good place to start.Hi weezerguy187

I suggest you print this out to help you follow the instructions.

First … you cannot get this computer online but, for the moment, make sure it stays offline.

*****************

You have a suspect service running. We need to disable it.

To stop a service and set to 'disabled'

Go to Start > Run and type in Services.msc then click OK

Click the Extended tab

Scroll down until you find the service

O23 - Service: Windows Management Instrument Driver Includes (WMIDriverInc) - Unknown owner - C:\WINDOWS\wmiprvse.exe (file missing)

Click once on the service to highlight it

Click Stop

Right-Click on the service

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand SIDE on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The service is now stopped and disabled.

*****************

Go to a computer that can get online. Download and save the Spybot Search & Destroy program to a disk from here …..

http://www.safer-networking.org/

Take that disk and load it on to the infected computer.

Install it and scan the computer. Let Spybot fix anything it wants to.

*****************

You need to remove NewDotNet ….

Go to Add/Remove Programs. If you see any installed programs called NewDotNet, new.net (or similar names) then uninstall them.

You may notice a NewDotNet uninstaller. If so you can run that to assist with the uninstalling process.

*****************

Reboot the computer to safe mode by tapping the F8 key on start up and selecting “safe mode” from the list of options available. NOTE >> if F8 doesn’t get you to safe mode try tapping F5 instead.

*****************

Open HijackThis again … click on “scan” …. Put tick/check marks next to all the following entries IF they are still present …

O2 - BHO: (no name) - {1A31E9A2-72D9-BCC1-3DB8-0B9EC0657E30} - C:\WINDOWS\system32\unlsvce.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O20 - Winlogon Notify: Winmsc - ms3d2a43d1.dll (file missing)



If you do NOT have a restricted account on this computer then fix the following entry as well…..

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Make sure you close ALL open windows – including this one – before you click on “Fix Checked” at the foot of the HijackThis window.

*****************

Now find and delete these files and folder IF still present ….

C:\Program Files\NewDotNet …. folder
C:\WINDOWS\system32\unlsvce.dll …. file
C:\WINDOWS\SYSTEM32\instcat.dll …. file
ms3d2a43d1.dll …. file >> carry out a system-wide search for this file and delete it.

*****************

Now reboot to normal mode.

See if you can get online with the infected computer.

If you can you must make sure your antivirus and firewall are up it date and fully operational.

There is more to do even if you can get online now.

Please post back a fresh HijackThis log AND an update in how the computer is working now.


OJ
Hi weezerguy187 .... not heard anything back from you in several days. How's it going?

3412.

Solve : How to Disable Norton??

Answer»

Ok, I had some problems with my Norton and after reading some, I have now downloaded the AVG and the Avast antivirus programs. Now when I restart my computer it says that the Avast cannot run because Norton is still running... How in the heck do you disable Norton!?!?Make sure you uninstall it COMPLETELY, and if that doesn't work, go here: http://service1.symantec.com/support/tsgeninfo.nsf/docid/2005033108162039?Open&docid=2004030411260104





Edit: Oh, and if you have already subscribed for the year with norton, I wouldn't recommend dumping it for a free one just quite yet, atleast use it until your subscription runs out so you don't waste money. Quote

DLoad the tool below...

Norton Removal Tool


1) Use Add Remove Programs first and un-install Norton...
2) From Windows Explorer search for any folders named Norton and Symantec and delete them...
3) DLoad and install ERUNT and have it make a backup of your registry...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next INSTANCE of Norton. Continue til you have reached the end of the registry...
5) Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6) Now run the Norton Removal tool you DLoaded...
7) Empty the recycle bin...
Go to My Computer and right clik the C: drive and select PROPERTIES and run disk cleanup...
9) Re-boot and run disk defrag....

There you're done !

See how easy Symantec makes it for you to dump their product ? ?

patio. 8-)
Do I have to uninstall it? I wanted to keep it just in case.... just disable it. And if I uninstall it, can I get it back from my recovery disks?An uninstall would be preferable, and the program may still not install if it is only disabled. You would also have to disable it EVERY time the machine is started. If you have only "restore disks" from your computer maker I doubt you can get Norton back without a complete system restoration if it is unistalled.Quote
Do I have to uninstall it? I wanted to keep it just in case.... just disable it. And if I uninstall it, can I get it back from my recovery disks?

If you have AVG there is no need for Norton...kiss it goodbye and don't look back.Uhhh...Right click on the bottom right icon on Norton and click on the thing that says 'Disable active protection' or something or other....I don't have Norton any more, thank god. =]We just love specific information like this.Thanks all for your help. I uninstalled the Norton, and wow! Noone mentioned that it would actually speed up my computer! I love this site and all the great help! Yeah, the Norton VIRUS is a big memory hog. I could list grievances for hours.Yes indeed. Norton is known to be eat up resources.

Now you have removed it you should consider carefully the full range of protection. What follows assumes you don't have a hardware router/firewall/NAT.

First ...
Quote
I have now downloaded the AVG and the Avast antivirus programs
Make sure you only have ONE antivirus and ONE firewall operating at any one time otherwise you will likely get conflicts and problems.

Here are a couple of excellent guides to reliable, free protection. There is a little duplication but both are well worth reading .....

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html


Safe surfing.


OJQuote
Thanks all for your help. I uninstalled the Norton, and wow! Noone mentioned that it would actually speed up my computer! I love this site and all the great help!

I do this intentionally....makes it like Christmas ! !LOL! Really kinda was!
3413.

Solve : Whats the best anti-spyware? (freeware)?

Answer»

Quote from: fullbug on April 09, 2007, 01:24:48 PM

Quote from: soybean on April 09, 2007, 01:02:44 PM
I can't recommend Windows Defender and I know you won't find much encouragement in this forum to use it. .
I use Windows Defender and I honestly cant tell if it does a good job or not, when I scan it never finds anything, I would think that would be good but when I run AVG, ect. it always finds quite a few things.....
I don't know about you, but I'd say that's a pretty big indicator that it doesn't do a good job.Quote from: CBMatt on April 10, 2007, 03:26:14 AM

I don't know about you, but I'd say that's a pretty big indicator that it doesn't do a good job.
Yeah, I just got rid of it, if this forum doesnt endorse it its gotta suck....Quote from: Jonas Wauters on April 10, 2007, 02:57:52 AM
Yes I know that's the problem.
I uninsulated Defender and I installed AVG anti-spyware but this program will only work for 30 day's that's Wat's keep ignoring me.
Avria anti-virus didn't found any threats but AVG did find 4 threats.
I really don't know any thing Else.

Actually AVG AntiSpyware will automatically get updates for 30 DAYS. After that the user must get the updates manually. Unless SCANS are scheduled, they must manually be run on demand.

I also update and run SPYBOT and Ad-Aware weekly and neither has found anything in months. Does this mean they don't work or am I just incredibly well protected?

As for Windows Defender, I still update and run weekly. Microsoft has acknowledged that it is a piece of garbage and independent testing has proved it but I'm keeping for now just to be ready for when they get their act together.
Quote from: Sidewinder on April 10, 2007, 05:58:18 AM
As for Windows Defender, I still update and run weekly. Microsoft has acknowledged that it is a piece of garbage.
They did? That surprises me, Microsoft rarely admits anything unless it has to....The info on AVG is inaccurate...i run the AVG Free virus program and it gets updates at 4:00 AM and does a complete scan at 5:00 AM.
No user intervention is required at all.

Their other product which is called AVG Anti-Spyware(formerly Ewido ) is also free and will update itself as well...
After 30 days the "live" scanner which runs in the background expires but the program itself remains fully functional and is a solid ADDITION to the AVG Free program.

Hope this clarifies things...
3414.

Solve : Frigin Stupid annoying smitfraud-c thing!!!!?

Answer»

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"DAEMON Tools"="\"C:\\Program Files\\DAEMON Tools\\daemon.exe\" -lang 1033"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"D-Link AirPlus G"="C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"
"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"
"SiSPower"="Rundll32.exe SiSPower.dll,ModeAgent"
"SoundMan"="SOUNDMAN.EXE"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_08\\bin\\jusched.exe\""
"FlashGet"="C:\\Program Files\\FlashGet\\FlashGet.exe /min"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"VGAUtil"="C:\\Program Files\\GigaByte\\VGA Utility Manager\\G-VGA.exe"
"SpyHunter"="C:\\Program Files\\Enigma Software Group\\SpyHunter\\SpyHunter.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{b292ec9f-a074-4115-8342-1f459702d8d2}"="characterizing"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalServiceREG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkServiceREG_MULTI_SZ DnsCache\0\0
rpcssREG_MULTI_SZ RpcSs\0\0
imgsvcREG_MULTI_SZ StiSvc\0\0
termsvcsREG_MULTI_SZ TermService\0\0
HTTPFilterREG_MULTI_SZ HTTPFilter\0\0
DcomLaunchREG_MULTI_SZ DcomLaunch\0TermService\0\0
UsnsvcREG_MULTI_SZ usnsvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - The King.job
C:\WINDOWS\tasks\XoftSpySE.job
********************************************************************

catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-03-29 17:49:12
C:\ComboFix2.txt ... 07-03-29 16:42
ok i hope this helps because if it doesnt im screwed. YES!!!! I think i cleared it out!!!!!! i think it works!!!!!!! i ran hijackthis and i got the log after i think i fixed the problem..!!!! here it is!!! (what's with the karma being -2?)
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:07:36 PM, on 3/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\sistray.exe
C:\Documents and Settings\Prince Jimmy\Desktop\HiJackThis_v2.exeO2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\screenshot thing\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\DOWNLO~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VGAUtil] C:\Program Files\GigaByte\VGA Utility Manager\G-VGA.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1409082233-796845957-682003330-1006\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Prince Jimmy')
O4 - HKUS\S-1-5-21-1409082233-796845957-682003330-1006\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User 'Prince Jimmy')
O4 - HKUS\S-1-5-21-1409082233-796845957-682003330-1006\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe (User 'Prince Jimmy')
O4 - HKUS\S-1-5-21-1409082233-796845957-682003330-1006\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Prince Jimmy')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exeO8 - Extra context menu item: &DOWNLOAD All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Queen\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153509395491
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155653367343
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 10212 bytes
Hello Tai Sen

Looking good. Much better. However, a close examination of the logs reveals possible problems still lurking.

Print this out to help you follow the advice.


## 1.

Make sure you have exposed all Hidden Files & Folders.

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labelled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labelled Show hidden files and folders.
7. Remove the checkmark from the checkbox labelled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labelled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.

***********************

## 2.

The HijackThis log is clean except for one entry. Open HijackThis and fix this one entry …

O3 - Toolbar: (no name) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)

******************

## 3.

Delete files & folder below noted in BOLD if they are still present ….

Files….
>> C:\WINDOWS\system32\swxcacls.exe

>> C:\WINDOWS\Acount maker.exe

>> C:\WINDOWS\system32\fyxkaah.dll

>> C:\WINDOWS\system32\c03288fde6.sys

Folder …..
>> C:\Documents and Settings\Steve\Desktop\SmitfraudFix

******************

## 4.

Run Ccleaner to clean out your system INCLUDING your recycle bin. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you MUST untick/uncheck the relevant box on download) …

http://www.ccleaner.com/

******************

## 5.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
******************

## 6.
1.Download DAFT from the link below and save it to your desktop ….
http://techsupportforum.com/Deckard/daft.exe
2.Double-click the daft.exe icon. Read the disclaimer and click okay.
3.Click on the Scan button.
Hopefully you get the message back that all your files associations are OK.

If not .. post the results back here for fixing.


******************

## 7.

Lastly … your security.

I remarked that I didn’t think Norton Internet Security (NIS) was robust enough for your system. You replied that you had spyware doctor, AVG and Spybot.

You must be clear here …it is VITAL that you have up to date antivirus and a firewall on this system. From your logs it seems you are using NIS for this and the other programs to help protect you from other malware.

I strongly recommend that you download a different antivirus & firewall. I would suggest AVG Free antivirus (in addition to AVG Anti Spyware) and Zone Alarm or Sygate firewall.

Once downloaded you should install them both then IMMEDIATELY disable NIS at that point.

To remove NIS from your system completely use this tool …

http://service1.symantec.com/support/tsgeninfo.nsf/docid/2005033108162039?OpenDocument&seg=hm&lg=en&ct=us

You should also read through these tutorials to help you with other protection ….

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.

******************

When you have done all I advise please post a final HijackThis log and another update on how your computer is working now.

Please also let us know what happened when you used the DAFT tool.


OJ

PS Like you I don't know what the "karma" note is below our avatars. Also I see I am described as a "beginner". Hmm.....ok sry. i havent really had tome to do the things you told me to i was too busy doing projects ok. ill so those things soon and post a new hjt log. sry about the inactivity...
3415.

Solve : i need help with this message... what does it mean??

Answer»

ok basically i'm getting this message everytime i get on my computer...it appears when i log on... here it is

RTHDCPL.EXE - illegal system DLL Relocation
The system DLL user32.dll was relocated in memory. The application will not run properly. The relocation occured becuase the DLL
C:\WINDOWS\system32\HHCTRL.OCX occupied an address range reserved for windows system DLLs. The vendor SUPPLYING the DLL should be contacted for a new DLL.

I have no clue how this got here...i just logged out and logged back on and i have no clue what this MEANS so help me out.
nevermind disregard this last post i thought it might have been a virus, but it was just spyware in the memory so i fixed it It isn't gone yet. This is from a glitch in the latest MS update...

Travel Here for the correct fix.I have got the same message. So I went to a DLL download site or two - no trace of this HHCTRL.OCX one. This must be caused by an update (I think) and how can you contact your supplier when you haven't an idea of what the HHCTRL.OCX thing refers too??? I am not very great at this SORT of PC stuff...but will try to find out more...Quote from: JMM on April 06, 2007, 05:49:33 AM

I have got the same message. So I went to a DLL download site or two - no trace of this HHCTRL.OCX one. This must be caused by an update (I think) and how can you contact your supplier when you haven't an idea of what the HHCTRL.OCX thing refers too??? I am not very great at this sort of PC stuff...but will try to find out more...

See the post above yours for the fix...o i see...you're RIGHT, thank you cuz i wouldn't of figured that
3416.

Solve : MCAfee and Advanced Spy?

Answer»

I PURCHASED Advanced SPY www.advancedspy.net after reading all the great reviews and wonders about the program. Well, the program is great, however, Mcafee Anti virus detects it. Support recommend put this into exception LIST. But i don't know where it. Any suggestions?Hi theone

Are you SURE it's McAfee antivirus that detects it or is it your firewall?theone.........
Advanced Spy records [highlight]all e-mail's sent and received[/highlight], all [highlight]AOL, ICQ, Yahoo and MSN chat conversations[/highlight], all [highlight]web sites visited[/highlight], [highlight]every application executed[/highlight], all [highlight]text and[/highlight] [highlight]images sent to the clipboard[/highlight], [highlight]every keystroke pressed, every [/highlight][highlight]password typed[/highlight], and more! It can run in Total Stealth mode and send activity logs to your email and/or upload to ftp server.

I'm not at all surprised that it is seen as a potential threat ....... because it is exactly that ........ a threat to ones security if used for the wrong reasons ......

dl65

3417.

Solve : dllhost.exe?

Answer»

I've heard various things about dllhost.exe and it's causing me a bit of confusion. Basically, I want to know if it's a concern at all because I'd hate to have this on my computer if it's actually a virus or spyware of some sort. It's never come up in my virus scans as malware, but I'd still appreciate knowing if there's any threat or if there are any signs to look for or anything.

I'm also having a heck of a time trying to figure out what this new ~f39a36.tmp file is in my running processes is. I'm hoping it has to do with Black & White (which I've started playing) somehow.Quote from iutilities.com about dllhost.exe - Quote

dllhost.exe is a process belonging to Microsoft Windows Operating System. The dllhost.exe file manages DLL based applications. This program is important for the stable and secure running of your computer and should not be terminated.
So it sounds like it's not a virus.
Do you have problems running games?
As for your other problem, read this.
It may enlighten you a little as to what the process is and why it's there.
Hope this helps.Hi CBMatt, Calum

CBMatt ... like Calum says the dllhost.exe is VITAL to the sucessful operation of your system. Don't disturb it.

The other file ~f39a36.tmp is nothing to worry about and is only temporary in nature. I agree it will most likely run when you load something like Black & White.

However, if you want to make sure all temporary FILES etc. are removed, or you just want to give your computer a good "spring clean", use AVG AntiSpyware for free.

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].



Calum ... that link you posted to daemon-tools.cc .... that site is coming up rather dubious. Site Advisor tells me that "Feedback from credible users suggests that downloads on this site may contain what some people would consider adware, spyware, or other unwanted programs" so be careful if you decide to d/l anything from there. I wouldn't.


OJOr use CCleaner to clean your temp files.
Use this guide to set it before use.
Just make sure that you set it not to clean any COOKIES that you want to keep, or you'll have to log into any sites that you log into, like this one, again.
The link I posted suggests that the temp file will run under certain circumstances, like when you attempt to run certain copy protected games under a virtual CD drive.
And I didn't know it was dodgy, sorry.
I wasn't going to download anything from it, but anyone thinking of it, take note.
I don't have SiteAdvisor as the one time I tried to use it it crashed my Firefox.
I'm careful anyway so I don't see a need for it (for me).
Anyway, looking at the SiteAdvisor report, all the downloads submitted came p clean according to McAfee.
So it doesn't seem to me that it's a problem anyway.Thanks, guys. The file's been on my computer for awhile, I believe, and I figured it was safe, but a few people on various sites had said otherwise, so I just wanted to make sure (I've been pretty cautious about malware lately). And to me, this is the most OBVIOUS PLACE to ask.

As for the other file...since posting, I've completely uninstalled Black & White. I accidentally did irreversable damage to my savegame file thanks to a very poorly-coded utility program. The whole thing was giving me a headache, so I just got rid of the darn game. Since then, that file hasn't shown up, so I have to assume it went along with the game. Just to be safe, I deleted the temp file and did a scan with AVG. I think I'm in the clear.

Thanks for the insight!Quote
And I didn't know it was dodgy, sorry.
No need to apologise for anything. I was just highlighting something Site Advisor told me, that's all.

Glad it's all OK with you, CBMatt. You can still use AVG Anti Spyware anyway. It's an excellent free scanner/cleaner. Ccleaner is good too but AVG AS scans deeper.
3418.

Solve : I think im infected?

Answer»

As soybean indicates there is nothing wrong with iexplore.exe. BC's startup programs database simply indicates programs that (as BC remarks) "... should not appear in Msconfig/Startup unless you add [them] manually!". They are not necessarily bad.

As unlovedwarrior mentions that file is dubious. Again, not necessarily causing the trouble you have but please go to this site ....

http://www.virustotal.com/en/indexf.html

Browse to this file on your system ...

C:\WINDOWS\system32\dllhost.exe

...and upload it to Virustotal for checking.

Post back the results here.


You said the bad file was spelt "Iexploere.exe" which indicates you have an infection as this is not the correct spelling of the legit file. You must be careful to post the correct spelling when reporting errors.

The log does not show any dreadful infections although this may be because you are starting the computer in selective startup mode. This means some running processes may not be visible. Please go to your msconfig and ensure all items are ENABLED at startup. This will give a clearer picture of what's occurring on your computer.

Couple of things about the log entries.

Trusted zone
You have two entries in this zone. It's your choice but my advice is never to have anything in permanently that zone. It's just too dangerous.

If you want to remove them then open HJT again ... click on scan ... put tick/check marks next to all 015 entries ... close ALL open browser windows (including this one) ... click "Fix Checked" at the foot of the HJT window.

The entries will the be gone.


Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please FOLLOW these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License AGREEMENT".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.
Reboot your computer to normal mode and use it as you usually do.

If this doesn't fix things post a fresh HJT log in full startup mode and give us an update on what's still not right.


OJthank you for the great response guys, looks like ive got some work to do. Ill post back when i've tried some of those things.oh and patio- no, i dont need both Norton and AVG. In fact, i didnt know Norton was still running. I thought i took it off but aparantly it's not that easy.http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039

removal toolDLoad the tool below...

Norton Removal Tool

Do not run it yet.

1) DLoad and install ERUNT and have it make a backup of your registry...
2) Use Add Remove Programs first and un-install Norton...
3) From Windows Explorer search for any folders named Norton and Symantec and delete them...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next instance of Norton. Continue til you have reached the end of the registry...
5) Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6) Now run the Norton Removal tool you DLoaded...
7) Empty the recycle bin...
Go to My Computer and right clik the C: drive and select Properties and run disk cleanup...
9) Re-boot and run disk defrag....

There you're done !



patio. For anyone who may be interested this is another good source of information on startup programs ...

http://www.sysinfo.org/startuplist.php


OJi ran the bootup with all files allowed to ron from msconfig. should i run it like that all the time? cuz theres certain programs like quiktime and stuff that i would rather not have at startup. Anyway, here is the HJT after that and all of the other suggestions


Logfile of HijackThis v1.99.1
Scan saved at 9:34:47 AM, on 4/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\Bacteria\Protections\medmanHijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://crossfit.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138591397\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0c\AOL.EXE" -b
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Canon CAMERA Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I'm not an experienced HijackThis analyzer but, while looking at some of your log, this item seems to be a suspicious one: yt.dllvirustotal came up with no threats on dllhost.exe

heres the link to it, i tried to post a pic but it didnt go thru..whatever:

http://www.virustotal.com/vt/en/resultadof?44ceb017762f293cc4bc301d1c7dab47As to the startup items you can DLoad a great little app from Mike Lin called Startup CPL which resides in the Control Panel...

Gives you full control on what loads up and what doesn't.Log is much improved.

That yt.dll is OK. It's part of the Yahoo! Companion and I see that the dllhost.exe file came up clean at Virustotal.

Just one thing in the log. Open HJT and fix this one ...

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Now run a system search and find the file(s) ... ALCMTR.EXE. Delete it/them.

Empty your recycle bin.


Make sure your java, antivirus, firewall and other protection programs stay fully up to date.


How is you computer operating now? Can Adaware now full scan?

Note that there is currently an issue with Adaware. It won't always update properly. If you experience this problem just bear with it and keep trying the update. Also keep looking at comments on the Lavasoft site & forums on that. They are hoping to clear it up soon.


OJ

well the messages about FAT32 and such have left, norton is officiall gone, and my java software has now been updated. Things seem to be going a bit better, however Adaware SE still isnt running properly but ill check in with their website about those problems. Also, internet has been running waaayyyy slow after all of this. I use Opera mostly but have Firefox as well and they both are slowing down.
I dunno if theres any suggestions about that, but either way, thank you all for the huge help with this.This can also relate to your internet connection...what type of service do you have ? ?Ive got comcast cable. THe problem seems to come and go. I thought it might have a little to do with the fact that i just cleared ALL of my cache, but i didnt think it would effect it this much. SOmetimes my Opera browser even "encounters an error" and must close. Firefox has never done that yet. Today, however, seems to be running fine right now (im on Opera).it could just be your provider is having problems or the stregnthen of the connection is getting weaker because you might be using it during the peak hours ... when does this happen?
3419.

Solve : Unable to virus scan....Pls HELP!!!!!?

Answer»

Oh, one more question. At the moment on my computer I have various security running (as per your instructions). Do I need to turn any of these off?
- AVG AntiSpyware 7.5
- ZoneAlarm
- SuperAntiSpyware
- TrojanHunter Guard
- AVG Free Edition (antivirus)

Thanks again.Hi

No don't turn off any of these at the moment. They are all good and won't conflict with each other.

The reports did find things. One bad file was removed and another suspicious one highlighted.

**************

Make sure you still have Hidden Files & Folders exposed.

**************

The Norton removal tool is at the link below. Be careful to read the warning about which versions of Norton it removes and also bear in mind the tool will REMOVE "everything Norton". So ... if you have another Norton product you want to keep you will have to reinstall it after using this tool .....

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2005033108162039?Open&src=&docid=2001092114452606&nsf=nav.nsf&view=pfdocs&dtype=&prod=&ver=&osv=&osv_lvl=

**************

Go to Start > Run and type "REGEDIT" in the dialogue box (WITHOUT the quote MARKS). Click OK.

Click on Edit > Find and type "lolla" in the box (again without the quote marks).

Make sure all the three little boxes below "Look at" are ticked/checked.

Click Find next and report back where the lolla files are located.

**************

Go to this site ...

http://www.virustotal.com/en/indexf.html

Browse to this file on your computer and upload it for scanning....

C:\WINDOWS\system32\bn.dll

Post back the results.

**************

PLEASE can you update me on how your computer is operating now.

What problems are you still having?

There maybe a rootkit at work here so we may need to dig deeper.


OJHi there,
SORRY about the delay. I broke the wireless on that laptop and am trying to find my cable. I did not give up or forget. Hopefully ièll find it soon and be able to continue with the reperation.
Tks
78ap

3420.

Solve : firewall has been turned off?

Answer»

I have a desktop computer running XP home service pack 2. I have just switched over to an adsl line with always on internet connection.
When I started the computer this morning I received a message saying my firewall was not turned on. I have not changed any settings myself. When I try to turn firewall back on windows says it cannot turn it on and suggests I do it manually via control panel and network and internet connections. This produces the following " windows firewall settings cannot be DISPLAYED because the associated service is not running. Do you want to start the Windows Firewall/Internet connection service?" Clicking yes produces " Windows cannot start the windows firewall/ internet connection service" I have done two system restores but no joy there.


Any ideas out there?
What firewall ? ?Hi Patio,

I have the windows (sp2) firewall. I have AVG free edition anti virus and the daily scan says no virus found. I have RUN AD aware and removed the usual batch of tracking cookies. Belarus informs me that all microsoft updates are in place. AVG and ad aware are up tp date.From the Mothership

patio. 8-)Hi Patio,

the mothership is not helping on this one which is why i posted here. my security centre informs me that the firewall is off. clicking the enable button produces message windows cannot turn firewall on, do it yourself using the control panel. trying that produces the error message detailed in my first post.Actually, as software firewalls go, I think most poeple here would agree that the Windoze built-in firewall isn't that good.

You would be better off getting a decent free firewall elsewhere. Zone Alarm and Sygate are my favourites. Here are the links with a few other choices .........

Zone Alarm > http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?dc=12bms&ctry=US&lang=en&lid=nav_za

Sygate > http://www.simtel.net/product.download.mirrors.php?id=53687

Kerio Firewall > http://www.sunbelt-software.com/Kerio.cfm

Agnitum > http://www.agnitum.com/products/outpost/

m0n0wall > http://m0n0.ch/wall/
(I’ve heard good things about monowall but it takes some setting up, I believe)

Smoothwall > http://www.smoothwall.org/

Tiny Personal > http://www.webmasterfree.com/tpfw.html

Outpost > http://www.agnitum.com/products/outpostfree/download.php

[Footnote to whoever redas this … the Norman Personal Firewall LOOKS like it isn’t compatible with vista but this may change.]


OJ
oddjob, what about Jetico ? ? Lightweight and effective.

Found it about 3 months ago.Agreed. Jetico is OK too.There are others. My list was only meant to be a selection, not comprehensive, but I guess you know that


OJ

3421.

Solve : Norton Vs Free Software??

Answer»

Hey guys,

I was TOLD just a couple days ago by Calum and unlovedwarrior about software that can compare to Norton or even be better, that avoids the fee of money. I've become interested in looking into these programs, so links and information would be appreciated.

Thanks,
Mike

AVG Free and Avast are 2 of the better ones.I personally RUN AVG here on all the computers and find it to be a great solution although not free in my case (multiple computers and commercial). Although if you're running it at home on a single computer definitely worth trying.

http://free.grisoft.com/doc/1Thanks! Ill make sure to check it out Quote

Hey guys,

I was told just a couple days ago by Calum and [highlight]unlovedwarrior[/highlight] about software that can compare to Norton or even be better, that avoids the fee of money. I've become interested in looking into these programs, so links and information would be appreciated.

Thanks,
Mike



hi i use avg

i was WORKING on reformating a pre sp2 computer w/ dail up on friday and they only had the macfee that came with AOL.

63 updates before sp2
then 100 + after
all =
fun for me thankfully i had my computer hooked up the other monitor

unlovedwarriorI have tried Norton, AVG , and Avast
I love Avast because its very light on resources and provides an excelent resident shield:

myavast.110mb.com
And as far as free goes you should add these to your package as well

Spybot
AdAware
AVG Anti-Spyware (formerly Ewido ).

I'm CURRENTLY testing jetico....a free firewall and will be posting a review here shortly.Avesta and AVG free dont alway protect you to be safe use both of them but let one of them auto protectI personally don't think it's necessary nor advisable to be running two (or more) different anti-virus scanners on one computer.I agree...one or the other.I urge you to try AVG Anti-Virus Free Edition 7.5. Not only is it absolutely free, but it does a much better job than Norton, in my opinion. I dropped Norton last year because my budget couldn't stand the $39.95 subscription fee. AVG runs like a dream and automatically updates itself on a daily basis. My system runs much smoother now because AVG REQUIRES much less space than Norton. Give it a try at the following link...



jandal

3422.

Solve : More Ad-Aware agro!?

Answer» ALTHOUGH I still can't update Ad-Aware by clicking on update in the program (It just brings up "Error updating") last time I was able to do it manually thanks to help given on this site. I have just tried to install the latest update, but now it asks me for a password (which I do not have) before it will unzip into the Ad-Aware program. I have REREAD the instructions, but as far as I can see am following them to the letter! Any suggestions please?My immediate suggestion is only the obvious one, I'm afraid .... you should try completely UNinstalling the program, reboot your PC then download/install a fresh copy.

Hope this works but, if not, other suggestions will follow. If not from me then from other members.


OJThanks Oddjob. I have tried this before, but will give it another try.It seems I am not the only one having problems with Ad-Aware. I found (eventually) the below on the Lavasoft site. I am taking the easy option and depending on SpyBot and A-Squared to find what Ad-Aware would have, and start reusing it again when they sort out the update problem.

From Lavasoft:-

We are currently experiencing problems with our definition file updating SERVICE for customers using certain Internet Service Providers (EARTHLINK, for example).
The problem produces the Ad-Aware SE warning: "Error retrieving updates" when performing a webupdate. It interrupts at 5% download completion .
(If your update stalls at another point than at 5 %, your problem stems from another issue.
See http://www.lavasoftsupport.com/index.php?showtopic=1336 )

The update problems are a result of expired DNS records for our previous definition update servers. Now, some Internet Service Providers DNS servers are routing erroneous domain requests to a custom webpage, rather than to the standard The domain you requested could not be found 404 error page. This stops our updating service from functioning .

We are currently resolving to fix this problem and have contacted the ISP:s in question.

As a temporary solution, you can reconfigure your DNS settings.

Check with your ISP (website FAQ:s or support) and find out if they provide any alternative DNS server addresses and instructions how to configure this.
(If you are using a router, you may need to change the DNS settings on the router.)

If you use Earthlink as ISP (or Earthlink owned ISP:s) you can try this solution (provided by Earthlink) for working your way around the problem:
http://kb.earthlink.net/case.asp?article=187117

There is a few 'Related ARTICLES' at the bottom of the webpage, how to manually specify DNS information, for various operative systems and ADSL modems.

The following link includes a list of other Earthlink owned domains.
http://kb.earthlink.net/case.asp?article=28968

Thank you for your patience as we endeavor to solve this web update issueWe thanks for that. Now we know.

Let us know how it goes.

Good luck.


OJ

Well done pantherman good Karma to you.
3423.

Solve : Port Scanning?

Answer»

I'm new to this forum, occationally I will get an alert certain ports are being scanned by IANA. I want to know if they are collecting information and if it would hurt anythig if I attempt to BLOCK there access?LCRJR... This would be your firewall giving you these alerts I'm guessing. Are you being asked to ALLOW access ?

dl65 Yes it my sygate firewall alerting me I'm being scanned. I backtrace the source to the internet numbers authority, I have the option to stop all actions, and can possibly block that IP from access but I don't know if it's nessisary or if it would interfere with my computer operation or internet access?Hey, I had sygate a little bit ago. But I found something alot better. It's called COMODO Firewall pro.

It's alot better then sygate...I've had sygate for ages, and tried many other products (like macafee, zonealarm etc.) and this is by FAR the best one i've had.


I would recommend downloading this...It's a good product, but anyway...

Port Scanning is usually triggered by games in my case, I PLAY alot of CSS and such, and I get port scanned from the same ip almost every time I start up my CounterStrike: Source, because it needs to know if your ports are AVAILABLE to use for the game...Or theres a small chance that it's a hacker and they are scanning your computer for open ports to start an attack...

Also, if you have trouble with doing something, or a port is blocked, you should try port forwarding...


3424.

Solve : adclicker and vundo Trojan can not clean?

Answer»

hi All,
So I have had the fortune of receiving a virus/trojan. I have tried several times tthe computer in safe mode, but to no avail. So I am here as a last ditch to save myself from doing a clean install.
System: SONY VAIO.
OS: Windows Xp Edition

Here is my log file. I hope someone can help.

Logfile of HijackThis v1.99.1
Scan saved at 3:56:36 PM, on 2/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRAM Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLSDBNT.EXE
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$PROPHETSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\PROGRA~1\ALLUME~1\StuffIt\MXTask.exe
C:\PROGRA~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPSP.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\WFXSVC.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinFax\WFXMOD32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Dell Printers\Additional Color Laser Software\Status Monitor\DLPWDNT.EXE
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\PROGRA~1\ALLUME~1\StuffIt\mxtask.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Ismael Carlo\Desktop\Temp\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,START Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AOLSearchHook CLASS - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AOL\AOL Search Enhancement\AOLSearch.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Merriam-Webster Online - {B7B76DD6-B6F0-4443-AF81-6A3ECF12A57D} - C:\WINDOWS\_MWOLTB.0.DLL
O3 - Toolbar: (no name) - {74DD705D-6834-439C-A735-A6DBE2677452} - (no file)
O4 - HKLM\..\Run: [IgfxTray] C:\WIsnooker910.... You have only a portion of the hijackthis log ...... the last entry should be a item #023 ........ just copy the rest from where you left off and put it in a separate post . You might also tell us what scanners you used and if you did it from safe mode and was the system restore turned off ?

DL65

3425.

Solve : Mail server timer?

Answer»

Well, I see why I couldn't find it. The PROPERTIES button in my E-Mail Scanner panel is greyed out. Any idea why?Soybean what version ? ?
I currently have 7.5.446...
Is the plugin bar on the same tab DISABLED ?Arlene, are you still having problems browsing the internet?
Did you run the two online scans I posted?
(Note, the AVG online scan is NOT an antivirus scan so don't get confused between AVG antivirus & AVG ANTISPYWARE... formerly known as Ewido).
A HJT LOG will tell us what's running on your computer (good & bad stuff) so we don't have to guess.
Email timing out & websites timing out is very indicative of malware.I have thunderbird mail. I have email spam checked for checking for scams. I have created a filter a MILE long. Every day I get approx 50 emails advertising pharmaceuticals for *censored* etc. or emails with *censored* content. In AVG I have my email spam fully functional and the port set at 10100. I

3426.

Solve : my mouse freezes at about 8.45am everyday...help!!!?

Answer»

Hope someone out there can help me. My mouse STARTS becoming unusable at around the same time EVERY morning and continues to malfuntion for about an hour. I am able to move it vertically up and down but that is it. I am all new to maintaing a computer and would appreciate any kind help out there. THANKS John See if it happens in safe mode?okay i will TRY tommorrow ....thanks
I suspect a scheduled background task such as your e-mail client phoning home or your Anti-virus running it's daily scan...

If not it's probably the lady next door blow drying her hair and getting ready for work.And just for the heck of it, you might want to try using a different mouse to see if the same thing happens.I was expecting another COL for the month of March...To be perfectly honest, I thought of it as an actual possible problem. Ha. But if it's any consolation, I did smirk.Good enough...This thread is being LOCKED, as the poster has 2 other threads going with the same issue.


dl65

3427.

Solve : Can someone please analysise?

Answer»

Hey there guys. I know there's alot of bad stuff in here (for example the Starsearch) and ive managed to clean up most of it, but i just want some help if at all possible. Thanks!

Chris

P.S Its not my laptop, would never let it get in this state.

Logfile of HijackThis v1.99.1
Scan saved at 19:54:38, on 07/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\DOCUME~1\WILLIA~1\LOCALS~1\Temp\2005817165617_mcinfo.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MESSENGER\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\William Edward\My Documents\hijackthis(2)\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.official-linerider.com/play.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcD+LDHhd+DajEYqju22UFQ0Lvznq3UYfw2T03BLp+xy5IywFw7A8tpsRJtvp3PInSb3Nlk05cwEgU3MThP6iFEgN1bCa8tHGoT6iKF4/mxcl1dex3JOCg81kRI/SqvD0d7ynuHeRUZSmdqbziFwcsECYbWtspJBUHta0PXirW+pxiFTJXpY/63pb9Bk6XzO+w2
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
R3 - URLSearchHook: ScriptInocUI Class - - (no file)
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL
O2 - BHO: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - C:\PROGRA~1\MINICL~2\MINICL~1.DLL (file missing)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - C:\PROGRA~1\MINICL~2\MINICL~1.DLL (file missing)
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\WILLIA~1\LOCALS~1\Temp\2005817165617_mcinfo.exe /insfin
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe
O4 - HKLM\..\Run: [My WEB Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\3.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk615AXGB
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0.0.15.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O16 - DPF: {EF98AF7B-1F54-4079-91BC-3996DEABA45A} (Sinstaller Class) - http://www.cursorcafe.com/app_cc/bin/cursorcafe.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACEB3280-7076-4C46-BC64-E18C7304D739}: NameServer = 158.43.240.4,158.43.240.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB9C4BCB-7B10-492E-9110-BA55E38F10ED}: NameServer = 158.43.240.4,158.43.240.3
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

chriscool9...... First ..... Run ccleaner ......... Get it at .......
http://www.filehippo.com/download_ccleaner/ ....... Install it , but do not install the yahoo toolbar...........
Run it ( cleaner part) and remove all that is found ........
Run it again using the "Issues part " make sure to backup when asked and then fix anything found ..........
Then using Hijackthis .........
Mark for remove the following :

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcD+LDHhd+DajEYq ju22UFQ0Lvznq3UYfw2T03BLp+xy5IywFw7A8tpsRJtvp3PInSb3Nlk05cwEgU3MThP6iFEgN1bCa8tH GoT6iKF4/mxcl1dex3JOCg81kRI/SqvD0d7ynuHeRUZSmdqbziFwcsECYbWtspJBUHta0PXirW+pxiFT JXpY/63pb9Bk6XzO+w2

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL

R3 - URLSearchHook: ScriptInocUI Class - - (no file)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\3.bin\MWSBAR.DLL

O2 - BHO: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - C:\PROGRA~1\MINICL~2\MINICL~1.DLL (file missing

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O3 - Toolbar: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - C:\PROGRA~1\MINICL~2\MINICL~1.DLL (file missing)

O4 - HKLM\..\Run: [msci] C:\DOCUME~1\WILLIA~1\LOCALS~1\Temp\2005817165617_mcinfo.exe /insfin

O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\3.bin\MWSBAR.DLL,S

O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk615AXGB

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/ZwinkyInitialSetup1.0 .0.15.cab

O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/supergerball/miniclipGameLoader.dll

O16 - DPF: {3A7FE611-1994-4EF1-A09F-99456752289D} (WildTangent Active Launcher) - http://install.wildtangent.com/ActiveLauncher/ActiveLauncher.cab

O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab

O16 - DPF: {EF98AF7B-1F54-4079-91BC-3996DEABA45A} (Sinstaller Class) - http://www.cursorcafe.com/app_cc/bin/cursorcafe.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{ACEB3280-7076-4C46-BC64-E18C7304D739}: NameServer = 158.43.240.4,158.43.240.3 ........ [highlight]If this is not a know and trusted site ...... do it as well[/highlight]

O17 - HKLM\System\CCS\Services\Tcpip\..\{EB9C4BCB-7B10-492E-9110-BA55E38F10ED}: NameServer =158.43.240.4,158.43.240.3
[highlight]If this is not a trusted site do it as well [/highlight]

Ok .... now click ...fix checked and then rerun hijackthis and lets see whats still there ...as there will be other entries to remove.

dl65

WOW thanks for the really fast reply!!
Ok well ill have to do it tommorow as ive left their house now. Ill do that tommorow and post the results.
Thanks!

Chris

P.S Feel free to just call me Chris instead of Chriscool9Newest log:

Logfile of HijackThis v1.99.1
Scan saved at 18:20:35, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Documents and Settings\William Edward\My Documents\hijackthis(2)\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.official-linerider.com/play.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcD+LDHhd+DajEYqju22UFQ0Lvznq3UYfw2T03BLp+xy5IywFw7A8tpsRJtvp3PInSb3Nlk05cwEgU3MThP6iFEgN1bCa8tHGoT6iKF4/mxcl1dex3JOCg81kRI/SqvD0d7ynuHeRUZSmdqbziFwcsECYbWtspJBUHta0PXirW+pxiFTJXpY/63pb9Bk6XzO+w2
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.euro.dell.com/
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACEB3280-7076-4C46-BC64-E18C7304D739}: NameServer = 158.43.240.4,158.43.240.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{EB9C4BCB-7B10-492E-9110-BA55E38F10ED}: NameServer = 158.43.240.4,158.43.240.3
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Belkin 54g Wireless USB Network Adapter (Belkin 54g Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Iap - Dell Inc - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Thanks alot!
Chris

P.S Just realised i spelt Analyise wrong
Hi Chris....... The LAST log is looking better , but there is still several things which need attention......

1.... [highlight]The java is outdated [/highlight]..... Please go and get the latest version...... http://www.java.com/en/download/index.jsp
the latest version is V5 update 11

2.... Now lets see if we can get rid of ..... starsearch .......
I have located a automated removal tool...... at....
http://www.spywareremove.com/removeStarware.html scroll down until you see the link to... Remove "Starware" Automatically:
[highlight]Download Starware removal software[/highlight]. its about 3.1mgs ....... run it .

3... Now just to be sure things are ok, reboot into [highlight]safe mode[/highlight] and run the Anti virus again , and then AVG antispyware 7.5 Remove anything found.

4....When these scans are complete reboot back into normal and do what should be hopefully the last hijackthis scan.


dl65
Quote

P.S Just realised i spelt Analyise wrong

It's OK Chris...we can analysise with the best of them. Chris ... when you post back a new HJT log for dl65 can you also please let him know how your computer is working now. Is it any better? Do you still have problems?


OJHey there, ok so yea the P.C is running ALOT better now. But DL65 i didint install that starware remover because there were many negative reviews on it. The 'Starware Automatic Cleaner' was SpyHunter.
Any other suggestions?
Thanks

ChrisChris , Glad to hear it's running better , however when you did the rescan with AVG and AVGASW in safe mode , was anything detected ?
As far as the automated remover ...... yes its Spyhunter ........ it will however ,point to the locations that the infection is in , but it will not remove it .........( they want you to purchase it ) Are you up for doing a manual removal of it ?
Did you update the java ?
You havent posted a current hijackthis log as requested .


dl65


3428.

Solve : Please Advise?

Answer»

Could somebody have a look at my log
Sometimes i have problem with text size Windows XP pro
When i boot up text size goes to Largest.
Logfile of HijackThis v1.99.1
Scan saved at 11:58:40, on 17/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\PROGRAM files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MPFSERVICE.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\SiteAdvisor\4608\SAService.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PCPal\PalAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MpfAgent.exe
C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Windows XP\Desktop\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mk:@MSITStore:C:\WINDOWS\Help\iexplore.chm::/iegetsrt.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~3\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PCPal] "C:\Program Files\PCPal\PalAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZC
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?b501759d484243658a89ec919c719df2
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?b501759d484243658a89ec919c719df2
O9 - Extra BUTTON: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148656698371
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{890127C2-FEDA-4043-8CB7-32FC1D2C5C83}: NameServer = 212.139.132.53 212.139.132.52
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~3\MPFSERVICE.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4608\SAService.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe
Thank you ivanoeHello ivanoe

Your text size problem isn't anything to do with what's in the log. The log is not that bad. Pretty clean actually.

Just a couple of things to tidy up.


1. >> Open HJT ... click on scan ... put tick/check marks next to these entries IF they are still present ...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R3 - URLSearchHook: (no name) - - (no file)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)

O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)


Close ALL open browser windows - including this one - then click on "Fix Checked" at the foot of the HJT window.

2. >> You have the java v5, update 11, but v6 is faster & newer. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
Please try your text issue again after this.

Post a new HJT log with an update on how the computer is behaving now.


OJthanks oddjob i did all that removed what you advised.can't tell if it's done anything ,
not clever enough but i'm sure it as.once again comp/hope to the rescue.thanks.

ivanoe.No problem.

How's the text issue? Any better?

Please post a fresh HJT log so we can check if all is clear from that point of view.


OJLike oddjob says, nothing in your log should be affecting your text. Try taking this problem over to the Windows board and see what everyone has to say about it. I hope you get it resolved.text size seems tobe ok now
heres the log file you ASK for
Logfile of HijackThis v1.99.1
Scan saved at 10:58:22, on 31/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MPFSERVICE.exe
C:\Program Files\SiteAdvisor\4608\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\keyhook.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\PCPal\PalAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\PROGRA~1\McAfee.com\PERSON~3\MpfAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\DOCUME~1\WINDOW~1\LOCALS~1\Temp\Temporary Directory 8 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~3\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\4608\SiteAdv.exe
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PCPal] "C:\Program Files\PCPal\PalAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM [emailprotected] 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZC
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?b501759d484243658a89ec919c719df2
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?b501759d484243658a89ec919c719df2O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.0.0971.42/WinSSWebAgent.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1148656698371
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{890127C2-FEDA-4043-8CB7-32FC1D2C5C83}: NameServer = 212.139.132.53 212.139.132.52
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\4608\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~3\MPFSERVICE.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe (file missing)
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\4608\SAService.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Program Files\WinClamAVShield\sp_clamsrv.exe

and thanks for you help oddjob and cbmattivanoe, after reading this thread, I'm still wondering exactly what was your problem? Exactly what text was larger than normal? The text in applications such word processing? In your web browser? The labels of icons on your desktop? All of your Windows menus and panels?

And, how did you correct it, before supposedly resolving it here in the forum? I'm assuming you did something to correct it after turning on your computer, as implied in your comments? What did you do?SOYBEAN .to answer your question i dont know how.( it went right. itself )
i clicked on view then text, and clicked medium,but everytime i switched back on,
it had gone back to large text,i did this several times ,then one time it stayed on
medium.no more problem.OK, thanks for the reply. By the way, in case you're not aware of it, holding the Ctrl key while turning the mouse WHEEL will change text size in a browser. And, that can happen by accident if you happen to unknowingly touch the Ctrl key and move the mouse wheel at the same time.
3429.

Solve : Beware Valentine day "emails" ...?

Answer»


Security EXPERTS are warning PC users to be on GUARD against viruses masquerading as Valentine's Day messages, which could damage computers.

"Computer users should keep a wary eye on any romantic messages received by e-mail, as many of them[highlight] could contain malicious code[/highlight]," said US security firm PandaLabs after detecting an increase in a worm it dubbed Nurech.A.

[highlight]The worm hides in e-mails with subjects like: "Together You and I," "Til the End of Time Heart of Mine."[/highlight]

PEOPLE who open an attached file such as postcard.exe can end up infecting their computers.

Security firm Symantec said it had detected "large-scale spamming" of e-mails including a Trojan horse, a program that contains or installs a malicious program.

Symantec said the malware was a new version of Trojan, Peacomm or the "Storm Trojan."

"With Valentine's Day approaching, this time around the authors are attempting to tug on the heartstrings of unsuspecting users with romantic subject lines such as 'My Heart belongs to you,' said Symantec's Orla Cox.

"The Trojan is much the same as we've seen before, the only difference being that the authors have used a modified packer in an (unsuccessful) effort to evade detection by antivirus vendors."

"As a general rule, don't open any suspicious e-mail, regardless of what is says it contains," said Luis Corrons, technical director of PandaLabs.

"Instead of GOING on instincts, let a security solution decide whether it's safe to open it or not," he said, urging users to scan any suspicious messages with an antivirus program.

Corrons said events like Valentine's Day and Christmas are often exploited by cyber-criminals to try and spread their creations by disguising infected e-mails as e-greeting cards.

This use of "social engineering" was used in the LoveLetter virus, which caused one of the biggest epidemics in computer history.

Too many viruses . . .
It's pathetic: a)that people have time to sit and write these things and have NOTHING better to do, and b) the amount of people that open these emails, ignoring common sense and all basic security rules.
They just don't pay attention to anything they're told or that they hear, and then wonder why they get infected.Thanks for the heads-up, honvetops.will see how many ppl come to us around v-day for helpQuote
Too many viruses . . .
It's pathetic: a)that people have time to sit and write these things and have nothing better to do, and b)[highlight] the amount of people that open these emails, ignoring common sense[/highlight] and all basic security rules.
They just don't pay attention to anything they're told or that they hear, and then wonder why they get infected.

I agree 100% but; there are still a large percentage of older (above55) internet users and others- who don't even know what virus protection is. I have spoken to 2 at work and even my dad a few months back who were totally "clueless" to the threat. As redundant as these warnings get, they still do serve a purpose to the uneducated*
This just adds to my theorem that one should automatically delete unsolicited email from anyone. (At least, the ones with attachments.) I remember the paranoia that even opening an email could destroy a PC -- pathetic.Quote
Thanks for the heads-up, honvetops.

agreed...

8-)fffreakOnce again lots of info ...no links.
Quote
Once again lots of info ..[highlight].no links.[/highlight]



http://p231.news.mud.yahoo.com/s/afp/20070209/od_afp/afplifestyleusinternet_070209230449
3430.

Solve : mouse problems..has someone got control of my computer??

Answer»

well, i BOUGHT a new mousse tosee if i had a hardware problem. Beofre with my new mouse, every MORNING at about 9.a.m, my mousse would become UNUSABLE by giving me vertical movement only. This would last about an hour before returning to USUAL. However, now, my new mousse jumps around all over the screen at any time of the DAY. I would say I have about 85% functional use of it now...The rest of the time it jumps around. I have yet to see if I will loose use of it tommorrow morn at 9.a.m. Help anyone! I am not very computer literate but I am tryibng to learn!! Help!!
No need to double post.

3431.

Solve : Norton Anti-Virus?

Answer»

I got norton Anti-Virus free with my computer but found it to be rather useless. So I got AVG and was much happier with it. But I have a friend of mine which THINKS Norton is great. Is there different versions or am I just missing something?IMHO you are missing all the headaches that Norton will give your friend. But then I'm an AVG Free fan But is it any less useful in finding viruses?I think so. In my short experience, AVG tends to find more than other virus scanners. But that may just be me.If your friend thinks Norton is great just agree with him...the "which is best" discussion gets beaten to death from TIME to time.

patio. 8-)i dont like norton CUZ when you final go to get rid of it its like a virus its self you have to get a special program to get rid of it. AVG is not a resource hog like norton is and it like \s to scan in safe mode better than norton


unlovedwarriorIn my experience, Norton's incoming firewall (blocking things from getting on your PC in the first place) is actually very GOOD. However, once a virus gets past the overly-protective firewall, there's no getting rid of it. AVG works much better.

It also works well in tandem with SpyBot, SpywareBlaster, Ad-Aware, A2[/sup, and CCleaner -- all free, though some have more powerful non-free versions. 8-)I dis-agree that any "paid" program is more powerful ! !What I mean is that the paid VERSION of ZoneAlarm is better than the free Zone Alarm, etc., etc.. Quote

However, once a virus gets past the overly-protective firewall, there's no getting rid of it. AVG works much better.

McAfee is the same exact way. The firewall and autodetect are great. I love how quickly it detects and blocks (if I choose to do so) PUP's and programs that want to mess with my registry and/or connect to the internet. But when it comes to viruses...it's not so great at getting rid of the threats it finds.
3432.

Solve : start up problem-pop up message?

Answer»

during start up i get pop up message saying"Windows cannot find'c\windows\system32\services\msxmidi.exe.Make sure you typed the name CORRECTLY and try again." After clicking o k a second pop up states "Could not load or run(above message).make sure file exists on COMPUTER or remove the reference to it in the REGISTRY."Start up freezes while messages are displayed.Could anyone help to solve this problem?You have managed to get a trojan infection.
DLoad and update AVG Anti Spyware (free).
Disconnect from the web and re-boot into safe mode by hitting F8 repeatedly on startup.
Run the AVG scan, then run an anti-VIRUS scan as well.
Then DLoad and install HijackThis. Don't install it to the desktop, give it it's own folder.
Run the scan and post a log in the Virus and Spyware section and we can advise further.

It will take more than one post to get the entire log, this is normal.

And on your follow up post list all the protection programs you currently have...

3433.

Solve : random windows restart?

Answer»

hi, i've just had windows restart randomly, and recived a message saying windows has recoverd from a serious error.
i sent the error report and it took me to this page: http://wer.microsoft.com/responses/Response.aspx/79/en-us/5.1.2600.2.00010300.2.0?SGD=402e73a9-0997-4d8d-9cc0-468a8e2a0c2d
which was no help at all... and this has never happend before :-?

all i was doing at the time was listning to music on my hardrive from windows media player, shutting down MSN, inserting a CD for a computer game (which i've done before many times without this happaning). and then all of a sudden windows shuts down.

i'm using WinXP home SP2, norton 2006 AV/firewall, all kept up to date

thanks in advance for any replies
i'm completely clueless on why this happend and how i can stop it from happaning again!heres a hijackthis log...ok GET AVG anti-spyware

spybot

Ccleaner
and update them

run all of the scans (including issues scan on Ccleaner and back up when ASKED) in safe mode with system restore off

unlovedwarriorHi Ted2 ... In addition to the above you MUST update java. Your Java is well out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it SAYS "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
When all is done please post a fresh HJT log

AND...

an update on how your compter is operating now.

There is at least one more HJT running process I don't like (and will be recommending its removal) and there may be other files that need deleting.

However, there's nothing in the log that indicates why you should have suffered a random restart. That issue may be down to hardware/software issues. Perhaps overheating too.

Let's deal with the obvious malware first though.


OJQuote
ok get avg anti-spyware

spybot

Ccleaner
and update them

run all of the scans (including issues scan on Ccleaner and back up when asked) in safe mode with system restore off

unlovedwarrior

done and done

thanks OJ, i wasen't aware of my Java being out of date, or it being a problem really. it's up to date now... i've had no more restarts so far...

whats next? i'd like to get rid of any malware possible..

oh, and i'm worried about the computer over heating too... it's a pre built computer, and i've had it for around 3 years. so i'm guessing it must be getting abit rusty by now :-/

i took some tempreture readings from Everest... while in game my CPU is around 61C
and while idle the temp is around 49C
i'm not sure if this is a good or bad thing.. but i am looking to upgrade at some point...sadly things have just got worse for me, i'm now unable to shut down windows!
i've had this problem which i've been ignoring for some time, but it just got worse..

ccApp.exe fails to shut down, normaly i wait a minute and it shuts down..
but now it just doesn't shut down at all! arfter waiting 30mins i go start/turn off again.. and nothing! i tried opening/closing norton,alt+ctrl+del - shut down does nothing either.
now the only way is to force my comp to shutdown
it only seems to do this sometimes, i've not worked out what triggers it yet.

i've had this smaller problem too where norton security 2006 crashes sometimes when i open it (normaly i just alt ctrl del it, load it up again and it's fine)... maybe it's all related, and norton is cuasing all the problems, i'm not sure. but it has worked fine for me in the past...


EDIT: lol! sorry, just noticed how full of questions this thead is! i'll ignore the norton crashes for now.. i'm more intrested in getting rid of this malware you spotted OJ.. i'm not sure how to read a HJT logDLoad the tool below...

Norton Removal Tool


1) Use Add Remove Programs first and un-install Norton...
2) From Windows Explorer search for any folders named Norton and Symantec and delete them...
3) DLoad and install ERUNT and have it make a backup of your registry...
4) Open regedit and type Norton in the search bar. Delete all entries it finds. F3 takes you to the next instance of Norton. Continue til you have reached the end of the registry...
5) Repeat the above process using Symantec instead in the search field. Delete any Symantec keys it finds...
6) Now run the Norton Removal tool you DLoaded...
7) Empty the recycle bin...
Go to My Computer and right clik the C: drive and select Properties and run disk cleanup...
9) Re-boot and run disk defrag....

There you're done !

See how easy Symantec makes it for you to dump their product ? ?

patio. 8-)Do you have a real Windows CD to reinstall with? It's been two days now and that is more than enough time to have installed, updated and reloaded your programs.

Of course this will not solve hardware issues, but a good format and reinstall solves all Windows problems.....for a while. Quote
thanks OJ, i wasen't aware of my Java being out of date, or it being a problem really. it's up to date now... i've had no more restarts so far...

whats next? i'd like to get rid of any malware possible..
Please post a fresh HJT log. We'll see where we go from there.


OJPatio, i'll keep note of that for later on thanks.. but i'll stay with norton until subscription runs out. arfter all, it is still doing it's job... just seems abit buggy is all :-/

and the reformat, i'm leaving that for a last resort... although it's defently time i made backups!! i'll by some blank CD's tomorow hopefully...

much appriceated
TedNo problem. I hope that subscription isn't too long...Hi

Please print this out as you will need to close all open windows for part of this fix.

The log is clean apart from the one program I alluded to earlier, ALCMTR.EXE.

This is related to Realtek AC97 Audio - Event Monitor. It's "Sypware" file used surreptitiously monitor one's actions. It is not a sinister one, like remote control programs, but it is being used by Realtek to gather data about customers. Undesirable.

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for it (IF it still exists) .........

C:\WINDOWS\ALCMTR.EXE


Open HijackThis and click on 'Do a System Scan Only'. Check the following entry (IF it still exists).....

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Please remember to close all other windows, including browsers before clicking Fix checked.


Go to the following file (in BOLD) and delete it .......

C:\WINDOWS\ALCMTR.EXE


Empty your recycle bin.


Reboot your system in Normal Mode.

Perform an online scan with Internet Explorer here .....

http://www.pandasoftware.com/products/activescan.htm

Click on the "Free To Use ActiveScan" located on the top right hand corner [list=1]
  • Click Check Now and a "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  • Enter your e-mail address, country, and state & click Scan Now * The download of the 8 MB Panda's ActiveX control will take place *
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
    • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    • Click on See report then click Save report[/color]
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
    * Turn off the real time scanner of any existing antivirus program while performing the online scan

    Paste the Panda Scan report here together with a new HiJackThis log.


    PLEASE ALSO LET US KNOW HOW YOUR COMPUTER IS OPERATING GENERALLY. ANY LINGERING ISSUES?


    OJ
generaly my computer is ok, performance is roughly what it should be i think...

alcmtr.exe - i'd rather keep this process

i remember using the free panda scan last year.. still gives the same result as it did before,
1 hack tool and 128 spyware detectedOn the Activescan report ...

This file: C:\HP\bin\KillIt.exe looks like something HP put there to delete bad stuff.

See this also ....
http://www.pcreview.co.uk/forums/thread-108839.php

If you do not use it you may delete it but, if HP put it there as part of a malware removal process, it may stop working.

You can upload/scan it online if you wish here:

http://virusscan.jotti.org/

http://www.kaspersky.com/scanforvirus

http://www.virustotal.com/flash/index_en.html

Or you can ask HP tech support about them: http://h10025.www1.hp.com/ewfrf/wc/siteHome

Once you make your decision you can delete it if you wish.

************

The others are cookies that Spybot and/or Ccleaner should get rid of. Load/update Programs from here ...

Spybot > http://www.spybot.info/

Ccleaner > http://www.spybot.info/
>>>NOTE >>> when downloading/installing Ccleaner make sure you UNtick the optional Yahoo TRoolbar download.

Scan your system with both and let them clean out cookies.

************

Empty your recycle bin.

************

Final thoughts.....

If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.

If you do suffer an infection again you should run first Spybot & Ccleaner to clean out your system.

Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.



OJ
3434.

Solve : virus [protection?

Answer»

how much protection do I need. Do I really need Windows FIREWALL, Norton, and Webrot spyware? Also, how are each of these significant?Yes, you should have firewall and anti-virus protection, and one or more spyware prevention and/or removal tools are recommended for anyone who uses a computer on the Internet.

Here's a reference on firewall: http://www.webopedia.com/TERM/f/firewall.html

Exactly what Norton products are you using? If you're using Norton Personal Firewall, then I would disable Windows Firewall. Having two software FIREWALLS running at the same time is generally not a good idea, IMO.

Firewall will not PREVENT viruses from coming into your system via EMAIL. Therefore, anti-virus is also needed.

And, spyware can be picked up from web SURFING or even installing certain software. So, removal tools are needed to keep your system clean of this harmful software.arlene ... what soybean say is right.

These two tutorials may also help you understand and give you more protection ...


http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.



OJ

3435.

Solve : Sasser?

Answer»

From reading a bit on the web, I think I might have a sasser worm.
When I tried to login, it briefly mention a file spelt like lsas.exe or something before it powered off. This is the problem I am having with my computer, it keeps turning itself off and its killing me! I can't see ANYTHING working. I first tried to go into the recovery console using my reboot CD but the laptop turned off...then I tried to completely reinstall windows and it did begin deleting files ready to reinstall it but then the laptop turned off.
So what I am stuck with now is a laptop which constantly turns itself off and which has vital windows files missing due to an interrupted re-installation (When i tried to login again it said it couldnt find some other vital file, no surprise as it had just been deleted). This all seems pretty hopeless eh?

edit-But now I am confused because maybe my computer was saying it couldn't find lsass.exe, the legitimate login file which makes sense considering I couldn't login. But why on earth would it keep powering off? Might this be a HARDWARE problem?The file you mention is lsass.exe and it could be resulting in the problem you describe. More information it here with some sugegsted help to fix it ....

http://www.askdavetaylor.com/deleted_lsassexe_from_system32_is_this_a_problem.html

Yes, overheating or other hardware may be causing/contributing to the problem. Make sure the computer's fans are CLEAN and air is flowing easily.


Post back if this doesn't work for you. Describe any ongoing problems in each post you make. It will help us to help you.


OJThanks. But it is the hardware that is causing the computer to turn off constantly then? Or the missing file?
The computer did get pretty hot last night I guess but it ALWAYS does and it certainly isn't hot now that it keeps turning itself off. Darn, I wish I had a warranty.You need that file on your system to logon properly. If it is absent or corrupted you need to reinstall/relapce the file.

The overheating may also be a problem so I suggest you try to keep the computer cool then see if you can log on SUCCESSFULLY.

It may help if you boot up in safe mode only.

If you still get the lsass.exe error and shutdown, even in safe mode, then you need to delete the corrupted file and/or reinstall a new one. Possibly from your master disk.

As your machine switched off when you tried to reinstall Windows that may be an overheating problem.

Keep trying and let us know how you get on.



OJThanks a lot for your help oddjob! I took out one of the drawers from the freezer and placed the computer on it, that gave me enough time to log in (in safe mode) and do a system restore. I think the fan is working and will see if the login file is still missing next time i go on my laptop but everything seems fine. Thanks! I never realised that it would power down so easily, it didn't feel hot on the outside but obviously it was on the inside thanks! Glad things are looking better but please post back if there's no improvement.

Yes, it is vital to ensure air can move freely ROUND the machine and remove the hot stuff.

Good luck.


OJ

3436.

Solve : yellow triangle with ! in it?

Answer»

ok my friends got this when i was gone and i think i got it but can u guys look at my hijackthis log

xp home

avg free
avg antispyware
adaware
spybot
ccleaner
everything updated

am i missing anything
Logfile of HijackThis v1.99.1
Scan saved at 10:00:29 AM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Grisoft\AVG Free\avgwb.dat
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\ivan\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170320697178
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I think we need a little more info. What device is being marked with the yellow triangle with ! in it? Maybe post a screen print of Device Manager?

Or, are talking about something else, a yellow triangle with ! in it in some program? .... What?srry it was in the task bar i just woke up and was *er - we don't need to know that*Hi

You have a spywarequake infection and the log shows smitfraud as well.

First go here and run through the removal instructions ....

http://www.bleepingcomputer.com/forums/topic47826.html


After that post a fresh HJT log AND an update on how your computer is operating now.


OJi thought i had smitfraud

Logfile of HijackThis v1.99.1
Scan saved at 5:10:19 PM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\ivan\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file)
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: VirtualExpander.lnk = C:\WINDOWS\system32\VirtualExpander\VirtualExpander.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1170320697178
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

The log is clean now apart from Limewire and a couple of HJT entries.

However, despite my request, you didn't say how your computer is operating now. We see things in logs but sometimes cannot be certain all is well unless you tell us. Remember .... HJT does NOT reveal all malware (contrary to popular belief). Far from it, in fact.

Please LET us know.

I personally do not support illegal downloading using programs like Limewire but that is your choice. There are dangers in such activities.

Many of the P2P programmes themselves come bundled with malware/spyware. But, say the prog itself is clean, the downloads may not be. P2P is a great WAY for malware writers to get mass distribution for their wares. There are some LEGIT pay-per-song SITES that are clean and if you want to download music then those are the places to go. Other than that my view is it's just not worth the risk.

If you want to remove it then go to Add/Remove Programs and uninstall from there.

As to the two HJT entries .... open HJT .... click on scan .... put tick/check marks next to both these entries IF they are still present.....


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file)



Remember to close all open browser windows - including this one - before clicking on "Fix Checked" at the foot of the HJT window.


Please post back to let us know how things are working now.


OJits good... the limewire is my roommatesIn my view your roommate isn't doing you any favours messing with LimeWire on the machine. It's almost bound to foul up at some point and could easily result in a messed up computer. Like I said ... if I were you I'd get rid of it.

Otherwise ... glad to hear all is well again.

If you are certain the machine has no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.

If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional YAHOO Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/


Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.


OJ

3437.

Solve : Give me your advice. NOW!!! It slaughtered my COM!?

Answer»

Oh! Here's a good 1!
Q:What do you call a person who can't spell, makes it obvious in his invading destructive .EXEs, sends them to attatch to your autoexec, screws System32 over, and suspends HALF your computer with various loaded.exe files that also corrupt PICTURE files?

A:You Tell Me!!! ...Please? :-/

Okay well...at LEAST tell me how to fix it! Or what it iz? [smiley=huh.gif] AGH!!! [smiley=angry.gif]

[smiley=evil.gif] Please, keep it below 7 to 10 smilies per post, and don't fill a LINE with smileys. It takes time to load and serves no real point. -DilbertWell you would call that person a cracker and a mispeller. First what kind of malware protections are you using and list your system specs. And welcome to the forum.

8-)fffreakAlso, a more accurate description of the SYMPTOMS would help. Oh, how did you get this virus, by the way? Sounds nasty; not the thing you'd get normally.I would call him someone NOT to let on your computer. A good format and reinstall, use of new proper passwords, network security and safe computing practices would prevent this in the future.

3438.

Solve : Ad-Aware SE Personal Update probs?

Answer»

For the last couple of years I have been able to update Ad-Aware SE Personal without problems. But now "Error retrieving file" comes up when I try to update it after 5%. All other programs update ok. Is there a problem with Lavasoft, or something I should do? I have tried uninstalling and reinstalling the program.
I did not know whether to post this here or on the software forum. So if it is in the wrong forum please just let me know.Lavasoft's servers tend to GET bogged down from TIME to time...I have had that happen before on an old computer of mine. Im not sure how it got fixed though. I just kept trying over and over again. I would reboot and then try again. I dont know I could have just gotten lucky, you could try that until someone with more experience in the matter comes along. Sorry I couldnt be more help.

-Melissa-Still no luck. Tried rebooting. Did download update file from MajorGeeks, but I don't know how to get the program to accept it, it just KEEPS trying to update on line?OK, go here and click "download current definition file".
Within the zip file you download is a file called defs.ref.
Extract that to C:\Program Files\Lavasoft\Ad-Aware SE Personal replacing any defs.ref file already there.
This will update your program, there is nothing more you need to do.
Hope this helps.Thanks Callum, that seems to have worked!You're welcome, GLAD to have helped.

3439.

Solve : HELP ME!!! Virus Causes Comp. To Reboot?

Answer»

I'm in the MOOD for beating a dead horse...

My AVG Free
Updates on it's own @ 4:00 A.M. EVERYDAY...
Scans the drives i've selected @ 5:00 A. M. everyday...
Removes anything bad that it finds everyday...

Basically it does everything i need without me ever even seeing it.

patio. 8-)Sounds like awesome software to me!!! [smiley=laugh.gif]Quote

Sounds like awesome software to me!!! [smiley=laugh.gif]

Re-install it...you won't be disappointed.Cmd.exe is not a virus, it’s COMMAND prompt. I suggest you obtain real AV software, e.g. AVG.
3440.

Solve : virus basically killed my pc...do i have any hope??

Answer»

my system specs were windows xp home, pentium 4

I was surfing through sites about nigeria because i will be going there for a month as part of my medical training. Anyway I went to one site that wouldent load, so I tried to close it with the x in top of screen, it wouldent close. So i then pushed C+A+D to close from task manager..."task manager has been disabled by administrator"...So I started to GET scared. Norton then popped up saying that malicious scripts were causing my pc to stop responding. I manually shut down(holding down power). after reboot which took much longer then normal, there was a false "antivirus program" that I never installed(not sure of name because at time I dident put much thought to it)running when i started up. I clicked cancel on the program, but that caused my pc to crash again. After this HAPPENED it wouldent boot to windows at all, just to the screen that lets you pick safe mode restart from previous etc; none of options worked, just kept restarting after i clicked any option. I then tried to use my Norton Install cd, but it would only scan 4 files for some reason...

I finally decide to try and find a bootdisk, because I am stupid and had no backup cd, or restore cd(my computer never had one when i bought it NEW). I get one at bootdisk.com burned it with my other pc(windows vista compaq). Using this I was able to get into MS-dos...Only to find out that ALL partitions had been erased...all personal files, all system files basically EVERYTHING.. so I mess around with bootdisk long enough to get the boot options onto my hd, thinking that this will solve prob.. well after that it only would load into dos, and when i pressed ver, it said I was running windows 98.
I then decided that buying a program to unerase was my best bet, first i tried the demo diskette from undelete ([emailprotected]), since it found my deleted PARTITION i decided to BUY full program to restore partition.....After multiple hours of restoring raw data, it still will only start in ms-dos windows 98... I cant run system restore from this dos(restrui.exe) or any other program basically...scan disk says that io.sys is corrupt in a/> drive and cannot be fixed\

do I have any hope at all besides having to buy new os software and possibly a new pc?Laylow..... Would you please D/L hijackthis and post the results here so we may see whats going on .
Get it at .. http://www.majorgeeks.com/download3155.html
use as many posts as required to post it here .

DL65

3441.

Solve : explorer keeps crashing! help!?

Answer»

We MIGHT've SCARED him off with all of the FORUM CONVERSIONS.

3442.

Solve : Ads Show Up The Top Of Every Page?

Answer»

Alright, here's the situation:

I have both Internet Explorer & Mozilla. I'd love to stick with Mozilla, however, whenever I copy tables from the Mozilla web browser and paste it in Excel, ALL the items appear in one cell and they don't get spread out.

IF THERE IS A WAY TO FIX THIS PROBLEM, THEN REPLY NOW AND YOU DON'T HAVE TO READ THE REST OF THIS. IF THERE ISN'T A WAY TO FIX THIS, PLEASE READ ON.

The only way to cut a paste a table from a web page to Excel is if I'm using the Internet Explorer web browser. However, in Internet Explorer (this doesn't appear in my Mozilla) ads show up at the top of every page. It didn't used to be like this, which TELLS me I have some sort of spy ware or something. The following links show examples:

http://i49.photobucket.com/albums/f253/Nacho311/problem1.jpg
http://i49.photobucket.com/albums/f253/Nacho311/problem2.jpg
http://i49.photobucket.com/albums/f253/Nacho311/problem3.jpg

These ads are constantly reloading, making the browser slow and makes it VERY difficult to copy & paste tables due to this. Here are some things I have already tried to get rid of these ads:

1) System Restore
2) Virus Scan
3) Spy Ware Scan
4) Deleted all Temporary Internet Files, Cookies & History
5) Disabled all Internet Explorer Add-Ons
6) Uninstalled Internet Explorer & then reinstalled
7) Disabled everything in the "Startup" tab in "System Configuration Utility"
Went to Add/Remove Programs and removed anything that I was unsure of

To no avail, I have not gotten rid of this thing yet. I viewed the HTML CODE from these ads and here is the code:

http://i49.photobucket.com/albums/f253/Nacho311/code.jpg

It's like a separate web page on top of the page I want to view. Anyway, does anybody know what is going on? Does anybody have any tricks on how I can get rid of this? If I should post this in a different topic room, please let me know.

Many thanks to all who help! :-)Alex...... Go to http://www.majorgeeks.com/HijackThis_d3155.html
and D/L hijackthis....... once it's installed ,close everything else up and choose run scan and save file ...... then post your log here and we can have a look at it .


dl65 Thank you for the reply, but I was able to download Ad-Aware and it did the trick! Thanks for replying though!ALSO you might want to grab a FireFox extension called ADBlock PLUS... before doing so grab MoZBack and make a backup of your current profile just in case...

3443.

Solve : JS/ForcePopup@troj" virus?

Answer»

Hello does anyone know how to remove this virus. I have googled it but havn't found anything about removing it. JS/[emailprotected]" virus

Thanks.What KIND of malware protection do you have?DLoad and run AVG Anti-spyware and Stinger in that order in safemode with System Restore turned off...Thanks for QUICK reply, but where do i get stinger from. I GOT the other thing you mentioned but can't find stinger.Here Ya Go...It's a low rated infection. More of a nuisance at this stage.

More info from BitDefender here ....

http://www.bitdefender.com/VIRUS-1000086-en--Application.JS.ForcePopup.A.html

Post a HijackThis log if you're having trouble getting rid of it.


OJThanks that did the trick You're Welcome...and thanx for posting back. Stop by anytime...

3444.

Solve : AVG .dll popups?

Answer»

I run Windows XP, using Firefox as my browser, and AVG as my antivirus. I often get popups saying "You have chosen to open ADSAdClient31.dll which is a application from http://rad.msn.com What should Firefox do with this file?" Choices are a dropdown menu that says "You are attempting to open a file of type 'Application Extension' (.dll)" If I click on the "open with" button, another popup says "Windows cannot open this file: File: ADSAdClient31-5.dll What do you want to do with it?" If I choose "use the web service to find the appropriate program", off we go to a "Windows File Association" popup that explains the file type and describes it, and offers a link to "Windows Live Search", which produces a dizzying array of files to choose from. If I choose "sel :-/ect the program from a list", up comes a long list of programs already on my C-drive, and I have no idea which one to use.
I assume this file is AVG trying to update iteslf, but what file should I download, and where is the best place on the NET to locate it? rad.msn.com is MSN's advertising service I believe.. Do a complete virus scan. Go over all your Firefox settings, it might be trying to add a search machine or something..Does this come up when you go to Hotmail by any CHANCE?
From what I've read, this appears to be some sort of tracking adware installed by Microsoft. Sounds a bit creepy, but not terribly threatening.

Download HijackThis and save it to C:\Program Files\HJT (you'll have to make a new folder). Run the program and tell it to scan and save a log. That will bring up a Notepad file. Please POST the contents of that file here. It will likely take several posts.Thanks, CBMatt... Later this evening, when I get home, I will do as you suggest. I really appreciate your input...

3445.

Solve : HighjackThis log - I need help please :/?

Answer»

Quote

oddjob what are these

C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe

USR is U.S. Robotics...Its my modem I useQuote
Well, umm I have a lil question...Should I just attach my next logs? because i noticed thats alot of stuff there >.<
Don't worry, it's fine to just post them normally. AVG cleaned up quite a bit, so your future virus-scan logs shouldn't be so big. Unfortunately, AVG didn't clean up that worm, which disappoints me some, but hey, it can't get everything. Worms can be a little trickier at times. Your log is a bit cleaner, but there's still some junk in there. The ones that concern me most are...

(NOTE: The following is just an observation. Whether I'm right or not, I would advise to not take any action until someone with more EXPERIENCE tells you to.)

O2 - BHO: (no name) - {4148A482-1466-15BE-4C84-60D4CCB5AABC} - C:\Windows\System32\iudum.dll (file missing)
I can't find any information on the CLSID or filename. It could be harmless, but I think it generally isn't a good idea when you can't find any information on something. HJT says that the file is missing, and if that's true, checking it for removal should be safe either way. IF you can find the file in C:\Windows\system32, then scan it on VirusTotal and post the results.

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

These two identical entries show traces of CoolWebSearch still remaining on your computer. As I have some experience with this particular INFECTION, I might not get scolded too bad for telling you what to do. Heh.

(You might want to print this out or save it to a Notepad file...)
1. Find those entries (they look the same, but there's two of them) and check them for removal.
2. Close all windows (including this one), except for HJT. Click on Fix Selected.
3. Reboot into Safe Mode.
4. Open up Add/Remove Programs and uninstall any mention of MyWebSearch or CoolWebSearch.
5. Navigate to C:\Program Files\MyWebSearch and delete it. Also look for a CoolWebSearch folder and delete it if you find one.
6. Just to be THOROUGH, run through the CWShredder procedure again. Then post another log to see if we've gotten rid of the infection.

O4 - HKLM\..\Run: [explorer] C:\Program Files\Mozilla Firefox\two.exe
I'm not very familiar with Firefox, so I don't know if two.exe is a normal executable. But I suspect it may be malicious. A bit of research leads me to think that it's a PurityScan infection, but this isn't the type of filename that I'm used to seeing, so I'm not 100% positive. Head over to VirusTotal and do a scan of C:\Program Files\Mozilla Firefox\two.exe and post the log.

O20 - Winlogon Notify: mszsrn32 - C:\Windows\System32\mszsrn32.dll
Here's our friend the worm again. I can't find any guides for proper removal for this particular infection, so my suggestion would be to fix the entry in HJT and then delete C:\Windows\System32\mszsrn32.dll in Safe Mode. However, I'll have to ask you to await the approval of oddjob or someone else.

There are a few more entries I would suggest that you fix, but the above entries are the ones that need immediate attention. Unfortunately, I'm still a trainee, so I can only extend my help so far. I'm confident when it comes to a simple infection such as CoolWebSearch, but there is some semi-unfamiliar territory here and I would really hate to advise you in the wrong direction. The best I can do right now without getting in trouble is help diagnose. But don't worry, we'll get this problem sorted out for you soon enough. Thank you for your patience.Kurt 2 other things you can do in the meantime.
DLoad Stinger.
Disconnect from the web.
Turn off system restore.
Re-boot into safe mode.
Run Stinger.
Re-run AVG anti-spyware.

It's possible these nasties are hiding in restore points and coming back each restart.

Let us know.Looks like oddjob is busy with things right now. He's told me to take a crack at this, so I'll be advising you as much as I possibly can. Sir patio makes a good point; follow his instructions. And because it's been a couple of days, please post a fresh log so we have a more current view of what we're working with here.Quote
O2 - BHO: (no name) - {4148A482-1466-15BE-4C84-60D4CCB5AABC} - C:\Windows\System32\iudum.dll (file missing)
I can't find any information on the CLSID or filename. It could be harmless, but I think it generally isn't a good idea when you can't find any information on something. HJT says that the file is missing, and if that's true, checking it for removal should be safe either way. IF you can find the file in C:\Windows\system32, then scan it on VirusTotal and post the results.

This file isnt there.

Quote
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

These two identical entries show traces of CoolWebSearch still remaining on your computer. As I have some experience with this particular infection, I might not get scolded too bad for telling you what to do. Heh.

(You might want to print this out or save it to a Notepad file...)
1. Find those entries (they look the same, but there's two of them) and check them for removal.
2. Close all windows (including this one), except for HJT. Click on Fix Selected.
3. Reboot into Safe Mode.
4. Open up Add/Remove Programs and uninstall any mention of MyWebSearch or CoolWebSearch.
5. Navigate to C:\Program Files\MyWebSearch and delete it. Also look for a CoolWebSearch folder and delete it if you find one.
6. Just to be thorough, run through the CWShredder procedure again. Then post another log to see if we've gotten rid of the infection.

Neither of them was on the HJT and the folders wasn't in my Program Files either.

Quote
O4 - HKLM\..\Run: [explorer] C:\Program Files\Mozilla Firefox\two.exe
I'm not very familiar with Firefox, so I don't know if two.exe is a normal executable. But I suspect it may be malicious. A bit of research leads me to think that it's a PurityScan infection, but this isn't the type of filename that I'm used to seeing, so I'm not 100% positive. Head over to VirusTotal and do a scan of C:\Program Files\Mozilla Firefox\two.exe and post the log.

This file is no longer there either. I checked my AVG log and this file is in the infections and was quarantined.

Quote
O20 - Winlogon Notify: mszsrn32 - C:\Windows\System32\mszsrn32.dll
Here's our friend the worm again. I can't find any guides for proper removal for this particular infection, so my suggestion would be to fix the entry in HJT and then delete C:\Windows\System32\mszsrn32.dll in Safe Mode. However, I'll have to ask you to await the approval of oddjob or someone else.

This file says (file is missing) in HJT log. I have this file quarantined in AVG as wellHere is my new HJT.


Logfile of HijackThis v1.99.1
Scan saved at 11:31:54 PM, on 3/25/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\Windows\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Windows\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Windows\System32\svchost.exe
C:\Windows\Explorer.EXE
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\SYSTEM32\USRshutA.exe
C:\WINDOWS\SYSTEM32\USRmlnkA.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1128817780\ee\aolsoftware.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Windows\twain_32\SiPix\SCDeluxe\DELUXECC.exe
c:\program files\common files\aol\1128817780\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
c:\program files\common files\aol\1128817780\ee\aolsoftware.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Trillian\trillian.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\LVComsX.exe
C:\Documents and Settings\Administrator\Desktop\High Jack This\Analyse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4148A482-1466-15BE-4C84-60D4CCB5AABC} - C:\Windows\System32\iudum.dll (file missing)
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\X1IEBHO.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O4 - HKLM\..\Run: [USRpdA] C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1128817780\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [explorer] C:\Program Files\Mozilla Firefox\two.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DELUXECC] C:\Windows\twain_32\SiPix\SCDeluxe\DELUXECC.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\nzspc.exe" -w
O4 - Startup: Dora Fairytale Adventures Registration.lnk = D:\ATR1.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: AdSubtract: Bypass Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/360
O8 - Extra context menu item: AdSubtract: Cloak Image - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/361
O8 - Extra context menu item: AdSubtract: Report Site - res://C:\Program Files\interMute\AdSubtract\AdSub.exe/359
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{869C53F5-AF1E-4866-AAD5-BC4E503BCB34}: NameServer = 64.136.28.122 64.136.20.122
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: mszsrn32 - C:\Windows\System32\mszsrn32.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - Unknown owner - C:\Documents and Settings\Administrator\Desktop\7.6 YurOTs\xampp\FileZillaFTP\FileZillaServer.exe (file missing)
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)Patio, Where would the best place to DLoad Stinger be?Quote
Patio, Where would the best place to DLoad Stinger be?
Try this ...

http://vil.nai.com/vil/stinger/

Also ... log reviewers ... like CBMatt says ... look/research these entries ...

O4 - HKLM\..\Run: [explorer] C:\Program Files\Mozilla Firefox\two.exe
>> probably not what you think it is.

O20 - Winlogon Notify: mszsrn32 - C:\Windows\System32\mszsrn32.dll (file missing)
>> a worm.

In safe mode ... fix both with HJT & delete corresponding files, if present.


MyWebSearch can be more of a nuisance than real malware (if it's still around). If OP wants to ensure it's gone ... fix MyWebSearch related entries in HJT & delete the folder ......

C:\Program Files\MyWebSearch


Afterwards ... fresh HJT log in normal mode & update on how machine is running.


OJ
3446.

Solve : HJT log, help please?

Answer»

Here is my wife's HJT log. She says that she is constantly having to reboot her computer. When I use it I also notice a few annoying things, such as "Dell assistance network update" pop up and a "wireless network found" constant popup. The major issue is obviously having to reboot a lot, but I need advice if I should do the dell update and how to stop the wireless network found pop up. There might be a few other things cluttering her computer. Can you take a look at the HJT log and give me some advise? Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 2:17:41 AM, on 2/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\REFN\PDF-X\PDFSaver.EXE
C:\Program Files\REFN\FormViewer\REFNViewer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\SUSANW~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\ProgrPlease post the remainder of your log right down to the last 023 entry. An HJT log may require more than one post to get it all on the boards. Thanks.

OJI made a few changes, but here is my updated log,

Logfile of HijackThis v1.99.1
Scan saved at 12:52:10 PM, on 2/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Apoint\Apoint.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Napster\napster.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\palmOne\HOTSYNC.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\RuO4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DriveCleaner 2006 Free] "C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe" /min
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /Minimized
O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint HIGH Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: SBC Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper20041107.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1157422083031
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload PLUGIN) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Unknown OWNER - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\InO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Quote

I made a few changes, but here is my updated log,
What changes? Did they improve anything?

Please don't change anything till we say. It confuses things when trying to compare an earlier log with a later one.


OJ
3447.

Solve : AVG free error and registry cleaner question??

Answer»

ok, so I let my lil cousin use my computer to watch youtube videos and download music, and the next time i got on there i kept getting pop ups from some "registry cleaner" site saying my registry is in danger and I must go to their site, get their reg cleaner and fix it.

i have heard of this before- a virus or whatever u call it- that says to go to their site to "fix" your pc and it actually loads bad stuff in it. i did NOT go to the site, but instead tried to update and scan my pc with ad-aware and spybot. it would not allow me to go to any other INTERNET sites. i resored my pc to an earlier time, and tried to update my scanners.

Ad-aware was apparently an outdated version that was no longer good. i tried to uninstall it and re-install it. during the re-install, something went wrong. it did not install completely so i tried to uninstall again, but when i go to "add or delete programs" and click to uninstall it, it says "installation failed! Installer installion failed due to following error: Initiation of launguage file C:/Program files\Grisoft\AVG free failed. General failure."

i tried to just re-install it, but it gives me an error message when loading. i cant figure out how to get that out of there so i can re-install it. ANy ideas?

Also wondering..... was this annoying pop-up a potential threat? how do u tell if its legit or if its trying to trick me? what should i do when/if this HAPPENS?

any thoughts or advice is appreciated!!

Thanks! Sorry! Forgot to add:

its a Dell Inspiron 8600 laptop running windows xp home.

i think that it! please help me! thanks!You should be able to just re-install the AVG software
Update it and add the following to your arsenal:
Spybot Search and Destroy
AdAware
AVG Anti-Spyware ( different than AVG AV )

Update all of these and dis-connect from the web.
Re-boot into safemode and run each scan...let them fix anything they find.

Post back with your results and we'll take it from there...No luck

First, i tried a fresh install. When i try to go to AVG control center, i get an error message that reads: "Could not initialize AVG Anti-virus kernel interface" If i try to go to AVG free edition for windows, it does nothing at all. acts as if i didnt click on anything.

also, when installing it gives an OPTION of fixing installed components. tried that second, still no go.

i already have spybot on there, and it found no THREATS. also, installed Super anti-spyware free edition today. it found quite a few probs and quarantined them. the avg spyware you mentioned is only a free trial. i will do it anyway and use the free trial.

any other suggestions on how to fix avg free? i have used it for awhile and like it. i thought about going to the program file and just sending that to my recycle bin but i'm afraid of messing anything up. please help! :-?Is AVG listed in add/remove ? ?
If so remove it from there and re-install...

P.S. The AVG anti-spyware is still good after 30 days...all that gets disabled is the real time scan which you don't need anyways.Yes, its listed under add/remove programs, but if i click Uninstall, it brings up an error message that reads, " Installation failed!!" when i click on details, it says, "error: installation of launguage file C:\program files\grisoft\avg free failed. general failure"

it only gives an option to click ok.Stay offline.

Use the AVG Free uninstaller to uninstall the program entirely.

Go to Add/Remove Programs to see if it's still showing as installed. (If so ... uninstall it again from there.)

Open your Task Manager (hit Ctrl + Alt + Del together).

You may see around 3 AVG processes still running. Use "End process" on each of them.

Now try re-installing AVG Free.

Did that WORK?


OJThe problem is that I can't get it to disappear from the Add/Remove Programs section. I have tried going through the Start menu to the AVG Free program, and choosing uninstall through there, but still no luck. When i try to uninstall, no matter from what way, it says, "installation failed!" and gives an error message, but does not give a action choice except "ok". It seems like when I re-install it does not re-write over the old files. I need to figure out how to re-write over those files, or maybe change the file name and/or destination. It will not let me change it though, it is pre-set and won't let you click on it.

I have not tried to end task through the task manager. I do not have the laptop with me right now, but i will try that this weekend and let you know if that worked.

If anyone knows how I could change the destination even though it wont allow me to, i think that would fix it. I really don't know what else to do, it seems to be stuck. What is in your C:\program files\grisoft directory?

3448.

Solve : Unending popups.?

Answer»

This probably isn't a virus, but it happened while researching them, so I figured I'd post it here...

I've never had a problem with popups on my computer, but something odd happened this morning at the following Bleeping Computer page...

http://www.bleepingcomputer.com/startups/isDeleteMe-11846.html

I clicked on the O4 Entry link and it started opening the page in a new window. Deciding I didn't want to look at the page after all, I went to exit out of it. But when I did that, the window popped up again. And again. And again... In a few seconds, I had maybe 20 or 30 windows. They weren't ADVERTISEMENT popups or anything; just the same page loading over and over again.

IEXPLORER.EXE was taking up about 100 MB of memory usage, so I ended the task and the windows stopped popping up. Totally freaked out, I immediately ran HJT, but the log came up clean. It looks the same as always. I scanned with AVG and TrojanHunter and neither of them found anything. McAfee ran the routine system scan, and although it was before this happened, it also came up clean, aside from a couple of cookies.

Like I said, I have never had a problem with popups on this computer. And I haven't had anymore problems since trying to open that page...until a few minutes ago. As a test, I tried it again, and the exact same THING happened. One thing I noticed, though, is that it only happens if I close the window before the page loads any content. If I let the page load and then try closing the window, it WORKS normally. I've never had anything like this happen before and I don't know what to make of it.

What's your take on this situation? Does it sound like some well-hidden malware or just some kind of bug/glitch? Does this problem happen with anyone else?

I'd appreciate any input.

Oh, and because I know someone was bound to ask...I tried viewing the page in Firefox and no, the same thing doesn't happen.Go ahead and disregard the original post. As soon as I posted that, a thought occured to me and I discovered the culprit. I tried thinking of any recent changes I've made and all I could think of were two additions: Age of Empires III and IE Developer Toolbar. Obviously, I'm not going to mess with my AoE, so I uninstalled the new toolbar and ran CCleaner just to see what would happen. I went BACK to the site and...no problems. So, there you have it. It was a nifty toolbar feature, but I don't need it, so I'll pass for now.

I just hate it when I spend all of that time describing a problem, only to figure it out for myself two minutes later. Oh well, I'm happy.Sometimes we are just THAT good at resolving issues...

Quote

Go ahead and disregard the original post. As soon as I posted that, a thought occured to me and I discovered the culprit. I tried thinking of any recent changes I've made and all I could think of were two additions: Age of Empires III and IE Developer Toolbar. Obviously, I'm not going to mess with my AoE, so I uninstalled the new toolbar and ran CCleaner just to see what would happen. I went back to the site and...no problems. So, there you have it. It was a nifty toolbar feature, but I don't need it, so I'll pass for now.

I just hate it when I spend all of that time describing a problem, only to figure it out for myself two minutes later. Oh well, I'm happy.

nice one! i would have helped you...
If you have a problem but manage to fix it yourself it's always good to post what happened. We can all learn from the experience.


OJ
3449.

Solve : sufficient software protection??

Answer»

can anyone help me with the following?

i opened up norton av & did not find a tab called "options". tabs INCLUDE "file, edit, view, scan, configure, histories, & help". I did find under the configure tab "file system realtime protection" & " Microsoft exchange realtime protection" but neither seemed to have a section on email protection. can you help me NAVIGATE so i can do the following:

"open up norton av ....... there should be a tab or button called options ....... click it ...... you should get a new window ...look for internet and in that section find Email protection ...click that and then make sure Email is ticked to monitor incoming as well as out going and that should do it ."

thanks!!!!!!!!!!ok i reset my internet explorer options as DIRECTED & now i can't access forums & can't get ie to work properly. for example one site said to: Your browser's cookie functionality is turned off. Please turn it on. another site said scripting is disabled in my ie browser & wouldn't LET me access site.

how do i fix these problems & still have some security on ie? thanksDid you use the trusted sites as directed?Try reply #6 again...
i need to download updated peoplepc dialup internet software ASAP but can;'t because i used the advice on this forum previously to make my IE more secure & now I can't download peoplepc software as I get message "javascript: void(0)" & can't use IE to access a number of websites as I get the message that "scripting is disabled in your browser." I looked at past forum notes & ccan't figure out how to fix this problem. can you help me asap? thanks, ded

i opened up norton av & did not find a tab called "options". tabs include "file, edit, view, scan, configure, histories, & help". I did find under the configure tab "file system realtime protection" & " Microsoft exchange realtime protection" but neither seemed to have a section on email protection. can you help me navigate so i can do the following:

"open up norton av ....... there should be a tab or button called options ....... click it ...... you should get a new window ...look for internet and in that section find Email protection ...click that and then make sure Email is ticked to monitor incoming as well as out going and that should do it ."
Reset IE to the defaults or use the Windows Internet Connection Wizard.Fed, where have you been? It might not be a bad idea to also get SiteAdvisor. I just INSTALLED it the other day and I'm so glad I did. Very handy indeed. It installs a small toolbar in your browser, but you can disable the toolbar (if they bug you as much as they bug me) and the program will still run normally.

3450.

Solve : Explorer Keeps Restarting...EMERGENCY?

Answer»

Let me start off by saying I have no experience with this side of the computer, This is the first time I have ever had anything go wrong with a computer of mine.

For four years I had a crummy desktop computer, and NOTHING ever went wrong on it. I buy a 1200 dollar notebook, and all of *censored* desends upon it.

Let me explain my situation. I have had this notebook for about two weeks now, It has Vista (Home Premium I believe) along with several Adobe products provided by my school. Ive been putting off installing AVG because I have a free trial version of Norton, that was a mistake.


Someone, through my unimagineable stupidity, I recieived the dreaded Spydawn. Shortly after I realized what had happened...IT happened. I recieved a message saying explorer was not responding and needed to be restarted. This has made it impossible to use my computer. Eventually I just ended the process, and am currently running all my programs using my task manager. I cannot install AVG for some unknown reason, but I managed to install hijack and did a scan.

If anyone could help me, it would be greatly appreciated, this problem is effecting my small time bussiness and I cannot affoard to go another week like this.
It will take several posts to include all of your log. The last entries are 023.

Spydawn can be removed with Spybot. Update it and run it in Safe Mode with System Restore turned off. Then restart and scan again. I just did this for a FRIEND last weekend. You probably have other malware as well so a good scan with Norton would be helpful as well.

Do you have some restore disks or what? As it is so new you may be ahead to just reinstall everything.



My computer never came with any backup discs, or anything of that sort.vik....... Without seeing the rest of your log it's hard to say what else is lurking in your machine ........ If spybot doesn't get Spydawn, go to this link ......
http://www.bleepingcomputer.com/forums/topic81275.html and D/L Smitfraud fix ....... and follow the detailed instructions listed there ...in fact it might be a good idea to print them out .


let us know how you fare.

dl65 sorry about the wrong spot, here is the full scan list...

Logfile of HijackThis v1.99.1
Scan saved at 2:11:25 AM, on 2/20/2007
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16386)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SpyDawn\SpyDawn.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AIM6\aim6.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\AOL\Loader\aolload.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\PROGRA~1\HPCONN~1\6811507\Program\HPCONN~1.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SEARCH Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Protection Bar - {84938242-5C5B-4A55-B6B9-A1507543B418} - C:\Program Files\Video ActiveX Object\iesplugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpyDawn] C:\Program Files\SpyDawn\SpyDawn.exe /h
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BPS Spyware Remover] C:\Program Files\AdwareCatcher.com\AdwareCatcher\SpyRem.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP ConnectionsO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: SUN Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - C:\Windows\system32\higehsg.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS PASSWORD Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

vik....... Ok ..... I would d/l the Smitfraudfix as I mentioned earlier ... Print out the instructions ........ make sure you have the smitfraud fix icon on your desktop.......... ( don't ) click on it YET ...... after you have the instructions printed out , reboot into safe mode and proceed with the removal exactly as indicated in the instructions.

Once its done it's job , you may wish to run your Anti virus from safe mode as well .... once complete , reboot back into normal mode and run a new hijackthis scan and post the log ......so we may make sure it's clean.

dl65 I can probably use my XP desktop for the instructions. Ill go ahead and do the above mentioned, and post my results. I appreciate the help