Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

301.

Solve : Hijack or forwarding?

Answer»

Win XP

Is it possible that your email be hijack or forwarded to another location by SOMEONE other than you?  For three days I've received no emails and that's unusual.  I receive my email at my ISP email center.  Thanks.Yes it is.

You should scan your system immediatly:

Virus scanners
AVG Free
-- Anti virus scanner
Trend Micro Housecall
-- Online anti virus scanner.

Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Use both a hardware and software firewall.
Be advised as dual software firewalls may cause problems


ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.

Install all the programs here.

If you have removed everything, and it still happens, immediatly contact your ISP and explain the problem.I did a scan - Norton gave 0, Spybot gave 0, Microsoft Antispyware Beta gave 0 results, Ad-Aware found 4 critical files - among which one was a "tracking cookies".  I deleted them but they keep on recurring.  I'm trying to include a logfile to see if you can help.  Thanks a lot.I'm INCLUDING a logfile of HijackThis to see if you can help me delete whatever there is that's not supposed to be.  And...  a million thanks!
Logfile of HijackThis v1.99.1
Scan saved at 10:33:47 AM, on 8/8/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\Brmfrmps.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\HP\KBD\KBD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Anonymizer\Anon2005\Anon2005.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Anonymizer\Anon2005\AnonProxy.exe
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\BitTornado\btdownloadgui.exe
C:\Documents and Settings\Compaq_Owner\My Documents\Downloaded programs\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=presario&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=33568
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Anonymizer 2005 Toolbar - {DB264E15-F83B-4603-BFC1-4EA7E3204686} - C:\Program Files\Anonymizer\Anon2005\AnonIEBar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard]C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Anon2005] C:\Program Files\Anonymizer\Anon2005\Anon2005.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Asmw Eraser Pro] C:\Program Files\AsmwSoft\asmweraserpro\Asmw Eraser Pro.exe s
O4 - HKCU\..\Run: [HD] C:\Program Files\U-Clean\Hd.cmd
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/SymAData.cab
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec PASSWORD Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

I didn't realize I had so many things in my PC, wow!  Thanks so very MUCH. Quote

among which one was a "tracking cookies".  I deleted them but they keep on recurring


That is because you are not using Mozilla Firefox with manual cookie control enabled...!

Quote
I didn't realize I had so many things in my PC, wow!  Thanks so very much


List the entries that you do not recognize or do not trust.

From what I can see, there seems to be nothing wrong, however, I am not very adapt at examining HijackThis logs..

Do you still not receive E-mail?Sent logfile because at one time you were able to help me getting rid of spyware.

I started getting emails again but I'm getting a lot of spoofs.

Can you tell me where can I find Mozilla Firefox?The name Mozilla Firefox (Click here) is a clickable Hyperlink.

Quote
 
I started getting emails again but I'm getting a lot of spoofs.


Do you mean spam?

Quote
Sent logfile because at one time you were able to help me getting rid of spyware.


Is there nothing that you do not recognize?

Quote
O4 - HKCU\..\Run: [HD] C:\Program Files\U-Clean\Hd.cmd


Quote
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe


What are these?
302.

Solve : Uninstallation of Spyware Guard software?

Answer»

After installing the Spyware Guard from a Html Website my INTERNET Explorer opened with a blank screen.  I have restored the explorer and REMOVED the Spyware Guard program from my computer.  But the problem is that I could not entirely uninstall the program.  Is it possible to remove all traces of Spyware Guard?  It still appears in Startup tool bar with a X on it.Try removing all registry ENTRIES related to it.

You can do so manually by:

1. Start
2. Run
3. Type Regedit

Or you can download the programs below:

Easy Cleaners
-- Freeware registry scanner
Registrar Lite
-- Excellent replacement for Windows Regedit
Crap Cleaner
-- Freeware registry scanner/history cleaner

Caution is advised when USING these programs!
Create backups of all important files before proceeding.
Spyware guard found a problem what was it!What o/s have you GOT!What other spyware/anti/ programs have you got!

303.

Solve : W h a z z a t ?????????

Answer»

[SIZE=16]validation failed for C:\Windows\Temp\VSINIT.DLL

You Probaly are MISSING a necessary root certificate.[/size][/color]

[size=16]After downloading Zone Alarm

from this link:

http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

When I went to install it:

I got the above message.

What's that?[/size] Quote

Re: W h a z z a t ??


That is no SUBJECT. Did you never LEARN to find the subject of a post at school?

You should empty the C:\Windows\temp folder and retry.
304.

Solve : got a virus called w32/tibick!p2p?

Answer»

got a virus called w32/tibick!p2p my antivirus McCathy keeps popping up saying its found a virus but it wont delete it. it says it does'nt know where the file is located...how do i kill it??
Quote

how do i kill it??


Remove is the proper term! It seems that video GAMES do promote VIOLENCE after all..  

See the following article for more INFORMATION:

Symantec SECURITY Response W32.TibickHave you tried to run McAfee in safe mode this method usually can remove stubborn pests and VIRUSES
305.

Solve : virus that hops network shares?

Answer»

can anyone tell me if it is possible for a Mac connected to a network, and logged into windows servers to infect the windows computers even though the virus is not one that would infect a mac?lrieken.... Have you been sharing known INFECTED files with the win pcs on the network ? I would have to say yes you could PROBABLY infect those other machines . Do you have a anti virus app on your Mac ?

dl65  We do not currently run antivirus SOFTWARE on the Macs and have not shared known infected files, but we were recently infected with a worm that is in the scbot family that only AVG from Grisoft has been ABLE to detect. Macafee, Comp Assc., and Norton were not able to detect it, and still have no info on it. It attempted to log on as common users and locked out accounts in active directories, modified some registry enteries and started the winamp service several times. We update AV software daily. it is CA's InoculatIT. Our email runs through Message Labs, any Ideas on what it could be or how we were infested?   Quote

can anyone tell me if it is possible for a Mac connected to a network, and logged into windows servers to infect the windows computers even though the virus is not one that would infect a mac?


What is the exact name of the worm you detected?the worms ScBot and D2SkyBot are a very nasty and also hard to remove, the damage to security and systems is severe and may RESORT to a complete format and start again
306.

Solve : aol and antivirus?

Answer»

hi my friend is trying to install AVG, she has now installed it. But aol says i CANT find the BROADBAND we think she needs to turn the fire wall off, she has not got a security centre OPTION in control PANEL for some reason, she was on 98 but has just upgraded to xp. can anyone help??? its ok we done it now !!! Quote

she has not got a security centre option in control panel for some reason


You should install Service Pack 2.
307.

Solve : File IBV.NZT?

Answer»

Basics on system...I have Windows XP Home, Norton Anti-Virus, Zone Alarm Pro, Linksys Router and connect through Sprint/Earthlink DSL.

I'm not sure I'm posting on the right forum, but since I can't find any info on this file name or extension, I'm assuming the worst  lol

While trying to clear up system before migrating to new computer I found 120 files by the name of ibv.nzt .  Has anyone heard of this or KNOW what it is?  I can't find it as a valid extension on any site and  with google the whole name comes up with nothing.    I continually run virus scans and come up with nothing.

Also, after checking properties all 120 files were CREATED on same day.  Is there a way to check what created it?

Where did you find these files?Was just logging back in to say I'd found the culprit.  I found a report file ending in ibv and thought that was too much of a coincidence, so I read it.  Turns out it all stem from an anti-virus program that an IT person at work told me was "the best there is"....I wouldn't know as all it ever did was crash my system at start up.  I had to uninstall it in safe mode as I couldn't access it any other way.  Apparently it didn't like being uninstalled in that mode and left garbage everywhere..   The program was InVircible by NetZ Computing.  It had put that file in drivers, most of my document files, messangers, i386, etc..  Sheesh...

Anyway, thanks for reading and trying to help  :-)  Have a great day!

DeeNever heard of that virus scanner. SOUNDS daft.lol  Actually it sounds good when you read about it...and maybe it just doesn't like XP Home.  All I know is when booting up I would get as far a having their frigging eagle logo on the screen and it would freeze everything.  

You can read on it at:    http://www.invircible.com/invircible.phpPerhaps the installation BECAME corrupt due to a virus or another problem.   Very possible, but with all the problems I had I don't even want to try it again.   Have enough going on in my life without fighting a computer to log on  lol   Thanks again for reading and replying.  Greatly appreciated!   If you ever get to Vegas, I'll buy you a drink  :-)

Dee

P.S.  New computer came with trial of Norton Internet Security.  Any feelings on their firewall as opposed to Zone Alarm Pro? Quote

Have enough going on in my life without fighting a computer to log on  lol


Annoying, isn't it? Everyone has a working computer, but somehow, the one you need to use most always has some kind of problem that simply will not go away..  

Quote
P.S.  New computer came with trial of Norton Internet Security.  Any feelings on their firewall as opposed to Zone Alarm Pro?


I have tried Norto Internet Security 2003, it came with the mainboard I bought (At least a year ago) but I can not remember much of it, it mustn't have been very good.

Zone Alarm Pro, I used that approximately a year ago as well but that seemed like a very decent program.

However, I prefered the following Firewall (Be it the paid or free version)

Sygate Personal
-- Free firewall - more configuration options

It had a lot more configuration options than Zone Alarm Pro (Or Free), but it was less user friendly. You have to know the jargon.

I GAVE up on paid firewalls, though. ZoneAlarm Free does an excellent job.Not convinced!Events log/sercuity logs!
308.

Solve : Comparitive sites?

Answer»

Does ANYONE know any links to comparitive sites for firewall,anti VIRUS,anti spyware,or anti TROJAN software done this year? PLEASE post any you know here, tks

309.

Solve : Another spanner in the works!?

Answer»

Do you have the geninue ARTICAL>

http://www.spywarewarrior.com/family_resemblances.htm

310.

Solve : Comp Problem for the Books?

Answer»

Begining the night after aquiring a new (paid for) legal P2P service, I woke the next morning to discover my Java Script writer had been activated. I immediately engaged Ad-aware, Norton and Housecall to isolate the problem. Upon recognizing the file and perparing to quarantine it the computer shut down. This continued for about an hour until I gave up on the process and employed the XP Pro system recovery. Upon completing that I once again began to check the system and sure enough the same problem happened again. This processed continued until finally I recived the Blue and Black screens of death.
Finally I turned to "Geeks on Call" for a full virus scan and system diagnostic to which after three whole weeks the best they could come up with was that they believed my video card was faulty and that my capassadors on my mother board had burned out because they failed to get a video screen on the monitor in that whole TIME. I then took it home and rewired the hardware and after three attempts to get a vid screen from the boot I got the BIOS screen up.
I tried to run in safe but after leaving the screen I got nothing but blackness. I have gotten the setup screen one other time since then but the majority of my startups are met with nothing but black screen, orange LIGHT goodness. At this point I know that reformatting is truely the only option but I was wondering if anyone has any advice.  Have you tried to reseat all hardware installed? Test each component in a different computer as well.

Quote

At this point I know that reformatting is truely the only option but I was wondering if anyone has any advice.


Why are you first describing a hardware problem and now think that reformatting is the only solution?

If you can not even see the POST, reformatting is going to do you little good.Have you ever  though of writing a book!or was the PAGE one!Chris Isaac.........  I would be starting my search with the P2P app you installed .

"Begining the night after aquiring a new (paid for) legal P2P service, I woke the next morning to discover my Java Script writer had been activated."

You must remember that when you install any of these P2P apps ....you have agreed to LET others access your pc whenever its online ..........    Before I got carried away and started a format, I would be seriously considering removing .......all evidence of that P2P if you can ........... You suggest that sometimes it starts.......?

let us know

dl65  Maybe you need a spelling book......to write your autobiography.......what p_2 PROGRAM was this.....kazza!
311.

Solve : AVG... Free??

Answer»

Hello all. I hear a lot of people talking about AVG being free, but all I see is a Free 30 Trial... How are people getting this all for free? (more than 30 days)

[glb]Flame[/glb]Go and look harder. AVG Free is there.  
Trust me Flame, you won't be disappointed.Ok. I'll look LOL  What I'm thinking of doing is just installing AVG and Sygate on my mom's computer... That way I don't waste my Norton usues... You canonly use it like 5 times... (INSTALL)

[glb]Flame[/glb]Good idea, get the previous version of Sygate, the current one has some issues which will be fixed in the NEXT version. Build 2710 is fine.
http://cdrom.wip.digitalriver.com/p.../bws_49/spf.msi
Ok thanks! I'll get this up soon...  

[glb]Flame[/glb]They really do hide the free version of AVG, sneaky  
http://free.grisoft.com/doc/2/lng/us/tpl/v5
Scroll down to the bottom mate.Thanks Fed! I'm actually reformatting right now, so you just saved me some time! Thanks! I'll have a good look at this... Looking at the bottom here, I see a download link with version number 7.338 ... This look right to you?  

[glb]Flame[/glb]Hey Fed... Also on Sygate... Where can I get the free version of that? It's hard to find becuase you SAID to get the older one... What version was that?

[glb]Flame[/glb]Yes, that's the latest version and it only came out today, I got mine this morning.
All you have to worry about is virus signature updates after that, they update almost every day, sometimes twice. After you install it, there is a recommended option to enable which does a more thorough (slower) scan.http://cdrom.wip.digitalriver.com/p.../bws_49/spf.msi Build 2710It says page not found lol

[glb]Flame[/glb]Sorry, they must have blocked direct linking.
Try here http://207.33.111.31/spf/spf5.5b2710.exe
Ok great! thanks so much! It's installing Windows XP Home now, so it'll be done in about 15 MINUTES... Once I get DSL woking on it, I'll download!    Thanks again Fed!

[glb]Flame[/glb]Sooner or later you will be a convert.  
Good luck with the OS install.  Thanks! You'll be hearing from me! lol

[glb]Flame[/glb]

312.

Solve : What brand?

Answer»

What brand do you THINK makes the best ANTI virus program?

A computer GUY that came over to my house like a 6 months ago said the best brand was NORTON anti virus and that Mcafee is 'a peice of *censored*' in his own words. So i'm wondering from people that know what good anti virus brands  that get the job done thororolyThe best brand of anti virus WOULD be common sense.

I never obtain any viruses, but I use AVG Free just in case.

313.

Solve : ????????

Answer»

how do i get rid of Backdoor.IRC.Contact and Slackbot 1.0

keeps showing up everyday?What scanners are you using?

See the following article:

       Backdoor.IrcContact.10 [Kaspersky], IRC-Contact [McAfee], security risk or a "backdoor" program [F-Prot]

Virus scanners
AVG Free
-- ANTI virus scanner
Trend Micro Housecall
-- Online anti virus scanner.

Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and PROFESSIONAL only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Use both a hardware and software firewall.
Be advised as dual software firewalls may cause problems


ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more CONFIGURATION options

Removal tools
The following files are not substitutes for the ONES described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.

314.

Solve : Adware Threat - Help?

Answer»

An Adware found in my system, currently running Windows XP.  Cannot remove   thru Microsoft Antisoftware, Lavasoft Ad-Adware

Information about the threat location

File Name: (DrPMon Print Monitor) Transponder.ABetterInternet.DrPMon
Type: Adware
File Path: c:\windows\system32\drpmon.dll
Pubilisher:  Direct Revenue
File Size: 28160 bytes.

Pls help me to remove and get rid of this adware.
Thanx..
ohh....gee that rough.  What kind of stuff is it doing?  Have you tried deleting the file manually?


Scan from safe mode.

To start with I would like you to do this

Please delete your temporary files by deleting all files and folders that are in those folders (do not delete the temp folder itself) like for example
C:\WINDOWS\Temp\
C:\Temp\
C:\Documents and Settings\username\Local Settings\Temp\
Also delete your Temporary Internet Files, be sure to also select delete all offline content.

Do a virus scan  good online scanner is at :  http://housecall.trendmicro.com.

If you get report of files that can’t be cleaned / deleted please write down the filenames and locations and post that in your reply.

Then please do this since it’s better to use automated tools to get rid of the bad stuff use these 2 programs first before doing the final cleaning with HJT

First use Spybot S&D.
http://www.safer-networking.org/index.php

Unzip,  and update. Install the updates and run. Delete all that it marks in red.
Reboot

Then it’s time for Ad-Aware
http://www.lavasoftusa.com/software/adaware/

Install and update by using the globe ICON. Restart your computer and run Ad-Aware.
Press scan now and select drives and/or partitions to be scanned. When done select all and click next. Remove all checked items and then reboot your computer.

Please go to this page and read the instructions for how to configure Spybot S&D & Ad-Aware www.zerosrealm.com/scanning.php and read up:  How To Setup Spybot SD and Ad-Aware

i'll come back later and CHECK up.
globalpal_ooty.......  Ok .....here's what to do ........reboot into safe mode .......

then shut down system restore .

Go into contol panel .........folder options ....click on the view tab .... now mark show hidden files and folders ...click aply and ok .

now run your scan with Ms antispyware .......... it should find it and remove it ......


let us know

dl65  What does this spyware/adware does:

First it shows an error msg as follows:
"NOTICE: If your computer has errors in the registry database or file system, it could cause unpredictable or erratic behavior, freezes, and cratches.

Would you like to install WinFixer 2005 to check your computer for free? (Recommended)"

If we give OK or Cancel

A Security Warning error showing
"http://winfixer.com/pages/scanner/WinFixer2005Scannerinstall. signed on an unknown date/time and distributed by
Vantage Software Inc.
You should only instal view

If I press Yes or No
It autmatically installs

Then ads pop up then and there
as Aurora - part of ABI Network......
..........
Repair and protect ur PC with WinFixer.......

I am ABLE to remove it completely, but it happens again and again when I open internet explorer.. Quote

I am able to remove it completely, but it happens again and again when I open internet explorer




Mozilla Firefox

Use the following applications to completely clean your system:

Virus scanners
AVG Free
-- Anti virus scanner
Trend Micro Housecall
-- Online anti virus scanner.

Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Using only one firewall is advised. Dual firewalls may cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.Logfile of HijackThis v1.99.1
Scan saved at 3:39:06 AM, on 07/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
c:\windows\system32\zrejjxq.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\MICROS~2\Office\WINWORD.EXE
C:\Program Files\Scribe Aid\Scribe Aid.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\WINDOWS\System32\SNDVOL32.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DocNeT\Bin\Wc32.exe
C:\DOCNET\BIN\DOCNETUPLOAD.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
Continued.....

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oemji.com/side_search.html
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: OemjiSearchPlus - {D240DC29-C093-4388-B71F-A7103C796B0C} - C:\Program Files\Oemji\OemjiSearchPlus\OemjiPls.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Oemji - {804DB5C7-31E6-4885-850A-F1941B58A4C7} - C:\Program Files\Oemji\Toolbar\OemjiSrc.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [exp.exe] C:\WINDOWS\System32\exp.exe
O4 - HKLM\..\Run: [qvpmmac] c:\windows\system32\zrejjxq.exe r
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [WinFixer 2005] C:\Program Files\WinFixer 2005\wfx5.exe
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: autowave.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.maalaimalar.com/wfplayer/tdserver.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1122039434500
O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/SpSp29952.41optYplkOmji/SpySpotterCabInstall.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = condigi1.com
O17 - HKLM\Software\..\Telephony: DomainName = condigi1.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{DFE7A3DA-73F1-44C0-8EF6-34A143E3ED07}: NameServer = 202.56.240.5,202.56.250.5
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED6000F7-10DB-4DCF-897D-02D49DD2AA24}: NameServer = 192.168.200.252
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = condigi1.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ichart.com,
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = condigi1.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ichart.com,
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exeTypical.......norton and msoft.........download this and run it>http://vil.nai.com/vil/stinger/.......disconnect from the net while scanning.....and disable system restore.....or download spysweeper.......you have a trojan!Use the tools described in my post. Quote
C:\Documents and Settings\Administrator\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe


Your copy of HijackThis needs to be in a folder of it's own. When HJT fixes anything, it makes backups of the original files in the folder it is in. For this reason it cannot be run from a Zip file or from Temporary folders because the backups will be deleted. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!

1. Please go to you're 'My Documents' folder, right-click and select 'New > Folder' then name the folder 'HJT'.

2. Copy and paste HijackThis.exe to the new folder.

3. SCAN with HJT

4. POST the new log in this thread





Aurora or ABI network removal help

After trying SpySpotter, Webroot SpySweeper, Microsoft AntiSpyware, Ad-Aware SE Personal, and so other things, also tmas-web-scan.exe from http://www.trendmicro.com/spyware-scan/, finally still i cannot get a permanent solution.  I am able to remove with all these, but cannot get a permanent solution.  When I open internet explorer, it automatically gets installed.  I have to run all these again and again.  Anyone experienced this type of problem.

Check out this blog too
http://netrn.net/spywareblog/archives/2005/05/10/got-aurora-nailexe/

Pls. check for this link too.
http://netrn.net/spywareblog/archives/2005/06/06/over-30000-search-engines-hits-for-nailexe-aurora/

I can provide what all things are needed.  I am going mad Pls Help Antispyware log

           Started Scanning
           Internet Cookies
                 Found 'cliks.org' in 'Internet Explorer Cache'
                 Found 'btg.btgrab.com' in 'Internet Explorer Cache'
                 Found 'as-us.falkag.net' in 'Internet Explorer Cache'
                 Found 'abetterinternet.com' in 'Internet Explorer Cache'
                 Found 'bannerspace.com' in 'Internet Explorer Cache'
                 Found 'doubleclick.net' in 'Internet Explorer Cache'
                 Found 'btg.btgrab.com' in 'Internet Explorer Cache'
                 Found 'offeroptimizer.com' in 'Internet Explorer Cache'
           Programs in Memory
           Windows Registry
                 Found '' in 'SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/VBouncer/INSTALL.LOG'
                 Found '' in 'SOFTWARE\Classes\Remove'
                 Found '' in 'SYSTEM\ControlSet001\Control\Print\Monitors\ZepMon'
                 Found '' in 'SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon'
           Internet URL Shortcuts
           Files and Directories
                 Found '~DFD9F2.tmp' in 'C:\Documents and Settings\Administrator\Local Settings\Temp'
           Finished Scanning
           Started Backup
           Finished Backup
           Started Cleaning
                 Checking for 'C:\Documents and Settings\Administrator\Local Settings\Temp\~DFD9F2.tmp' in shortcut areas.
                 Checking for 'C:\Documents and Settings\Administrator\Local Settings\Temp\~DFD9F2.tmp' in startup areas.
                 Cleaning 'C:\Documents and Settings\Administrator\Local Settings\Temp\~DFD9F2.tmp'
           Finished Cleaning
           Started Scanning
           Internet Cookies
           Programs in Memory
           Windows Registry
           Internet URL Shortcuts
           Files and Directories
           Finished Scanning
Disconnect from the net.........while doing scans.....while still atttached to the net.....is a waste of your time?And futile....has winxp backup files......held in the system file protection folder and the system restore folder and hidden from the user the recycler folder. and using another browser does not solve trojans!Have you downloaded or installed any files lately......!Do you have any psp programs.....kazza/limewire/bearshare/napster/blubster....etc.....
315.

Solve : J & M virus detected?

Answer» AVG FOUND a nasty virus called J&M.A

It SAYS that it is embedded.  How do I get rid of it?

Thanks in Advance,

JoeyNo comments on avg! is it in the quarrentine folder! Quote
AVG found a nasty virus called J&M.A

It says that it is embedded.  How do I get rid of it?

Thanks in Advance,

Joey


Does it fail to remove the virus or does it come back?

List the virus full name!It's a very OLD & common virus & there are plenty of SITES on the net that tell you how to get rid of it.
Just google for it.joey dodge......It's a boot sector virus ........originated back in the mid nineties .......... do as FED suggested .....to rid it ......

dl65
316.

Solve : Reactivate NAV 2005 After HD Reformat?

Answer»

I must reformat my hard DRIVE and reinstall all programs.  NAV 2005 was originally installed and ACTIVATED 11/04.  I would like to determine the reactivation process prior to proceeding with my reformat.  SYMANTEC's support site provides no information on this issue.  Has anyone had any experience with this issue?First of all, don't reformat until you have backed up your drive, as this could cause loss of valuable information!!! Why do you need to reformat? Quote

I must reformat my hard drive and reinstall all programs.  NAV 2005 was originally installed and activated 11/04.  I would like to determine the reactivation process prior to proceeding with my reformat.  Symantec's support site provides no information on this issue.  Has anyone had any experience with this issue?


You may need to contact Symantec before reactivating.

Quote
Why do you need to reformat?
corndale....Re the reinstall of NAV 2005...... If you are doing a clean format as opposed to a restore install......you should not encounter any issues ....... You are allowed to reinstall NAV on the same pc ( 5 times I think without any problem) I would just go ahead and do your clean format....... AFTER you make copies of anything you wish to RETAIN.    It might be a good idea to write down the subscription expiration date .......just in case you have to call Norton .

dl65  Thanks everyone.
317.

Solve : Reactions when finding spyware?

Answer»

Back when i first learned about spyware/adware...I would semi freak-out and panic and think the world is coming to an end  

But now..

I just think "now how in the world did that shady (like its in with the wrong crowd...lol) spyware get on my system?"  And...it doesn't seem like that big of a deal...

What do you all think of itI never get spyware.Are you deathly honestly stick a needle in your eye serious???

I only get it on occasion...However...some software even includes it now...

It can not be completely avoided unless you do not connect your computer to the internet. Quote

I only get it on occasion...However...some software even includes it now...


Read the EULA.

Quote
Are you deathly honestly stick a needle in your eye serious


Not even tracking cookies.  

Quote
It can not be completely avoided unless you do not connect your computer to the internet.


Mozilla Firefox with SEVERAL security extensions.
Mozilla Thunderbird with Gmail. No SPAM whatsoever.
Zonealarm (Program control)
Adaware SE (Obsolete)
AVG Free (Obsolete)
Router with Firewall
Modified Host file
Common sense.

The latest may be the most difficult to obtain. Quote
Read the EULA.


I TRY, most are miles and miles long.  They make me feel like I have ADD.

Quote
The latest may be the most difficult to obtain.


And probably the most important...I never read the EULA either, unless I have a reason to distrust the software being installed.I love viruses/trojans worms......the SCRIPTS are interesting to say the least.......
318.

Solve : Microsoft Anti Spy Ware?

Answer»

Has anyone tried this program?

i got some killer Crap on my PC that the regular Spyware programs could not tuch so i tryed this.

It is kick *censored*. It has Totaly Cleard my PC from 53 things that the rest could not get,

Really download this!


http://www.microsoft.com/athome/security/spyware/software/default.mspx



Ross (one happy guy)I Know It Rules!Microsoft done something right, Free and Good yeh it does. thats the best thing microsoft have done since Flight Simulator 2004 Lol yea, i like to think of Microsoft AntiSpyware as this:
Your computer is a nightclub and theres this guy(Spyware) Who you want out but no luck this guy aint gonner move so you calling in the SWAT TEAM (Microsoft AntiSpyware) It shoots the s*it out of this spyware so and takes it AWAY!Hahahahhahhahahahahahahahahaha.....

I like the fact that it has special features like the Browser Restore....

Plus it connects you to spy net to keep you up-to-date....

Plus Plus...its free!!Oh yes its all GOOD!

Actually, it was bought by Microsoft and created by Giant software. Do not give Microsoft full credit!  yes I agree with Raptor  MS did not produce the Antispyware tool, ALSO Spybot S&D has had PROTECTION for INTERNET explorer , popup, web site browser, protection for a few years but few people used it or new how to
Spybot S&D advanced mode/tools
Spybot S&D advanced mode/host file
Spybot S&D advanced mode/ IE Tweeks
etc can protect just as good as the newly  purchased ex giant software antispyware from ms

319.

Solve : Involuntary Favorites?

Answer»

When I start  up my Windows XP 2 files are added to my favorites. I delete them. When I sign back on trhe same items reappear in my favorites. I can not get rid odf these items.  I have run spybot but the problem still remains. Any Ideas?  Have you downloaded or install any software lately...what websites are they......if you wish to tell us.
curtis...... They could be a nasty .........and there is a entry in the registry which will NEED removing .......What O/S are you using ?

dl65   Quote

When I start  up my Windows XP 2 files are added to my favorites. I delete them. When I sign back on trhe same items reappear in my favorites. I can not get rid odf these items.  I have run spybot but the problem still remains. Any Ideas?  


Exactly what files are these? Quote
curtis...... They could be a nasty .........and there is a entry in the registry which will need removing .......What O/S are you using ?

dl65  



He said XP...I think it could be sometype of new spy/adware or even worse a virus...
Thank you for responding. I have SINCE installed & run the lavasoft adaware which had REVEALED 165 items that I have quarantined.  Still the items reappear.  The items are: 1)7 days of free Porm  2)Sex only Website  3)Log. Also these Items cannot be renamed. I have been told that I would need to do a system restore. What do you think?  I have not done this before.  Any other ways to eliminate these items without doing a system restore? I appreciate your Ideas. This is very annoying.  Empty the quarrentine folder......and reboot pc>> now scan again if they come  back......disable system restore....and scan again.....curtis   If you don't already have it ....d/l Microsoft antispyware Beta ...it's very good ( its free )
http://www.microsoft.com/downloads/details.aspx?FamilyID=321cd7a2-6a57-4c57-a8bd-dbf62eda9671&displaylang=en

I would do the following .....
turn off system restore.
Reboot into safe mode .
scan with your anti virus .
scan with Spybot
scan with Ad-aware
scan with antispyware

remove anything they find .

Reboot back into normal mode and SEE if the problem is gone .

dl65  Thanks again. How is system restore turned off or disabled?http://support.microsoft.com/default.aspx?scid=kb;en-us;310405corlasky....  To turn off system restore in Win XP ......
click ......START/All Programs/Accessories/System Tools/System Restore ......When system restore window opens ...click on system restore settings...... when the system properties opens........ put a tick in the box that is in front of "Turn off system restore on all drives"........then click apply and ok .........

another way to do the same thing is ......click START /Control Panel /System......then choose the SYstem Restore Tab .......put a tick in the box that is in front of....... "Turn off system restore on all drives" click apply and ok .

When you have FINISHED all the scans and your system is clean .......simply reverse the procedure to turn system restore back on .


dl65   Quote
Thank you for responding. I have since installed & run the lavasoft adaware which had revealed 165 items that I have quarantined.  Still the items reappear.  The items are: 1)7 days of free Porm  2)Sex only Website  3)Log. Also these Items cannot be renamed. I have been told that I would need to do a system restore. What do you think?  I have not done this before.  Any other ways to eliminate these items without doing a system restore? I appreciate your Ideas. This is very annoying.  


You may actually wish to disable system restore and rescan your system in safe mode.

Use the following applications:

Virus scanners
AVG Free
-- Anti virus scanner
Trend Micro Housecall
-- Online anti virus scanner.

Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Using only one firewall is advised. Dual firewalls may cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.

These combined should be able to help you get rid of the infection.


This has been discussed! Quote
This has been discussed!


Thanks for letting me know. Stop trying to jag up your post count by posting meaningless messages. I tire of your insolence. Do you really think that I bother to read everyones post? I don't, I only read the posts written by those who are seeking help.

Besides, I won't bother reading your posts since they do not make any sense at all.Thank you. I have followed your instructions however the problem remains, although the computer is actually a little faster now. Is a system restore my only hope?

Sorry if this was discussed before, I had not seen it on previous discussions.
320.

Solve : multiple baddies..help??

Answer»

Hi everybody!  My computer is badly ill.  I had some kind of pop-up thing the day before yesterday, but I  had to go to work, right, I couldn't deal with it, then.  I think my mistake was just HIBERNATING my computer for the day, though, because the minor pop-up issue (ad-aware and spywareblaster and spybot failed to make these go away in the morning) had mutated into a beast that turned my wallpaper blue with a message that said 'security warning: a fatal in IE has occured.  Error was caused by trojan-spy.html.smitfraud.c'  I tried to run my spyware things again, but they just freeze up, and of course internet explorer won't go anywhere but to a start page crowded with 'adult friend' adverts.  I've also got a message that says 'windows explorer has encountered a problem and has to close.'  I don't even know what that means.
So I can't do anything to try and fix this situation on my own because I can't download anything, but I did get a hijackthis log, which looks is horrible.  I know it might be partly because I couldn't scan with my other stuff before I did it, but the pop-ups and bho warnings from spywareguard wouldn't go away after I ran those, so I don't know.  
If there's anything someone could tell me to do without seeing my fat-*censored* log, that would be truly excellent.  I'm just not very keen on transcribing four pages of this thing (about 2 of them look like this: 01 - hosts: 66.180.173.39  www.google. [country abbreviation: ae, am, as, at, and on.]).  If it would help to see my logfile, though, I'll find a way to get it here.
So that's it.  Thanks to anybody who would choose to tackle this; maybe it's not as bad as it seems.
_TuesdayOk its a torjan Horse,

Did you open a Email looking like this?

Smith Barney: Security Maintenance

or did you go to
www.smithbarney.com (DONT GO TO IT NOW!!!!!!!!!)

ok to remove it go here and follow the INSTRUCTIONS.
http://www.wilderssecurity.com/showthread.php?t=75890

he tells it alot better than i could.

Also get rid of the tempory internet files. Right Click on the shortcut to IE then go to properties and click on delete files and clear cookies.

RossCan you still access Windows and can you still use the Internet?

What scanners are you using and what has been located so far?

Can you copy your HijackThis log for us to see?Okay.  
No, Ross, I cannot remember opening an email like that, or GOING to that site.  I'm not even sure why I would in the first place.  I've followed Pieter's instructions as best I could, but the files he was SAYING needed to be removed, they weren't there!  I definitely selected 'show hidden files,' so that wasn't the problem.  They just weren't there, not the ones listed for any version of this smitfraud mother.
I deleted temp files, cookies, and I scanned with all that stuff, only for killbox, I don't know if I typed in the files correctly.  It wouldn't let me paste, so I typed them in one at a time....I have absolutely no clue as to how that might be relevant, I'm just WORRIED that it didn't work like it's supposed to.  
See, the blue screen with the warning is gone and my desktop properties came back, but everything else is still there.  Every time I reboot, all the warnings start blowing up again.  The 'IE must close' and 'Windows Explorer must close' ones put in an appearance every minute or more (whether I'm trying to use IE or not), and none of my taskbar things work.  Spywareguard works for a minute, and then blinks away.  There's a message for all of them when Windows boots up that says they must close.  Also, there are messages for things that have a lot of numbers and letters, saying they have to close, too.  I guess these are processes?

And Raptor, while I can access Windows in this crippled state, IE is definitely not functioning.  
I'm not at all sure what's been located so far.  I'm using adaware and spybot and spywareblaster, and all the ones located listed in the wilders thread (I put them on a disc from another computer).  I remember coolwebsearch and a bunch of popup things, and I definitely had (have) the smitfraud thing.  Also, I saw on the adaware thing (it keeps being reborn), 'winn32.trojandownloader.small.aly' .

I'll copy my hijackthis log, but it's going to take a few minutes.
_Tuesday
You should do the following:

1. Before Windows loads, press F8
2. Select safe mode and press Enter
3. Disable system restore (Windows ME/XP)
4. Use all scanners currently installed

Under no circumstance select safe mode with network support.

321.

Solve : Please help! Many Problems...?

Answer»

Hey guys, been reading these forums recently cause im out of luck, mabe u can help?

Problem #1: I created a new account by accident and it wiped out all of my files from my desktop except for shortcuts and all of my settings are defaulted. Orriganily i had just the admin account but i MADE another, is there a way of reverting back to it ?

Problem #2: A lot of internet based files that I WOULD like to use are have an End Program now because this program is not responding window popping up, it says ( get ready this is a big one) that kernel32.dll is the problem, is my kernel32.dll infected??? it then gives me a path to the "mod name" but i cant find the file.

Problem #3: When i start up windows, i eplorer always opens up automatically and diplays a search page, im THINKING adware.

Problem #4: When i try and play movies in programs like WMP, WinAmp and DivX PLAYER, my computer locks up and the program playing the movie goes to 99 priority and lags my computer to *censored*.

These are the first obstacles, can you guys pleeeaaase help me.AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more USER friendly
Sygate Personal
-- Free firewall - more configuration options
no offence, but that doesnt really help my situation, i have no idea what to doYou do not understand how to install and configure an application?

322.

Solve : random illegal operation message?

Answer»

at randome moments my computer will display a MESSAGE saying istsvc has preformed an illegal operation and will be shut down.i click on details and i see this:ISTSVC caused an invalid page fault in
module ISTSVC.EXE at 0167:00404e78.
Registers:
EAX=80080005 CS=0167 EIP=00404e78 EFLGS=00010246
EBX=0064fc14 SS=016f ESP=0064e6dc EBP=0064fbb4
ECX=0064ffff DS=016f ESI=00008c38 FS=122f
EDX=00000000 ES=016f EDI=0064f388 GS=0000
Bytes at CS:EIP:
8b 02 8b 8D bc f3 ff ff 51 ff 90 10 01 00 00 66
Stack dump:
0064ffff 0064fbc8 00000167 bff91730 c188be70 719a135c 80070057 00000004 c188be70 00000000 0064e72c 719a1809 0064e710 00000094 00000004 0000000a

can u please help me with this"istsvc.exe" is PART of ISTbar. This INTERNET Explorer add-in is spyware and a homepage and search page hijacker.
ISTbar may also INSTALL other parasites including TinyBar, ToolbarCrash, SearchbarCrash, RapidBlaster and Download Plus.
http://www.neuber.com/taskmanager/process/istsvc.exe.html

Your computer has a bug.  Another piece in the ie jigsaw>>>>>you could try this >http://www.wilderssecurity.net/bhblaster.html

323.

Solve : NEED HELP!--Can't use computer...?

Answer»

My brothers computer is no longer allowing him access. It is infected with some SORT of virus. Right now all I know is it is running windows 98. First he said after powering up all his ICONS where listed on the left, and his wallpaper was changed to a blue screen with an advertisement saying click here for anti-spyware... Now it went to a black screen and all icons are missing, only a partial TOOL bar is at the bottom of screen.

PLEASE tell me what to do to get you info to fix his probs.

Thanks in advance!
Well i dont know if there is much you can do. I mean if he is locked out of windows there isnt much chance of you being able to install a antvirus or a stinger!

Because of it only being windows 98 you wont be able to do a system restore back a few weeks then launch the stinger or antivirus.

I dont know myself, but im sure that Raptor or Flame or one of the super smart dudes may know what to do.

Sorry i could not help

RossBoot to safe mode.....hold odwn the f5 key on boot......and chose start WINDWS from the command prompt......A:\>  type this in scanreg/fix..>So it look like this...........A:\>scanreg/ fix      it will display a splash screen re-building reg.....>>>   I would  strongly advise disconnect from the net and run a virus scan before using the above command ok.there you go what did i tell you lol Tis tis...... change the sagam modem ross......to speedtouch!i shall look into it buddy Ok m8 .......and keep an eye on the spam and spyware from you know who! they like people to disable the firewall to get to there main website

sagam MODEMS are as bad as their moby phones...Can you pull the string tighter i can hear you what!Ha Ha your right, I had a Sagem my-x5 (or somthing) and i sent it back to O2 with in the week of getting it. Im pretty sure if i tell you all the bad things about it they would sue me But im Very happy with me Sony Ericsson K500i now.

One of my friends has a strange Fish looking Modem from Freeserve but it is always connected. I still have to Sign in evry time i turn on the pc.

324.

Solve : Disk Utility locked MSN Scan Disk?

Answer»

Urgent need to resolve this problem which renders Scan Disk inoperable:

After some 15 hours scanning (1.5 million bytes), box appeared: "Cannot continue because a program such as disk utility has locked this drive. Close the program or wait for it to finish then restart Scan Disk".
No idea which utility or how to correct it.

Meanwhile I have found and downloaded EMSA DISK CHECK. In 20 minutes it scanned some 4.8 BILLION bytes on C drive. Found 1 error: c:\Windows\win386.SMP.

Unfortunately e.systems.ro offers no Support so I know  not how to correct the error -- whether or not it is the culprit Disk Utility locking MSN Scan Disk.

Look forward to your HELP!

Cordially,  RO

Scan in safe mode.Thanks Raptor for prompt reply.
Please excuse my INEXPERIENCE and provide path to do the Safe Mode scan.

After doing so, will I then be able to use the normal Scan Disk? Will I ever know which disk utility was the culprit,  cause of it locking or how to get rid of it?

I'd also welcome your comments on the ESMA DISK CHECK program, and its results.

Cordially,   ROhttp://support.microsoft.com/?kbid=286810&sd=RMVPSo far, I have only used scandisk to verify the integrity of Hard Disk Drives when these were reformatted.

The steps to Safe mode;

1. Before Windows loads, press F8
2. Select Safe mode and press Enter.Just curious what is your operating system......?win98 is it? Code: [Select]
Thank you Merlin_2 for both replies.
The KB article at first glance was all I needed! Unfortunately, not so. First it's for Melinium edition and second I do not have Speed Disk of Norton, only their anti-virus.

What really bothers me is for several years Scan Disk has run routinely (some 4 1/2 million bytes). What has caused this change I wish I knew.

Yes, I'm on W98SE, 192 mb, IEv6; Toshiba PROTEGE  7200CTe  laptop.

Cordially,  RO

Quote

Scan in safe mode.
You may have chosen the wrong option in the scandisk program.....and CHOSE the thorough....option......reboot pc.....run disk cleanup and defrag.....or go to the hardrive....mainsite and test the drive....maxblast/seagate etc......scandisk may have encountered a bad block/ sector....Thank you, Fed & Merlin_2.

Re FED: Aside from inexperience with Safe Mode, the KB article referred to in earlier reply, specifically says the problem also exists in Safe Mode.

Re Merlin_2: I always use THOROUGH plus checking auto correct errors. I run CleanUp & Defrag daily.   Unsure how to Test Drive but will access Maxblast & Seagate, never mind  ETC!

I would appreciate your  comments re the substitute Scan Disk program from e-systems.com: DiskCheck 1057

Also the one error its scan showed: c:\\Windows\win386.SMP.
What and where (path) can I do about it?
Should it be deleted or repaired?

Cordially,
Safe Mode will only start your computer with the bare essentials.
http://computer.howstuffworks.com/question575.htm
Why don't you hit Ctrl+Alt+Del and see what this dreaded disk locker is?Have you change any hardware....the nearest check is c:\windows \win386\msmp 401 is a an adapter driver......i will have another look when i fire   up the old pc . i would try diskkeeper lite.......and  here is some more things to do with your pc>http://support.microsoft.com/default.aspx?scid=kb;en-gb;835834 Quote
[/quote/]
Hi FED: Much as I've used CTRL/ALT/DELETE it did not occur to me to use it when ScanDisk locks. This may well go a long way to resolving the problem.
When it is named will End Task be sufficient to cure for all times
Howstuffworks verty worthwhile. Thanks.

Hi Merlin_2: Don't even know what hardware adaptors arer, much less having added any.
Your referrence to c:\w...\win386... seems to be the one error that came up on the DiskCheck progtam I mentioned above. Unsure what to do with it, and the other websites in your message very confusing. Hopefully you'll get back to me as indicated. Thank you.

Cordially,  RO
Additional to Merlin_2s
Forgot to thank you for the 125 Tipd for W98. Very good!

Also, Maxblast only sells thongs, but Seagate a real find. I downloaded one of their Disk Checks programs on diskette. Ran it on all three disks listed. All Passed.

Cordially,  RO

Good ...the file mentioned is not related to win98 so just do this tools/internet options/adavanced.....scroll down and untick the display script error notification box....
325.

Solve : Virus update list?

Answer»

Its SEEM that WHATEVER the trojan is ......a common fauilt with winxp etc.....is the desktop icons missing and pc acting strange maybe its time to update your anti-virus program>>Here is the lastest list>>http://securityresponse.symantec.com/avcenter/vinfodb.htmlPeople have read this .......has it helped!Yay! MERLIN and his links...

People get this information automatically when they update their definitions...

Norton always seems to BLOCK Trojan Horses from ENTERING our computer.  It seems I always get blamed for them "trying" to enter....

326.

Solve : nccxbdu.exe?

Answer»

my computer is infected with nccxbdu.exe i cant delete it quarantine it with MCAFFEE internet security suite or giant from microsoft any help?? please help me what do i do i dont have a RESCUE diskerich....  Which program IDENTIFIED it ?   I cannot find anything on   "nccxbdu.exe "   are you certain you have it spelt CORRECTLY ?


dl65   Quote

my computer is infected with nccxbdu.exe i cant delete it quarantine it with mcaffee internet security suite or giant from microsoft any help?? please help me what do i do i dont have a rescue disk


TRY removing it from safe mode.
327.

Solve : 12 Viruses Found?

Answer»

Hi
First of all can somone tell me how i have come to have 12 viruses when i have updated Norton Antivirus regular. Isnt Norton suppose to stop me getting a virus and if not how do i get them.

Are all viruses able to be fixed without having to Reformat my drive. Or do some require that i will have to Format.Norton is SUPPOSED to stop viruses from entering, but only if AutoProtect is enabled.. Is it? Also, when was your last scan?

[GLB]Flame[/glb]Where should it say auto protect. I last scaned about 7-8 weeks ago and found Nothing.From memory....you RIGHT click on the norton icon that sits in the bottom right task bar.......and click the enable norton protect......this may already be so.....and the virus files are held in the quarrentine box...The image displayed on the taskbar may vary depending on which version of Norton you are using... In the 2004 version, if AutoProtect is disabled, you will see a picture of a computer with a red X going through it... If it is enabled, you will just see the picture of the computer without the red X... In the 2005 version, if Autoprotect is disabled you will see a yellow circle with a small red X on it... if it is enabled, you will only see the yellow circle... (Note: Inside the yellow circle is some kind of tool that doctors use, and I know the word but cannot spell it lol  )

[glb]Flame[/glb]Crafty........ Several questions for you.
First ....which version of Norton are you using ?
Then ....what operating system are you using ?
I dont know how much you use you computer , but doing a full system scan once every 7 or 8 weeks isnt OFTEN enough ...... Depending on which version you have ...you should be able to schedule an automatic scan any hour of the day and any day of the week.

Now as far as why do you have "12 viruses "   ....they may not be viruses ...but rather trojans..... Norton is excellant at virus protection ....but doesn't do the greatest job with trojans........ Norton should identify these for you even if it is unable to remove them.

Get back with the answers to my questions and if possible a list of the things Norton identified .


dl65  

Ok thanks for your replys, I am using windows XP upgraded from ME, Norton 2003. I reinstalled about six months ago so i could get latest virus definitions. 

As for the list of viruses found, i will let you know tomorrow as i am away from that computer at the momment.

Yes the Auto protect was already enabled.

After the scan it said recomend to quarentine, so i said yes, then it said could not REPAIR. I went to the report and quarentine there is a list of things wich i will send you tommorow, and again it asked if i wanted to repair, I again said yes, But it wouldnt repair them.

One other thing, Can viewing your email thorough an internet cafe cause this. I was away abroad and just got back, But while away i sent and viewed my emails.

Can the fact i used another computer to view my email, give me a virus, if the computer i used to view the Email had one. Not saying it had one because i dont know, Im just curious.Crafty......ok you reinstalled Norton 2003 .....is the subscription date current or has it lapsed ?

Next ...whatever Norton detected , it was unable to deal with ......... did it not list the offenders and refer you to how to remove them ?

When you were at the internet cafe ....where you using your laptop ?  or ....where you simply accessing your Email thru web mail or something similar ?

If the computer you where using to view was unprotected and infected .....and you simply viewed your messages on Web mail .......the original message would just be stored on the server and you could D/l them when you returned home..........and unless you forwarded the email you viewed on an infected machine to your home pc , there is no way to transfer it .

At least I dont think so ......

dl65  

Not sure what you mean by this, I reinstalled 2003 six months ago and am able to D/L definations and that, but is it the latest ones?. I always thought it was.

No it didnt list anything, it  just asked if i wanted to quarantine and repair at first. i did this but it wouldnt repair. There is a list in the report wich ill send tomorrow as its on the other computer.

No not Laptop just a internet cafe computer i think Unless my Gilrfriend tells me otherwise.

Good point im not sure if i D/l and sent them to myself will let you know tomorrow as im not on that computer now and maybe the Girlfriend did it.

                               Thanks Againmake sure that is the only antivirus software u r running, running more than one can give u viruses i've found!!

328.

Solve : hwclock.exe??

Answer»

anyone know what hwclock.exe is??

is it a valid MICROSOFT file??Name:        Hardware Clock Driver

hwclock - hwclock.exe - PROCESS Information

You should install the security tools that I recommended.zaqualung.......here's what it is .........sounds LIKE you have an infected pc .......

hwclock - hwclock.exe - Process Information
Process File: hwclock or hwclock.exe
Process Name: W32.Hwbot-A Trojan
 
Description:
hwclock.exe is a process which is registered as the W32.Hwbot-A Trojan. This Trojan allows ATTACKERS to access your computer, stealing passwords and personal data. It is a registered security risk and should be removed immediately. Please see additional details regarding this process

What O/S do you have installed ?

dl65  

329.

Solve : nasty infection, please help?

Answer»

OK. My problems first began when a few days ago I booted up my computer

for the first time in a while, as I usually hibernate the system at

night and dont do a full shut down. I found that windows XP would not

boot and I ran Checkdisk using the Windows Recovery Console. The system

then booted fine except that I had no taskbar and my icons were locked

on the screen (immovable). System Restore says it cannot protect my

computer, I cannot load windows Search function, I have very limited

copy/paste abilities (only notepad text will function, and I cannot

move any files). After some playing with the taskbar properties I was

ABLE to show the bar at the bottom; however, minimized windows show

above the taskbar and not in it as usual. The system still takes an

inordinate amount of time to load windows at startup. I have ran Avast,

Grisoft AVG, Ewido, Xoftspy, Registry Mechanic, Registry Fix, Malware

Remover, PCBugDoctor Ad-Aware, Spybot, CCleaner, Mcaffee Stinger, Ace

Utilities Etc; all failing to fix my problem. I have been searching

throughout the internet for days trying to figure out just what has

infected my computer. I tried the Smitrem file and that also failed. I

looked at my HiJack This log and cannot see anything unusual. Im hoping

someone can help me as Im out of ideas.

BTW: whatever has infected my system is also preventing me from running

online scans such as Panda and Trendmicro.


Logfile of HijackThis v1.99.1
Scan saved at 11:26:27 AM, on 7/21/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Documents and Settings\John Fenski\Desktop\framxpro\FreeRAM XP Pro 1.40.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\John Fenski\Desktop\Desktop Shortcuts\Internet and SECURITY Programs\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %SYSTEMROOT%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Documents and Settings\John Fenski\Desktop\framxpro\FreeRAM XP Pro 1.40.exe" -win
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) - http://encarta.msn.com/encnet/external/MSSurVid.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido security suite control - ewido NETWORKS - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Virus scanners
AVG Free
-- Anti virus scanner


Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Using only one firewall is advised. Dual firewalls may cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.Missed spysweeper......from webroot......i would boot pc hold down the f8 safe mode and scan from there......and disconnect from the net while running any scans.......most virus/trojans/worm hide in system restore and windows make it worst by backing the files up..... my system restore feautre has never been used.....its disabled...my choice i may add!tried spysweeper with no positive result.jpfenski.....Just read your post...and I would try this ......
reboot into safe mode .......then turn off system restore .
then run your scans from there starting with your anti virus ..........
BTW ...your hijackthis log file is clean.......


let us know

dl65  I dont think i can turn off system restore bc when i try to load the program it tells me that "system restore cannot protect your computer. please reboot and try to run system restore again" no matter how many times i reboot, safe-mode or not.

i cannot enter system restore to make any changes whatsoever. jpfenski.......Ok .......can you fully boot up in safe mode ?
If you can ...have you tried to run your anti virus from safe mode ?

Do you know if your system restore is turned on or off?

Do you have a floppy drive on your pc ?

dl65  I can fully boot up in safe mode. I ran antivirus in safe mode and saw no difference in detection.

I have no idea if my windows restore is on or off it simply says that system restore cannot protect my computer and to resatart.

I do have a floppy.jpfenski....Ok .....Click ......START/ALL PROGRAMS/ACCESSORIES/SYSTEM TOOLS/SYSTEM RESTORE .........when the restore window opens click on " SYSTEM RESTORE SETTINGS" .......System properties will be displayed .......click on the system restore tab............  In the little square box , is there a check mark ?  If there isn't one it's turned on and if there is one it's off ........ It should be off the do the scans ........

We will deal with the floppy after you reply to this post .

dl65  system restore will not open at all.If you need to disable system restore, you can also do it by taking these steps:

1. Start
2. Run
3. Type services.msc
4. Right click on system restore-service
5. properties
6. Startup type: disabeled

System restore will now be disabeled.John you could also do this >...http://www.michaelstevenstech.com/XPrepairinstall.htm

Unplug the pc from the net if you are going to do the above.......Is this desktop/laptop?when i right click and select properties nothing happens. i cannot change anything in the services.
same goes for local security as i tried to disable the "ctrl-alt-del" at startup procedure. whatever has infected my desktop is probably blocking my ability to change anything in here.Something else to do in the cmd prompt:SFC - System File Checker - (SFC /Scannow)

/SCANNOW
Scans all protected system files immediately.
/SCANONCE
Scans all protected system files at the next boot.
/SCANBOOT
Scans all protected system files at every boot.
/REVERT
Windows XP: Return to default settings.

Chdsk /r   <did you try it?ran chkdsk and scannow. no change in my problem. i think the infection is blocking scripts bc neither trendmicro housecall nor panda activescan will work from the web.

330.

Solve : Removing Viruses?

Answer»

Operating System Windows ME and using AVG Free. The PROBELM is that every time I scan the computer is shows two viruses Have removed each time,  but when you scan again they are there and have done it many times over the past 2 weeks. They have the word restore in the name of the viruses.
Can anyone tell me how to get rid of them? Thanks.
1. Before Windows ME loads, press F8
2. Select safe mode
3. Disable System Restore
4. Rescan.You may want to press Ctrl instead of F8 for ME.ME REQUIRES CTRL? I recall pressing F8 when working on a Windows ME computer.I think it needs Ctrl, I never personally tried it because when I installed ME I deleted it after 5 minutes & put 98 back on.  Actually I think the key for setup is BIOS dependent. At that point in the boot process it's too early for the OS to play a part. If you can DISMISS the splash screen (if any), there is usually an on-screen message telling you what key to hit.

My 2¢ worth.  You're catching my problem Sidewinder, I neglect to read the screen too. LOL The 'other' boot options setup THING mate.Thank everyone will give safe mode a go and will let you know what happens.the key for safemode is f8 the same as winxp!!i would download spysweeper.......


or disconnect from the net and do this......locate the c:\windows\options\cabs  folder....use the search options...to find it......now you have found it...scroll down the list till you come across the scanreg icon...>>...now next to it is one called setup.... if you clicked this icon ...it will re-install winme will no file loss.....and will take it back to the day it was first booted up..........and disconnect from the net......thats the beauty of win9x........Maybe both F8 & Ctrl work?
Does anyone still have ME to try it?
Quote

Booting up in "Safe Mode" is an often-recommended step that many Windows users just aren't aware of. Win 95 and XP users, when Windows is loading, look for the "Starting Windows" message and when you see it come up, immediately press F8 (a few Win 95 machines still use F5 or Del). Win 98/ M E users can just hold down the Control key before Windows begins to boot up.


This looks semi-official lol
http://www.companionlink.com/faq/howto/ht0007.htmlHi Everyone Have done what was suggest Safe Mode etc. Did not clear our the viruses they are still there. One question it was SUGGESTED to disable system restore how do you do that?http://forums.majorgeeks.com/showthread.php?t=31668 Quote
Does anyone still have ME to try it?


Merlin  

Quote
Hi Everyone Have done what was suggest Safe Mode etc. Did not clear our the viruses they are still there. One question it was suggested to disable system restore how do you do that?


I am not quite certain how to do it in Windows ME, but I believe you had to:

1. Right click on My Computer
2. Properties
3. System restore tab
Thanks for that will try and disable the system restore
331.

Solve : DO you want to run the test?

Answer» http://gemal.dk/browserspy/They even have a test for the REALPLAYER virus.  .........Interesting site .......

It even told me my drink needed refilling ....lol

dl65  Most of that SEEMS to be done through JAVASCRIPT.

Download Javascript blocker as a Firefox extension..
332.

Solve : Fireall for ME?

Answer»

Can ANYONE tell where to get a Free Firewall for operating system Windows ME and ALSO Antispyware Microsoft will not run on ME  Thankshttp://www.majorgeeks.com/Sygate_Personal_Firewall_Free_d3356.html

The biggest killer for all o/ses is windows updates.....

No one listens till it to late!!passHere's a listing for all Sygate firewalls, if 5.6 gives you a problem (there is a KNOWN bug in it) then use the version before it. 5.5b2710 and then wait until the bug is fixed in the NEW version.
http://207.33.111.31/spf/ Quote

Can anyone tell where to get a Free Firewall for operating system Windows ME and also Antispyware Microsoft will not run on ME  Thanks


Unfortunately .......M/S Antispyware wasn't designed to run on Win ME .....

For a firewall you might try Zone Alarm ...it's not a BAD one and it's free

dl65
333.

Solve : Cannot delete from favorites & more?

Answer»

A program has placed UNWANTED items into my favorites. When I delete & sigh back on they reappear.  Spybot does not solve the problem. Whan trying to install"CounterSpy" protection I get  an error message which stops the program from loading.  Any Ideas?  Virus scanners
AVG Free
-- Anti virus scanner


Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Using only one firewall is advised. Dual firewalls may cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. Post the HijackThis log GENERATED only if REQUESTED!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant HIJACKER.

334.

Solve : Most wanted person in the world?

Answer»

Whenever i copy a file to the floppy, an image file called 'picture of the most wanted person in the world.jpg' file also copies.  Cannot repair with norton antivirus.  Please helpVirus scanners
AVG Free
-- Anti virus scanner


Anti spy/malware
Microsoft ANTISPYWARE
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

Firewalls
Using only one firewall is advised. Dual firewalls MAY cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a certain kind


HijackThis
-- Manual malware remover. POST the HijackThis LOG generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.Scan in safe mode!Is this your pc!Yea the infected one is my personal PC..currently RUNNING Windows XP Quote

Scan in safe mode!


[glb]Flame[/glb]
If norton displays this: M_2>Cannot repair with norton antivirus.  Please help


I would download spysweeper from webroot.com. As norton has a problem detecting trojans!
335.

Solve : Are they gone??

Answer»

I have erased two toolbars causing problems from my registry.  Like an IDIOT I downloaded Kazaa.  I hope it is all gone.  How to I catch everything?Run all the Raptor scans.   

Virus scanners
AVG Free
-- Anti virus scanner


Anti spy/malware
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
Adaware SE Personal
-- Anti spyware scanner

FIREWALLS
Using only ONE firewall is advised. Dual firewalls may cause problems.
Using a hardware firewall and a software firewall is even more adviced.

ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Removal tools
The following files are not substitutes for the ones described above.
They are either diagnostic tools or removal tools for malware of a CERTAIN kind


HijackThis
-- Manual malware remover. Post the HijackThis log generated only if requested!
McAfee Stinger
-- Virus removal tool. No substitute for a fully functional virus scanner!
CWshredder
-- CoolWebSearch removal tool. Widely known and persistant Hijacker.
Mandy Boyd......Oh,oh ......when you run the scans as suggested by Fed ..........be sure to do that in safe mode to get the best results.
You may even wish to do a manual edit of the registry to be sure that Kazaa is completely removed.

dl65  EASY Cleaners
-- Freeware registry scanner
Registrar Lite
-- Excellent replacement for Windows Regedit
Crap Cleaner
-- Freeware registry scanner/history cleaner

Caution is advised when using these programs!
Create backups of all important files before proceeding.
i would try Microsoft Antispyware...just an idea, i guess...Is that you, Flame...Who, Me?ROTFLMAO!  oops...http://www.free-web-browsers.com/remove-kazaa-ads.shtml


336.

Solve : mssvcnes.exe what is this?

Answer»

everytime i start up WINDOWS a box comes up saying something like
windows cannot find the file name 'mssvcnes.exe'
go to strt and then search to find this file

something along those lines

so anyway when i go to search and TYPE in mssvcnes.exe
it comes up with
01
MSSVCNES.EXE-0DA1132.pf in folder-C:\WINDOWS/Prefetch size-16kb
type-pf file date modified - 27/06/2005

so when i click on this file another box comes up with windows cannot open this file to open this file windows need to know which prgram created it then it gives me a choice on whether i want to search for the program manually or go on the web to find it


what do i do

please help im worried that this is gonna affact my computer asian_angel.....Here's what I would do ........

Go to My Computer   C drive ...........Windows ...open windows folder ...find the Prefetch folder and open it ......then DELETE all the files that are listed in there ...... It wont harm your system to delete them .  Windows will simply replace whatever it needs as it needs it . ( they are junk files )

You should probably run a spyware and malware scanner to clean out your system as well .


Let us know

dl65  u r 100% sure that it WNT harm my system

and if theyr junk files then why wld windows hv those filesYes, DL65 is right. Deleting the files in the prefetch folder will not harm your system. Windows uses the folder for faster loading but over time it just get cluttered with entries. Delete the files within the folder, not the folder itself. Personally I empty my prefetch folder on every boot.

Don't forget to scan for viruses and spyware. hi dl65 i did waht u sed and cleared out my prefetch folder and did a  virus scan using notron but it still comes up with the box saying the file mssvcnes.exe could not be found



waht do i doWhen you boot your computer is trying to start a program that does not exist.
You will need to find that starting entry & delete it.
First try http://www.ccleaner.com and scan for issues.
You could also search your registry for the file name but that's a little TRICKY unless you feel very confident.
Id ccleaner doesn't fix it for you, come back & we can go another step.
What operating system do you have?
Don't panic, this is nothing.iv got windows xpOK, go and do it  i used da system u recomeneded and scanned 4 issues this is what came up click on d image like 2 or 3 times so u r able 2 c wot came up

Click the fixit button then see if your 'mssvcnes.exe' warning has gone.soz i keep replyin  bt am totally computer illeterate

when i go 2 fix selected issues it says do you want to backup CHANGES to the registry

yes or no

which one do i selectSelect yes.iv selected yes but it still comes up with the cannot find mssvcnes.exe dialogueClick Start>Run and type msconfig & hit enter.
Look under the startup tab & see if mssvcnes.exe is trying to start from there.
If it is, untick it, click apply,ok & reboot.
Quote

You should probably run a spyware and malware scanner to clean out your system as well .

Quote
Don't forget to scan for viruses and spyware.

Have you done these things as instructed, if not, do them first.is there a good spyware scanner that you can recomend
337.

Solve : Weird Files!!!!!!!!!!!!!!?

Answer»

I have these files on my computer, and i'm prittty sure they are viruses... There are files like insidegrid and help glue cast
But, I can't seem to be able to delete them.., Always when I try to, my computer tells me that the files are being used and cannot be deleted... My computer is slower than before and I think these files are causing it... I can't find the files in the ctrl+alt+del menu either... They APPEARED in the Application Data folder--->  c:\documents and settings\(user)\application data\"type tick" or "default idle ref"  
I ALSO used the freeware program EasyCleaner to stop some of them from activating when I start my computer, and I even managed to delete some of them, but few of them just won't go away...
Please HEEEEEEEEEELP!!!!!!!!!  HUH Huh Huh Huh Huh HuhPlease only post the same question once...

[glb]Flame[/glb]Google for KillBox Quote

Google for KillBox


Killbox
-- Removes files that seem to be constantly in use.
Driver Cleaner
-- Removes driver remains after the UNINSTALLATION thereof.

Be certain that the files you are removing, are not important[/u] system files
338.

Solve : LOP.COM?

Answer»

I HATE LOP.
Okay, so everytime i restart my computer, the lop.com toolbar and HOMEPAGE and all that is on my computer/IE. Soooo, I go to www.lop.com and click on the uninstall button under help, and I go through this WHOLE process of removing it. (Or, so I think..) So yeah, my computer runs smoothly for a day or so... then it starts running very, VERY slow. I end up restarting it, because it gets to the point where everything freezes and crashes on me. So, I restart it. Thennnnnn, lop.com and all that crap is there ALL OVER AGAIN! Somebody PLEASE help me remove this stupid thing from my computer FOREVER. It is the most annoying thing I have ever encountered.

Thanks in advance!OS?AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and PROFESSIONAL only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options
http://www.lop.com is blocked by my HOST file. You may wish to add it to your host file as well.This could well be a case for Highjackthis.To the HijackThis mobile!

HijackThis download


Ashley T......... Definately a hijacker ........use hijackthis as suggested above .

dl65  Also this may help>http://www.wilderssecurity.net/bhblaster.html

339.

Solve : Firewall issues?

Answer»

Hello! Let me exlpain the story... I installed my modem for my DSL connection, and it worked, but at random moments, it would DISCONNECT for about 1/2 a second, and then jump right back... I just called Verizon, and they thought it COULD be the firewall... So I disabled it... I am using McAfee Personal Firewall Plus... Once I disabled the firewall, this stopped happening... There must be a setting on McAfee that does this... Anyone know what I can try? I don't have a firewall enabled now...  

[glb]Flame[/glb]Are you connected to the INTERNET..? You may wish to take your own advice and add the Router (Most likely 192.168.1.1) to the trusted zone, if that is possible and not allready automatically configured.Yes, I am now connected to the internet flawlessly. Also, I do not have a router. Just the modem...

[glb]Flame[/glb]Is the Windows XP firewall enabled perchance?Yes it is... Is that the problem? McAfee and the Windows Firewall can not be enabled together?!

[glb]Flame[/glb]Try and see. I do not know why you would use both the Windows firewall and a software fireawll, thoughActually, becuase I had McAfee, I kind of FORGOT about the Windows SP2 firewall until now... lol  Anyway... here's the latest... I DISABLED McAfee firewall, and I no longer get kicked off at random moments! One problem... If I re-enable it, it'll do the same thing again... There must eb a setting that mcAfee firewall has that is trying to block the connection or something... Any dieas?

[glb]Flame[/glb]You might look to see if there is some kind of Internet Zone Control Wizard. Norton has one and most likely so does McAfee.

My 2½¢ worth.  Hey Sidewinder. I found something like that wizard, and changed a few things around. So far, so good. Thanks for the reply guys! I'll keep the status posted should anything happen...  

[glb]Flame[/glb]So the gay McAfee & Norton are playing with the gay XP firewall? ROTFLMAO!  
Show them all the closet door and get AVG & Sygate.Wait Fed... Take a closer look.... There is no conflict between the software... For some reason McAfee (which is quite gay), is cutting off my connection at random moments for about 1/2 a second. No software conflicts... That was justa theory. lol  I messed with some of the settings, as suggested, and the problem seems to be fixed!    I think you just misunderstood the problem.  

[glb]Flame[/glb]CEO of Mcafee?



Or a FUTURE prediction of Flame's fashion choice?It IS quite fashionable... lol  (No way in *censored*) lol   Actually Raptor, I think this might be the CEO of McAfee... Maybe.. lol  remember?

Flame, I didn't have to read your problem to know how to fix it.
Just remember though, when you try to uninstall McAfee and Norton, go to their websites for the special uninstall (virus removal) instructions. I think Norton even has a removal program for it's software (virus).  So you favor McAfee over Norton?  

[glb]Flame[/glb]

340.

Solve : Major PC problem?

Answer»

Hi, newbie here - hope you can help. My PC has suddenly and for no apparent reason decided to slow down to a near crawl. I have tried a system restore - no good. I have tried defragmenting - got to 3% after 36 hours so I stopped it. I ran Spybot - it found some bogeys - but would not fix thme - said some dll file was missing? Now i cannot even start it up. It gets as far as my wallpaper and the start button and thats it - after about 8 hours. I'm assuming this is malware-related but i really don't know. Any help would be much appreciated.Well, if you can not start the computer, then your best THOUGHT would be to reformat....

[glb]Flame[/glb]Yeah - but i was hoping to avoid this in order to avoid losing all the data. The problem seems to be progressive - at first it was slow to boot up, but did and I was able to connect to the Internet, now it is just freezing.Have tried safe mode? Run spybot and your AV from there.Do you have a CD burner? You can SAVE all your data to a CD in safe mode and then erase if you can not fix it...

[glb]Flame[/glb]Thanks - Gonna try that when I get home - wasnt SURE whether spybot would work in safe mode. I know its hard to tell but is it possible it's a hardware problem? thats another reason I don't want to reformat - I'd hate to erase all taht data and then find out it's the CPU or something.Yeah - i have a CD burner. Thanks I'll try this.Actually, many people do not know this, but you SHOULD run system restores, etc. in safe mode for the best results... Suprising eh? Give us a shout when you get a chance to try these suggestions...

[glb]Flame[/glb]AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options

Download, install and configure these programs. Apply them in safe mode.Have most of those on the PC.

Tried running Spybot in safe mode. Safe Mode took about 20 minutes to boot up. Spybot ran ok and found a number of problems - however, when I tried to fix the problems it came up with various errors. One said a dll file was not a valid windows image. Another said a dll file (wbtengine.dll) could not be found.  You should use a registry cleaner first.Where will i get a registry cleaner? I can't connect to the Internet in Safe mode. When I try to boot up normally it just freezes.If you are using Windows XP, you should select safe mode with NETWORK support

Or copy the data ONTO a medium.

Easy Cleaners
-- Freeware registry scanner
Registrar Lite
-- Excellent replacement for Windows Regedit
Crap Cleaner
-- Freeware registry scanner/history cleaner

(Does anyone have any recommendations?)I recommend that we first try and figure out what the OS is. It's a waste of time trying to clean it up while restore is running.HJT LOG

Part 1:

Logfile of HijackThis v1.99.1
Scan saved at 17:45:38, on 08/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\sistray.EXE
C:\WINDOWS\System32\khooker.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\OpenOffice.org1.1.0\program\soffice.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Colin Shaw\Desktop\HJT\hijackthis1991.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.co.uk
R3 - URLSearchHook: (no name) - {34A44FCF-50E3-63A5-A8DA-7835752B9571} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\System32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: OpenOffice.org 1.1.0.lnk = C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe
O4 - Global Startup: Image Transfer.lnk = ?


341.

Solve : Shields up or down!?

Answer» READ more on SHIELDS up &GT;>>>..http://grcsucks.com/

342.

Solve : startpage 19j?

Answer»

i have STARTPAGE 19j and can't get rid of it AVG picks it up but it keeps comming back have also RAN SPYBOT and adware. running'98 (see ASLO ian kings download problems) I would download the best........spysweeper from webroot.......avg/spybot no comment.....

343.

Solve : AVG problem?

Answer»

I have the free version of AVG installed on my computer. Today when booting it said "Internal virus database is out of date".....I go to Check for updates and it says "No NEW update file is available at this moment.

How can I solve this problem? I feel totally unprotected at this moment.Is this the LATEST version of AVG?

[glb]Flame[/glb]Yes this is the 7.0
Would I be better to purchase the profession version? I cannot even get onto the AVG forum. They sent me a password, etc, but when I go to LOG in it says I am still unregistered...........Sheeshhhhhhproblem solved!! I had messed up the calendar date, and it was reading AUGUST....THUS throwing everything off!!

Ok, so your problem is solved now, right?

[glb]Flame[/glb]AVG even tells you if you screw up your dates.

344.

Solve : flsmngr.dll. What is that??? Help...?

Answer»

I got a message on my desktop that flsmngr.dll is not a valid windows icon. I look at the sistem folder ...system32 and this file was 0 bytes. After that I can not connect to the Internet. It says  "can not find the server". When I delete flsmngr.dll the message disapear but I still can not use IE. I ran SpyBot and Ad-Aware SE and it says that the disc is clean. What can I do. Help me please!!!!!!!!If you are certain that you do not need the file, remove it from safe mode.

CastleCops Flsmng.dll. Seems to be part of a Hijacker. Remove it.I delete it in save mode, the warnning message disapeare but the IE still SAY "cannot find server".After deleting I restart the PC but st ill nothing. Is it a good idea if I reinstall the IE?Now in the blue line on the top of the open WINDOW it says: " C:\WINNT|System32|shdoclc.dll|dnserror.htm". What that mean???Is this winme??your internet explorer is damaged ....what version 4/5/5.5/6It is a LITTLE bit old   hahahah  5What you suggest to re-install it with a later versio???No!  go to the control panel///add/remove/ scroll down the list and click on the internet explorer program....now click the add/remove button....a splash screen will apppear.....click the repair option.......I can't see the IE in Add/Remove programs. miso25...... flsmngr.dll ....... this little beauty is part of the CWS assistant ( hijacker) as Raptor pointed out ......So simply D/L hijackthis ....... scan and save logfile and post it here and we can tell you what to mark for removal.

dl65  Sorry man but I don't know how to do it. Please tell me.
My IE still says "cannot find server". I checked the connections but nothing. I am on LAN settings.download this a run it>http://www.majorgeeks.com/CWShredder_Last_Merijn_Version_d4086.html and keepit on your desktop

another nice onre to try is spysweeper.........

i would recommend you disable system restore.....i dont use system restore myself??I don't know what happened!!!! I downloaded the file, eextract it and run it. I got only two OPTIONS- 1. scan or 2. fix.
I scan it and it was clean but there was a very short summary probably 10 lines.
Do you know what is that- CSNW - Client Service for NetWare?? I got this in Control Panelhttp://www.wilderssecurity.net/bhblaster.html

http://windowsxp.mvps.org/IEFIX.htm

^Two to try.^.....or you could   do this disconnect your pc  from the net.. type   scanreg/restore after the msdos prompt and
chose the last good cab file.....answer yes to the splash screen.....

345.

Solve : Tons of e-mail?

Answer»

Help!! All of a sudden I'm receiving 1000's of messages that says mail is undeliverable. It seems I have a virus or SOMETHING that is cranking out messages that are not being accepted thus the return messages.
I run Lavasoft adaware and spybot to no avail. My o/s is windows me.
Anybody help?Take a deep BREATH. It's Spam E-Mail... There's been a lot of that going around... Is there a link there to a German website? It's no virus...

[glb]FLAME[/glb]What or who is your E-mail provider? Quote

It seems I have a virus or something that is cranking out messages that are not being accepted thus the return messages.

Exactly right, you have a worm just like Flame's mother.
Run some anti-spyware/virus programs to find what it's name is, then Google for a removal tool.
http://www.pandasoftware.com/activescan/
It may also be that a zombie has spoofed your email address and is sending them out with your name on them, watch your internet activity & see if your sending stuff when you shouldn't be.Actually Fed, no worms were found... It's just Spam from what I can see...

[glb]Flame[/glb]Yeah right Flame, so now you're in denial eh?  
Notice though, kilowatt is not receiving direct email, rather he's receiving bounced email so his problem seems to be more than a sudden surge in spam.
They're getting pretty tricky now, my wife & probably ½ the planet, receives email from herself that is sent from someone else.one of your mates is USE a mail bomber.......download mailwasher......or block the emails.........if you are using outlook .....use your isp webmail instaed.....remove outlook via the add/remove.......click windows setup......then click outlook express remove....or scan for bugs in safe mode.......or disable system restore then scan....Hey, thanks all.. I'm sort of slow. Let me state my problem again. I'm getting these e-mails (1000's of them). They are coming from services all over the WORLD. They all say that my message was undeliverable. All state just that but of course in different words. I have sent none of these mails. It seems someone or something is creating mails under my address and when they can't be delivered I receive the undeliverable responses. I have run spybot, spysubtract, lavasoft adaware. All these have served me well in the past but they do nothing for this. I guess I could just change my address.. couldn't I? I use outlook express.
Thaks again.I see 3 possibilities.
1) Your own computer has been taken over and is serving as a zombie, sending emails without you being aware of it.
1st step, check your firewall for internet traffic when there shouldn't be any activity.

2) Another computer is sending the emails out & using you as the return address.
1st step, carefully check the email headers & see if you can find how you're being spoofed.

3) See Merlins post above, he must have some fun mates.

PS, try some other antibug programs.
http://www.pandasoftware.com/activescan/

Download, install, update & run
http://www.microsoft.com/athome/security/spyware/software/default.mspxWho or what is your E-mail Provider?!Hi there!
I know I am just a newbie here but as FED stated I was receiving 100s of emails that apparently had been sent by me and were being returned as 'undelivered'.

Killowatt if you want to spend some time looking at the cause:
1. to check that your computer is not sending these emails ie you have a worm, by checking your connection when on the net - if you are not sending or receiving then your status should show no activity therefore no worm
2. if someone has hijacked your email address there are 3 ways to stop it. The first and easiest is to change your email address   second is to download an ANTI-SPAM programme eg G-Lock spam combat and the third is longer but more effective   go to the spoofer's ISP and complain

346.

Solve : What is Learn2 Player?

Answer»

In Add or REMOVE Programs there's "Learn2 Player (Uninstall Only)". Can anyone tell me what exactly this is and what the purpose is... and most importantly, is it legit?It's a browser PLUGIN like REAL player or adobe reader.
It is legit but only useful for specialised files.
Google for "Learn2 Player"Thanks - I did google Learn2 Player but didn't find much as to what I WANTED to know. I did see a lot of people asking what it was... But ANYWAY, thanks

347.

Solve : removed spy ware and cant access files?

Answer»

I recently removed spyware and now my comp. cant find files ALSO I cant display any icons on my desktop area,and my programs arent closeing properly  :-/What scanner have you used?ADAWARE Ihope this is right IJUST followed inst. I dont kow much about comp.What have you removed?
Ok heres the deal.
Im using windowsxp professional.
I had spysherrif, i found instructions on a forum and it worked.
What i did to remove spysherrif was do a adaware scan then a ediew scan then i usued cleanup then hijack this.
However my desktop icons dissapered, clicking on the desktop does nothing. I do have a taskbar and start button.
Also I cant install programs, windows installer feezes in the middle.
Also some services were disabled by someone such as remote assistance.
I do not have my windows installation cd.
I hope I explained everthing well enough.
Thanks in advance for the help.You may wish to restore whatever you have removed and try programs that are easier to configure and allow for more efficient/friendly REMOVAL.

Also be certain to disable system restore. You had best scan in safe mode.

Pick from this list:

AVG Free
-- Anti virus scanner
Adaware SE Personal
-- Anti spyware scanner
Microsoft Antispyware
-- Anti spyware scanner. Windows XP Home and Professional only.
Spybot Search & Destroy
-- Anti spyware scanner
ZoneAlarm Free
-- Free firewall - more user friendly
Sygate Personal
-- Free firewall - more configuration options
well system restore isnt working so i cant restore BACK to before the removal .
if you have any solution for my situation that im in now then ill be outta the woods.
thanks in advance for the helpI was actually referring to the back-ups most programs create when they remove files. See if these backups are still present.

348.

Solve : Trojan Simulator?

Answer»

Try it out  
http://www.misec.net/trojansimulator/I have the EICAR files on an ECDL CD. They WORK very well.

I will also look into this Trojan test.There is a site that allows you to send the eicar virus to your computer in about 20 different disguised ways.
It will also allow you to send it to friends & enemies too.
But I'd use an untraceable proxy for the latter.
I HATE the 1 minute time delay on Winpatrol but they are fixing up SPYBOT so I guess it won't be LONG before I can use it again.Spybot S&D can do what Win Patrol can?

I only install Spybot S&D on other machines, so I never work long enough with it to try all the functions.You need to enable the teatimer in spybot to protect your computer in real time.
I believe spybot will be up there with the best soon, they just need to sort out the gui problem.Might install that as well, then. Will you still be using WinPatrol?Nope, once the spybot gui is fixed I'll stop using Winpatrol, I don't like the minimum 1 minute setting for displaying registry changes, the paid version is real time.
Spybot has a heap of features & when I can use it I want to fully learn the program.Good idea. Keep me informed.

349.

Solve : open ports?

Answer»

how to KNOW my computer's open ports?

If i am using firewall (zone alarm), can HACKERS STILL see the open ports?How have you set it up.........check your logs?/\

more info here&GT;http://lists.gpick.com/portlist/portlist.htmDOS prompt 'netstat -a' or a free portscan at
http://scan.sygate.com/
You could ALSO download & run fport from a dos prompt.
fport, every computer should have it. Quote

how to know my computer's open ports?

If i am using firewall (zone alarm), can hackers still see the open ports?



Gibson Research Company.

Take the ShieldsUp! tests.
350.

Solve : Registry Key?

Answer»

I got rid of Aurora/Nail USING spyware software. I have a regestry key named aurora in my REGISTRY editor. I cannot delete nor CHANGE permissions. All suggestions appreciated. Thanksre-boot pc and try again....Rebooting does not work. I got rid of aurora a week ago. I just happened to come across this registry key while looking for something else. Thanks anyway.You may wish to use a registry scanner.

Removing it from safe mode MIGHT work as well.Is this a uni pc........