Explore topic-wise InterviewSolutions in .

This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.

3451.

Solve : Possible virus problem??

Answer»

Hi all,

I am having some strange problems with my PCs and hopefully someone will be ABLE to advice me. Thanks in advance.

How it started was that my sis's notebook running windows 2000 starts to act werid. Sometimes the notebook can bootup, other times, it will not boot up and you will get this error:

Windows 2000 could not start because the following file is missing or corrupt:

\system32\ntoskrnl.exe.

Please reinstall a copy of the above file.

And if successfully bootup, I will sometimes get a domain is not avaliable error and still not able to login. After many many tries, I will be able to get in. So we suspect it's a virus, and I tried running virus scan (NORTON, AVG, Online scanning) but the virus scan will not be able to complete the scan, it will usually hang around 50-53%).

So what I did next was to take out the hdd and connect it as a USB drive to my PC. The hdd show up and I attempt to carry out a virus scan with AVG Free. But of course, the scan could not complete and again hangs at around 53%. And it also cause some of the programmes running in my windows XP system to lock up. When I do a reboot at this point, I was not able to get my XP system to start up and I get the following error:

Windows 2000 could not start because the following file is missing or corrupt:

\system32\ntoskrnl.exe.

Please reinstall a copy of the above file.

I am totally buffled since my pc is running XP and not Win2k, how is that error possible? A vrius..A boot sector virus ? So I tried to reboot the system from cd-rom, with the XP pro cd in it, it failed. So I decided to pop in the Win2k Pro cd, and what happen next is very strange.

I let the system reboot, and when the prompt came up "press any key to contiune booting from cd-rom", I ignore that and the system bypass the cd-rom, but somehow, because the win2k cd is in the drive, my system manage to boot into xp normally ( I tried the same thing without the win2k cd in the cd-rom and the system just return me the same ntoskrnl.exe error, a win XP cd will not work too).

I make the mistake of replacing the ntoskrnl.exe through repair console from the XP pro cd, and after this, the system no longer boot up at all. So I did a format on the C: (holding the OS), and did a clean install of XP. Everything went well until I had to reboot after the installation, and to my horror, the same ntoskrnl.exe error came back. Again I had to pop in the win2k cd into cd-rom and do the same thing as before to boot up XP.

Next I went into bios to set the boot up device [1] as Hdd, and disabled the rest of the options. And somehow, this seems to set everything right, and I was able to boot into XP normally.

(My previous boot set up are [1] cd-rom, [2] hdd, [3] floopy).

I also run a full system scan on my system (all my 5 partitions) and AVG was able to complete the scans and all partitions came up as clean.

But I am still not sure if my system is indeed ok. Is there any chance, anyone knows what is happening here? Work of a virus?

Another question, how can I check if my boot sector is really clean? If I am indeed infected by a boot sector virus, I would not have been able to boot up my system, is that right?

I have no idea what I have caught from my sis's HDD since the virus scan cannot complete. Any help is greatly appreciated.

Thank you for reading such a long post.
romi.... Are we talking about 2 differant machines or just the laptop?
What is the current status of the problematic MACHINE ?
I have just reread the post again and it is the laptop.......
Have you booted it up in Safe mode and run a full antivirus scan with AVG ?
It would be a good idea to D/L AVG antispyware and run it in safe mode as well.
http://free.grisoft.com/doc/20/lng/us/tpl/v5
I am going to move this post into the spyware and virus section as well.
dl65 I am talking mainly about the problems on my XP machine.
It somehow caught what was on the hdd from my sis's notebook.
Nothing has been done about the notebook yet.
I am trying to fix my PC first. I hope this clears up the confusion.

The main catch of the problem is that my pc is running XP but I am GETTING a windows 2000 error.romi.... ok....... reboot the XP machine into safe mode and run scans with both AVG anti virus and AVG antispyware.
Let us know the results of the scans.

dl65 Quote

romi.... ok....... reboot the XP machine into safe mode and run scans with both AVG anti virus and AVG antispyware.
Let us know the results of the scans.

I will do that tonight when I get home. But I did do a full scan with AVG Free and nothing turns out. Will follow up.romi.... Was the scan run in safe or normal mode ?

dl65 Follow what dl65 already advises but make sure you have exposed all Hidden Files & Folders first.

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.

***********************

(On Windows 2000 or XP)...

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].



Post back the scan report and update us.


OJ

3452.

Solve : Difference-McAfee Antivirus & AOL AntiVirus?

Answer»

I am setting up a P-III for my daughter. She already has an AOL account. I purchased McAfee's latest AntiVirus program for installation on her computer. However, I see that AOL offers free AntiVirus by McAfee. Other than the fact that the AOL version is free, what, if any, are the DIFFERENCES between the 2? A friend who has the AOL version told me that it is very disk intensive. Does the AOL version include AOL related items which cause it to be more taxing on the computer's CPU?I'm not too well educated on AOL and its services, but where I come from, whenever an ISP offers a virus scanner its usually a farce and only good for scanning E-mail. Have you got a link for me so I can have a look-see?

By the way, I'd use AVG Free instead of Mcafee. It's free, yet BETTER..Quote

I'm not too well educated on AOL and its services, but where I come from, whenever an ISP offers a virus scanner its usually a farce and only good for scanning E-mail. Have you got a link for me so I can have a look-see?

[highlight]By the way, I'd use AVG Free instead of Mcafee. It's free, yet better..[/highlight]
I agree. I have SecurityCenter and it works really well and I love the features, but I still have AVG as a backup because McAfee doesn't catch everything.AVG Free.

4 years running and no problems...

Actually from what i read i BELIEVE AOL is now using Kaspersky for their protection package...
3453.

Solve : impossible situation?

Answer»

Are there any experts out there that can help? - I have employed 5-6 computer techs and one networking specialist company and nobody can figure out what is up with my computers. We clean the hard drive - flash the bios, on one repaired the MBR - and trojan always comes back - a python scripting program that rewites the registry and takes control. Is this a problem at some other level like the video memory or ram? Excuse my ignorance, I am not a computer person - but I so need my computers back as it has been 10 weeks and I have a business that is suffering! Please, any advice! I think that it was a link through this site that helped me discover that it was a "rootkit" about 4-5 weeks ago - Now I need to get some ideas about how to get rid of it! Thanksneedtoknow........ It sounds like you have more than one machine , is that correct ?
If thats the case, are they all on the same network ?
Do they all share the same resources ?
Is more than one machine infected ? ( it's possible that they all could be infected )
Do you have any idea , what the intruder has been identified as ?

dl65 Hi--
At one time or another there were 3 laptops and a desktop all hooked up on a router - the problem kept reoccuring and eventually we were down to just hooking up the desktop to "wait and see". Now I have 2 laptops and my NEW desktop (was infected) at a computer network co x 1.5 weeks and I don't think they know what the problem is. I was told by an online site after sending a report about 4-5 weeks ago from hijackthis that there was a "rootkit" Problem is - we have wiped the drives and reinstalled - and this trojan/virus keeps getting on somehow - somewhere other than the hard drive - I am wondering at what level can virus be? We only shared a printer. How does the intruder get identified? I know that at one point the registry settings were changed so that even the Norton, Zone Alarm, AVG were not logging correctly. I am so at a loss -- I am wondering if I need an excercist instead of a computer company. Any ideas would be welcome. I almost feel that I should resign to not using computers anymore. I have paid big bucks so far with no results.needtoknow..... This may seem like a pain, however , if you could isolate your desktop from the network ........ and run another hijackthis scan and post the log here ........ we would like to have a look at it .

BTW, are the other 2 laptops clean ?

dl65 Hi--
I actually only have one computer (laptop) at home - and this one is definitely infected. My others at at a business (Networking specialists) and they are trying to figure out the problem but aren't getting anywhere. If you can tell me how to hook up a laptop without using a wireless connection I will email you a log. We have a internet cable connection. Will a log do anything more than tell you that there are services running that shouldn't be? Thanks for your reply!needtoknow........ I assume you have a laptop at home with you ...... Can you not PLUG the laptop into your modem via a cat5 cable ? There should be a port on it to accept the STANDARD cable ..... ( the same as you use to connect to your desktop )

And yes the hijacklog should reveal something ...... however if the infection is really a true Rootkit ..... it may be in stealth and may not show up .........

dl65
here is the log - I think it is even much more involved than this

thanks

Logfile of HijackThis v1.99.1
Scan saved at 7:48:20 PM, on 6/29/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\LJS1\Local Settings\Temporary Internet Files\Content.IE5\645ZQUC1\hijackthis[1]\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [workflo] D:\install\workflow.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\JAVA\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe

I have never seen an entire Hijack log file fit into one post.

Why no SP2 on that machine?needtoknow..... Wow ......... I just had a look at the logfile you posted....... There most definately is something wrong with something .......

Here's what jumps out you.......
1.Quote

Scan saved at 7:48:20 PM, on [highlight]6/29/2005 [/highlight]
Todays date is Feb 21ST 2007

2. Quote
Platform: Windows [highlight]XP SP1 [/highlight](WinNT 5.01.2600)
The current SP is 2 ........ why do you not have it installed ?

3. I can see no evidence of any Anti virus program installed ........Why not ?

4. I can see no evidence of any firewall installed ...... Why not ?

5. The installed java is also out of date .

6. Do you have all the latest M/S updates installed ?

7. Was this hijackthis scan done in safe mode or in normal mode ?


We await your reply.

dl65


It really is odd seeing such a short log. One thing I'd like to add...

You may want to move your copy of HijackThis to a permanent location. You currently have it in Temporary Internet Files, where it and its backups are likely to get deleted. I would suggest making a folder called HJT in C:\Program Files and moving the program there where it can be nice and safe.Two small comments.

needtoknow ... you say your systems "share one printer". Maybe that's the problem. Wiping hard drives, reinstalling but finding the same problem recurring indicates an external issue.

IMPORTANTLY ....do NOT install SP2 on any machine belived to be infected with malware. It will cause more trouble as it won't install porperly.


OJOK-relax----

I am using this laptop for nothing else than to find out what is going on and why this ugly thing keeps taking over my system. I had to reinstall the ops system and It took me 2 hours to get an internet connection - My focus was not on updating to SP2, it was on getting a log. I found the driver for my ethernet connection and got the log, turned off services for remote server, etc., turned off the computer and went to bed too late. When I got up and booted up all those services were running, and my connection was gone - my ethernet not visible on devices. Can somebody please tell me where the trojan can be besides the hard disk? In the RAM? In the video memory? I am not a computer person! But after repeated attemps to wipe all my computers (new desktop, laptop) this thing always comes back. I don't know if I need to camp out at the police station until computer crime division helps me??? 3 mo's without a computer and I have a business - countless "techs" have not been able to help me. Any ideas??You have frequently remarked that you have wiped disks and reinstalled. I have a feeling that something you "reinstall" contains this "bug" or whatever it is.

This file ....

C:\WINDOWS\System32\S24EvMon.exe

.....brings up differing opinions. I don't have it running on my machines personally but others say it is "vital", others that "it is optional and won't do any harm if removed/stopped" and some even go so far as to say it can cause havoc with internet connections and is completely unnecessary. It's a monitoring file/process.

It may be that, if you stopped this process running, you may improve things.

As I say I am not an expert on this particular process (others here may have more idea) but I guess stopping it can't make anything worse.

It would be good to try and get just ONE of your machines up and running before linking it up to the others.


Please let us know what you think.


OJYes, I agree that I should try to just get one of my machines up and running - but have not been able to do this in many weeks. I keep getting the same level of control by remote server. My big QUESTION is: where can this keep loading from? I am certain that it is not coming in from internet - it did once but now it is being stored somewhere besides my hard drive - Is this information that only a specialist would have? Do I need to find a specialist? ThanksHave you tried disabling/stopping/removing that file I specified in my last post? What was the result?


OJ
3454.

Solve : Check this out?

Answer»

Can one of you check this out please
Past couple of days it seems that the computer has a mind of its own
Whilst viewing pages on the internet the pages just drop down and the text size
changes to largest then it goes back a page
Windows xp home
browser IE
I have used spybot,adware,avg,and have shown up nothing except the usual cookies etc,
I wasn't able to scan in safe mode as you recommend because i cant get into safe mode
when start up and press F8 all goes well but i cant move the up and down keys to safe mode.
is there anything in here that shouldn't be
thank you

Logfile of HijackThis v1.99.1
Scan saved at 20:25:35, on 15/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\SiteAdvisor\6021\SiteAdv.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Tesco internet phone\TescoIP.exe
C:\Program Files\PCPal\PalAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\ZyXEL\ZyXEL G-202 Wireless Adapter Utility\ZyXEL G-202.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\SiteAdvisor\6021\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [QAGENT] "C:\Program Files\QUICKENW\QAGENT.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6021\SiteAdv.exe
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE" /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"
O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe"
O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GooO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4963/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6021\SAService.exe
O23 - Service: Windows Defender (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)
skyblue..... What kind of keyboard and mouse are you using ?
Quote

when start up and press f8 all goes well but i cant move the up and down keys to safe mode.

If using something other than a PS/2 its possible there arent any drivers available in safe mode.


dl65 dl165
Quote
What kind of keyboard and mouse are you using ?
Wireless with mouse,drivers did come with it but instructions said "not required for xp"
not sure who made it one of these made in china
[ HID Keyboard Device ]

Keyboard Properties:
Keyboard Name HID Keyboard Device
Keyboard Type IBM enhanced (101- or 102-key) keyboard
Keyboard Layout United Kingdom
ANSI Code Page 1252 - Western European (Windows)
OEM Code Page 437
Repeat Delay 1
Repeat Rate 27

[ HID-compliant mouse ]

Mouse Properties:
Mouse Name HID-compliant mouse
Mouse Buttons 5
Mouse Hand Right
Pointer Speed 1
Double-Click Time 690 msec
X/Y Threshold 6 / 10
Wheel Scroll Lines -1

Mouse Features:
Active Window Tracking Disabled
ClickLock Disabled
Hide Pointer While Typing Enabled
Mouse Wheel Present
Move Pointer To Default Button Disabled
Pointer Trails Disabled
Sonar DisabledI 'm thinking that in safe mode the required drivers for the wireless keyboard isnt being loaded ...hence you cant use the up /down arrow keys to load in safe mode....... try going into safe mode using a ps/2 keyboard .........


dl65 Quote
try going into safe mode using a ps/2 keyboard .........
Thanks for that i will have to borrow one
Why is it so important to scan in safe mode and why don't the company's who
produce anti virus software also advise this??.so in other words normal scanning is useless!!!!!!!!! unless scanning is done in safe mode
Does the hijack log file LOOK ok??
SkyblueHi skyblue

I recommend you print this out to help you follow the advice.

Your HJT folder is in a temporary location. The program makes automatic backups and there is a danger those backups will be lost. Please go to the HJT folder here ....

C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe


....and move it the C: drive for safety.

************

These entries in your log ...

C:\Program Files\Multimedia Combo Set\MouseDrv.exe

O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe"

.... may indicate the presence of the CRYPTER.A Trojan.


Please go here ...

http://www.virustotal.com/en/indexf.html

Browse to the file ...

C:\Program Files\Multimedia Combo Set\MouseDrv.exe

Upload it to Virustotal ... scan it for malware .... post back the results here.

************

Boot to safe mode ... open HJT again ... click on scan ... put tick/checkmarks next to the following entries IF they are still present ...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O18 - Filter: text/html - (no CLSID) - (no file)


Close ALL open windows - including this one - before you click on "Fix Checked" at the foot of the HJT window.

************

Reboot to normal mode, scan again with HJT and post back the results of the Virustotal scans and the fresh HJT logfile.


[NOTES >> I see you have Limewire. I don't recommend it as it's a potential source of malware infections but that's your choice.

Your java is a little out of date. You should update to to version 6 and uninstall/remove all older versions via Add/Remove Programs.]


OJOJ
Did as you advised
Logfile of HijackThis v1.99.1
Scan saved at 08:41:40, on 17/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\sistray.EXE
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\QUICKENW\QAGENT.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\SiteAdvisor\6021\SiteAdv.exe
C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Tesco internet phone\TescoIP.exe
C:\Program Files\PCPal\PalAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\ZyXEL\ZyXEL G-202 Wireless Adapter Utility\ZyXEL G-202.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\SiteAdvisor\6021\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\msiexec.exe
C:\DOCUME~1\Mike\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tiscali.co.uk/broadband/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [QAGENT] "C:\Program Files\QUICKENW\QAGENT.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6021\SiteAdv.exe
O4 - HKLM\..\Run: [SmartDefrag] "C:\Program Files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe" /startup
O4 - HKLM\..\Run: [EPSON Stylus CX3600 Series] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BE.EXE" /P26 "EPSON Stylus CX3600 Series" /O6 "USB001" /M "Stylus CX3600"O4 - HKLM\..\Run: [WireLessMouse ] "C:\Program Files\Multimedia Combo Set\MouseDrv.exe"
O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tesco internet phone] "C:\Program Files\Tesco internet phone\TescoIP.exe" /autostart
O4 - HKCU\..\Run: [PCPal] "C:\Program Files\PCPal\PalAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O4 - Global Startup: ZyXEL G-202 Wireless Adapter Utility.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,4963/mcfscan.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6021\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6021\SAService.exe
O23 - Service: Windows Defender (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)

And heres the scan
STATUS: FINISHED
Complete scanning result of "MouseDrv.exe", received in VirusTotal at 02.16.2007, 17:40:56 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.37 02.16.2007 no virus found
Authentium 4.93.8 02.15.2007 no virus found
Avast 4.7.936.0 02.16.2007 no virus found
AVG 386 02.16.2007 no virus found
BitDefender 7.2 02.16.2007 no virus found
CAT-QuickHeal 9.00 02.16.2007 no virus found
ClamAV devel-20060426 02.16.2007 no virus found
DrWeb 4.33 02.16.2007 no virus found
eSafe 7.0.14.0 02.16.2007 no virus found
eTrust-Vet 30.4.3405 02.16.2007 no virus found
Ewido 4.0 02.16.2007 no virus found
Fortinet 2.85.0.0 02.16.2007 no virus found
F-Prot 4.2.1.29 02.15.2007 no virus found
F-Secure 6.70.13030.0 02.16.2007 no virus found
Ikarus T3.1.0.31 02.16.2007 no virus found
Kaspersky 4.0.2.24 02.16.2007 no virus found
McAfee 4964 02.15.2007 no virus found
Microsoft 1.2204 02.16.2007 no virus found
NOD32v2 2066 02.16.2007 no virus found
Norman 5.80.02 02.16.2007 no virus found
Panda 9.0.0.4 02.16.2007 no virus found
Prevx1 V2 02.16.2007 no virus found
Sophos 4.14.0 02.16.2007 no virus found
Sunbelt 2.2.907.0 02.15.2007 no virus found
Symantec 10 02.16.2007 no virus found
TheHacker 6.1.6.059 02.16.2007 no virus found
UNA 1.83 02.14.2007 no virus found
VBA32 3.11.2 02.16.2007 no virus found
VirusBuster 4.3.19:9 02.16.2007 no virus found
Aditional Information
File size: 503808 bytes
MD5: 89dd130712f2b1b8507d83f3c405c3df
SHA1: cb6671c8112c90dcb7fc2a2db024a51c4deabd9 d
Hi

The log looks better (apart from Limewire, IMO) but you haven’t successfully moved the HJT folder to a permanent place. All you have done is move it to another "temporary" location.

Can you go to the HJT folder .... left click on it ... hold the mouse button then "drag & drop” the folder directly on to your C: drive? That should do the trick.

How is your computer behaving now? Can you boot to safe mode? How's your web browsing experience? Still wrong or OK now?


OJQuote
How is your computer behaving now? Can you boot to safe mode? How's your web browsing experience? Still wrong or OK now?
Thanks for your help Seems to be ok ,but i still cant get into safe mode, the up and down keys still don't function,btw up and down keys work in normal mode

Quote
try going into safe mode using a ps/2 keyboard .........
O4 - HKLM\..\Run: [WireLessKeyboard ] "C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe"
is the above a ps/2 keyboard
Skyblue
PS
Why!!!!!!
Quote
Why is it so important to scan in safe mode and why don't the company's who
produce anti virus software also advise this??.so in other words normal scanning is useless!!!!!!!!! unless scanning is done in safe mode
Hi again

Can't get to safe mode ....

First thing you need to check is if the keyboard is fully functional.

If you can get in to BIOS - F1, F2, Del, F10, depending on the configuration of your machine, if you can access this, and your arrow keys DON'T work, then your keyboard has had it. If they do, its a software problem and you'll need to reinstall Windows.

For a long shot, try a PS2 keyboard attached, see if that helps.

[credit for this tip .... Kevin Gibson, ST&T member]


try going into safe mode using a ps/2 keyboard .........

You ask "why".

Often when a user is working with a wireless or USB device something...well... just screws up. A ps/2 connected device is lighter on resources, uses simpler drivers etc. Sometimes, when a wireless or USB device doesn't work fully, a ps/2 device will work. It's always worth trying.


Why is it so important to scan in safe mode and why don't the company's who
produce anti virus software also advise this??.so in other words normal scanning is useless!!!!!!!!! unless scanning is done in safe mode


The simple reason is that much malware won't run unless the computer is fully booted up. Booting to safe mode stops such malware running and makes it inactive. That makes it easier for malware detection programs to detect their presence and do something about it.

Most protection programs will also run in normal mode (some perhaps will ONLY run in normal mode) and I suspect the manufacturers feel that the average user won't understand an instruction to "boot to safe mode before scanning with (our product)". They feel a uesr WOULD much rather just scan in normal mode for simplicity.

Also it depends on what type of malware the progam is scanning for. Some are just as easy to fix in normal mode as safe mode.

My advice ... always scan in safe mode unless the program bring used specifically instructs scanning in normal mode only.

Please post back again and let us know how you are geting on booting to safe mode etc.


OJOJ
Firstly thanks for your lengthy explanation why we have to scan in safe mode, makes sense i suppose(just like to now why we have to do things a certain way)
Now back to the problem
F2 got me in bios and the up and down keys worked perfectly
I also tried my old keyboard and that also works in bios and safe mode
in your opinion is it the new wireless keyboard that is or is it a reinstall, if its the latter i think i will leave things as they are since all the functions seem to work OK in normal mode, and if i need to go in safe mode its just a case of plugging in my old keyboard
SkyblueSo long as everything ELSE is working as it should I think you can assume the trouble is indeed with that keyboard. Yes, you can do what you suggest, and only use the other keyboard if you need to go to safe mode, but I would also try uninstalling then reinstalling the malfunctioning keyboard first.

Also run a full system scan with AVG Anti Spyware to give it a good spring clean out.

Good Luck. Safe surfing.

Post back if you've further questions.


OJ
3455.

Solve : Trojan Protection?

Answer»

Hello, I was wondering what is the best trojan software I should purchase? I am not a constant online gamer but I do play games online now and then. Also I do use p2p PROGRAMS not often but occasionaly as well. I have McAffe secuirty centre but as you know, an anti-virus program is not enough to protect against trojans. What do you think of McAffe anyway?

Thanks againAVG anti-spyware does a nice job of cleaning Trojans but does not stop them from getting to your machine.
Common sense surfing is your best bet along with not opening e-mail attachments that you're not familiar with.
Unfortunately p2p networks are like walking into a minefield with really big floppy shoes on.I have McAfee SecurityCenter and I'm happy with it. It's really good at detecting trojans and PUP's, but it can't always prevent them. It's definitely a good idea to have AVG at your disposal.

And patio's right...if you use P2P networks, you should expect to get malware on your computer.Ok so what do you think of trojan HUNTER or trojan remover or even tauscan?

I also have spybot search and destroy.

I use p2p yes but not as often as one may think. I am going to delete it as it's so unsafe.I've never used those trojan programs, but I'm sure SOMEBODY here has their opinions. As for spyware removal...I'm partial to Ad-Aware, but I think some of the guys here have Search & Destroy, so I'm sure it can't be bad.Many of us have both. Anti-virus.....detects and cleans known virii.
AdAware......detects and removes adware.
Spybot.........detects and cleans spyware and some adware.
Trojan Hunter......detects and removes trojans.

Keep in mind there are many forms of threats out there which is why a well rounded arsenal is neccessary for protection.

Trojan Hunter is a FINE program...a free alternative would be AVG Anti-Spyware (formerly Ewido)

patio.I will have to check out AVG.They offer 2 excellent free programs: AVG Free anti-virus and AVG Free Anti-spyware...

You probably won't be disappointed along with adding some of the others mentioned here.

We take our Security pretty seriously here and our feedback is from years of TESTING and trying a lot of products on the market.

The added bonus is because we have spent the time doing so you can protect your machine in all ways with top-notch programs without having to spend a dime...

It's part of what we do.

3456.

Solve : Still having problems. Here's my HJT log.?

Answer» NOPE. None of those. Anywhere else I could look?You say that windows reports a "driver error". Doesn't it give you more information than that? If so PLEASE post it here.


OJWhen my COMPUTER shuts off and turns back on sometimes it says "system has RECOVERED from a serious error". I posted the screencap in that other post. Then when I send the report to Windows it takes to to a page that say it was a driver error. No other info was given as to what driver and why. It said it couldn't give me any further information.I looked into the driver ISSUE and found this page:

http://support.microsoft.com/kb/322205

That is what my computer is doing. I don't recall updating any drivers though. Maybe it is my printer driver? I think that might have ATTEMPTED to update. So I'm reinstalling the one from hp.com in hopes of something.Due to lack of response this thread now locked.

Should the original poster require it re-opening please PM GX1_Man or a moderator.
they pm you GX
3457.

Solve : trojan - Hijack This logfile?

Answer»

Posted here as per Patio’s direction. Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 3:45:56 PM, on 3/8/2007
Platform: WINDOWS XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\System\loader.exe
C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Common Files\AOL\1139894366\ee\AOLServiceHost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Documents and Settings\Linda\Desktop\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Run Manager - Critical] C:\WINDOWS\syss32.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SBC Yahoo! Connection Manager] "C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [Logitech Hardware ABSTRACTION Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Loader] C:\WINDOWS\System\loader.exe
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Stcontinued...

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1A595EDD-978A-48C7-B730-AF3B9CC64DAB} (DLManager Class) - http://63.251.81.180/component/VZWDLManager.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117792072028
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABCFFC5C-3D5E-4F5B-9141-D589A1061FEC}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

I recommend you print this out to help you follow the advice.

Your Java is well out of date. I will post the fix for that seperately (see below).


Please download FixWareout from one of these sites ....

http://downloads.subratam.org/Fixwareout.exe

http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it.
Click Next, then Install, then make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
When your system reboots, follow the prompts.

AFTERWARDS, HijackThis will launch. You may close it at this stage.

*******************

Download and install the fully working trial version of Trojanhunter from here ….

http://www.misec.net/

DO NOT use it yet.

*******************

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

*******************

Update your AVG Anti Spyware to the latest definitions then REBOOT to safe mode.

Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

*******************

First scan the computer with Trojanhunter then scan with AVG Anti Spyware. Let them fix whatever they find.

*******************

REMEMBER TO SAVE THE AVG Anti Spyware SCAN REPORT and also remember where you saved it.

*******************

You have Viewpoint on this system. It considered to be intrusive “foistware” and not good. I have included the removal of this program in the instructions below.

*******************

You also have Logitech Desktop Messenger. It’s installed with the software for Logitech products. It’s optional but my advice is not to keep it. It automatically checks for software upgrades AND new products, services and “special offerings” from Logitech. It’s not required, let’s Logitech into your system, it only infrequently run tasks that can be run manually. It clutters up your machine and can turn HijackThis logs into a huge mess.

However, it’s your choice. As LDM is only optional I have left it alone. If you want it removed let me know and I’ll run you though the procedure.

*******************

Now to the first fix …


Go into HijackThis > Config > Misc. Tools.

Open process manager.

Select the following and click “Kill process” (IF it still exists) .....

C:\WINDOWS\System\loader.exe

*******************

Open HijackThis again and click on 'Do a System Scan Only'. Check the following entries
IF they still exist (make sure you do not miss any …..

O4 - HKLM\..\Run: [Run Manager - Critical] C:\WINDOWS\syss32.exe
O4 - HKLM\..\Run: [Loader] C:\WINDOWS\System\loader.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABCFFC5C-3D5E-4F5B-9141-D589A1061FEC}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101


O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)

O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing)


NOTE
>> the four 017 all trace back to the Ukraine and relate to the Wareout infection. I'm assuming they are NOT your IPS so have included them in the above fix. If you are in doubt about the validility of those entries you must check with your ISP before including them in the fix.


Please remember to close all other windows, including browsers then click Fix checked.

*******************

Delete the following Files indicated in BOLD IF they still exist ………….


C:\WINDOWS\System\loader.exe

C:\WINDOWS\syss32.exe

C:\WINDOWS\System32\hwclock.exe

C:\WINDOWS\System32\cfmon.exe

*NOTE >> BE VERY CAREFUL with that last one… cfmon.exe. Note the exact spelling. There are legit files on your system with the name ctfmon. Note the missing letter “t” from the bad version.


*******************

Reboot your system in Normal Mode and use the computer as you would normally do.

Update your verison of java (see below) then post back ...


1. A fresh HijackThis log,

2. The AVG Anti Spyware scan log and

3. An update on how your computer is operating now.


OJ
Due to the restrictive length of posts this is "part 2" of the first fix...


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the BOX that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
OJI think you fixed my computer! In fact, I'm almost POSITIVE you did.

Logfile of HijackThis v1.99.1
Scan saved at 11:58:23 PM, on 3/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\AOL\1139894366\ee\AOLServiceHost.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Linda\Desktop\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1139894366\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SBC Yahoo! Connection Manager] "C:\Program Files\SBC Yahoo!\Connection Manager\ConnectionManager.exe"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitcontinued...

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1A595EDD-978A-48C7-B730-AF3B9CC64DAB} (DLManager Class) - http://63.251.81.180/component/VZWDLManager.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1117792072028
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\..\{ABCFFC5C-3D5E-4F5B-9141-D589A1061FEC}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101
O17 - HKLM\System\CS1\Services\Tcpip\..\{27FAA52D-304B-4B90-874E-AAAB8883CDE4}: NameServer = 85.255.116.70,85.255.112.101
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.70 85.255.112.101
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 4:53:56 PM 3/9/2007

+ Scan result:



HKU\S-1-5-21-1801674531-1454471165-682003330-1004\Software\Internet Security -> Adware.Generic : Cleaned.
:mozilla.76:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.77:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.78:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.79:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.41:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.37:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.38:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.39:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.40:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.67:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.64:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.65:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.66:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.61:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.62:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.59:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.74:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.75:C:\Documents and Settings\Linda\Application Data\Mozilla\Firefox\Profiles\lyw9gf6r.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Linda\Cookies\[emailprotected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end


~~~~~~~~~~~~~

No evidence of ny virus or spyware remains (not that I can see). There is no trace of the odd # icon.

I agree w/ your advice on removing LDM and would appreciate your help in that.

As per your warning to check w/ my ISP in regards to those 017 items, I did and was advised against including them in the fix.

Lastly I updates Java and as seen above, have posted the HJT and AVG logs.

Thank You!

Hi

Again I suggest you print this out.

Update your AVG Anti Spyware to the latest definitions again and scan your machine. The log should come up more or less clean again. Remember to do this regularly to help keep the computer out of trouble.

**************

Removing LDM & Viewpoint……


Go to Add/Remove Programs and uninstall/remove the following programs ….


Viewpoint

Logitech Desktop Messenger

**************

Open Task Manager …. Highlight these Running processes …. Click on End Task to stop them IF they are running (let me know which ones you didn’t find) ….

C:\Program Files\Viewpoint\Common\ViewpointService.exe

C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe


**************

Fix these entries with HijackThis in the same way you did before IF they are still present….

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.7.0\ViewBarBHO.dll

O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.7.0\IEViewBar.dll

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O23 - Service: Sound Sservice Driver (Sound Service) - Unknown owner - C:\WINDOWS\System32\cfmon.exe (file missing)

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



[Remember to close ALL open browser windows before hitting “Fix checked”; if windows remain open the fix may not work]

NOTE >>> I am concerned that the cfmon 023 entry is still present in your log. Did you miss this one in the last fix? Has it returned after you fixed it with HijackThis?

If it won’t go away peacefully we will have to use another method to remove it. Let me know what happens.

**************

I can assure you those 017 entries trace back to the Ukraine and relate to the scum that send out much of the malware on your machine. I am very surprised your ISP told you not to fix the entries.

I still believe you should fix all those four 017 entries with HijackThis.

Who is your ISP and what exactly did they say? Did you get the impression they definitely knew what they were talking about or that, maybe, they were unsure & just playing safe.

**************

Please post back a fresh HijackThis log with feedback on the above various issues.

We’ll take it from there.


OJHi, thanks again!

My ISP is Roadrunner/Time-Warner cable. I called tech support, told them I had a trojan, that I was using HJT to fix the problem, and also that I was told I should confirm with them before deleting those items. Actually he did sound as though he was playing it safe. I read it for him over the phone "HKLM\System..." and asked him if any of that sounded familiar. He said yes and that I should not delete anything that contained Tcpip as that is what enables me to connect. In my own head I was thinking well yeah, but isn't that also something one of those nasty little buggers would use too?
I'll go out on a limb here and say that oddjob's expertise is light years ahead of the tech support guy at Time Warner...Quote
I'll go out on a limb here and say that oddjob's expertise is light years ahead of the tech support guy at Time Warner...

yep, I'm inclined to agree Thanks for the approbation.

It should be safe to kill those 017's with HJT.

Open HJT ... click on scan and fix those four 017 entries IF they are still there and IF they still have exactly the same IP numbers as they did before.

Then carry out the rest of what I asked in my last post.

Thanks.


OJThis thread has been locked now that it is resolved.

Should the original poster require it re-opening please PM GX1_Man or a moderator.
3458.

Solve : Hi there, another analysis please.?

Answer»

Hi there, ive done everything, Anti Spyware, Virus scan and its cleaned up. But before i do i think tis worth mentioning that when ever on this computer the URL www.google.com is typed in it redirects us to http://uk.msn.com// The .co.uk version of Google works fine though. If someone could analysis this i would appreciate it. Thanks

Logfile of HijackThis v1.99.1
Scan saved at 18:24:35, on 22/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe
C:\DOCUME~1\Helena\LOCALS~1\Temp\2005817165455_mcinfo.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Lexmark 5200 series\lxbtbmon.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Helena\My Documents\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/Default.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark 5200 series] "C:\Program Files\Lexmark 5200 series\lxbtbmgr.exe"
O4 - HKLM\..\Run: [LXBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBTtime.dll,[emailprotected]
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Helena\LOCALS~1\Temp\2005817165455_mcinfo.exe /insfin
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /min
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: phase6_17_demo_erinnerung.lnk = C:\Program Files\phase6\phase6_17_demo\WinStart\WinStartDemo.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://arcade.icq.com/carlo/zuma/popcaploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BBEA726E-E10E-42BF-B098-CAD68B05A606}: NameServer = 158.43.240.4,158.43.240.3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxbt_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbtcoms.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

Hi

The log's not too bad. Few things to clear up though (along with that redirection you refer to).

You might want to print this out to help you follow the recommendations.

************

First ... what is this program?

C:\Program Files\phase6

I can't find out much about it. Did you install it? Do you want it?

In this fix I have assumed you want it to stay. If not, please say and we can advise on its removal.

************

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file TYPES. Click OK.

************

You should run Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/

************

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

************

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for it (IF it still exists) .....

C:\DOCUME~1\Helena\LOCALS~1\Temp\2005817165455_mcinfo.exe

************

Click > Start > Control Panel > Add / Remove Programs and uninstall the following program (If it exists in your list):

WinFixer_2006

************

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any) .....

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.co.uk/Default.asp

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Helena\LOCALS~1\Temp\2005817165455_mcinfo.exe /insfin

O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /min

O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll



Please remember to close all other windows, including browsers then click Fix checked.

************

Delete the following Folders indicated in BOLD IF it is still PRESENT .....

C:\Program Files\WinFixer_2006

************

Reboot your system in Normal Mode.

Perform an online scan with Internet Explorer with Panda ActiveScan here .....

http://www.pandasoftware.com/products/activescan.htm

Click on the "Free To Use ActiveScan" located on the top right hand corner [list=1]

  • Click Check Now and a "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  • Enter your e-mail address, country, and state & click Scan Now * The download of the 8 MB Panda's ActiveX control will take PLACE *
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
    • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
    • Click on See report then click Save report[/color]
    * You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
    * Turn off the real time scanner of any existing antivirus program while performing the online scan

    ************

    Now re-hide the protected files & folders by reversing the procedure set out at the start of this fix.

    ************

    Paste the Panda Scan report here together with a new HijackThis log and your thoughts on the "phase6" program mentioned earlier.

    PLEASE ALSO tell us how the computer is operating now. Any lingering issues/problems?


    OJ


    [FOOTNOTE .... you have the MyWaySearch spyware junk. Do you use it? If it's not causing you trouble then perhaps you will leave well alone as it's really awkward to remove. See here for a discussion on removal & associated problems ....

    http://www.castlecops.com/a6162-The_Dell_and_My_Way_Saga.html ]

Ok thanks for that! But I cant do it until Tuesday. So please don't think ive posted and have forgotten about it, because i haven't. Also about the 'Phase6' I have no idea because its not actually my computer. Ill have a look through it though. Anyway thanks alot i appreciate it. Like i say the soonest ill be able to reply is Tuesday.
Thanks

ChrisIf you can't do anything for so long then that log will be useless. HJT logs are only any good if they are acted on in, max, 2 days.

By alll means try what I suggest but I won't be surprised if the next log is worse than the first.


OJHuh? SORRY how come that is?

ChrisMalware attracts more malware. If there's malware in a log it will be active until fixed. If the infected computer contines to be used online during the intervening period there is a strong possiblity it will be infected further.

Don't forget to post the three things requested at the end of my first fix. We'll see how the computer is then.

All the best.


OJ
3459.

Solve : norton Update without internet?

Answer»

I have a norton antivirus 2002 installation and I have an internet connection. I am able to run LIVE updates on my computer. HOWEVER I have installed the same norton antivirus 2002 at my friends place but he does not have an internet connection. Which folder or files shall I copy from my updated norton (from my hard disk drive) to my friends place (WITHOUT using live update at friends place) so his norton antivirus will to be up-to-date.

I believe this is the PAGE you are looking for.
The page also includes LINKS to instructions to update without an internet connection.
Hope this helps.
Calum.
3460.

Solve : Does this sound like a virus to you??

Answer»

Before my current computer, I had an eMachines W2247 with Windows XP Home SP2, 128 MB, and an AMD Athlon XP Processor 2200+. It's been awhile, so I can't remember anything I had done, but it just totally crapped out one day. It first started having a lot of trouble booting up, and then by the end of the night, it wouldn't boot up at all. Or even attempt to. To this day, when I turn it on, nothing happens. The power light blinks on and off, but that's it. It doesn't MAKE any noise or anything. Also, the lights on the keyboard will blink in a random pattern. Does anyone have any idea of what might be GOING on with it?

I thought maybe there was something wrong with the power supply, but I don't know if that's the case. I tried using another cable and the exact same thing happens. Also, when I hook the keyboard up to any other computer, the lights still do that weird blinking. It's weird to me that the keyboard would also be infected in the case of faulty power supply or dust or whatever. The computer is a piece of junk compared to my new one, so it's fine if I can't get it up and running again. However, there are files that I would like to RECOVER if at all possible. Will I have to take it down somewhere to do this, or would that be a pointless waste of money?

I'd appreciate any input on the matter. The computer had a few virus problems, so I'm guessing that's the culprit. eMachines certainly aren't the best computers out there, but it was actually a decent model and did well for maybe four years; I doubt it just suddenly died of old age.This sounds like a hardware issue and, as you mentioned, the power supply seems the likely culprit. And, since that keyboard behaves the same way on another computer, I suspect the keyboard is also faulty.

Concerning the files you'd like to retrieve from that hard drive, I would just remove it from the eMachines W2247, and put in the other computer as a slave drive, even if only temporarily, to retrieve files off of it. Another option would be to get an external enclosure with a USB cord to connect to your computer, and install that hard drive in it.

Either way, you can delete all the Windows and other program files on that old hard drive and continue to use it as a second internal drive or as an external hard drive (in the external enclosure). The external hard drive makes a good backup device.It's possible that the keyboard is faulty, but it seems odd because it worked just fine before this happened. Unless a LOSS in power supply somehow fried the keyboard... Could that even happen?

As for using it as a slave drive...it's a good idea and I could certainly use a few extra GB. However, I'm not at all familiar with the inner workings of a computer tower. I've only been inside of a computer to clean it out and remove stuck disks. I haven't the slightest idea how to go about installing a second drive and I'm afraid of mucking something up. However, I do have a couple of other computers I could maybe practice on.

Is there some kind of in-depth tutorial I could refer to that would guide me along in the process of doing all of this? I'd love to be able to access those old files. And it'd be nice if I could steal the hard drive out of a Dell that my sister doesn't use anymore. Heh. Thanks for your help, soybean.Here are several references that should help:

How to Install a Second Hard Drive
How to Change the Master/Slave Designation on a Hard Drive, and
Setting Hard Drive Jumpers (includes images of hard drive jumpers)

Removing the old hard drive should give you some insight into how the drive is mounted in the case and how the power and data cable connectors fit together. However, the actual mounting can vary from one computer case to another; it depends on the design of the case.

The data cable must be connected a certain way. Look carefully at the pins on the hard drive and the connector on the cable before trying to connect the cable to the drive. The hard drive will probably have one pin position where there is no pin and the connector will have a blocked pin position which corresponds to the pin pattern on the hard drive connector. This is designed to preclude connecting the cable the wrong way, or upside down.

Likewise, the power cable will not fit onto the drive's power connector in an upside down position. Two corners of the power cable connector will be beveled. Look at it closely and you'll surely see this.

Regarding the hard drive jumper position for the slave setting, look on the hard drive for a diagram of the master and slave jumper settings. You see this in the third reference above.Thanks for the links, soybean. Looks like I've got a bit of homework tonight. Heh.I haven't tried doing this yet because I wanted to get the Dell up and running first (which I just did a little while ago), but I thought I would mention something else...

When I plug in the eMachines, I can hear a slight high-pitched humming sound coming from the back. Maybe this is normal, but I don't remember ever noticing it before. Also...it didn't do this before, but now it sounds like it's trying to power up when I turn it on. But the lights don't come on and it doesn't actually do anything. What are your thoughts on that? Does it still sound like a power supply issue?computers are like playing with legos , DONT be scared.

most probably you have a psu dying (try checking the voltages with a voltmeter) Usually pre built machines are installed with terrible psu. the huming is due to the build up of dust around the fans, if you clean them there will be less humming.try running your rig with one set of ram or with other ram, as ram failiures are quite often. do you get any beeps ?I have never had RAM go bad in my life, and I have owned and worked on quite a few machines.

A bad power supply from eMachines is much more common.Yep, it still sounds like a power supply problem. If you want to replace it, ebay might worth looking at; see: POWER SUPPLY FOR EMACHINES W2247 computer

That computer could be a decent machine, with more memory. I'm running an AthlonXP 2200, the same processor as the one in that eMachine, with 512MB of RAM and an AGP video card. I believe the eMachines W2247 has onboard video but also has an AGP slot. So, more RAM and an AGP video card are two options for a better performing computer.

Here's what Crucial.com shows for it: http://www.crucial.com/store/listparts.aspx?model=W2247Ooh boy, I just opened that thing up and...man...sure looks like I neglected that poor machine. No wonder it crapped out on me. I've never seen such a dusty computer. I should've expected such a thing after moving to a farming community like this. Although I doubt it will make much of a difference, I'm going to give it a very thorough cleaning (it can't hurt, right?). And I need to make sure I do some preventive care for my Gateway. I'll be back in a few hours...Oh, and thanks, soybean. I'll definitely add that auction to my watchlist!Whew, that was one heck of a job. As I figured, it didn't really help anything (although one of the lights did come on for a few seconds), but it feels good to have that all cleaned out. Even though I'm probably going to die of lung cancer now. Heh. I think I'm going to try installing a new power supply before messing around with anything. But if that doesn't work, I'll move on to installing the hard drive into another computer. Expect plenty more questions from me if/when it comes down to that. Ha.This is quite a bump, but I figured I'd give an update. I've been watching PSU's on eBay and I don't have the funds to buy one yet and I was getting anxious, so I finally tried putting the W2247 hard drive into the Dell...and it actually worked without a hitch. I didn't even have to mess with the BIOS or anything fancy. I just hooked it up and the Dell did the rest. It's rare for things to be this easy for me. It looks like a hillbilly computer because the Dell doesn't have a drive cage, so I kinda had to rig something up, but it works wonderfully. It's a little slow, but who cares? I'm just happy to finally have access to these files again. Thanks a lot, soybean, for the very helpful links! Now I don't have to buy a PSU...but I still might just for the heck of it. Maybe I'll fix this thing up and sell it to a friend or something. I would just put the hard drive in my Gateway for an extra bit of space, but I think I'd rather wait until I can buy a brand new one with about 500 GB. Anyway...thanks a bunch. Now, it's time to get back to backing up my files.

3461.

Solve : Pop up virus?

Answer»

Thank you for your help it has been very useful.

I am now more wary about this sort of thing and will HOPEFULLY have the right stuff to COMBAT it.This thread has been locked now that it is RESOLVED.

Should the original poster require it re-opening PLEASE PM GX1_Man or a MODERATOR.

3462.

Solve : Analysis/Help please?

Answer»

Well, i'll give a little background I guess. You could call me a gamer, and as most people do - I encounter the occasional virus or adware problems. I use McAfee which includes a firewall and virus scanner as well as Webroot Spy Sweeper which has many accessories (spy sweeper, startup shield...I'm sure most of you know this already.) With those TWO things I can usually get rid of most viruses I COME across.

Well, I went away on vacation for 4 days, and I come back and I load up the game I play (Battlefield 2142) I cant walk in a straight line. My ping is jumping from 30 to 350, spiking all over the place. My ping settles down to around 60 but I still experience lag. After a while, everything feels normal but again, it comes back and I'm lagging real bad for a good 10 MINUTES I log off and have been trying to find out the problem. I'm not sure what happened because I was away, but I have a younger sister who I guess could have had something to do with it but I cant get anything out of her.

Anyways, I went through the FAQs and have downloaded many a spysweepers and etc. So far I have run: McAfee, Webroot, Ad-Aware SE, CCleaner, Spybot search and destroy, as well as Vcleaner. I have picked up a few things like low risk cookies as well as one noted-high risk called download.small.co which I have quarantined.

I saw a lot of other posts that have that Hijackthis thing so I'll post that, I hope i did it right.

Logfile of HijackThis v1.99.1
Scan saved at 4:29:11 PM, on 2/23/2007
Platform: WINDOWS XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\iTunes_Carly\iTunesHelper.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Documents and Settings\All Users\Desktop\Main\Anti Virus\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: SSVHelper CLASS - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [OASClnt] "C:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes_Carly\iTunesHelper.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1165888161765
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - file://C:\TempEI4\EI40_\msxml4.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

Edit - Add some system specs:
Operating: Windows XP (I own a legitimate CD)
Mobo: Desktop D865GLC
Processor: Intel Pentium 4 2.4Ghz (these two are going to be replaced by the end of the week)
Vcard: 7800 GS
Sound: Sound-Blaster


Anyways, thanks a bunch for any help - i'd really appreciate it.Anybody? The Hijack This experts are not here 24/7...be patient and someone will be along shortly.Your HJT log is fine aside from a couple of missing file entries.

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

Your lagging could be due to internet congestion, the game server itself or even your own ISP.
Have you talked to anyone else who plays on the same server to see if they are experiencing problems.They dont get any problems. You can tell its on my side because of the massive ping jumps. I'll have a 150+ Ping when I usally get around 30. And its comes in spikes.

Sorry, I didnt mean to sound impatient or whatever, I just bumped itTalk to your ISP, see what they say about it.okay, thanks anyways

3463.

Solve : Problem with ie?

Answer»

Quote

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

I find this confusing. I have J2SE Runtime Environment 5.0 Update 11. That update occurred on 2/15/07; it was automatic, since I have Java to automatically check for updates. So, I supposedly have the latest version. Yet, you say the latest version is Java Runtime Environment (JRE) 6. I just opened my Java Control Panel and CLICKED on the Update Now button to see whether it would GET another update. It tells me I have the latest update. What's the scoop here?soybean .... please do not hijack someone else's THREAD. Please start your own topic.


OJBut ..., hijacking is fun. Actually, I debated about whether to post the question here or start a new topic. I'll post it as a new topic.This thread has been LOCKED now that it is resolved.

Should the original poster require it re-opening please PM GX1_Man or a MODERATOR.
This thread has been locked now that it is resolved.

Should the original poster require it re-opening please PM GX1_Man or a moderator.
3464.

Solve : inetsrv folder?

Answer»

I am running WINDOWS XP Home, SERVICE pack 2.
My norton antivirus picked up a virus in system32. I forgot what the virus name was but it was in a folder i have never seen before called 'inetsrv'.
My antivirus got rid of it and the folder but when i restart/turn on the computer, there is an undeletable empty folder named 'inetsrv'
Anyone have any idea what this is?Could be a Wareout infection. We need to see a HijackThis log first though.

I suggest you print this out to help you follow my advice.


Please download FixwareOut from one of the following sites .....

http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

http://downloads.subratam.org/Fixwareout.exe


SAVE it to your desktop and run it.

Click Next, then Install, make sure "Run fixit" is checked and click Finish.

The fix will begin; follow the prompts.

If your FIREWALL gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.

Then you will be asked to reboot your computer; please do so. Your system MAY take longer than usual to load; this is normal.

Once the desktop loads please post the text that will open (report.txt) and a new HijackThis log.

Note: ONLY if you have connection problems after performing above steps - go to Start > Control Panel choose work Connections, right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) and select the radio button that says obain DNS servers automatically. Click OK twice and restart your computer.

*******************

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

*******************

If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow for whatever it is that's causing the problem.


OJHey thanks man, ill try thatSorry but I have had to correct the wording in my advice (above). No substantive changes ... just corrections to my spelling. I really need to improve...... Due to lack of response this thread now locked.

Should the original poster require it re-opening please PM GX1_Man or a moderator.

3465.

Solve : Another analysis please?!?

Answer»

Hi there. This time its MY laptop. I cant finish the other one i have posted until Tuesday like i said. First off, my SB S&D keeps telling me its removed these entries below, but whenever I do a scan they return. Im doing the scans with Sys Restore turned off. Any Ideas?!
http://img181.imageshack.us/img181/1596/kjsr1.jpg
EDIT: Now Ive done another scan and i got these. http://img251.imageshack.us/img251/6983/sadgi8.png
Second off I know i have infection. Avast! keeps telling me something is trying to access a server. I know what it is, the Process is called v6.exe and I know that that is the virus. Below is the HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 19:28:00, on 25/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_11\BIN\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Internet Explorer\csrss.exe
C:\WINDOWS\system32\sistray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\v6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Chris'\My Documents\My Downloads\hijackthis(3)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=3981
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
O2 - BHO: (no name) - {03E41DBC-C9F8-3A24-FE20-0B94A61C884F} - C:\WINDOWS\system32\qsokfli.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [ddhonui.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Chris'\Local Settings\Application Data\ddhonui.dll",ysuecmg
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvxig.dll,startup
O4 - HKCU\..\Run: [] "C:\Program Files\Internet Explorer\csrss.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\ProO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkjkih - C:\WINDOWS\SYSTEM32\jkkjkih.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll
O20 - Winlogon Notify: winmyy32 - C:\WINDOWS\SYSTEM32\winmyy32.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe





Thanks ChrisHello again Chris

Not only do you have the v6.exe malware but you also have Vundo/Smitfraud/Browseraid and other malware.

I recommend you print this out to help you follow the advice.


Open Task Manager … click “End process” for this one (the malware you mentioned) ……

C:\WINDOWS\system32\v6.exe

******************

Download SUPERAntiSpyware here …...

http://www.superantispyware.com/

Update to the latest definitions and run a full system scan.

******************

Open HijackThis … click on scan … put tick/check marks next the following entries IF they are still present ….

O2 - BHO: (no name) - {03E41DBC-C9F8-3A24-FE20-0B94A61C884F} - C:\WINDOWS\system32\qsokfli.dll

O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe

O4 - HKLM\..\Run: [ddhonui.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\Chris'\Local Settings\Application Data\ddhonui.dll",ysuecmg

O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvxig.dll,startup

O20 - Winlogon Notify: jkkjkih - C:\WINDOWS\SYSTEM32\jkkjkih.dll

O20 - Winlogon Notify: winmyy32 - C:\WINDOWS\SYSTEM32\winmyy32.dll


Remember to close ALL open windows – including this one - before clicking on “Fix Checked” at the foot of the HijackThis window.

******************

Locate these files and delete them IF they are still present ….

C:\WINDOWS\system32\qsokfli.dll

C:\WINDOWS\system32\v6.exe

C:\WINDOWS\system32\drvxig.dll

C:\WINDOWS\SYSTEM32\jkkjkih.dll

C:\WINDOWS\SYSTEM32\winmyy32.dll

******************

Empty your recycle bin.

******************

Reboot your system into normal mode and use it as you would usually do.


Hopefully everything will have improved.


IF NOT then run a fresh HijackThis scan and look to see IF either of these files have returned …

O2 - BHO: (no name) - {03E41DBC-C9F8-3A24-FE20-0B94A61C884F} - C:\WINDOWS\system32\qsokfli.dll

O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvxig.dll,startup


IF they are present in the log do this …..

Please download VundoFix.exe to your desktop.
1. Double-click VundoFix.exe to run it.
2. When VundoFix re-opens, click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. You will receive a prompt asking if you WANT to remove the files, click "YES".
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will reboot your computer, click "OK".

7. Please post the contents of C:\vundofix.txt and a new HiJackThis log.

If vundofix cannot delete a file, it will try to delete it during a reboot, after the reboot vundofix will open again, you must run vundofix again, from "Click the Scan for Vundo button" ... and you must keep running vundofix untill it does delete the file... I've known a stubborn vundo file take 5 or 6 reboots before it is deleted...

Run vundofix again & again until you get the message "no infected files were found".

******************

Is Spybot S&D working OK now (don’t forget to update that program too)?

When you have done all this post a fresh HijackThis log with an update on how things are operating now.


OJ
Hi there, thanks alot!! Ok first off qsokfli.dll and v6.exe wernt present, but jkkjkih.dll and winmyy32.dll where. However when i tried to delete winmyyy32 it said that it cant delete it because 'Access is denied, Make sure the Disk is not read or write protected and hat the file is not currently in use'. For jkkjkih it said 'Cannot delete jkkjkih.dll: It is being used by another person or program. Close any programs that MIGHT be using the file and try again'. Below is another log.

Logfile of HijackThis v1.99.1
Scan saved at 18:14:53, on 26/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Internet Explorer\csrss.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Chris'\My Documents\My Downloads\hijackthis(3)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bbc.co.uk/weather/5day.shtml?id=3981
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {601774FD-4B3F-44F0-99E3-B0E4E0146F65} - C:\WINDOWS\system32\jkkjkih.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [] "C:\Program Files\Internet Explorer\csrss.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: jkkjkih - C:\WINDOWS\SYSTEM32\jkkjkih.dll
O20 - Winlogon Notify: WBSrv - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Hi

Run the vundofix routine explained at the end of my last post. Run it as often as necessary till you see "no infected files were found".


After that post another fresh HJT log ....

AND ....

....another update on how your computer is working now.


OJWell theres no difference. My Antivir keeps popping up saying that jkkjkih.dll has been DETECTED, and i choose to delete them but an hour later it will come up with the exact same.
Ive ran Vundo a couple of times and it keeps finding things but ill keep going.
Thanks!

ChrisHow's it all going, Chris? Fixed yet?


OJ

3466.

Solve : Suspicious dll in XP (trojan related I'm sure)?

Answer» GLAD all seems to be well again.

NOW you can do what I suggested in post #9

SAFE surfing.


OJ
3467.

Solve : Autorun.inf Virus?

Answer»

Hello everyone,

a friend of mine caught the autorun.inf virus..he is on a dial up so it is hard to update virus definitions..i heard that there is a way to remove it by deleting all the files named autorun in local drivers but this didn't solve the problem..is there any way to remove it without the NEED to update?

thxDownload AVG Free onto that computer and run the updater and just be patient. I'm on dial-up (28.8 kbps) and the last big update took me maybe ten or fifteen minutes to download. Or you can even download the manual updates from the site on broadband and then put them on his computer. Either way, it's certainly better than just deleting some files. You're pretty much guaranteed to have traces leftover. And malware likes to have parties. Once you get one, it will often let others in. So, there's a good chance he has more than one virus. Just be patient and take the time to install the necessary updates. Slow and steady wins the race.seems that this is the only way my friend..deleting or replacing files didn't solve it..guess the only option is to download those updates..thx for the help man..Like CBMatt says .... malware attracts malware.

That autorun problem could indcate a number of issues.

What I suggest is that, after AVG has been run and updated, post a HIJACKTHIS log here for further review. Hopefully anything bad will show up in that log.

If you're unsure how to do this .....

download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and PASTE the HJT logfile to this thread. More specific removal instructions will follow for anything SHOWING up as bad.


OJ

the best way to run any ANTIVIRUS is in SAFE MODE, reboot the computer and keep pressing the F8 key and then select the SAFE MODE, when you are into the windows protected screen run the antivirus then there is a bigger chance it will be cleaned out.
Try Asquared
from here:- http://emsisoft.com/en/software/free/
OR
AVG Anti-Spyware from here:- http://free.grisoft.com/doc/1

3468.

Solve : Help Unable to View Links with IE 6?

Answer» unlovedwarrior ... no problem. Please add anything at any time if you feel it would be useful.

Nhksrv.exe > Should be OK. See here ..
http://www.liutilities.com/products/wintaskspro/processlibrary/nhksrv/

snmp.exe > Again, should be OK. Microsoft SNMP Agent service that allows the user to configure and manage the SNMP (Simple Network Managament Protocol).

****************

littelp24 ... You should print this put to help you follow the advice.

Make sure you have EXPOSED all Hidden Files & Folders.

To enable the viewing of Hidden files follow these steps:

1. Close all PROGRAMS so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click FOLDER Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and close My Computer.

***********************

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

*******************

STILL in safe mode ... open HJT ... click on scan ... put tick/check marks next to these entries IF they are still present ...

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O15 - Trusted Zone: http://www.match.com
O15 - Trusted Zone: http://www.mcartsworkshop.com
O15 - Trusted Zone: http://www.webkinz.com
O16 - DPF: {70522FA2-4656-11D5-B0E9-0050DAC24E8F} - http://download.iwon.com/ct/pm3/iwonpm1,0,2,5.cab


Remember to close ALL open browser windows – including this one – before clicking on “Fix Checked” at the foot of the HijackThis window.

NOTE >> The 015 fixes above are optional. I would never keep anything in the Trusted Zone. It's just too dangerous. However, it's your choice to fix them or not.

*******************

Reboot to normal mode and use the computer as you would usually do.

*******************

Update your Webroot Spysweper to the latest definitions and scan the computer with it. Let it fix what it wants to.

*******************

Make sure you have the latest version of java installed. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control PANEL double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
*******************

Also make sure your antivirus and firewall are both fully up to date.

*******************

Run a full system-wide search of your computer for iwon. Post BACK the results here giving the locations of anything found.

Also post back a fresh HJT log and the scan report from AVG Anti Spyware.


Let us know if anything has improved.


OJ
3469.

Solve : Some nasty virus resident memory! Need help!!?

Answer»

Hi everyone,

I got a virus in the resident memory And all my efforts to clean it had come flat.

First, it killed my firewall (sygate firewall) and my antivirus (AVG Pro). Now, everytime I try to put a firewall or an antivirus, I got a pop up saying that It can't find the *.exe files to put the software on the computer. I was able to put escan (for virus) and trojanhunter on the computer, but not real good help.

The virus had corrupt the files wshcon.dll. That I manage to fix it (download a new one and put it back instead of the other)

I can't see anything when I open the add-remove programs in the control panel. So I can't go there to find a way to put a firewall and an antivirus that could eleminate the treat.

When I start the computer in save mode, it CRASH and say to check for virus.

When I start the computer (regular) 3 time, the escan program told me that a file name program could hurt the computer and ask to rename it so it is safe

Also, when I used trojanhunter, it said: c:\pagefile.sys not scanned (in use by another application)...I can't found this file.

I found that folders had been put on the computer those are: $WIN_NT$.~BT, FOUND.003 and FOUND.004.

Could someone that have a clue to correct this can give me a hand?

I thank you in advance

Prulon
Being unable to scan pagefile.sys is normal, it's your paging file and as such always in use. You won't be able to see it unless you enable it to show hidden files and folders.
The folders there are normal - the first is a temporary folder left over from Windows installation, and the others are folders with recovered files in, usually from scandisk.
You say you can't boot into safe mode - what exactly happens when you try to?
What antivirus programs do you have on the C, and which ones work?

Can a mod please move this to viruses?
Thanks.

Blackberry: done
Cheers - CalumHi, everyone and thanks to answer me Blackberry.

I found that I have the mitglieder.q.

I find it with stopzilla. Problem is I can't remove it for the program is a TRIAL and it does not remove virus with the trial.

Do you know a free program that would do the job?

the only av that would installed was escan. I tried many top av but all didn't work.

It's late so I'll go to sleep. Tomorrow, I'll try again in safe mode and write down what the message is, then I'll post it.

Thanks again

Prulon thanos...... Just so we know, will your pc boot up in normal mode ?
You say the trojan Killed the anti-virus ....... I suspect it just disabled it and hopefully you can restart it.

Will it start up in safe mode ?

dl65 Hi,

Thank to post dl65...

The stopzilla free tiral 4.4 just found and block the virus, not remove it. Need the registred version for that.

I still can't start the computer in safe mode, but it start in the 'normal mode'.

The safe mode start well until I see : 'Loading SPTD.SYS'...It stay on the bottom of the screen for a couple of second then a blue sceen appear.

Here is a trancript of what it is writting on the blue screen in the safe mode:

'' ***stop:0x0000007B (0xEB41B84C, 0xC0000043, 0,00000000, 0,00000000) INACCESSIBLE_BOOT_DEVICE

Check for viruse on your computer, check you hard drive to see if it is proprely configured and terminated.

Run CHKDSK /F to check for hard drive corruption, and then restart your computer.''

I did the latter a couple of time. The hard drive have corrupt string and was repaired, but it come back.

I know that my hard drive is fine, and I know that I have the MITGLIEDER.Q. (At least, it is what stopzilla said)

Now, need to found a way to remove it.

Also if someone know a firewall and an AV that won't be 'killed' by virus or other thing, I'll appreciate your input on the best of both.

Thanks again

Prulon thanos ........ ok....... you didnt really say if AVG pro will open ......
But in any event ....how about d/L hijackthis....... get it from ....
http://www.majorgeeks.com/download3155.html once you have it D/L ...... to your desktop , close up everything else , install and run a scan , save the log and post it here so we can see whats going on.
Use as many posts as necessary to get it all posted .


dl65
Hello

Here is the hijackthis.log...And by the way, thanks for your fast help...

Logfile of HijackThis v1.99.1
Scan saved at 4:41:56 PM, on 2/13/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\hldrrr.exe
C:\Program Files\GTCO CalComp\TabletWorks\TWCP.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\PROGRA~1\eScan\TRAYSSER.EXE
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\eScan\TRAYICOS.EXE
C:\Program Files\Common Files\MicroWorld\Agent\MWASER.EXE
C:\Program Files\Common Files\MicroWorld\Agent\MWAgent.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.globetrotter.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Toon Boom Animation\Toon Boom Studio 3.5\Resources\English.lproj\help\fullPC\wwhelp\wwhimpl\common\html\blank.htm
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://by103fd.bay103.hotmail.msn.com/cgi-bin/HoTMaiL?curmbox=00000000%2d0000%2d0000%2d0000%2d000000000001&a=938d72bb6586a89e5f02f3daae11ebb5020085e5c909ae61b1b31c788889826e&fti=yes"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\0eufqvrq.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CNetscape_France.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\0eufqvrq.slt\prefs.js)
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ZILLAbar BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\ZB2.dll
O2 - BHO: FlpLauncher Class - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - C:\Program Files\E-Book Systems\FlipViewer\fplaunch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: GOOGLE Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\ZB2.dll
O4 - HKLM\..\Run: [UpdService] C:\Program Files\Common Files\Microsoft Shared\MSWNInfo\UpdService.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [STOPzillaInstall] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\STOPzilla\SZSetup.exe product_install=STOPzillaFULL.msi sz_install=finish
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [STOPzilla] "C:\Program Files\STOPzilla!\STOPzilla.exe" /autorun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TabletWorks.lnk = C:\Program Files\GTCO CalComp\TabletWorks\TWCP.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll

Part 2 follow...Here is part two of the hijackthis log file:

O10 - Unknown file in Winsock LSP: c:\winnt\system32\mwtsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\mwtsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\mwtsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O20 - Winlogon Notify: WgaLogon - C:\WINNT\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: BvrpKrnl - Unknown owner - C:\Program Files\WinFax eXPert\BVRPKrnl.exe
O23 - Service: DirectX Service (DirectXopr) - Unknown owner - c:\winnt\system32\directx.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: eScan Server-Updater (eScan-trayicos) - MicroWorld Technologies Inc. - C:\PROGRA~1\eScan\TRAYSSER.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: License Management Service ESD - Unknown owner - C:\Program Files\Common Files\element5 Shared\Service\Licence Manager ESD.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MWAgent - MicroWorld Technologies Inc. - C:\Program Files\Common Files\MicroWorld\Agent\MWASER.EXE
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Pro Home 2007.SP1\RpcSandraSrv.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

Hope this help to solve the problem...You will see that I tried a lot of software to try to fix it.

Thanks again

Prulonthanos.....
ok....lets see what we can do.
[highlight]C:\WINNT\system32\hldrrr.exe [/highlight]this is not good and must be removed.
Use the task manager to shut it down........ then download Prevx1 to remove it completely http://info.prevx.com/downloadremove.asp .

Once this has been done let us know what was found and that it was removed.

dl65 Hello,

I try Prevx1. It find malware, but didn't want to put them in the jail, so I couldn't delete them.

I try avg anti-spyware, and it found 332 files that it quarantine and delete.

But that seem not to do the thing because my pc still had problem after.

I figure that it would be because Prevx1 didn't put the malware to the jail to be delete, but hold them to do no harm. So I just uninstall Prevx1 and redo a scan with avg anti-spyware...Will see...

The avg software found those at the first scan (in the 332 files):

dropper.delf.vt
hijacker.vb.ku
worm.bagle.ht
worm.bagle.hx
worm.bagle.hw
dropper.agent.bct

Have a clue of what thoses are?

There is two other things:

When windows start, it open a window from program files\common. And in it is a file name vsovprev.ax...What's that?

Also, a pop up appear that say: winnt\csc\00000002 is corrupt and unreadable. do chkdsk /f.

I did it a couple of time (the chkdsk /f) and everytime computer reboot itself like forever then when it start windows WITHOUT rebooting, the same thing appear again. (both thing above)

By the way, I tried to open in safe mode, but still boging...

Anyway...With the help I have from you and the thing I read on the net, I'm sure I'll manage to fix it...

Thanks again

Prulon thanos .... what dl65 says is right. That process is from the W32/Bagle-KF worm infection.

However .... you have many other problems. Your java is well out of date, you have a CWS infection and, probably most importantly, a Trojan that allows a remote intruder to gain access and control over your computer through IRC channels.

Please print this out to help you follow the advice.

This is in the log ....

O23 - Service: DirectX Service (DirectXopr) - Unknown owner - c:\winnt\system32\directx.exe

We must stop & disable this added service.

1. To stop the service and set to 'disabled' .....

Go to Start > Run and type in "Services.msc" (without the quotes) then click OK

Click the Extended tab

Scroll down until you find the service

O23 - Service: DirectX Service (DirectXopr) - Unknown owner - c:\winnt\system32\directx.exe

Click once on the service to highlight it

Click Stop

Right-Click on the service

Click on 'Properties'

Select the 'General' tab

Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box

From the drop-down menu, click on 'Disabled'

Click the 'Apply' tab, then click 'OK'

The service is now stopped and disabled.

***********

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.

***********

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

***********

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

***********

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for each one (IF it still exists) ...........

C:\WINNT\system32\hldrrr.exe

***********

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (IF they still exist; make sure you do not miss any) .........

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Program Files\Toon Boom Animation\Toon Boom Studio 3.5\Resources\English.lproj\help\fullPC\wwhelp\wwhimpl\common\html\blank.htm

O4 - HKLM\..\Run: [UpdService] C:\Program Files\Common Files\Microsoft Shared\MSWNInfo\UpdService.exe

O23 - Service: DirectX Service (DirectXopr) - Unknown owner - c:\winnt\system32\directx.exe


Remember to close ALL open windows & browsers, including this one, then click "Fix Checked" at the foot of the HJT window.

***********

Delete the following Files indicated in BOLD IF they are still present ....

C:\WINNT\system32\hldrrr.exe

C:\Program Files\Common Files\Microsoft Shared\Stationery\Blank.htm

C:\Program Files\Toon Boom Animation\Toon Boom Studio 3.5\Resources\English.lproj\help\fullPC\wwhelp\wwhimpl\common\html\blank.htm

C:\Program Files\Common Files\Microsoft Shared\MSWNInfo\UpdService.exe

C:\winnt\system32\directx.exe

***********

Still in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

***********

Reboot your system in Normal Mode.

***********

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
***********

Please post the results of the AVGAS scan and a fresh HJT log.

Please also say how your computer is operating now.


OJI was working on the above fix whilst you were posting your most recent comments. As you can see you have multiple problems but please proceed with the fix I posted. That should clean you up quite a bit.

We can move on from there.


OJNice Work, oddjob !Hi,

And thanks OJ for your advice.

I just got a 'little' problem with what you wrote...I can't reboot in safe mode.

On the net I found this (below) for I taught I may have the Win32.Agent.zf.

It suppose to help me reboot clean...Remember that I have win2k pro pack4.

I would appreciate if you can tell me if it is a good thing to do or not.

Here here goes:

'' Manual removal:

1. Create a c:\rescue.bat file which contains the following strings:
@echo off
:try
del C:\WINDOWS\SERVICES.EXE
if exist C:\WINDOWS\SERVICES.EXE goto try
2. Modify the following system registry entry: from
[HKLM\System\CurrentControlSet\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
to
"ImagePath"="C:\rescue.bat"

Doing this ensures that rescue.bat will be launched instead of the Event Log system servcie.
3. Reboot the computer. The Trojan will be deleted once the system has been rebooted.
4. Restore the original ImagePath value:
[HKLM\System\CurrentControlSet\Services\Eventlog]
"ImagePath"="%SystemRoot%\system32\services.exe"
5. Delete the following keys from the system registry:

[HKLM\Software\Microsoft\Serenta]

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"SERVICES.EXE"="%Windir%\SERVICES.EXE"
6. Modify the following parameters:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe %Windir%\SERVICES.EXE"
to:
"Shell"="Explorer.exe"
"Userinit"="C:\WINDOWS\system32\userinit.exe,,%Windir%\SERVICES.EXE"
to:
"Userinit"="C:\WINDOWS\system32\userinit.exe"
7. Update your antivirus databases and perform a full scan of your computer (download a trial version of Kaspersky Anti-Virus). ''

I won't do nothing till I hear from you.

Prulon Hi again,

I just post not so long ago.

A pop up always come that say that winmgmt.exe had generated an error and will be closed by windows you will need to restart the program.

No program seem to work at the time. Here the log file:

(Thu Sep 22 15:20:02 2005) : core was asked if ok to unload and returned 0x1(Thu Sep 22 15:23:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 15:53:19 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:21:22 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:37:04 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 16:40:37 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 17:16:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 17:25:57 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:23:30 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:33:33 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 19:35:06 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 20:02:06 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 22 20:05:19 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:22:51 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:47:20 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 07:53:10 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 08:14:23 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 11:51:21 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 12:01:59 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 12:07:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 14:44:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:02:09 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:05:40 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:21:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 16:43:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 17:34:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:04:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:37:41 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 23 23:44:47 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 08:24:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 13:25:53 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 13:45:24 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Sep 24 23:38:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 00:14:16 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 10:38:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Sep 25 23:16:01 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Sep 26 23:29:43 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Sep 27 14:50:08 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Sep 27 18:40:25 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 08:06:41 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 11:00:50 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Sep 28 11:57:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Sep 29 08:08:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Sep 30 22:39:28 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Oct 01 22:48:23 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 03 02:17:39 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 04 12:40:08 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 04 13:11:16 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 05 12:55:10 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Oct 06 23:00:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Oct 07 19:53:11 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sat Oct 08 22:42:22 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Oct 09 08:15:46 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Sun Oct 09 22:27:17 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 10 21:31:32 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 11 22:01:33 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 12 07:49:12 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 12 23:51:25 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Thu Oct 13 20:26:36 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Fri Oct 14 23:36:43 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Mon Oct 17 22:27:31 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Tue Oct 18 21:47:04 2005) : core is being shut down by WinMgmt.exe, it returned 0x0(Wed Oct 19

Next I'll post the last hijackthis log.

Prulon
3470.

Solve : NOD32 Diskette, How Can I do it??

Answer»

How can i create a DISKETTE from NOD32, to BOOT and VERIFY the computer??

3471.

Solve : question about Inspiron running slowly?

Answer»

I recently came into possession of a Dell Inspiron 6000; before me, it was owned by a friend.

When I first got it, it was very reliable, very fast, and very quiet. A few months later, and now it seems to be running slower and the fan is now constantly on -- not extremely loud, but like I said, it used to be dead-quiet. I downloaded a few free anti-adware programs, which enabled me to get rid of a few malware programs on my computer (there weren't many, though), checked for viruses that weren't there, and I also ran Defrag, but the computer is much less RESPONSIVE than it used to be (which ultimately makes me FEEL like a failure as computer-owner).

I notice the computer is really slow at start-up. When I'm running a few different programs (like I usually have Windows Media Player, INTERNET Explorer, and Word Processor all running at once), the computer is pretty slow and unresponsive. However, if I'm running just Internet Explorer using multiple tabs for different sites, it runs generally okay. So I basically have two main questions:

1.) What more can I do to try to make my computer RUN as fast and as responsively as it did only a mere few months ago?

and

2.) Is it normal for my computer's fan to be running constantly like this? (It should also be NOTED that I downloaded a program that allows me to check on the CPU temperature, and when I only have on program running, the average temp is usually around 28 degrees C, but higher when I have more programs running.)

Thanks in advance,
Joshok can we get some more info? like os and hardware specs and what software you used?



unlovedwarrior

3472.

Solve : How can I tell if someone is on my computer??

Answer»

Ok my computer has been acting a little funny latly, and I was woundering if it is possible if someone had maybe cracked my computer. What are some of the signs that someone else is using your computer/system? I have heard of things called Trojan Horses before but what else could it be? And what can I do to get rid of whatever it might be or tell if there is even anything wrong at all? I only use avg and I run it everyday. Is there any other free anti virus programs that I can dowload to help keep my computer safe?

-Melissa-Hello Melissa

Please can you give more details as to what you mean by "a little funny".

*******************

Also do this.

If you are on Windows 2000 or XP download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

*******************

If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own FOLDER ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the MENU click on "Do a system scan and save a logfile".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow for whatever it is that's CAUSING the problem.


OJOk well for staters its really slow starting up and when I say slow I mean like it takes a good 10 min to just start the computer up and get it to a point where I can actually do things on it without it freezing. Another is that when Im playing online games, sometimes the charecter Im using or the game in it self, will just start playing by itself. Like the charecter will start running around the screen by itself with out me touching anything. (And this is in the middle of the game after everything is already loaded) Another is that the mouse flips all over the screen. Im on a laptop and that seems a little funny to me. And my biggest problem is that someone has been screwing around with my llife big time using a computer. On msn and Nexopia someone figured out my passwords and was sending msgs to my friends and boyfriend, telling them that I was no good and that I was cheating (which I wasent) And that (and this came from whoever is doing this themselfs) that even if I changed my passwords on all of my accounts, that they would still have access to them because they were already logged in. Now I thought that you get logged out of most of these things as soon as your computer gets turned off or goes into sleep mode, which means that this person would pretty much have to sit in front of there computer 24/7 to keep there computer from shutting off, just so that they could stay on my accounts. Seems pretty weird to me. And also whoever is doing this seems to know me pretty well. Like they know even small stuff about me like bad habbits and the way I act and stuff I have done in the past. Which means that its probably someone I know. But the think is that no one I know has the capability to do all of this. So im really stuck and lost and I dont know who to trust out of my friends cause really it could be anyone. Wow sorry that was a really long post. I dont know if thats spamming or not. If it is then Im really sorry and you can just delete this.

-Melissa-OK. This is my recommended course of action.

If I were you I would report this behavior to the moderators/administrators of the sites in question.

Next, derigister from ALL the organisations/websites and stay away from them for a few days. Don't tell anyone if you're suspicious of your "friends".

Now run through the AVG AntiSpyware & HijackThis instructions I gave you in my earlier advice.

Post back the AVG scan report and the HijackThis logfile.

We will see if there's anything obviously bad, fix that first then, when you're clean, you can think about rejoining the sites.

But that's me. You do what you think is best but I must see those two scan reports please.

Post back as soon as you can.


OJNo, a long post it not spamming. LOL. But, a long paragraph is hard to read.

Are you using a firewall on your computer? Are you using Windows XP? Do you have Service Pack 2 (SP2) installed?Quote

Do you have Service Pack 2 (SP2) installed?
Mellisa ... if you don't have SP2 installed DO NOT install it yet. If your computer in infected with malware SP2 will not install correctly and could make your problems worse.


OJLogfile of HijackThis v1.99.1
Scan saved at 1:41:56 PM, on 3/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\admServ.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\RioMSC.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TELUS eCare\bin\mpbtn.exe
C:\Program Files\Java\jre1.5.0_08\bin\jucheck.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\PROGRA~1\Motive\ASSTCO~1\MOTIVE~1.EXE
C:\Program Files\TELUS eCare\bin\mad.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Melissa\Local Settings\Temporary Internet Files\Content.IE5\C04X7RVQ\setup[1].exe
C:\DOCUME~1\Melissa\LOCALS~1\Temp\is-A65TL.tmp\is-SQL77.tmp
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [LaunchAp] "C:\Program Files\Launch Manager\LaunchAp.exe"
O4 - HKLM\..\Run: [PowerKey] "C:\Program Files\Launch Manager\PowerKey.exe"
O4 - HKLM\..\Run: [LManager] "C:\Program Files\Launch Manager\HotkeyApp.exe"
O4 - HKLM\..\Run: [CtrlVol] "C:\Program Files\Launch Manager\CtrlVol.exe"
O4 - HKLM\..\Run: [LMgrOSD] "C:\Program Files\Launch Manager\OSDCtrl.exe"
O4 - HKLM\..\Run: [Wbutton] "C:\Program Files\Launch Manager\Wbutton.exe"
O4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exe
O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TELUS] E:\Install\TELUS.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\IO4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TELUS eCare.lnk = C:\Program Files\TELUS eCare\bin\matcli.exe
O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Melissa\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Rio MSC Manager (RioMSC) - Digital Networks North America, Inc. - C:\WINDOWS\system32\RioMSC.exe

OK Melissa. Having looked at your log, and remembering your concerns, you have two options.

OPTION 1

If you are still concerned about other people somehow having access to your personal information the only real way to fix it is this ...

1. Save all your important information, music, pictures etc.
2. Reformat/wipe your hard drive clean
3. Reinstall the operating system, all programs and information/pictures etc.

That way you can be virtually certain that any unauthorised access to your computer will be gone.

THEN you can re-register with any sites WITH NEW USERNAMES AND PASSWORDS.


OPTION 2

You can try to fix whatever is causing your concerns but there are no guarantees here and it will take a long time. Certainly longer than Option 1.


If you want to try Option 2 to this is the first stage ........

There are things wrong with the log so let's address those first. This first fix will be over two posts.

Please print out or copy both posts to Notepad in order to assist you when carrying out the following instructions.

Read everything to ensure you understand it all before you start work.

**************

I suspect many of your problems come from using P2P. Limewire in particular. My advice is for you to stop using P2P and remove Limewire completely. It's a magent to malware.

If you decide to do this tell us in your next post.

**************

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

**************

Download Ccleaner from the link below but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/

Run the program immediately with the default settings and let it clean out/remove the clutter from your system.

**************

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it until you reboot into safe mode later in this fix.

**************

Go to this file ...

C:\Program Files\TELUS eCare\bin\mad.exe

Right click > properties & see if it’s a Microsoft file.Tell us what you find.

This file is found on Windows NT4/2000/XP/2003 Server editions only. This service is the System Attendant Service for Microsoft Exchange Server from version 4.0 onwards. Do you know why you have this file on your system?

**************

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work.

Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406

Login on your usual account. Make sure to close any open browsers.

**************

Click > Start > Control Panel > Add / Remove Programs and uninstall the following program (IF it still exists):

BroadJump

**************

Run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

**************

Open HijackThis and click on 'Do a System Scan Only'. Check the following ENTRIES (If they still exist, make sure you do not miss any)......

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - Startup: PowerReg Scheduler V3.exe

O8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTM

O20 - AppInit_DLLs:



Please remember to close all other windows, including browsers then click Fix checked.

**************

Delete the following Folder and Files indicated in BOLD IF they still exist .....

C:\Program Files\BroadJump .... whole folder

PowerReg Scheduler V3.exe >> run a system wide search for this file and delete it IF found

**************

Reboot your system in Normal Mode.

Now do what I advise in the next post.


OJ

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
***************

There is one piece if scumware that hides itself if it knows HJT is running so you need to rename the HijackThis program. This will reveal it.

Right click on the HJT file itself and click on rename. Change the name to "MelissaHJT.exe".

Now run the MelissaHJT.exe file (which still HJT with a new name) and post the log.


Please also post the AVG Anti Spyware log AND an update on how you feel your computer is working now (or if you've decided to choose Option 1 instead).

[By the way please take care when you post your HJT log. The last line at the end of your post number 6 has been cut off. Please make sure you post everything]


OJI think you scared her off with Option 2... Who knows. Melissa............And there you have it...Due to lack of response this thread now locked.

Should the original poster require it re-opening please PM GX1_Man or a moderator.
3473.

Solve : Invisible files?

Answer»

Hello

All the music from my computer recently DISAPPEARED, but the memory was still being used.

I couldn't understand it and posted in a few forums, to no avail.

When I go to the folder the music files were in, there are now no files. Hovering over the folder, it says it contains 0 BYTES and 0 folders.

The folder in which the ALBUMS were stored is something along the lines of:

D:/Documents and Settings/Tim/My Music

When I type this into the Windows explorer bar, it appears, as usual, blank.

However, I recently found that if I type the same, but then add the album folder name, the album will open, complete with MP3s...

D:/Documents and Settings/Tim/My Music/Neil Young - Harvest

So... the files are definately in the folder.

Problem is, I had 40gb of music and cant remember every album's file name to type into the bar. Plus, sometimes it will open the folder when I type the album name in, but other times it won't.

Please would somebody help - I'm out of ideas!

Thanks!
TimDouble post.
I suggest that the discussion is continued in the POSTER's other thread, where it has a response already.
I also think it is more appropriate there.Due to lack of response this thread now LOCKED.

Should the original poster require it re-opening please PM GX1_Man or a moderator.

3474.

Solve : "Locking" abandoned malware topics??

Answer»

Sorry oddjob I should have explained it clearer.
What I meant is that I don't see it as a problem, sure we get the occasional thread dragged up that is abandoned or completed but it doesn't happen very often or cause any harm.
BTW, a belated welcome to you, I for ONE appreciate your presence here as I'm sure EVERYONE else does.
Do you know riprip from ASAP?

A HJT training thread would go great in the FAQ forum IMO.Quote

If it ain't broke don't fix it.
It doesn't hurt to make improvements.

Quote
A HJT training thread would go great in the FAQ forum IMO.
I agree, but I think it'd be even BETTER if we had our own training "school". It's just too bad we don't have the resources to do so.My post #10 indicates TWO different wordings when LOCKING the thread AND a prompt to the OP on how to reopen if needs be. Hopefully OPs will be intelligent enough to realise what to do and not get irate with mods/admins.

This process works well on other sites and I have no reason to think it would work differently here.


Fed ... no, I'm afraid I don't know him/her. I only know a few people at ASAP itself. Actually, I think they could do with help themselves on their own HJT analysis work. People become members of ASAP not necessarily to help out at that site but to carry on whatever work they were already doing on other sites.

As to a "HJT training" sticky I've said already that I would be happy to put something together but I do need the authority/approval of site admin to do it, I think. Especially if site admin is to pin it as a sticky.


CBMatt ... yes it would be excellent to have our own HJT training school but, as you say, the resources required would be massive. Anyway, as you already know, there are plenty of excellent training schools already around.


OJ
3475.

Solve : ** NEW HJT**?

Answer»

Quote

My ADVICE would be for INFECTED users to not use the program at all until it's RELEASED from beta.
Fair enough but, if they do, then they shouldn't hit the "submit" button.


OJWell, yeah, with a EULA like that, I'll have to agree.
3476.

Solve : Help - HijackThis Log attached!!?

Answer»

Hi, I was hoping someone could please help. My computer was infected with a virus called W32.Alcra.F - I have deleted all the infected files, but when I go to the "Run" window and type 'cmd' I get an error message. I have been able to bypass this by typing 'command' but when I try to type 'cd %SYSTEM%' I get an error message saying it is an invalid directory. I'm not sure what to do because 'regedit' doesn't work anymore as a valid command either.

I have installed AVG, Spyware, Spybot and Ccleaner, and have run scans of all of them in safe mode with the system restore turned off. But there has been no change.

Logfile of HijackThis v1.99.1
Scan saved at 3:49:55 PM, on 3/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Hewlett-Packard\HP SOFTWARE Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Corel\WordPerfect Office 2000\Programs\Wpwin9.exe
C:\Program Files\Corel\WordPerfect Office 2000\Programs\POP90.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\PROGRA~1\HOTDOC~1\Player\hdfill6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"You will need more than one post to include the entire log...

And re-list all malware program scans you have ran already...

P.S. Welcome Aboard !Thank you...I'm so new to this lol! OK so far I've used Norton Antivirus, AOL Active Virus Scan, AVG Anti-Spyware, Spybot, AVG7.5 and Ccleaner. Norton is no longer on my system, but I ran all the scans in safe mode with system restore turned off. Here's the first part of the HJT log file

Logfile of HijackThis v1.99.1
Scan saved at 3:49:55 PM, on 3/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Corel\WordPerfect Office 2000\Programs\Wpwin9.exe
C:\Program Files\Corel\WordPerfect Office 2000\Programs\POP90.EXE
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\PROGRA~1\HOTDOC~1\Player\hdfill6.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startupAnd part II is below...thank you!

O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [aol] "C:\Program Files\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/duanereade/app/opcuploader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\DRIVER\1150\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
Hi

Do your Run/cmd/regedit functions work OK now? You don't say.

There's nothing too dreaful in the log but you are running the computer in selective startup mode which will hide things.

*************

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

*************

Your HJT folder is in a temporary area. The program makes automatic backups and these may be lost unless HJT is located in a permanent place.

Go to the HJT folder ......

C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

Cut/paste the HJT folder to the C: drive to keep it safe.

*************

Your Java is a little out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
*************

Please go to MSConfig and enable all items at startup.

*************

Post a fresh HJT log AND an update on how your computer is operating now.


OJHi Again. Ok so I've updated my Java and I wasn't sure where temporary file was so I saved the HJT.exe file to my desktop. My run/cmd/regedit commands still aren't working...here is my latest HJT log (I've unhidden the folders and other stuff as instructed)

Logfile of HijackThis v1.99.1
Scan saved at 8:13:29 PM, on 3/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\AOL\Active Virus Shield\avp.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder\OrderReminder.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [aol] "C:\Program Files\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.12.1.1\PlaxoHelper.exe -a
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: CorelCENTRAL Alarms.LNK = C:\Program Files\Corel\WordPerfect Office 2000\programs\alarm.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) - https://www.plaxo.com/down/latest/PlaxoInstall.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {60EFC337-15C2-4369-B2A0-3429B071D8B8} (Hewlett-Packard Printer Diagnostics) - http://ispe.sdc.hp.com/awebui/jsp/answerweb/applets/HPISWebManager.CAB
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish.com/SnapfishUpload.cab
O16 - DPF: {B2FCED61-570E-11D3-B160-00A0C9E70E84} (OmniForm Form Control) - https://www4.lsac.org/LSACD_XMLWebServices/Http/OIFActiveX/ofmctl.cab
O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://interface.net-prints.com/wpp/duanereade/app/opcuploader.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\hpzipm12.exe
This line in your log ...

C:\DOCUME~1\JOYJAM~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

....still says that the version of HJT you are running is located in a temporary folder.


Again the log isn't showing anything dreadful. That said, HJT doesn't see everything. Not by a long way.


Can you use run/cmd/regedit in safe mode?



Please run these online scans. Make sure the first two are set to clean automatically ....

Panda Activescan > http://www.pandasoftware.com/activescan/com/activescan_principal.htm

TrendMicro Housecall > http://housecall60.trendmicro.com/en/start_corp.asp?id=scan

Kapersky > http://www.kaspersky.com/virusscanner (NOTE >> this scanner will detect malware but will NOT remove it. I need to see the scan report).


There will be files that these scans will not remove. Please include that information in your next post.


Reboot and post a new HijackThis log and the info you saved from these virus scans.


OJTry running cmd.exe instead of cmd and regedit.exe instead of regedit.
If they run then search your computer for cmd.com and regedit.com and tell us what you find?
3477.

Solve : Email - DO NOT OPEN?

Answer»

I received a STRANGE EMAIL today, with the following recipients:

[emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected], [emailprotected]

The body of the message is as follows:

Quote

please read the attachment

Attachments include vitamin.doc and wordicon.exe. I find this email, and the number of recipients, highly suspect. If ANY of you get this message, DO NOT OPEN.thnx for the warning DilbertThanks for the info, Dilbert. Do you happen to recall the subject of the e-mail so we could maybe catch this a bit easier?No subject.Quote
No subject.
Always a bad sign IMO. Doubly so if you don't recognise the SENDER's name(s).


OJ
3478.

Solve : Major brower problem.?

Answer»

all of my browers i have seem to do the same what ever i do to try and correct it
basicaly i can be randomly surfing the web and it changes to some random page like 888.com or this http://winantivirus.com/download/2007/
and along with about 20 different pages.
the 2nd thing that happenes is it starts ALOT of browers up, starting at 1 and keeps adding untill i end the iexplorer.exe in processes
had it up to 50 browers before now.

my hijack this log is too big to post on here so i uploaded for your convience
http://eswclan.net/images/hijackthis.log

this is seriously affecting my ability to do the stuff i normaly do like controll my gameservers.

Thanks for your help in Advance

Robin MitchellDefinitely sounds like you have some kind of adware/spyware. What protection do you have? Also, to be on the safe side, please scan with HijackThis again and post the results here instead of attaching them or linking to them. It will take several posts, but that's alright. We don't want to take the risk of spreading whatever infection(s) you might have. Do that and someone will come along to help you out.

I would also advise downloading SiteAdvisor and SpywareBlaster, which will both make your internet browsing a lot safer. However, I wouldn't do this until your log has been checked and you have been given a clean bill of health.Quote

..... it changes to some random page like .... http://winantivirus.com/download/2007/
and along with about 20 different pages.
My edit in bold is the key here.

Winantivirus is malware and a definite unwanted program. Part of the Vundo/Virtuemonde scum.


Download VundoFix.exe to your desktop from here ....

http://www.atribune.org/ccount/click.php?id=4

* Double-click VundoFix.exe to run it.
* Click the Scan for Vundo button.
* Once it's done scanning, click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts REMOVING Vundo.
* When completed, it will prompt that it will reboot your computer, click OK.

Note >>> It is possible that VundoFix encounters a file it could not remove.
In this case, VundoFix will run on reboot; simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

You may need to run it a few times to get rid of it fully.

Post back and let us know how you get on.


OJLogfile of HijackThis v1.99.1
Scan saved at 13:47:50, on 14/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Download Manager\DLM.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Robin\My Documents\VundoFix.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\sktjvkvo.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu ITEM: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision CORPORATION - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

i use mcafee internet security (firewallplus, antivirus, antispam & privacy service)
i have adaware personal, search and distroy and i also used trend micro's online scan
vundofix picked up 9 files in my system32 folder....vundo got rid of the files and i have done any scan i can find and it seems to have fixed it, if u can check my hijackthis log and see if theres anything left i would be greatfullThe log is clean of vundo but still a couple of things to sort out.

Open HJT ... click on scan ... put a tick/check mark next to this entry IF it is still present ...

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

Remember to close ALL open browser windows before clicking on "Fix Checked" at the foot of the HJT window.

***************

Now carry out a system-wide search for this file ...

ALCMTR.EXE

DELETE it.

***************

Empty your recycle bin.

***************

Your Java is a little out of date. Older VERSIONS have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications"…..

  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6-windowsi586-p.exe to install the newest version.
****************

If you are having no more problems please post back once more to confirm and I will let you have some final advice on PC protection.



OJok i did all what u said and everything seems great, except my printer problem but i will post in a diff topic for that.

u said u have some advice for me??

i use mcafee as my main securityIf you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.

More on System Restore ...

http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx


What may have lead up to your infection and help keep your computer free of malware …

http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html

http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html

There is a little duplication but these tutorials are both well worth reading.


If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …

http://www.ccleaner.com/


Also run through this before posting another HijackThis log …

http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html


Best wishes.


OJok its kinda back, i did a vundofix and it didnt work, i have mcafee site adviser, ccleaner, spyblaster, adaware, search and distroy.

it redirects me to this http://64.111.208.122/click.php?c=7acef945551a0b3da504&r=1

helpppppppppp......Please download FixwareOut from one of the following sites .....

http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

http://downloads.subratam.org/Fixwareout.exe


Save it to your desktop and run it.

Click Next, then Install, make sure "Run fixit" is checked and click Finish.

The fix will begin; follow the prompts.

If your firewall gives an alert, (because this tool will download an additional file from the internet), please don't let your firewall block it, but allow it instead.

Then you will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Once the desktop loads please save the text that will open report.txt.


Note: ONLY if you have connection problems after performing above steps - go to Start > Control Panel choose work connections, right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) and select the radio button that says obtain DNS servers automatically. Click OK twice and restart your computer.

**************

Now install Ccleaner from the link above and clear out your system with it.


After all this please post back a fresh HJT log, the report.txt and an update on how the computer is operating now.


OJdidnt fix it

Logfile of HijackThis v1.99.1
Scan saved at 18:13:11, on 15/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SiteAdvisor\5248\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDPOP3.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\SiteAdvisor\5248\SiteAdv.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Creative\ShareDLL\CADI\NotiMan.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll
O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\PROGRA~1\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file)
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [RCSystem] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" RCSystem * -Startup
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\5248\SiteAdv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h20264.www2.hp.com/ediags/dd/install/HPInstallMgr_v01_4.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by135fd.bay135.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\5248\SiteAdv.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exeO23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\5248\SAService.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

report.txt


Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE"
"CTDVDDET"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\DVDAudio\\CTDVDDET.EXE\""
"RCSystem"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" RCSystem * -Startup"
"AudioDrvEmulator"="\"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\DLLML.exe\" -1 AudioDrvEmulator \"C:\\Program Files\\Creative\\Shared Files\\Module Loader\\Audio Emulator\\AudDrvEm.dll\""
"VolPanel"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\Volume Panel\\VolPanel.exe\" /r"
"CTHelper"="CTHELPER.EXE"
"CTxfiHlp"="CTXFIHLP.EXE"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"Launch LGDCore"="\"C:\\Program Files\\Common Files\\Logitech\\G-series Software\\LGDCore.exe\" /SHOWHIDE"
"Launch LCDMon"="\"C:\\Program Files\\Common Files\\Logitech\\LCD Manager\\lcdmon.exe\""
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="C:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding"
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\CLIStart.exe\""
"LiveMonitor"="C:\\Program Files\\MSI\\Live Update 3\\LMonitor.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"SiteAdvisor"="C:\\Program Files\\SiteAdvisor\\5248\\SiteAdv.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

***************

Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK.

***************

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Login on your usual account. Make sure to close any open browsers.

***************

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries (If they still exist, make sure you do not miss any)

O2 - BHO: (no name) - {15D1B0EB-0055-4F51-BE03-8A4DADA1B8D6} - C:\WINDOWS\system32\qgbvftac.dll

O2 - BHO: (no name) - {36FDF945-9540-4823-A84A-AC43FA97A0E5} - (no file)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {C3178C97-FE42-4A9F-8574-C9BF97524A17} - (no file)


Please remember to close all other windows, including browsers then click Fix checked.

***************

Delete the following File indicated in bold IF it still exists[/b] ......

C:\WINDOWS\system32\qgbvftac.dll

***************

Reboot your system in Normal Mode, use it as you would usually do and let us know how it's working now.

Please also post back a fresh HJT log.


OJ
3479.

Solve : Trying to see if I have viruses?

Answer»
Fixwareout Last EDITED 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for OLDER varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky ANTI-Virus 6.0\\avp.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="\"C:\\Program Files\\Steam\\Steam.exe\" -SILENT"
"AIM"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
....
Hosts file was reset, If you use a custom hosts file please REPLACE it
»»»»» End report »»»»»



this was my fixit report. I dont know if something is wrong but it is shorter than other peoplesHi Psychopath34

What made you think you had a wareout infection?

It may be shorter because you didn't have the malware in the first place so perhaps Fixwareout had nothing to "fix".

If you want to check if you have viruses, and try to remove them, please do this.

Download Ewido/AVG Anti Spyware from here ….

http://www.ewido.net/en/

It has a fully working 30 day trial period.

Install it and update it to the latest definitions.

Do NOT use it yet.


Now boot to safe mode. Here’s a “how to” if you’re not sure ..

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406


When in safe mode run a full system scan with AVGAS and let it fix what it wants to.

REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it.

Reboot to normal mode and use the computer as you would usually do.

[FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time].

*******************

If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here …….

http://downloads.malwareremoval.com/hijackthis_sfx.exe

Save it to your Desktop.

Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder ……

C:\Program Files\HijackThis

Go to this folder and run the hijackthis.exe file.

From the menu click on "Do a system scan and save a logfile".

Copy and paste both the AVG AS scan report and the HJT logfile to this thread.


At that time also give us some idea of why you have concerns about viruses and malware problems on your computer.

More specific removal instructions will follow for whatever it is that's worrying you.


OJwell, from time to time on my taskbar, the button sometimes grow smaller and I'm not doing anything.Not quite sure what you mean but proceed with my advice and use Ewido/AVG Anti Spyware & HJT.

Post the logs back when finished WITH an update on how the computer is operating now.


OJ
3480.

Solve : Patching??

Answer»

How do you patch up holes in your machine?By installing patches.
If you want a better answer you will to give me details on what exactly you want to patch.Well, What I really want to KNOW is, what if I EXPLOIT one of my other computers and there is no patch on the internet to download, how do you patch then? Can you make your own patch?Yes in theory you could make your own patches but this will usually not be feasible with any closed source software like Windows for example. Besides if you need to ask this is way, way, way above your level.
I still don't understand what it is you want to do though. If you want to patch Windows go to Windows Update. If you're looking for patches for any other PROGRAM visit its homepage.I'm using Linux. It is above my level, that's why I'm only asking, I'm not actually trying to do it. I was just wondering if it was possible so I can start learning how.I made my own program in Perl to run an exploit on the other machines on my network. It was SUCCESSFUL, but there is no patch for it, because I discovered the hole.Topic Closed

We are not here to teach exploit basics.

Sorry.

3481.

Solve : Your opinion?

Answer»

CBmatt
What do you think of this ?
I value your expertise on this site and have taken your advice in the past ,
do you think this is safe to use
http://www.2-spyware.com/hjt.php
Skyblue
I uploaded a log there and it didn't even give me any output.Works for me try copy and paste INSTEAD of upload
SkyblueYes I did copy and paste, I do have 2.0.2 beta, maybe it only works with 1.9.1 ? I'd wait for CBMatt though, before you start trusting it.Well, it seems like a handy site, but it needs a LOT of work. First of all, the site is buggy and it took me five tries to get it to analyze a log. And when it did, the results were pretty inaccurate. Out of the 42 bad entries from the log I used, it recognized 3. And one of those was a legitimate entry. It also doesn't give any information about the HijackThis version, OS, anti-virus, or firewall. It's nice effort, but it's going to be a long time before it's ready.

Right now, you're better off with HijackThis.de. Of COURSE, you should never rely on a log analyzer because although they can be helpful, there are many characteristics they aren't able to look for. And they also don't pay attention to most file extensions. If an infection is changing your .exe files to .usr files, these sites won't be able to pick it up. UNLESS you already know how to read logs, you shouldn't use these sites. However, once you learn how to read logs, these can be useful in helping you double-check your work.Sometimes checking the results on various sites is interesting to say the least.
http://www.hijackthis.de/index.php?langselect=english
http://www.help2go.com (Detective)
http://exelib.com/hijack
http://hjt.networktechs.com/
http://www.prevx.com/hijackthis.asp
http://www.2-spyware.com/hjt.php

I think HJT should be the last resort for actually removing MALWARE.Quote from: Fed on August 27, 2007, 03:07:22 PM

I think HJT should be the last resort for actually removing malware.
really?!! is HJT not safe or somthin?!!Yes, it's not safe if you don't know what you're doing. You can disable your antivirus accidentally, or even apparently render your computer unbootable.Quote from: DeltaSlaya on August 28, 2007, 03:25:44 PM
Yes, it's not safe if you don't know what you're doing. You can disable your antivirus accidentally, or even apparently render your computer unbootable.
and how does one know that he/she is doing the right thing? dont we just run HJT and send the log file to be studied by someone who has good knowledge about all this! what can possibly go wrong in doing that?Quote
... it's not safe if you don't know what you're doing.

As above.Ivy, simply scanning with HJT and posting a log will do absolutely nothing to your computer. This doesn't make any changes whatsoever. However, if someone uses the program to remove things, they could easily do some serious damage if they don't know what they're doing. That's why you shouldn't trust these sites. It's best to be instructed by someone who has had proper training and knows what everything does.Oh now i understand! this means HJT is absolutely safe if you know the right thing to do.Yes, exactly what I said. If you just scan nothing can go wrong, it's checking and 'fixing' the entries that does the damage.
3482.

Solve : AVG Free edition- reccuring result question.?

Answer»

So I keep getting the following results every time I scan my computer using AVG Free edition. It's updated daily and is a wonderful program so far. But I'm new to It and I'm not sure what this means?

(i) kernel32.dll CHANGE C:\WINDOWS\system32\kernel32.dll
(i) user32.dll Change C:\WINDOWS\system32\user32.dll
(i) shell32.dll Change C:\WINDOWS\system32\shell32.dll
(i) ntoskrnl.dll Change C:\WINDOWS\system32\ntoskrnl.dll

Every thing i read says they should be there, of course. I just don't KNOW if the files should come up on every scan as being changed?

I have a ligit copy, OEM Windows XP Professional.
recently re-installed and running smoothly on a SATELLITE M30 Laptop.

Thanks for you time.




There is a way to clear the change result, I just can't remember how atm.
Nothing to worry about though.

Edit: You could try the AVG forums, if you find out let me know.If you recently re-installed your OS, it may still be installing updates, which would account for the changes. It's usually nothing to worry about. Try giving it a few days and see if the changes are still being reported.
3483.

Solve : wats a TRT/ZXOP.viral file mean??

Answer»

ok so ive been trying to do clean ups on my familys computers so like i go to uncles and his kid has this file he has no virus software or anything and his comps full to the brim and if i delete anything it comes back and i can download anything he has dell not sure about anything else on it but this TRT/ZXOP.viral popped up and ive searched through it a bit and it seems to be counting down all it is a timer if u open it...... its odd we cant delete and he keeps saying ur gonna buy me a new comp..... i aint the one on his comp downloading music soooo...... yeah he needs this for schoolhes running windows vista using IE 7 and msn i think is his isp its a dell if i didnt say it
200gb 7200rpm ULTRA ATA/ 100 hard drive is WAT it seems to beCcleaner Slim
RogueRemover
Ewido/AVG Anti-Spyware Online Scan
Panda Activescan

Ccleaner will free up some space.
RogueRemover for the pups that aren't neccessarily viruses or spyware.
AVG Antispyware will remove all but the viruses.
Panda Activescan will remove the viruses.

You may have to use another computer to get Ccleaner & RogueRemover.
You may have to start in safe mode + networking for the online scans.yeah we tried that but we get a message in a green BOX and it SAYS to much memory please remove permanent files from your *censored* folderYou may have to start in safe mode + networking, remove some files or uninstall some programs then carry out the scans.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem.

3484.

Solve : Could Someone Take A Look At My HJT?

Answer»

Hey, I know there's probably nothing wrong with my log but I'm just curious as to a few entires and I was wondering if someone could take a look and see what they think. Also, I have NOD32 and use Vista's firewall, do I need any additional SPYWARE protection, such as SUPERantispyware or something? What is recommended?

Logfile of TREND Micro HijackThis v2.0.2
Scan saved at 11:54:01 p.m., on 21/08/2007
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Pure Networks\Network Magic\nmapp.exe
C:\Program Files\Steam\Steam.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\conime.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\DeltaSlaya\Desktop\Jeremy's Stuff\Files\Computer Stuff\HJT\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.nz/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/programs/OnlineScanner.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179126965031
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179127107640
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPAHelper.exe - Unknown owner - C:\Program Files\iPod Access for Windows\iPAHelper.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Windows Display Driver Manager - Unknown owner - C:\Program Files\Common Files\System\Nvcpl.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8483 bytesFor the most PART, things look pretty clean. There are a few entries you should check, though...

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O13 - Gopher Prefix:

O20 - AppInit_DLLs:

O23 - Service: Windows Display Driver Manager - Unknown owner - C:\Program Files\Common Files\System\Nvcpl.exe (file missing)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

(You should check these two entries if you didn't place these restrictions on purpose.)

Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and enable hidden files and folders. Then navigate to and delete the following file if it still exists...

C:\Program Files\Common Files\System\Nvcpl.exe

After that, you should be all set. And yes, I would suggest getting SUPERAntiSpyware. I would also suggest getting Spybot - Search & Destroy because it has an active scanner. Other than that, things are looking pretty good.Thanks, no I didn't set any restrictions but I might have changed its associations?

No that file "Nvcpl.exe" is not present, and I'll get those two applications as well.It's possible that the restrictions were set by NOD32. I'm not terribly familiar with its features, so I don't know for sure if it has such a setting or not. I do know that Spybot can do such a thing, and users often apply it without realizing it. I can't say for sure what happened, but I don't think it was caused by an infection. But to be on the safe side, you should update your protection and scan in Safe Mode whenever you get a chance to do so.Just curious, in Spybot do you think I should keep SDHelper and Teatimer enabled? Are they necessary? I'm running Windows Vista and I don't use IE so do I need them?If you don't use IE, then SDHelper isn't really necessary. However, I think it would be a good idea to enable the TeaTimer so Spybot can be on alert and actively detect spyware. It's up to you, though. As long as you have NOD32 active, you don't need Spybot TeaTimer active...it's just strongly recommended.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged.

If you are not the original poster and you REQUIRE help, PLEASE start a New Topic with information about your computer and your problem.

3485.

Solve : Antispyware software for Windows 98?

Answer»

I have an Intel PENTIUM 166MHz w/MMX and use Windows 98. The only time I spend online is when I access email. At times, however, I do check out a few Web sites of INTEREST. Can anyone recommend a good antispyware PROGRAM for Windows 98 users like me? Thank you.

jandal Quote from: jandal on September 04, 2007, 04:45:11 PM

I have an Intel Pentium 166MHz w/MMX and use Windows 98. The only time I spend online is when I access email. At times, however, I do check out a few Web sites of interest. Can anyone recommend a good antispyware program for Windows 98 users like me? Thank you.

I have a Win98SE computer. A little bit faster, at 350 MHz.

Using Ad-Aware Personal here. It takes a minute to load - I can't say whether or not that is normal, I just don't know - and it seems to work ok.

It has been some time since I INSTALLED it, but I think this is where you can get it:
http://www.lavasoftusa.com/products/ad_aware_free.php

As far as how good it is for Win98 users - I suppose you mean in comparison to other anti-spyware programs? Can't say. Somebody else will probably be along shortly to offer opinion(s). My purpose in replying is just to let you know that it works.

While we are on the topic of protection/prevention though, are you using anti-virus software? and keeping it up to date?
For what it is worth, AVG works great here on the Win98SE machine.

http://www.free.grisoft.com

AVG also has free anti-spyware, and a link is on that page.
It says it supports Win98 in their description there, but I also see:
"* Some older operating systems such as Microsoft Windows ME, Microsoft Windows NT and Microsoft Windows 98 will only be supported until August 2008 as a minimum."

I haven't tried it. Maybe somebody else will comment on it and/or compare it to Ad-Aware for you.



CLEANUP
Ccleaner
(During install, uncheck the Yahoo Toolbar option)
(After install, set Options>Advanced> 'Uncheck the 48 hour BOX')
ANTI SPYWARE
Adaware
Spybot S&D
ANTI VIRUS
AVG Free
(After install, set Options to 'scan all files')
ANTI TROJAN
Ewido for W2K & XP
or
A-squared a² for 98 & ME
(Winall)
3486.

Solve : is my network hacked??

Answer»

My pc was hacked last month ,on my router i accidentally left my wireless on 2g and 5 G by accident. (I use an ethernet cord on my pc) so I did a FRESH install of my os, and i downloaded and ran a program CALLED netwatch and it shows two 'routers' on my network, one said cable box arris router the other says arris router, when i go to the connected devices on my router page it just shows my pc as being connected, and my voip vonage box,. I have my wireless 2g and 5 g disabled and i also got a new routerIf you did a fresh install and purchased a new router you should be good to go. Just make sure you have strong passwords.

3487.

Solve : rejg Ransomware removal?

Answer»

my files are affected (encrypted) rejg RANSOMWARE? not all my files have .rejg file extension in addition to their respective file extension



Could you please suggest the methods / ways to remove and recover the REJG ransomware?

With this Ransomware there is 2 parts to decrypting the files. The Key which is in the txt file and the 2nd part which you need to pay a ransom for. There is no other WAY to decrypt the files at this time without the 2 parts.
I recommend changing the drive/s and loading a CLEAN operating system. There may be a way in the FUTURE to unencrypt the files so if you have important data keep the drive safe.

Now is a good time to look at your backups, if you don't have any it would be a great time to start.
Also, paying the ransom is no guarantee that your files will be recovered. That is why regular back-ups of your computer is so important in this perilous times.

3488.

Solve : can a virus execute by itself??

Answer»

Is there any type of viruses can execute by itself after download then on the HDD without CLICKING on it??

if there is ..... can you refer me to any sites about them?

Computer viruses are not very common these days because there's no money in it. You're more apt to get Ransomeware or Adware on your computer. However, you can get a lot of information here.Quote from: Richard20 on April 15, 2019, 11:09:07 AM

Is there any type of viruses can execute by itself after download then on the HDD without clicking on it??

if there is ..... can you refer me to any sites about them?

I think it's more accurate to say 'a virus can't execute itself, unless it has the cooperation of the Operating System and/or SOFTWARE bugs and/or the user.

If the OS allows files to be executed automatically because of their name or location (for example an email ATTACHMENT) then a virus can masquerade as a legitimate file and be executed by the OS without user intervention. This used to be the default behaviour in early email clients.

Also, if the OS or specific software has errors that a virus can exploit to run its code, then a virus can start itself.

But users are most OFTEN the means for a file to be executed. I was SURPRISED recently when a work-colleage told me she thought her computer had a virus after she opened an attachment in an email from a complete stranger. I thought she would have known better.
3489.

Solve : I Think I Found The Problem But I Don't Know How To Fix It?

Answer»

I decided to use the HP Virtual Agent which tested my OS. (Windows 10)

The screenshot below shows corrupt files of some sort. I don't KNOW what to do to fix it.


I don't see any corrupt files.Do you have the OS DISK(s)?Your comment has been removed. PLEASE do not post malware advice, or post here in the malware FORUM, unless you need help.Superdave.

3490.

Solve : free internet protection?

Answer»

Whats the best FREE internet protection that doesn't slow the pc down, got malwarebytes on at moment but keeps saying trial has expired.. don't know much about this pc lark..cheersIt depends on which OS you're using. I always recommend MicroSoft Security Essentials but this won't run on XP and Vista and it probably won't run on Windows 7 in a few days. Windows 10 has its own AV called Windows Defender. Im running Windows 8, I have windows defender on WOULD that be enough protection or should I be running something ELSE with it. Thanks.Only one AV should be enabled on a computer. More than that cause all kinds of problems. That is all I use on all my COMPUTERS.

3491.

Solve : I think I have a virus?

Answer»

Hello everyone,,
This post is further to one earlier today - "Email query/problem" - I wasn't sure how to amend my earlier post.

I've just found my email has another lot of AUTO replies and undelivered notices about messages that I have not sent. As far as I can figure out, a message purporting to be from me has been sent to all the addresses in my CONTACTS list. This list (added to by AOL with every NEW addressee) includes my own Hotmail address, and when I checked that I found that the message was in fact a link to a healthcare website. It seems like a scam to direct people there. I'm not sure what to do to stop this - would deleting all contacts work? - or uninstalling all AOL stuff and getting a new email account? (AOL is no longer my ISP).

Advice needed.It would appear that your email account has been hacked. You will need to change your password and MAKE sure you create a strong password.Quote from: Gujarish on January 18, 2020, 04:38:19 AM

Hello everyone,,
This post is further to one earlier today - "Email query/problem" - I wasn't sure how to amend my earlier post.
snaptube.cam/ syncnet.onl/telegram-web/ 9apps
I've just found my email has another lot of auto replies and undelivered notices about messages that I have not sent. As far as I can figure out, a message purporting to be from me has been sent to all the addresses in my contacts list. This list (added to by AOL with every new addressee) includes my own Hotmail address, and when I checked that I found that the message was in fact a link to a healthcare website. It seems like a scam to direct people there. I'm not sure what to do to stop this - would deleting all contacts work? - or uninstalling all AOL stuff and getting a new email account? (AOL is no longer my ISP).

Advice needed.

Thank you my issue has been solved,...
3492.

Solve : Best way to remove Pop Up Ads.?

Answer»

My PC does not have a malware ting. Instead, my Chrome BROWSER wants to show me stuff I don't want. What is the right WAY to stop this nonsense?
So it is not malware, it is Nag Ware.You could try this:

Open. Google Chrome. ...
Click ?. It's in the top-right corner of the WINDOW. ...
Click Settings. You'll find this option near the BOTTOM of the drop-down menu. ...
Scroll down and click Advanced ?. ...
Scroll down and click Content Settings …. ...
Click Ads. ...
Click the BLUE "Allowed" switch. ...
Click the "Back"Thanks. I will do that.

3493.

Solve : Toshiba Satellite L455D Laptop virus??

Answer»

Hello everyone,,

I am wondering what could be the cause of my issue with my laptop. It was brought to my attention about a couple weeks ago. I would start the laptop and everything would just freeze up. Network would not connect, antivrius was disabled, and start menu was not responding. Eventually I would get a message saying Windows was not RESPONDED and to end the process. Bad news, right? But it would start in safe mode fine. So I backed up all my files and did a system restore (reset to factory settings)

The restore went through, but I had a long of factory standard junk software I didn't care for. So, shortly after I did a CLEAN install of Windows 7, deleted all partitions, and started over fresh. I put all my files back on again, and it worked fine for a few days. In fact, it worked perfectly. Then suddenly the same things started to happen -it would start up, then not respond, lock up, and eventually require a hard restart. The whole time safe mode works just fine, but normal mode will not.

Thinking it was a file that was causing it to be corrupt, I did another clean install of Windows 7, updated all my drivers, and it was running like a peach again. Worked fine through plugged in, unplugged, restarts, idle, SHUT down and back up again. There was nothing wrong with it. I did not put any old files on it this time, just keep the updates up on it and didn't go to any strange sites or download anything bogus. Just kept a clean copy to monitor. But just today now it is LOCKING up on startup again, acting the same way. I know it is not a file causing it. I'm thinking it has to either be a windows update that is messing with the hardware, or there is a virus.

Has anyone heard of a virus that works like this? Is something hiding deep in the system that is programmed to show up after so long? Or do you think it was an update through Windows that has a compatibility issue? I haven't seen any other complaints on this model, so I am thinking it is not specific to my make/model. Aside from Windows I am running Avast, ThreatFire, Google Chrome, and that's about it. I have no other software installed aside from normal java updates, flash player, and drivers from the company's site for this model.
Hi

Your laptop is around 9 years old if it hasn't had any upgrades to the MEMORY (2 GB) and had a diagnostic of the hard drive ( 250 GB 5400 rpm). This would be the first to check. Also when you start the Laptop in Standard mode is it running warm. Warmer than in safe mode. Also running Avast on 2 GB of memory is a little harsh on the laptop. You can check your fan speeds and also your computer's temperatures by downloading and running Speedfan

3494.

Solve : Windows 10 - Norton Vault password auto-fill not working?

Answer»

I have a new laptop with Windows 10. I called Norton to see if I could find out why the little Norton Vault icon doesnt show up next to the user/login/password for different login websites, and they said they would have to access my computer remotely. I asked them if they would walk me through it and they put me on hold and then came back and said they would have to remotely access my computer to troubleshoot and fix the problem. I told them I would try to fix the problem myself, but I havent yet. I guess something in windows 10 is blocking this
One of my concerns and questions is, would you trust them to remotely access my computer ?
ThanksQuote

One of my concerns and questions is, would you trust them to remotely access my computer ?
THANKS
No, I can not recommend that.
Instead, find somebody AMONG your family or friends that can help you.
That is the best I can say. Thanks Geek-9pm. I really dont know anyone who might be able to help. Would you have any ideas as to what I could check, that might be causing this issue ?
Or a safe way to generate and save user names and passwords ?From dictation.
Okay, I'll try to give you a more detailed OUTLINE of what I have in mind. Years ago I is to work as a computer help technician and would talk to people over the phone about how to fix certain problems.
In your case, the problem is not something I would consider to be very critical to your productivity. You should have some alternate method of managing your passwords if the Norton utility is not serving you well. I understand the problem, I also have difficulty finding the right tool for the job and one of the tools I've used now has to be updated and it's a real pain in the neck.
The most reasonable workaround is to just have a piece of paper somewhere that you keep all your passwords on and you keep it with you at all times. This is not a joke, the password management system that's used on computers is much more complicated than it really needs to be. If you can write down your passwords on a piece of paper and keep it on your person that should be all you really need.
Excuse my frankness, but after several years of experience with helping people with computers I find that often the most practical solution is the best one. But I do have another suggestion.
In your community there are some other people who have computers and considered to be a hobby. Those individuals are willing to give you some of their time at no cost and they will try to help you the best they can. But even so, you want to be sure you know who these individuals are and be very careful about giving them any privileges that could possibly cause you harm. The world we live in is not any better now than it was 20 or 30 years ago. There are just too many people out there looking for an opportunity to defraud someone who is not sure what they're doing.
So you might try a search and see if there is a LOCAL computer club in your area. You can talk to some of them and make your own decision about which of those individuals appear to be honest and straightforward. Is much easier to do that than it is to try to make a judgment of someone over the Internet people on the Internet people will lie about almost anything. Even if 99% of the people on the Internet are truthful, it's that 1% the can really do you lasting harm. So that's why I recommend you start first dealing with local people that already have some experience and you can evaluate them personally with eye to eye contact and listen to them talk to you and you can answer questions and they can interact with you.
As to Norton, I'm not sure why they cannot just tell you over the phone what you need to do rather than trying to take control of your computer. In my time I did some very difficult things of people over the phone without the use of remote control. So I know it's possible to walk people through almost anything over the phone if you know how to communicate and ask questions and follow directions.
Of course, a local contact is even much better. A real live person in flesh and blood can communicate much better than someone talking to you over the phone. Body language and gestures and facial expressions do make a big difference when trying to communicate with other people. So far, the Internet is a great tool, but has some serious areas of misuse when it comes to the matter of trust and security.
I do hope this is of some help to you. Try finding local people in your area. Ask your neighbors, ask anybody you know what they do when they have a computer problem. Even young children sometimes know what to do.
End of dictation. Now that sounds like some really down to earth advice, and Im glad you explained it like that.
I can tell you that I will CONTINUE doing things just as you mentioned...writing them down.
Thanks
3495.

Solve : Windows 10 doesn't need antivirus? True??

Answer»
I'm going to install soon WIN 10 on my machine. A few days ago I watched some video about Win 10 on YT.
Some guy there mentioned that installation of AV program on OS Win 10 is needless. That Win 10 is so good and secured, moreover, this OS has implemented own AV program that is sufficient enough for security of our COMPUTERS. And stuff like that.

It's hard to believe in that for me. That's why I'm writing this post here.
I'm curious what you guys are going to say about this Crap? Windows Defender is part of Windows 10 and it is a good AV solution. There are better 3rd party AV's (mostly not for free), but as long as you practice smart computing Defender should be fine.Actually, there is one word that stands out in your post that is very important — "our" — and that is important because of the question that arises about you having some sort of internal net where different FOLKS are using computers on that internal net.

Point is that the more people you have using a bunch of computers the easier it is to have somebody make a mistake and accidentally invite some BAD bug into your internal net and that means you might want a HIGHER grade of protection.

So I think for anyone to give you a good answer the information about your use of "our" could be useful, BUT I wouldn't be so quick to post information out here in public because that is also a flaw in the area of maintaining security.

But I can sometimes get seriously paranoid about security, and there might be some who will state that I am being too paranoid about the idea you should PM a tech person you think you can trust here on this site, or another site, and do your discussion in that environment where only you and that tech person you have decided to trust can figure things out.

By the way, the — "And stuff like that." — would also have a security professional asking what stuff?

But I am again going to state that with security all sorts of little details posted in public can be a problem if a really skillful bad person is paying attention to what you post. There might be a good professional here in this CompHop Community that wouldn't mind helping you through a private means here or elsewhere.

Not me, by the way. I am not reliable. I am a cancer patient and my medical situation can get very iffy and I might disappear from the Net for days on end because something in the chemotherapy went haywire.
3496.

Solve : 'Delivery Failure' - Phishing for What??

Answer»

My Spam folder is catching about half a dozen or so messages a day titled "Delivery Status Notification (Failure)" from [emailprotected]

They read that my message could not be delivered to random group addresses.

I don't email groups. I don't belong to Google groups. Etc. etc. There's no HACKED emails in my Sent Items.

The "More INFORMATION can be found here" redirects to a legitimate Google link.

Is this a phishing attempt? Do I have a weird ADDRESS BOOK virus? Does someone else?

If it is a phishing attempt, I can't for the life of me figure out the con.Your gmail account MIGHT be compromised.Neglected to add - this isn't my Gmail.

3497.

Solve : New to Phishing?

Answer»

Never heard of this before. Someone has been using my old email address to beg for money from all my contacts. I don't know what to do about it. I can't even GET into that ACCOUNT they must have changed my password. I have opened a new email account but my FRIENDS and family keep ringing to say whoever it is is still SENDING emails begging for money.
Any idea what I can do?

3498.

Solve : Running two antivirus software?

Answer»

Does it hurt to have avast and WINDOWS defender running together on a laptop?Yes. You should have only one anti virus app INSTALLED and running.If two antiviruses work together then one antivirus will become a virus so it is better to run one antivirusQuote from: gorge441 on June 23, 2020, 10:22:59 AM

If two antiviruses work together then one antivirus will become a virus so it is better to run one antivirus

First of all, that's a ridiculous post. SECOND, the question was answered a MONTH ago. No need for you to SAY ANYTHING.That was rude... I am sorry.
3499.

Solve : Formatting disk after virus infection?

Answer»

Ok so long story SHORT I got a virus in my PC running win10, and ended up deciding that resetting the ssd (m. 2) would be the best option... The problem is that it won't let me do so from windows. I therefore decided that I would try to reset it from a PC running kali live. So I buy a m.2 to USB adapter, plug it in the kali pc. At this point I check the disk manager and it appears even if I am unable to interact with it. I then try gparted but it doesn't find the ssd... At this point I am out of ideas and need help. ThanksHi 4aure
First things, even Windows 10 will not see all M2 drives on all MOTHERBOARDS without drivers and gparted under linux has the same problem. Both Linux and Windows should be able to see the M2 drive using the USB to M2 adapter.
Is this plugged into a USB3.0 port as most M2 will not be able to get enough power from a USB2 port some won't work even from usb3. You could check the M2 specs for current REQUIREMENTS or post the model here. I would only use a M2 to sata adapter board.
It would help if you could post.

Motherboard make and model

M2 Make and model

How the M2 is configured in the Bios
Thanks Instead of messing with Kali, download the Media Creation Tool from MS and create a bootable USB THUMB drive with Win 10 on it. It will allow you to boot from the thumb drive and install Win 10 on the PC. Make sure that you delete the current partitions on the Win 10 PC and then complete the install. Since you already have Win 10 on that PC, Windows will automatically activate.

Don't COMPLICATE things by using Kali and a USB adapter.

Here's the link to download the Media Creation Tool: https://www.microsoft.com/en-us/software-download/windows10

3500.

Solve : SpywareBlaster 6.0 won't open in Windows 10?

Answer»

SpywareBlaster won't open. I have turned-off all anti-virus and anti-malware programs. I ran Process MONITOR but the log file was empty. Renaming/restoring the original profiles.ini of Firefox did not work. Neither running REPAIRS in Tweaking.com Windows Repair, nor restoring the registry, has HELPED. This is the only program that has stopped.

Please tell me what the next step is! I'm not sure what Firefox has to do with anything, but try uninstalling and reinstalling SpywareBlaster. If that doesn't work, do a FULL scan with your installed AV program. Finally, you can reach out to Brightfort support if NEED be.