InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3451. |
Solve : Possible virus problem?? |
|
Answer» Hi all, romi.... ok....... reboot the XP machine into safe mode and run scans with both AVG anti virus and AVG antispyware. I will do that tonight when I get home. But I did do a full scan with AVG Free and nothing turns out. Will follow up.romi.... Was the scan run in safe or normal mode ? dl65 Follow what dl65 already advises but make sure you have exposed all Hidden Files & Folders first. To enable the viewing of Hidden files follow these steps: 1. Close all programs so that you are at your desktop. 2. Double-click on the My Computer icon. 3. Select the Tools menu and click Folder Options. 4. After the new window appears select the View tab. 5. Put a checkmark in the checkbox labeled Display the contents of system folders. 6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. 7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types. 8. Remove the checkmark from the checkbox labeled Hide protected operating system files. 9. Press the Apply button and then the OK button and close My Computer. *********************** (On Windows 2000 or XP)... Download Ewido/AVG Anti Spyware from here …. http://www.ewido.net/en/ It has a fully working 30 day trial period. Install it and update it to the latest definitions. Do NOT use it yet. Now boot to safe mode. Here’s a “how to” if you’re not sure .. http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 When in safe mode run a full system scan with AVGAS and let it fix what it wants to. REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it. Reboot to normal mode and use the computer as you would usually do. [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time]. Post back the scan report and update us. OJ |
|
| 3452. |
Solve : Difference-McAfee Antivirus & AOL AntiVirus? |
|
Answer» I am setting up a P-III for my daughter. She already has an AOL account. I purchased McAfee's latest AntiVirus program for installation on her computer. However, I see that AOL offers free AntiVirus by McAfee. Other than the fact that the AOL version is free, what, if any, are the DIFFERENCES between the 2? A friend who has the AOL version told me that it is very disk intensive. Does the AOL version include AOL related items which cause it to be more taxing on the computer's CPU?I'm not too well educated on AOL and its services, but where I come from, whenever an ISP offers a virus scanner its usually a farce and only good for scanning E-mail. Have you got a link for me so I can have a look-see? I'm not too well educated on AOL and its services, but where I come from, whenever an ISP offers a virus scanner its usually a farce and only good for scanning E-mail. Have you got a link for me so I can have a look-see?I agree. I have SecurityCenter and it works really well and I love the features, but I still have AVG as a backup because McAfee doesn't catch everything.AVG Free. 4 years running and no problems... Actually from what i read i BELIEVE AOL is now using Kaspersky for their protection package... |
|
| 3453. |
Solve : impossible situation? |
|
Answer» Are there any experts out there that can help? - I have employed 5-6 computer techs and one networking specialist company and nobody can figure out what is up with my computers. We clean the hard drive - flash the bios, on one repaired the MBR - and trojan always comes back - a python scripting program that rewites the registry and takes control. Is this a problem at some other level like the video memory or ram? Excuse my ignorance, I am not a computer person - but I so need my computers back as it has been 10 weeks and I have a business that is suffering! Please, any advice! I think that it was a link through this site that helped me discover that it was a "rootkit" about 4-5 weeks ago - Now I need to get some ideas about how to get rid of it! Thanksneedtoknow........ It sounds like you have more than one machine , is that correct ? Scan saved at 7:48:20 PM, on [highlight]6/29/2005 [/highlight]Todays date is Feb 21ST 2007 2. Quote Platform: Windows [highlight]XP SP1 [/highlight](WinNT 5.01.2600)The current SP is 2 ........ why do you not have it installed ? 3. I can see no evidence of any Anti virus program installed ........Why not ? 4. I can see no evidence of any firewall installed ...... Why not ? 5. The installed java is also out of date . 6. Do you have all the latest M/S updates installed ? 7. Was this hijackthis scan done in safe mode or in normal mode ? We await your reply. dl65 It really is odd seeing such a short log. One thing I'd like to add... You may want to move your copy of HijackThis to a permanent location. You currently have it in Temporary Internet Files, where it and its backups are likely to get deleted. I would suggest making a folder called HJT in C:\Program Files and moving the program there where it can be nice and safe.Two small comments. needtoknow ... you say your systems "share one printer". Maybe that's the problem. Wiping hard drives, reinstalling but finding the same problem recurring indicates an external issue. IMPORTANTLY ....do NOT install SP2 on any machine belived to be infected with malware. It will cause more trouble as it won't install porperly. OJOK-relax---- I am using this laptop for nothing else than to find out what is going on and why this ugly thing keeps taking over my system. I had to reinstall the ops system and It took me 2 hours to get an internet connection - My focus was not on updating to SP2, it was on getting a log. I found the driver for my ethernet connection and got the log, turned off services for remote server, etc., turned off the computer and went to bed too late. When I got up and booted up all those services were running, and my connection was gone - my ethernet not visible on devices. Can somebody please tell me where the trojan can be besides the hard disk? In the RAM? In the video memory? I am not a computer person! But after repeated attemps to wipe all my computers (new desktop, laptop) this thing always comes back. I don't know if I need to camp out at the police station until computer crime division helps me??? 3 mo's without a computer and I have a business - countless "techs" have not been able to help me. Any ideas??You have frequently remarked that you have wiped disks and reinstalled. I have a feeling that something you "reinstall" contains this "bug" or whatever it is. This file .... C:\WINDOWS\System32\S24EvMon.exe .....brings up differing opinions. I don't have it running on my machines personally but others say it is "vital", others that "it is optional and won't do any harm if removed/stopped" and some even go so far as to say it can cause havoc with internet connections and is completely unnecessary. It's a monitoring file/process. It may be that, if you stopped this process running, you may improve things. As I say I am not an expert on this particular process (others here may have more idea) but I guess stopping it can't make anything worse. It would be good to try and get just ONE of your machines up and running before linking it up to the others. Please let us know what you think. OJYes, I agree that I should try to just get one of my machines up and running - but have not been able to do this in many weeks. I keep getting the same level of control by remote server. My big QUESTION is: where can this keep loading from? I am certain that it is not coming in from internet - it did once but now it is being stored somewhere besides my hard drive - Is this information that only a specialist would have? Do I need to find a specialist? ThanksHave you tried disabling/stopping/removing that file I specified in my last post? What was the result? OJ |
|
| 3454. |
Solve : Check this out? |
|
Answer» Can one of you check this out please when start up and press f8 all goes well but i cant move the up and down keys to safe mode. If using something other than a PS/2 its possible there arent any drivers available in safe mode. dl65 dl165 Quote What kind of keyboard and mouse are you using ?Wireless with mouse,drivers did come with it but instructions said "not required for xp" not sure who made it one of these made in china [ HID Keyboard Device ] Keyboard Properties: Keyboard Name HID Keyboard Device Keyboard Type IBM enhanced (101- or 102-key) keyboard Keyboard Layout United Kingdom ANSI Code Page 1252 - Western European (Windows) OEM Code Page 437 Repeat Delay 1 Repeat Rate 27 [ HID-compliant mouse ] Mouse Properties: Mouse Name HID-compliant mouse Mouse Buttons 5 Mouse Hand Right Pointer Speed 1 Double-Click Time 690 msec X/Y Threshold 6 / 10 Wheel Scroll Lines -1 Mouse Features: Active Window Tracking Disabled ClickLock Disabled Hide Pointer While Typing Enabled Mouse Wheel Present Move Pointer To Default Button Disabled Pointer Trails Disabled Sonar DisabledI 'm thinking that in safe mode the required drivers for the wireless keyboard isnt being loaded ...hence you cant use the up /down arrow keys to load in safe mode....... try going into safe mode using a ps/2 keyboard ......... dl65 Quote try going into safe mode using a ps/2 keyboard .........Thanks for that i will have to borrow one Why is it so important to scan in safe mode and why don't the company's who produce anti virus software also advise this??.so in other words normal scanning is useless!!!!!!!!! unless scanning is done in safe mode Does the hijack log file LOOK ok?? SkyblueHi skyblue I recommend you print this out to help you follow the advice. Your HJT folder is in a temporary location. The program makes automatic backups and there is a danger those backups will be lost. Please go to the HJT folder here .... C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe ....and move it the C: drive for safety. ************ These entries in your log ... C:\Program Files\Multimedia Combo Set\MouseDrv.exe O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe" .... may indicate the presence of the CRYPTER.A Trojan. Please go here ... http://www.virustotal.com/en/indexf.html Browse to the file ... C:\Program Files\Multimedia Combo Set\MouseDrv.exe Upload it to Virustotal ... scan it for malware .... post back the results here. ************ Boot to safe mode ... open HJT again ... click on scan ... put tick/checkmarks next to the following entries IF they are still present ... R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O18 - Filter: text/html - (no CLSID) - (no file) Close ALL open windows - including this one - before you click on "Fix Checked" at the foot of the HJT window. ************ Reboot to normal mode, scan again with HJT and post back the results of the Virustotal scans and the fresh HJT logfile. [NOTES >> I see you have Limewire. I don't recommend it as it's a potential source of malware infections but that's your choice. Your java is a little out of date. You should update to to version 6 and uninstall/remove all older versions via Add/Remove Programs.] OJOJ Did as you advised Logfile of HijackThis v1.99.1 Scan saved at 08:41:40, on 17/02/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\sistray.EXE C:\WINDOWS\system32\keyhook.exe C:\Program Files\QUICKENW\QAGENT.EXE C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\SiteAdvisor\6021\SiteAdv.exe C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE C:\Program Files\Multimedia Combo Set\MouseDrv.exe C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Tesco internet phone\TescoIP.exe C:\Program Files\PCPal\PalAgnt.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\WINDOWS\system32\mrtMngr.EXE C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\ZyXEL\ZyXEL G-202 Wireless Adapter Utility\ZyXEL G-202.exe C:\Program Files\LimeWire\LimeWire.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\Program Files\SiteAdvisor\6021\SAService.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\WINDOWS\system32\msiexec.exe C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/ F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe O4 - HKLM\..\Run: [QAGENT] "C:\Program Files\QUICKENW\QAGENT.EXE" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6021\SiteAdv.exe O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE" /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe" O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Tesco internet phone] "C:\Program Files\Tesco internet phone\TescoIP.exe" /autostart O4 - HKCU\..\Run: [PCPal] "C:\Program Files\PCPal\PalAgnt.exe" /startup O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O4 - Global Startup: ZyXEL G-202 Wireless Adapter Utility.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://driveragent.com/files/driveragent.cab O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4963/mcfscan.cab O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6021\SAService.exe O23 - Service: Windows Defender (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing) And heres the scan STATUS: FINISHED Complete scanning result of "MouseDrv.exe", received in VirusTotal at 02.16.2007, 17:40:56 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.16.2007 no virus found Authentium 4.93.8 02.15.2007 no virus found Avast 4.7.936.0 02.16.2007 no virus found AVG 386 02.16.2007 no virus found BitDefender 7.2 02.16.2007 no virus found CAT-QuickHeal 9.00 02.16.2007 no virus found ClamAV devel-20060426 02.16.2007 no virus found DrWeb 4.33 02.16.2007 no virus found eSafe 7.0.14.0 02.16.2007 no virus found eTrust-Vet 30.4.3405 02.16.2007 no virus found Ewido 4.0 02.16.2007 no virus found Fortinet 2.85.0.0 02.16.2007 no virus found F-Prot 4.2.1.29 02.15.2007 no virus found F-Secure 6.70.13030.0 02.16.2007 no virus found Ikarus T3.1.0.31 02.16.2007 no virus found Kaspersky 4.0.2.24 02.16.2007 no virus found McAfee 4964 02.15.2007 no virus found Microsoft 1.2204 02.16.2007 no virus found NOD32v2 2066 02.16.2007 no virus found Norman 5.80.02 02.16.2007 no virus found Panda 9.0.0.4 02.16.2007 no virus found Prevx1 V2 02.16.2007 no virus found Sophos 4.14.0 02.16.2007 no virus found Sunbelt 2.2.907.0 02.15.2007 no virus found Symantec 10 02.16.2007 no virus found TheHacker 6.1.6.059 02.16.2007 no virus found UNA 1.83 02.14.2007 no virus found VBA32 3.11.2 02.16.2007 no virus found VirusBuster 4.3.19:9 02.16.2007 no virus found Aditional Information File size: 503808 bytes MD5: 89dd130712f2b1b8507d83f3c405c3df SHA1: cb6671c8112c90dcb7fc2a2db024a51c4deabd9 d Hi The log looks better (apart from Limewire, IMO) but you haven’t successfully moved the HJT folder to a permanent place. All you have done is move it to another "temporary" location. Can you go to the HJT folder .... left click on it ... hold the mouse button then "drag & drop” the folder directly on to your C: drive? That should do the trick. How is your computer behaving now? Can you boot to safe mode? How's your web browsing experience? Still wrong or OK now? OJQuote How is your computer behaving now? Can you boot to safe mode? How's your web browsing experience? Still wrong or OK now?Thanks for your help Seems to be ok ,but i still cant get into safe mode, the up and down keys still don't function,btw up and down keys work in normal mode Quote try going into safe mode using a ps/2 keyboard .........O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" is the above a ps/2 keyboard Skyblue PS Why!!!!!! Quote Why is it so important to scan in safe mode and why don't the company's whoHi again Can't get to safe mode .... First thing you need to check is if the keyboard is fully functional. If you can get in to BIOS - F1, F2, Del, F10, depending on the configuration of your machine, if you can access this, and your arrow keys DON'T work, then your keyboard has had it. If they do, its a software problem and you'll need to reinstall Windows. For a long shot, try a PS2 keyboard attached, see if that helps. [credit for this tip .... Kevin Gibson, ST&T member] try going into safe mode using a ps/2 keyboard ......... You ask "why". Often when a user is working with a wireless or USB device something...well... just screws up. A ps/2 connected device is lighter on resources, uses simpler drivers etc. Sometimes, when a wireless or USB device doesn't work fully, a ps/2 device will work. It's always worth trying. Why is it so important to scan in safe mode and why don't the company's who produce anti virus software also advise this??.so in other words normal scanning is useless!!!!!!!!! unless scanning is done in safe mode The simple reason is that much malware won't run unless the computer is fully booted up. Booting to safe mode stops such malware running and makes it inactive. That makes it easier for malware detection programs to detect their presence and do something about it. Most protection programs will also run in normal mode (some perhaps will ONLY run in normal mode) and I suspect the manufacturers feel that the average user won't understand an instruction to "boot to safe mode before scanning with (our product)". They feel a uesr WOULD much rather just scan in normal mode for simplicity. Also it depends on what type of malware the progam is scanning for. Some are just as easy to fix in normal mode as safe mode. My advice ... always scan in safe mode unless the program bring used specifically instructs scanning in normal mode only. Please post back again and let us know how you are geting on booting to safe mode etc. OJOJ Firstly thanks for your lengthy explanation why we have to scan in safe mode, makes sense i suppose(just like to now why we have to do things a certain way) Now back to the problem F2 got me in bios and the up and down keys worked perfectly I also tried my old keyboard and that also works in bios and safe mode in your opinion is it the new wireless keyboard that is or is it a reinstall, if its the latter i think i will leave things as they are since all the functions seem to work OK in normal mode, and if i need to go in safe mode its just a case of plugging in my old keyboard SkyblueSo long as everything ELSE is working as it should I think you can assume the trouble is indeed with that keyboard. Yes, you can do what you suggest, and only use the other keyboard if you need to go to safe mode, but I would also try uninstalling then reinstalling the malfunctioning keyboard first. Also run a full system scan with AVG Anti Spyware to give it a good spring clean out. Good Luck. Safe surfing. Post back if you've further questions. OJ |
|
| 3455. |
Solve : Trojan Protection? |
|
Answer» Hello, I was wondering what is the best trojan software I should purchase? I am not a constant online gamer but I do play games online now and then. Also I do use p2p PROGRAMS not often but occasionaly as well. I have McAffe secuirty centre but as you know, an anti-virus program is not enough to protect against trojans. What do you think of McAffe anyway? |
|
| 3456. |
Solve : Still having problems. Here's my HJT log.? |
|
Answer» NOPE. None of those. Anywhere else I could look?You say that windows reports a "driver error". Doesn't it give you more information than that? If so PLEASE post it here. OJWhen my COMPUTER shuts off and turns back on sometimes it says "system has RECOVERED from a serious error". I posted the screencap in that other post. Then when I send the report to Windows it takes to to a page that say it was a driver error. No other info was given as to what driver and why. It said it couldn't give me any further information.I looked into the driver ISSUE and found this page: http://support.microsoft.com/kb/322205 That is what my computer is doing. I don't recall updating any drivers though. Maybe it is my printer driver? I think that might have ATTEMPTED to update. So I'm reinstalling the one from hp.com in hopes of something.Due to lack of response this thread now locked. Should the original poster require it re-opening please PM GX1_Man or a moderator. they pm you GX |
|
| 3457. |
Solve : trojan - Hijack This logfile? |
|
Answer» Posted here as per Patio’s direction. Thanks!
Logfile of HijackThis v1.99.1 Scan saved at 11:58:23 PM, on 3/9/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Common Files\AOL\1139894366\ee\AOLServiceHost.exe C:\Program Files\TrojanHunter 4.6\THGuard.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe C:\Program Files\palmOne\Hotsync.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\TrueAssistant\TrueAssistant.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\WINDOWS\system32\msiexec.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Linda\Desktop\HijackThis.exe R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe O4 - HKLM\..\Run: [SBC Yahoo! Connection Manager] "C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe" O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe" O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitcontinued... O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {1A595EDD-978A-48C7-B730-AF3B9CC64DAB} (DLManager Class) - http://63.251.81.180/component/VZWDLManager.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117792072028 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101 O17 - HKLM\System\CCS\Services\Tcpip\..\{ABCFFC5C-3D5E-4F5B-9141-D589A1061FEC}: NameServer = 85.255.116.70,85.255.112.101 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101 O17 - HKLM\System\CS1\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101 O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing) O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 4:53:56 PM 3/9/2007 + Scan result: HKU\S-1-5-21-1801674531-1454471165-682003330-1004\Software\Internet Security -> Adware.Generic : Cleaned. :mozilla.76:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.77:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.78:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.79:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.41:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.37:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.38:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.39:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.40:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.42:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.67:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.64:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.65:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.66:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.61:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.62:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.59:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.74:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.75:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Linda\Cookies\[emailprotected][1].txt -> TrackingCookie.Yieldmanager : Cleaned. ::Report end ~~~~~~~~~~~~~ No evidence of ny virus or spyware remains (not that I can see). There is no trace of the odd # icon. I agree w/ your advice on removing LDM and would appreciate your help in that. As per your warning to check w/ my ISP in regards to those 017 items, I did and was advised against including them in the fix. Lastly I updates Java and as seen above, have posted the HJT and AVG logs. Thank You! Hi Again I suggest you print this out. Update your AVG Anti Spyware to the latest definitions again and scan your machine. The log should come up more or less clean again. Remember to do this regularly to help keep the computer out of trouble. ************** Removing LDM & Viewpoint…… Go to Add/Remove Programs and uninstall/remove the following programs …. Viewpoint Logitech Desktop Messenger ************** Open Task Manager …. Highlight these Running processes …. Click on End Task to stop them IF they are running (let me know which ones you didn’t find) …. C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe ************** Fix these entries with HijackThis in the same way you did before IF they are still present…. O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing) O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe [Remember to close ALL open browser windows before hitting “Fix checked”; if windows remain open the fix may not work] NOTE >>> I am concerned that the cfmon 023 entry is still present in your log. Did you miss this one in the last fix? Has it returned after you fixed it with HijackThis? If it won’t go away peacefully we will have to use another method to remove it. Let me know what happens. ************** I can assure you those 017 entries trace back to the Ukraine and relate to the scum that send out much of the malware on your machine. I am very surprised your ISP told you not to fix the entries. I still believe you should fix all those four 017 entries with HijackThis. Who is your ISP and what exactly did they say? Did you get the impression they definitely knew what they were talking about or that, maybe, they were unsure & just playing safe. ************** Please post back a fresh HijackThis log with feedback on the above various issues. We’ll take it from there. OJHi, thanks again! My ISP is Roadrunner/Time-Warner cable. I called tech support, told them I had a trojan, that I was using HJT to fix the problem, and also that I was told I should confirm with them before deleting those items. Actually he did sound as though he was playing it safe. I read it for him over the phone "HKLM\System..." and asked him if any of that sounded familiar. He said yes and that I should not delete anything that contained Tcpip as that is what enables me to connect. In my own head I was thinking well yeah, but isn't that also something one of those nasty little buggers would use too? I'll go out on a limb here and say that oddjob's expertise is light years ahead of the tech support guy at Time Warner...Quote I'll go out on a limb here and say that oddjob's expertise is light years ahead of the tech support guy at Time Warner... yep, I'm inclined to agree Thanks for the approbation. It should be safe to kill those 017's with HJT. Open HJT ... click on scan and fix those four 017 entries IF they are still there and IF they still have exactly the same IP numbers as they did before. Then carry out the rest of what I asked in my last post. Thanks. OJThis thread has been locked now that it is resolved. Should the original poster require it re-opening please PM GX1_Man or a moderator. |
|
| 3458. |
Solve : Hi there, another analysis please.? |
|
Answer» Hi there, ive done everything, Anti Spyware, Virus scan and its cleaned up. But before i do i think tis worth mentioning that when ever on this computer the URL www.google.com is typed in it redirects us to http://uk.msn.com// The .co.uk version of Google works fine though. If someone could analysis this i would appreciate it. Thanks
Thanks ChrisIf you can't do anything for so long then that log will be useless. HJT logs are only any good if they are acted on in, max, 2 days. By alll means try what I suggest but I won't be surprised if the next log is worse than the first. OJHuh? SORRY how come that is? ChrisMalware attracts more malware. If there's malware in a log it will be active until fixed. If the infected computer contines to be used online during the intervening period there is a strong possiblity it will be infected further. Don't forget to post the three things requested at the end of my first fix. We'll see how the computer is then. All the best. OJ |
|
| 3459. |
Solve : norton Update without internet? |
|
Answer» I have a norton antivirus 2002 installation and I have an internet connection. I am able to run LIVE updates on my computer. HOWEVER I have installed the same norton antivirus 2002 at my friends place but he does not have an internet connection. Which folder or files shall I copy from my updated norton (from my hard disk drive) to my friends place (WITHOUT using live update at friends place) so his norton antivirus will to be up-to-date. I believe this is the PAGE you are looking for. The page also includes LINKS to instructions to update without an internet connection. Hope this helps. Calum. |
|
| 3460. |
Solve : Does this sound like a virus to you?? |
|
Answer» Before my current computer, I had an eMachines W2247 with Windows XP Home SP2, 128 MB, and an AMD Athlon XP Processor 2200+. It's been awhile, so I can't remember anything I had done, but it just totally crapped out one day. It first started having a lot of trouble booting up, and then by the end of the night, it wouldn't boot up at all. Or even attempt to. To this day, when I turn it on, nothing happens. The power light blinks on and off, but that's it. It doesn't MAKE any noise or anything. Also, the lights on the keyboard will blink in a random pattern. Does anyone have any idea of what might be GOING on with it? |
|
| 3461. |
Solve : Pop up virus? |
|
Answer» Thank you for your help it has been very useful. |
|
| 3462. |
Solve : Analysis/Help please? |
|
Answer» Well, i'll give a little background I guess. You could call me a gamer, and as most people do - I encounter the occasional virus or adware problems. I use McAfee which includes a firewall and virus scanner as well as Webroot Spy Sweeper which has many accessories (spy sweeper, startup shield...I'm sure most of you know this already.) With those TWO things I can usually get rid of most viruses I COME across. |
|
| 3463. |
Solve : Problem with ie? |
|
Answer» Quote Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.I find this confusing. I have J2SE Runtime Environment 5.0 Update 11. That update occurred on 2/15/07; it was automatic, since I have Java to automatically check for updates. So, I supposedly have the latest version. Yet, you say the latest version is Java Runtime Environment (JRE) 6. I just opened my Java Control Panel and CLICKED on the Update Now button to see whether it would GET another update. It tells me I have the latest update. What's the scoop here?soybean .... please do not hijack someone else's THREAD. Please start your own topic. OJBut ..., hijacking is fun. Actually, I debated about whether to post the question here or start a new topic. I'll post it as a new topic.This thread has been LOCKED now that it is resolved. Should the original poster require it re-opening please PM GX1_Man or a MODERATOR. This thread has been locked now that it is resolved. Should the original poster require it re-opening please PM GX1_Man or a moderator. |
|
| 3464. |
Solve : inetsrv folder? |
|
Answer» I am running WINDOWS XP Home, SERVICE pack 2. |
|
| 3465. |
Solve : Another analysis please?!? |
|
Answer» Hi there. This time its MY laptop. I cant finish the other one i have posted until Tuesday like i said. First off, my SB S&D keeps telling me its removed these entries below, but whenever I do a scan they return. Im doing the scans with Sys Restore turned off. Any Ideas?! |
|
| 3466. |
Solve : Suspicious dll in XP (trojan related I'm sure)? |
|
Answer» GLAD all seems to be well again. NOW you can do what I suggested in post #9 SAFE surfing. OJ |
|
| 3467. |
Solve : Autorun.inf Virus? |
|
Answer» Hello everyone, |
|
| 3468. |
Solve : Help Unable to View Links with IE 6? |
|
Answer» unlovedwarrior ... no problem. Please add anything at any time if you feel it would be useful. Nhksrv.exe > Should be OK. See here .. http://www.liutilities.com/products/wintaskspro/processlibrary/nhksrv/ snmp.exe > Again, should be OK. Microsoft SNMP Agent service that allows the user to configure and manage the SNMP (Simple Network Managament Protocol). **************** littelp24 ... You should print this put to help you follow the advice. Make sure you have EXPOSED all Hidden Files & Folders. To enable the viewing of Hidden files follow these steps: 1. Close all PROGRAMS so that you are at your desktop. 2. Double-click on the My Computer icon. 3. Select the Tools menu and click FOLDER Options. 4. After the new window appears select the View tab. 5. Put a checkmark in the checkbox labeled Display the contents of system folders. 6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. 7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types. 8. Remove the checkmark from the checkbox labeled Hide protected operating system files. 9. Press the Apply button and then the OK button and close My Computer. *********************** Download Ewido/AVG Anti Spyware from here …. http://www.ewido.net/en/ It has a fully working 30 day trial period. Install it and update it to the latest definitions. Do NOT use it yet. Now boot to safe mode. Here’s a “how to” if you’re not sure .. http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 When in safe mode run a full system scan with AVGAS and let it fix what it wants to. REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it. [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time]. ******************* STILL in safe mode ... open HJT ... click on scan ... put tick/check marks next to these entries IF they are still present ... R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing) O15 - Trusted Zone: http://www.match.com O15 - Trusted Zone: http://www.mcartsworkshop.com O15 - Trusted Zone: http://www.webkinz.com O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://download.iwon.com/ct/pm3/iwonpm1,0,2,5.cab Remember to close ALL open browser windows – including this one – before clicking on “Fix Checked” at the foot of the HijackThis window. NOTE >> The 015 fixes above are optional. I would never keep anything in the Trusted Zone. It's just too dangerous. However, it's your choice to fix them or not. ******************* Reboot to normal mode and use the computer as you would usually do. ******************* Update your Webroot Spysweper to the latest definitions and scan the computer with it. Let it fix what it wants to. ******************* Make sure you have the latest version of java installed. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update. Updating Java:
Also make sure your antivirus and firewall are both fully up to date. ******************* Run a full system-wide search of your computer for iwon. Post BACK the results here giving the locations of anything found. Also post back a fresh HJT log and the scan report from AVG Anti Spyware. Let us know if anything has improved. OJ |
|
| 3469. |
Solve : Some nasty virus resident memory! Need help!!? |
|
Answer» Hi everyone,
Please post the results of the AVGAS scan and a fresh HJT log. Please also say how your computer is operating now. OJI was working on the above fix whilst you were posting your most recent comments. As you can see you have multiple problems but please proceed with the fix I posted. That should clean you up quite a bit. We can move on from there. OJNice Work, oddjob !Hi, And thanks OJ for your advice. I just got a 'little' problem with what you wrote...I can't reboot in safe mode. On the net I found this (below) for I taught I may have the Win32.Agent.zf. It suppose to help me reboot clean...Remember that I have win2k pro pack4. I would appreciate if you can tell me if it is a good thing to do or not. Here here goes: '' Manual removal: 1. Create a c:\rescue.bat file which contains the following strings: @echo off :try del C:\WINDOWS\SERVICES.EXE if exist C:\WINDOWS\SERVICES.EXE goto try 2. Modify the following system registry entry: from [HKLM\System\CurrentControlSet\Services\Eventlog] "ImagePath"="%SystemRoot%\system32\services.exe" to "ImagePath"="C:\rescue.bat" Doing this ensures that rescue.bat will be launched instead of the Event Log system servcie. 3. Reboot the computer. The Trojan will be deleted once the system has been rebooted. 4. Restore the original ImagePath value: [HKLM\System\CurrentControlSet\Services\Eventlog] "ImagePath"="%SystemRoot%\system32\services.exe" 5. Delete the following keys from the system registry: [HKLM\Software\Microsoft\Serenta] [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "SERVICES.EXE"="%Windir%\SERVICES.EXE" 6. Modify the following parameters: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] "Shell"="Explorer.exe %Windir%\SERVICES.EXE" to: "Shell"="Explorer.exe" "Userinit"="C:\WINDOWS\system32\userinit.exe,,%Windir%\SERVICES.EXE" to: "Userinit"="C:\WINDOWS\system32\userinit.exe" 7. Update your antivirus databases and perform a full scan of your computer (download a trial version of Kaspersky Anti-Virus). '' I won't do nothing till I hear from you. Prulon Hi again, I just post not so long ago. A pop up always come that say that winmgmt.exe had generated an error and will be closed by windows you will need to restart the program. No program seem to work at the time. Here the log file: (Thu Sep 22 15:20:02 2005) : core was asked if ok to unload and returned 0x1(Thu Sep 22 15:23:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 15:53:19 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:21:22 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:37:04 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:40:37 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 17:16:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 17:25:57 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:23:30 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:33:33 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:35:06 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 20:02:06 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 20:05:19 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:22:51 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:47:20 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:53:10 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 08:14:23 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 11:51:21 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 12:01:59 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 12:07:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 14:44:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:02:09 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:05:40 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:21:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:43:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 17:34:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:04:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:37:41 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:44:47 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 08:24:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 13:25:53 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 13:45:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 23:38:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 00:14:16 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 10:38:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 23:16:01 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Sep 26 23:29:43 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Sep 27 14:50:08 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Sep 27 18:40:25 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 08:06:41 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 11:00:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 11:57:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 29 08:08:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 30 22:39:28 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Oct 01 22:48:23 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 03 02:17:39 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 04 12:40:08 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 04 13:11:16 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 05 12:55:10 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Oct 06 23:00:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Oct 07 19:53:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Oct 08 22:42:22 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Oct 09 08:15:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Oct 09 22:27:17 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 10 21:31:32 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 11 22:01:33 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 12 07:49:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 12 23:51:25 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Oct 13 20:26:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Oct 14 23:36:43 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 17 22:27:31 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 18 21:47:04 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 19 Next I'll post the last hijackthis log. Prulon |
|
| 3470. |
Solve : NOD32 Diskette, How Can I do it?? |
|
Answer» How can i create a DISKETTE from NOD32, to BOOT and VERIFY the computer?? |
|
| 3471. |
Solve : question about Inspiron running slowly? |
|
Answer» I recently came into possession of a Dell Inspiron 6000; before me, it was owned by a friend. |
|
| 3472. |
Solve : How can I tell if someone is on my computer?? |
|
Answer» Ok my computer has been acting a little funny latly, and I was woundering if it is possible if someone had maybe cracked my computer. What are some of the signs that someone else is using your computer/system? I have heard of things called Trojan Horses before but what else could it be? And what can I do to get rid of whatever it might be or tell if there is even anything wrong at all? I only use avg and I run it everyday. Is there any other free anti virus programs that I can dowload to help keep my computer safe? Do you have Service Pack 2 (SP2) installed?Mellisa ... if you don't have SP2 installed DO NOT install it yet. If your computer in infected with malware SP2 will not install correctly and could make your problems worse. OJLogfile of HijackThis v1.99.1 Scan saved at 1:41:56 PM, on 3/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Acer\Empowering Technology\admServ.exe C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\RioMSC.exe C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TELUS eCare\bin\mpbtn.exe C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\winlogon.exe C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE C:\Program Files\TELUS eCare\bin\mad.exe C:\Program Files\LimeWire\LimeWire.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Melissa\Local Settings\Temporary Internet Files\Content.IE5\C04X7RVQ\setup[1].exe C:\DOCUME~1\Melissa\LOCALS~1\Temp\is-A65TL.tmp\is-SQL77.tmp C:\Program Files\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe" O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe" O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe" O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe" O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe" O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe" O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe" O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe" O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe O4 - HKLM\..\Run: [TELUS] E:\Install\TELUS.exe O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe" O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\IO4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Startup: PowerReg Scheduler V3.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Melissa\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe OK Melissa. Having looked at your log, and remembering your concerns, you have two options. OPTION 1 If you are still concerned about other people somehow having access to your personal information the only real way to fix it is this ... 1. Save all your important information, music, pictures etc. 2. Reformat/wipe your hard drive clean 3. Reinstall the operating system, all programs and information/pictures etc. That way you can be virtually certain that any unauthorised access to your computer will be gone. THEN you can re-register with any sites WITH NEW USERNAMES AND PASSWORDS. OPTION 2 You can try to fix whatever is causing your concerns but there are no guarantees here and it will take a long time. Certainly longer than Option 1. If you want to try Option 2 to this is the first stage ........ There are things wrong with the log so let's address those first. This first fix will be over two posts. Please print out or copy both posts to Notepad in order to assist you when carrying out the following instructions. Read everything to ensure you understand it all before you start work. ************** I suspect many of your problems come from using P2P. Limewire in particular. My advice is for you to stop using P2P and remove Limewire completely. It's a magent to malware. If you decide to do this tell us in your next post. ************** Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK. ************** Download Ccleaner from the link below but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) … http://www.ccleaner.com/ Run the program immediately with the default settings and let it clean out/remove the clutter from your system. ************** Download Ewido/AVG Anti Spyware from here …. http://www.ewido.net/en/ It has a fully working 30 day trial period. Install it and update it to the latest definitions. Do NOT use it until you reboot into safe mode later in this fix. ************** Go to this file ... C:\Program Files\TELUS eCare\bin\mad.exe Right click > properties & see if it’s a Microsoft file.Tell us what you find. This file is found on Windows NT4/2000/XP/2003 Server editions only. This service is the System Attendant Service for Microsoft Exchange Server from version 4.0 onwards. Do you know why you have this file on your system? ************** Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Here’s a “how to” if you’re not sure .. http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 Login on your usual account. Make sure to close any open browsers. ************** Click > Start > Control Panel > Add / Remove Programs and uninstall the following program (IF it still exists): BroadJump ************** Run a full system scan with AVGAS and let it fix what it wants to. REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it. Reboot to normal mode and use the computer as you would usually do. [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time]. ************** Open HijackThis and click on 'Do a System Scan Only'. Check the following ENTRIES (If they still exist, make sure you do not miss any)...... R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe O4 - Startup: PowerReg Scheduler V3.exe O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM O20 - AppInit_DLLs: Please remember to close all other windows, including browsers then click Fix checked. ************** Delete the following Folder and Files indicated in BOLD IF they still exist ..... C:\Program Files\BroadJump .... whole folder PowerReg Scheduler V3.exe >> run a system wide search for this file and delete it IF found ************** Reboot your system in Normal Mode. Now do what I advise in the next post. OJ Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update. Updating Java:
There is one piece if scumware that hides itself if it knows HJT is running so you need to rename the HijackThis program. This will reveal it. Right click on the HJT file itself and click on rename. Change the name to "MelissaHJT.exe". Now run the MelissaHJT.exe file (which still HJT with a new name) and post the log. Please also post the AVG Anti Spyware log AND an update on how you feel your computer is working now (or if you've decided to choose Option 1 instead). [By the way please take care when you post your HJT log. The last line at the end of your post number 6 has been cut off. Please make sure you post everything] OJI think you scared her off with Option 2... Who knows. Melissa............And there you have it...Due to lack of response this thread now locked. Should the original poster require it re-opening please PM GX1_Man or a moderator. |
|
| 3473. |
Solve : Invisible files? |
|
Answer» Hello |
|
| 3474. |
Solve : "Locking" abandoned malware topics?? |
|
Answer» Sorry oddjob I should have explained it clearer. If it ain't broke don't fix it.It doesn't hurt to make improvements. Quote A HJT training thread would go great in the FAQ forum IMO.I agree, but I think it'd be even BETTER if we had our own training "school". It's just too bad we don't have the resources to do so.My post #10 indicates TWO different wordings when LOCKING the thread AND a prompt to the OP on how to reopen if needs be. Hopefully OPs will be intelligent enough to realise what to do and not get irate with mods/admins. This process works well on other sites and I have no reason to think it would work differently here. Fed ... no, I'm afraid I don't know him/her. I only know a few people at ASAP itself. Actually, I think they could do with help themselves on their own HJT analysis work. People become members of ASAP not necessarily to help out at that site but to carry on whatever work they were already doing on other sites. As to a "HJT training" sticky I've said already that I would be happy to put something together but I do need the authority/approval of site admin to do it, I think. Especially if site admin is to pin it as a sticky. CBMatt ... yes it would be excellent to have our own HJT training school but, as you say, the resources required would be massive. Anyway, as you already know, there are plenty of excellent training schools already around. OJ |
|
| 3475. |
Solve : ** NEW HJT**? |
|
Answer» Quote My ADVICE would be for INFECTED users to not use the program at all until it's RELEASED from beta.Fair enough but, if they do, then they shouldn't hit the "submit" button. OJWell, yeah, with a EULA like that, I'll have to agree. |
|
| 3476. |
Solve : Help - HijackThis Log attached!!? |
|
Answer» Hi, I was hoping someone could please help. My computer was infected with a virus called W32.Alcra.F - I have deleted all the infected files, but when I go to the "Run" window and type 'cmd' I get an error message. I have been able to bypass this by typing 'command' but when I try to type 'cd %SYSTEM%' I get an error message saying it is an invalid directory. I'm not sure what to do because 'regedit' doesn't work anymore as a valid command either.
Please go to MSConfig and enable all items at startup. ************* Post a fresh HJT log AND an update on how your computer is operating now. OJHi Again. Ok so I've updated my Java and I wasn't sure where temporary file was so I saved the HJT.exe file to my desktop. My run/cmd/regedit commands still aren't working...here is my latest HJT log (I've unhidden the folders and other stuff as instructed) Logfile of HijackThis v1.99.1 Scan saved at 8:13:29 PM, on 3/13/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\AOL\Active Virus Shield\avp.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe C:\Program Files\Microsoft Hardware\Mouse\point32.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\qttask.exe C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\AOL\Active Virus Shield\avp.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Dell Support\DSAgnt.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe C:\PROGRA~1\Webshots\webshots.scr C:\WINDOWS\system32\msiexec.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [POINTER] point32.exe O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [aol] "C:\Program Files\AOL\Active Virus Shield\avp.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/duanereade/app/opcuploader.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\ O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing) O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing) O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe This line in your log ... C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe ....still says that the version of HJT you are running is located in a temporary folder. Again the log isn't showing anything dreadful. That said, HJT doesn't see everything. Not by a long way. Can you use run/cmd/regedit in safe mode? Please run these online scans. Make sure the first two are set to clean automatically .... Panda Activescan > http://www.pandasoftware.com/activescan/com/activescan_principal.htm TrendMicro Housecall > http://housecall60.trendmicro.com/en/start_corp.asp?id=scan Kapersky > http://www.kaspersky.com/virusscanner (NOTE >> this scanner will detect malware but will NOT remove it. I need to see the scan report). There will be files that these scans will not remove. Please include that information in your next post. Reboot and post a new HijackThis log and the info you saved from these virus scans. OJTry running cmd.exe instead of cmd and regedit.exe instead of regedit. If they run then search your computer for cmd.com and regedit.com and tell us what you find? |
|
| 3477. |
Solve : Email - DO NOT OPEN? |
|
Answer» I received a STRANGE EMAIL today, with the following recipients: please read the attachment Attachments include vitamin.doc and wordicon.exe. I find this email, and the number of recipients, highly suspect. If ANY of you get this message, DO NOT OPEN.thnx for the warning DilbertThanks for the info, Dilbert. Do you happen to recall the subject of the e-mail so we could maybe catch this a bit easier?No subject.Quote No subject.Always a bad sign IMO. Doubly so if you don't recognise the SENDER's name(s). OJ |
|
| 3478. |
Solve : Major brower problem.? |
|
Answer» all of my browers i have seem to do the same what ever i do to try and correct it ..... it changes to some random page like .... http://winantivirus.com/download/2007/My edit in bold is the key here. Winantivirus is malware and a definite unwanted program. Part of the Vundo/Virtuemonde scum. Download VundoFix.exe to your desktop from here .... http://www.atribune.org/ccount/click.php?id=4 * Double-click VundoFix.exe to run it. * Click the Scan for Vundo button. * Once it's done scanning, click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, your desktop will go blank as it starts REMOVING Vundo. * When completed, it will prompt that it will reboot your computer, click OK. Note >>> It is possible that VundoFix encounters a file it could not remove. In this case, VundoFix will run on reboot; simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot. You may need to run it a few times to get rid of it fully. Post back and let us know how you get on. OJLogfile of HijackThis v1.99.1 Scan saved at 13:47:50, on 14/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\CTsvcCDA.EXE c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\CTXFIHLP.EXE C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe c:\program files\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\MSI\Live Update 3\LMonitor.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Download Manager\DLM.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\MSI\Core Center\CoreCenter.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\Robin\My Documents\VundoFix.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\sktjvkvo.dll",setvm O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Logitech SetPoint.lnk = ? O8 - Extra context menu ITEM: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision CORPORATION - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe i use mcafee internet security (firewallplus, antivirus, antispam & privacy service) i have adaware personal, search and distroy and i also used trend micro's online scan vundofix picked up 9 files in my system32 folder....vundo got rid of the files and i have done any scan i can find and it seems to have fixed it, if u can check my hijackthis log and see if theres anything left i would be greatfullThe log is clean of vundo but still a couple of things to sort out. Open HJT ... click on scan ... put a tick/check mark next to this entry IF it is still present ... O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE Remember to close ALL open browser windows before clicking on "Fix Checked" at the foot of the HJT window. *************** Now carry out a system-wide search for this file ... ALCMTR.EXE DELETE it. *************** Empty your recycle bin. *************** Your Java is a little out of date. Older VERSIONS have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update. Updating Java:
If you are having no more problems please post back once more to confirm and I will let you have some final advice on PC protection. OJok i did all what u said and everything seems great, except my printer problem but i will post in a diff topic for that. u said u have some advice for me?? i use mcafee as my main securityIf you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis. More on System Restore ... http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx What may have lead up to your infection and help keep your computer free of malware … http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html There is a little duplication but these tutorials are both well worth reading. If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) … http://www.ccleaner.com/ Also run through this before posting another HijackThis log … http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html Best wishes. OJok its kinda back, i did a vundofix and it didnt work, i have mcafee site adviser, ccleaner, spyblaster, adaware, search and distroy. it redirects me to this http://64.111.208.122/click.php?c=7acef945551a0b3da504&r=1 helpppppppppp......Please download FixwareOut from one of the following sites ..... http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe http://downloads.subratam.org/Fixwareout.exe Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead. Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. Once the desktop loads please save the text that will open report.txt. Note: ONLY if you have connection problems after performing above steps - go to Start > Control Panel choose work connections, right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) and select the radio button that says obtain DNS servers automatically. Click OK twice and restart your computer. ************** Now install Ccleaner from the link above and clear out your system with it. After all this please post back a fresh HJT log, the report.txt and an update on how the computer is operating now. OJdidnt fix it Logfile of HijackThis v1.99.1 Scan saved at 18:13:11, on 15/03/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\WINDOWS\system32\CTsvcCDA.EXE c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\SiteAdvisor\5248\SAService.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\CTXFIHLP.EXE C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe c:\program files\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe C:\PROGRA~1\mcafee.com\mps\mscifapp.exe C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\MSI\Live Update 3\LMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\SiteAdvisor\5248\SiteAdv.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe C:\Program Files\MSI\Core Center\CoreCenter.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file) O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe" O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\5248\SiteAdv.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe" O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Logitech SetPoint.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\5248\SAService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe report.txt Fixwareout Last edited 2/11/2007 Post this report in the forums please ... »»»»»Prerun check »»»»» System restarted »»»»» Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" .... .... »»»»» Misc files. .... »»»»» Checking for older varients. .... Search five digit cs, dm, kd, jb, other, files. The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection. Click browse, find the file then click submit. http://www.virustotal.com/flash/index_en.html Or http://virusscan.jotti.org/ »»»»» Other »»»»» Current runs [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" "CTDVDDET"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\DVDAudio\\CTDVDDET.EXE\"" "RCSystem"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" RCSystem * -Startup" "AudioDrvEmulator"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" -1 AudioDrvEmulator \"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\Audio Emulator\\AudDrvEm.dll\"" "VolPanel"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\Volume Panel\\VolPanel.exe\" /r" "CTHelper"="CTHELPER.EXE" "CTxfiHlp"="CTXFIHLP.EXE" "UpdReg"="C:\\WINDOWS\\UpdReg.EXE" "Launch LGDCore"="\"C:\\Program Files\\Common Files\\Logitech\\G-series Software\\LGDCore.exe\" /SHOWHIDE" "Launch LCDMon"="\"C:\\Program Files\\Common Files\\Logitech\\LCD Manager\\lcdmon.exe\"" "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" "VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask" "VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe" "OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe" "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe" "MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe" "MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe" "MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding" "MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe" "MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup" "HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe" "ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\"" "LiveMonitor"="C:\\Program Files\\MSI\\Live Update 3\\LMonitor.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" "SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\5248\\SiteAdv.exe" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\"" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" .... Hosts file was reset, If you use a custom hosts file please replace it »»»»» End report »»»»» Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions. *************** Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK. *************** Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers. *************** Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any) O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file) Please remember to close all other windows, including browsers then click Fix checked. *************** Delete the following File indicated in bold IF it still exists[/b] ...... C:\WINDOWS\system32\qgbvftac.dll *************** Reboot your system in Normal Mode, use it as you would usually do and let us know how it's working now. Please also post back a fresh HJT log. OJ |
|
| 3479. |
Solve : Trying to see if I have viruses? |
|
Answer» Fixwareout Last EDITED 2/11/2007 Post this report in the forums please ... »»»»»Prerun check »»»»» System restarted »»»»» Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" .... .... »»»»» Misc files. .... »»»»» Checking for OLDER varients. .... Search five digit cs, dm, kd, jb, other, files. The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection. Click browse, find the file then click submit. http://www.virustotal.com/flash/index_en.html Or http://virusscan.jotti.org/ »»»»» Other »»»»» Current runs [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe" "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot" "AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky ANTI-Virus 6.0\\avp.exe\"" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -SILENT" "AIM"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" .... Hosts file was reset, If you use a custom hosts file please REPLACE it »»»»» End report »»»»» this was my fixit report. I dont know if something is wrong but it is shorter than other peoplesHi Psychopath34 What made you think you had a wareout infection? It may be shorter because you didn't have the malware in the first place so perhaps Fixwareout had nothing to "fix". If you want to check if you have viruses, and try to remove them, please do this. Download Ewido/AVG Anti Spyware from here …. http://www.ewido.net/en/ It has a fully working 30 day trial period. Install it and update it to the latest definitions. Do NOT use it yet. Now boot to safe mode. Here’s a “how to” if you’re not sure .. http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 When in safe mode run a full system scan with AVGAS and let it fix what it wants to. REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it. Reboot to normal mode and use the computer as you would usually do. [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time]. ******************* If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here ……. http://downloads.malwareremoval.com/hijackthis_sfx.exe Save it to your Desktop. Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder …… C:\Program Files\HijackThis Go to this folder and run the hijackthis.exe file. From the menu click on "Do a system scan and save a logfile". Copy and paste both the AVG AS scan report and the HJT logfile to this thread. At that time also give us some idea of why you have concerns about viruses and malware problems on your computer. More specific removal instructions will follow for whatever it is that's worrying you. OJwell, from time to time on my taskbar, the button sometimes grow smaller and I'm not doing anything.Not quite sure what you mean but proceed with my advice and use Ewido/AVG Anti Spyware & HJT. Post the logs back when finished WITH an update on how the computer is operating now. OJ |
|
| 3480. |
Solve : Patching?? |
|
Answer» How do you patch up holes in your machine?By installing patches. |
|
| 3481. |
Solve : Your opinion? |
|
Answer» CBmatt I think HJT should be the last resort for actually removing malware.really?!! is HJT not safe or somthin?!!Yes, it's not safe if you don't know what you're doing. You can disable your antivirus accidentally, or even apparently render your computer unbootable.Quote from: DeltaSlaya on August 28, 2007, 03:25:44 PM Yes, it's not safe if you don't know what you're doing. You can disable your antivirus accidentally, or even apparently render your computer unbootable.and how does one know that he/she is doing the right thing? dont we just run HJT and send the log file to be studied by someone who has good knowledge about all this! what can possibly go wrong in doing that?Quote ... it's not safe if you don't know what you're doing. As above.Ivy, simply scanning with HJT and posting a log will do absolutely nothing to your computer. This doesn't make any changes whatsoever. However, if someone uses the program to remove things, they could easily do some serious damage if they don't know what they're doing. That's why you shouldn't trust these sites. It's best to be instructed by someone who has had proper training and knows what everything does.Oh now i understand! this means HJT is absolutely safe if you know the right thing to do.Yes, exactly what I said. If you just scan nothing can go wrong, it's checking and 'fixing' the entries that does the damage. |
|
| 3482. |
Solve : AVG Free edition- reccuring result question.? |
|
Answer» So I keep getting the following results every time I scan my computer using AVG Free edition. It's updated daily and is a wonderful program so far. But I'm new to It and I'm not sure what this means? (i) kernel32.dll CHANGE C:\WINDOWS\system32\kernel32.dll (i) user32.dll Change C:\WINDOWS\system32\user32.dll (i) shell32.dll Change C:\WINDOWS\system32\shell32.dll (i) ntoskrnl.dll Change C:\WINDOWS\system32\ntoskrnl.dll Every thing i read says they should be there, of course. I just don't KNOW if the files should come up on every scan as being changed? I have a ligit copy, OEM Windows XP Professional. recently re-installed and running smoothly on a SATELLITE M30 Laptop. Thanks for you time. There is a way to clear the change result, I just can't remember how atm. Nothing to worry about though. Edit: You could try the AVG forums, if you find out let me know.If you recently re-installed your OS, it may still be installing updates, which would account for the changes. It's usually nothing to worry about. Try giving it a few days and see if the changes are still being reported. |
|
| 3483. |
Solve : wats a TRT/ZXOP.viral file mean?? |
|
Answer» ok so ive been trying to do clean ups on my familys computers so like i go to uncles and his kid has this file he has no virus software or anything and his comps full to the brim and if i delete anything it comes back and i can download anything he has dell not sure about anything else on it but this TRT/ZXOP.viral popped up and ive searched through it a bit and it seems to be counting down all it is a timer if u open it...... its odd we cant delete and he keeps saying ur gonna buy me a new comp..... i aint the one on his comp downloading music soooo...... yeah he needs this for schoolhes running windows vista using IE 7 and msn i think is his isp its a dell if i didnt say it |
|
| 3484. |
Solve : Could Someone Take A Look At My HJT? |
|
Answer» Hey, I know there's probably nothing wrong with my log but I'm just curious as to a few entires and I was wondering if someone could take a look and see what they think. Also, I have NOD32 and use Vista's firewall, do I need any additional SPYWARE protection, such as SUPERantispyware or something? What is recommended? |
|
| 3485. |
Solve : Antispyware software for Windows 98? |
|
Answer» I have an Intel PENTIUM 166MHz w/MMX and use Windows 98. The only time I spend online is when I access email. At times, however, I do check out a few Web sites of INTEREST. Can anyone recommend a good antispyware PROGRAM for Windows 98 users like me? Thank you. I have an Intel Pentium 166MHz w/MMX and use Windows 98. The only time I spend online is when I access email. At times, however, I do check out a few Web sites of interest. Can anyone recommend a good antispyware program for Windows 98 users like me? Thank you. I have a Win98SE computer. A little bit faster, at 350 MHz. Using Ad-Aware Personal here. It takes a minute to load - I can't say whether or not that is normal, I just don't know - and it seems to work ok. It has been some time since I INSTALLED it, but I think this is where you can get it: http://www.lavasoftusa.com/products/ad_aware_free.php As far as how good it is for Win98 users - I suppose you mean in comparison to other anti-spyware programs? Can't say. Somebody else will probably be along shortly to offer opinion(s). My purpose in replying is just to let you know that it works. While we are on the topic of protection/prevention though, are you using anti-virus software? and keeping it up to date? For what it is worth, AVG works great here on the Win98SE machine. http://www.free.grisoft.com AVG also has free anti-spyware, and a link is on that page. It says it supports Win98 in their description there, but I also see: "* Some older operating systems such as Microsoft Windows ME, Microsoft Windows NT and Microsoft Windows 98 will only be supported until August 2008 as a minimum." I haven't tried it. Maybe somebody else will comment on it and/or compare it to Ad-Aware for you. CLEANUP Ccleaner (During install, uncheck the Yahoo Toolbar option) (After install, set Options>Advanced> 'Uncheck the 48 hour BOX') ANTI SPYWARE Adaware Spybot S&D ANTI VIRUS AVG Free (After install, set Options to 'scan all files') ANTI TROJAN Ewido for W2K & XP or A-squared a² for 98 & ME (Winall) |
|
| 3486. |
Solve : is my network hacked?? |
|
Answer» My pc was hacked last month ,on my router i accidentally left my wireless on 2g and 5 G by accident. (I use an ethernet cord on my pc) so I did a FRESH install of my os, and i downloaded and ran a program CALLED netwatch and it shows two 'routers' on my network, one said cable box arris router the other says arris router, when i go to the connected devices on my router page it just shows my pc as being connected, and my voip vonage box,. I have my wireless 2g and 5 g disabled and i also got a new routerIf you did a fresh install and purchased a new router you should be good to go. Just make sure you have strong passwords. |
|
| 3487. |
Solve : rejg Ransomware removal? |
|
Answer» my files are affected (encrypted) rejg RANSOMWARE? not all my files have .rejg file extension in addition to their respective file extension |
|
| 3488. |
Solve : can a virus execute by itself?? |
|
Answer» Is there any type of viruses can execute by itself after download then on the HDD without CLICKING on it?? Is there any type of viruses can execute by itself after download then on the HDD without clicking on it?? I think it's more accurate to say 'a virus can't execute itself, unless it has the cooperation of the Operating System and/or SOFTWARE bugs and/or the user. If the OS allows files to be executed automatically because of their name or location (for example an email ATTACHMENT) then a virus can masquerade as a legitimate file and be executed by the OS without user intervention. This used to be the default behaviour in early email clients. Also, if the OS or specific software has errors that a virus can exploit to run its code, then a virus can start itself. But users are most OFTEN the means for a file to be executed. I was SURPRISED recently when a work-colleage told me she thought her computer had a virus after she opened an attachment in an email from a complete stranger. I thought she would have known better. |
|
| 3489. |
Solve : I Think I Found The Problem But I Don't Know How To Fix It? |
|
Answer» I decided to use the HP Virtual Agent which tested my OS. (Windows 10) |
|
| 3490. |
Solve : free internet protection? |
|
Answer» Whats the best FREE internet protection that doesn't slow the pc down, got malwarebytes on at moment but keeps saying trial has expired.. don't know much about this pc lark..cheersIt depends on which OS you're using. I always recommend MicroSoft Security Essentials but this won't run on XP and Vista and it probably won't run on Windows 7 in a few days. Windows 10 has its own AV called Windows Defender. Im running Windows 8, I have windows defender on WOULD that be enough protection or should I be running something ELSE with it. Thanks.Only one AV should be enabled on a computer. More than that cause all kinds of problems. That is all I use on all my COMPUTERS. |
|
| 3491. |
Solve : I think I have a virus? |
|
Answer» Hello everyone,, Hello everyone,, Thank you my issue has been solved,... |
|
| 3492. |
Solve : Best way to remove Pop Up Ads.? |
|
Answer» My PC does not have a malware ting. Instead, my Chrome BROWSER wants to show me stuff I don't want. What is the right WAY to stop this nonsense? |
|
| 3493. |
Solve : Toshiba Satellite L455D Laptop virus?? |
|
Answer» Hello everyone,, |
|
| 3494. |
Solve : Windows 10 - Norton Vault password auto-fill not working? |
|
Answer» I have a new laptop with Windows 10. I called Norton to see if I could find out why the little Norton Vault icon doesnt show up next to the user/login/password for different login websites, and they said they would have to access my computer remotely. I asked them if they would walk me through it and they put me on hold and then came back and said they would have to remotely access my computer to troubleshoot and fix the problem. I told them I would try to fix the problem myself, but I havent yet. I guess something in windows 10 is blocking this One of my concerns and questions is, would you trust them to remotely access my computer ?No, I can not recommend that. Instead, find somebody AMONG your family or friends that can help you. That is the best I can say. Thanks Geek-9pm. I really dont know anyone who might be able to help. Would you have any ideas as to what I could check, that might be causing this issue ? Or a safe way to generate and save user names and passwords ?From dictation. Okay, I'll try to give you a more detailed OUTLINE of what I have in mind. Years ago I is to work as a computer help technician and would talk to people over the phone about how to fix certain problems. In your case, the problem is not something I would consider to be very critical to your productivity. You should have some alternate method of managing your passwords if the Norton utility is not serving you well. I understand the problem, I also have difficulty finding the right tool for the job and one of the tools I've used now has to be updated and it's a real pain in the neck. The most reasonable workaround is to just have a piece of paper somewhere that you keep all your passwords on and you keep it with you at all times. This is not a joke, the password management system that's used on computers is much more complicated than it really needs to be. If you can write down your passwords on a piece of paper and keep it on your person that should be all you really need. Excuse my frankness, but after several years of experience with helping people with computers I find that often the most practical solution is the best one. But I do have another suggestion. In your community there are some other people who have computers and considered to be a hobby. Those individuals are willing to give you some of their time at no cost and they will try to help you the best they can. But even so, you want to be sure you know who these individuals are and be very careful about giving them any privileges that could possibly cause you harm. The world we live in is not any better now than it was 20 or 30 years ago. There are just too many people out there looking for an opportunity to defraud someone who is not sure what they're doing. So you might try a search and see if there is a LOCAL computer club in your area. You can talk to some of them and make your own decision about which of those individuals appear to be honest and straightforward. Is much easier to do that than it is to try to make a judgment of someone over the Internet people on the Internet people will lie about almost anything. Even if 99% of the people on the Internet are truthful, it's that 1% the can really do you lasting harm. So that's why I recommend you start first dealing with local people that already have some experience and you can evaluate them personally with eye to eye contact and listen to them talk to you and you can answer questions and they can interact with you. As to Norton, I'm not sure why they cannot just tell you over the phone what you need to do rather than trying to take control of your computer. In my time I did some very difficult things of people over the phone without the use of remote control. So I know it's possible to walk people through almost anything over the phone if you know how to communicate and ask questions and follow directions. Of course, a local contact is even much better. A real live person in flesh and blood can communicate much better than someone talking to you over the phone. Body language and gestures and facial expressions do make a big difference when trying to communicate with other people. So far, the Internet is a great tool, but has some serious areas of misuse when it comes to the matter of trust and security. I do hope this is of some help to you. Try finding local people in your area. Ask your neighbors, ask anybody you know what they do when they have a computer problem. Even young children sometimes know what to do. End of dictation. Now that sounds like some really down to earth advice, and Im glad you explained it like that. I can tell you that I will CONTINUE doing things just as you mentioned...writing them down. Thanks |
|
| 3495. |
Solve : Windows 10 doesn't need antivirus? True?? |
|
Answer» I'm going to install soon WIN 10 on my machine. A few days ago I watched some video about Win 10 on YT. Some guy there mentioned that installation of AV program on OS Win 10 is needless. That Win 10 is so good and secured, moreover, this OS has implemented own AV program that is sufficient enough for security of our COMPUTERS. And stuff like that. It's hard to believe in that for me. That's why I'm writing this post here. I'm curious what you guys are going to say about this Crap? Windows Defender is part of Windows 10 and it is a good AV solution. There are better 3rd party AV's (mostly not for free), but as long as you practice smart computing Defender should be fine.Actually, there is one word that stands out in your post that is very important — "our" — and that is important because of the question that arises about you having some sort of internal net where different FOLKS are using computers on that internal net. Point is that the more people you have using a bunch of computers the easier it is to have somebody make a mistake and accidentally invite some BAD bug into your internal net and that means you might want a HIGHER grade of protection. So I think for anyone to give you a good answer the information about your use of "our" could be useful, BUT I wouldn't be so quick to post information out here in public because that is also a flaw in the area of maintaining security. But I can sometimes get seriously paranoid about security, and there might be some who will state that I am being too paranoid about the idea you should PM a tech person you think you can trust here on this site, or another site, and do your discussion in that environment where only you and that tech person you have decided to trust can figure things out. By the way, the — "And stuff like that." — would also have a security professional asking what stuff? But I am again going to state that with security all sorts of little details posted in public can be a problem if a really skillful bad person is paying attention to what you post. There might be a good professional here in this CompHop Community that wouldn't mind helping you through a private means here or elsewhere. Not me, by the way. I am not reliable. I am a cancer patient and my medical situation can get very iffy and I might disappear from the Net for days on end because something in the chemotherapy went haywire. |
|
| 3496. |
Solve : 'Delivery Failure' - Phishing for What?? |
|
Answer» My Spam folder is catching about half a dozen or so messages a day titled "Delivery Status Notification (Failure)" from [emailprotected] |
|
| 3497. |
Solve : New to Phishing? |
|
Answer» Never heard of this before. Someone has been using my old email address to beg for money from all my contacts. I don't know what to do about it. I can't even GET into that ACCOUNT they must have changed my password. I have opened a new email account but my FRIENDS and family keep ringing to say whoever it is is still SENDING emails begging for money. |
|
| 3498. |
Solve : Running two antivirus software? |
|
Answer» Does it hurt to have avast and WINDOWS defender running together on a laptop?Yes. You should have only one anti virus app INSTALLED and running.If two antiviruses work together then one antivirus will become a virus so it is better to run one antivirusQuote from: gorge441 on June 23, 2020, 10:22:59 AM If two antiviruses work together then one antivirus will become a virus so it is better to run one antivirus First of all, that's a ridiculous post. SECOND, the question was answered a MONTH ago. No need for you to SAY ANYTHING.That was rude... I am sorry. |
|
| 3499. |
Solve : Formatting disk after virus infection? |
|
Answer» Ok so long story SHORT I got a virus in my PC running win10, and ended up deciding that resetting the ssd (m. 2) would be the best option... The problem is that it won't let me do so from windows. I therefore decided that I would try to reset it from a PC running kali live. So I buy a m.2 to USB adapter, plug it in the kali pc. At this point I check the disk manager and it appears even if I am unable to interact with it. I then try gparted but it doesn't find the ssd... At this point I am out of ideas and need help. ThanksHi 4aure |
|
| 3500. |
Solve : SpywareBlaster 6.0 won't open in Windows 10? |
|
Answer» SpywareBlaster won't open. I have turned-off all anti-virus and anti-malware programs. I ran Process MONITOR but the log file was empty. Renaming/restoring the original profiles.ini of Firefox did not work. Neither running REPAIRS in Tweaking.com Windows Repair, nor restoring the registry, has HELPED. This is the only program that has stopped. |
|