InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3551. |
Solve : Folder Duplicate? |
|
Answer» My windows folder will duplicate by itself. How to prevent it?Much more info is needed... |
|
| 3552. |
Solve : SP2 being read as SP1???? |
|
Answer» yes to all three. i'm still trying to see if anyone can get me a windows disc, but no luck so far.wait. CBMatt: i called microsoft to see if they would give me tech support, but i haven't asked them to send me a cd yet. my friend is asking around to see if she can find one. so i'm waiting it to be a last resort situation.I could be wrong, but I believe they'll ship out the proper CD for only the cost of shipping. Just don't quote me on that one.Quote from: JXY on August 23, 2007, 02:47:37 AM of course im going somewhere.yup because these days all triads are selling computers lol and if you're not careful, you could end up buying a pirated copy of windows. it happened to me once, and i never bought comps from street shops again. because you're running a pirated copy of windows, the microsoft support site won't be able to verify whether you're OS is genuine or not. THerefore, all updates will fail. (it happened to me). and also, things like SP2 won't install properly. (happened to me) and in the end, i had to re-install windows using a genuine version of windows. (other SYMPTOMS include : unable to access cmd or task manager).I think thats common sense though ....... i bought parts from street makrets before ..... and let me be the 1st to say its all ripped -off junk ...... if you do regular virus scans etc .... you can actually pick up the patch that cracks x-p , i have about 6 or 7 diffrent x-p serials , that where given to me by a street salesmen ... now they all work , but there not legit ..... they where wrote on a piece of paper etc..... and i know its illegal to sell the codes out side of the microsoft products , he sold me the orginal cd , but the code was on paper ....... he gave me so many because he thought they might not work , that speaks for itself ........W2K has none of these problems. ...except i bought my computer from dell...i've had to have my windows system VERIFIED to even get stuff of the windows website. no offense, but none of the last few comments have helped along my problem...Dell would be the one to contact for a CD...MS won't as they didn't sell it to you...Quote no offense, but none of the last few comments have helped along my problem...Sorry for the input saytheya, I confess to not reading this thread all the way through (it's very long) and I assumed from the previous posts we were dealing with a pirated copy of XP. I'll keep quiet now but continue to watch |
|
| 3553. |
Solve : help wierd *censored* virus on my computer? |
|
Answer» Alright there is this virus on my computer, This GUY advertised it as a game CHEAT so i decided to check it out. It added its self on startup and its always running under wpa.dbl.exe in my taskmanager. I try to remove is from startup from typing run and msconfig but no luck the process doesnt show up there or as a service. Now the directory this virus is in is C:\WINDOWS\system32\wpa.dbl.exe . The wierd thing is when i end the process and try to go in that folder its not there. I tried to uncover the hiddin files and again no luck . So i try to delete it with a batch command. It says there is no file in that directory with that name. Now the wierd part is when i try to re start it up with the back command it starts up. Correct me if im wrong but these are the results i get. |
|
| 3554. |
Solve : huge problem? |
|
Answer» Well I have these 2 computers in my house that both have this problem. When you turn them on, nothing appears on the monitor. It was only a problem with one of them at first but not neither of them work. I am using 2 different monitors and when i PLUGGED my laptop in to the monitors it worked fine. Does anybody have any idea how to fix this?I think this is going to be an hardware problem. |
|
| 3555. |
Solve : computer virus problem? |
|
Answer» Hello. I'm LOOKING for some help. |
|
| 3556. |
Solve : Flashget? |
|
Answer» Hello again, im using a dell xps 210 vista premium i have never had any problems with spyware terminator.Spyware Terminator has a bad history of leading users astray with false information. But if you wish to keep using it, that's entirely up to you. |
|
| 3557. |
Solve : Tell me the problem? |
|
Answer» Logfile of HijackThis v1.99.1
Looks like you've got yourself some dialers and downloaders. AVG AS appears to have caught most of them, but there are still a few infections on your computer. First, download CCleaner (install without Yahoo! toolbar) and configure it according to this guide. To delete quarantined items, click on the Infections tab. This will list everything in Quarantine. Click on Select All and then Remove Finally. That will get rid of everything AVG detected. You don't have to WORRY about this messing up your computer. Now...the program you have is very good, but you still need anti-virus. Anti-spyware alone just doesn't cut it. Go ahead and download AVG Free (made by the same people who created your anti-spyware). Update it and scan with AVG Free in Safe Mode. Let it remove whatever it wants. Reboot your computer back into Normal Mode. Once you have done all of that, post a new HijackThis LOG, as there are still things that need to be taken care of.C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\New Folder\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.comcast.net/toolbar2.0/search/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=presario&pf=desktop&parm1=seconduser R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer presented by Comcast R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing) O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file) O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file) O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jujwakxr.dll",forkonce O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000 O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} - http://www.comcast.net/ (file missing) O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} - http://www.comcastsupport.com/ (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} - http://online.comcast.net/help/ (file missing) O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing) O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: Secondary Logon seclogonSNDSrvc (seclogonSNDSrvc) - Unknown owner - C:\WINDOWS\system32\adsntd.exe (file missing) Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file. Open HijackThis and scan again. Check the following entries, but don't do anything to them yet... R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL O3 - Toolbar: (no name) - {25D8BACF-3DE2-4B48-AE22-D659B8D835B0} - (no file) O4 - HKLM\..\Run: [Intel system tool] C:\WINDOWS\system32\svehost.exe O4 - HKLM\..\Run: [icq.com] rundll32.exe "C:\WINDOWS\system32\jujwakxr.dll",forkonce O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJfox000 O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab O23 - Service: Secondary Logon seclogonSNDSrvc (seclogonSNDSrvc) - Unknown owner - C:\WINDOWS\system32\adsntd.exe (file missing) Now, close all windows (including this one) besides HijackThis, then click Fix Checked. Close HijackThis and reboot into Safe Mode and enable hidden files and folders. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)... MyWebSearch RXToolbar Please note any other programs that you dont recognize in that list in your next response. Navigate to and delete the following folder(s) if present... C:\Program Files\MyWebSearch Navigate to and delete the following file(s) if present... C:\WINDOWS\system32\adsntd.exe C:\WINDOWS\system32\jujwakxr.dll C:\WINDOWS\system32\svehost.exe (Do not get this confused with SVCHOST.exe!) Once you've done all of this, reboot into Normal Mode and post a new HijackThis log so we can see if there's any other junk we need to clean up. Let me know how everything's running now and if you had any PROBLEMS following my steps.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with INFORMATION about your computer and your problem. |
|
| 3558. |
Solve : Be aware of this {just in case}? |
|
Answer» Alert: I checked with Norton Anti-Virus, and they are gearing up for this virus so I believe this is real. I checked snopes.com and this is for real Get this sent around to your contacts ASAP...we don't need this spreading around. You should be alerted during the next days: Do not open any message with an attached filed called "INVITATION", REGARDLESS of who sent it. It is a virus that opens an Olympic Torch which "burns" the whole hard disc C of your computer.. This virus will be received from someone who has your e-mail address in his/her contact list, that is why you should send this e-mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it. If you receive a mail called "invitation", THOUGH sent by a friend, do not open it, and shut down your computer immediately. This is the worst Virus announced by CNN. It has been classif ied by Microsoft as the most destructive virus ev er. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus. This virus simply destroys the ZERO Sector of the Hard Disc, where the vital information is kept. I got this from an email/ friend not sure if this is valid I doubt very much so that this is true . . . "It is a Virus that opens an Olympic Torch which "burns" the whole hard disc C of your computer". If Norton had a copy of this then it would be spreading, therefore it would already be a PROBLEM, not wait a couple of days. "This virus simply destroys the Zero Sector of the Hard Disc, where the vital information is kept." Whats this so-called "Zero sector"? Is there even such a thing? And even if there was, there is no 'vital' information stored on the hard drive. They come blank, generally.It appears that email is remarkably similar to this: http://www.hoax-slayer.com/olympic-torch-virus-hoax.html ??good- find* thanks for disproving the email, I told my friend to quit FORWARDING them to me in the future, THANKS |
|
| 3559. |
Solve : Help!! I think theres something wrong with my Computer!!? |
|
Answer» I recently had my computer scanned using Avast Home edition and I got a bunch of viruses most of them Trojans and spywares. after that I was getting some error message saying "Error Message,"Duplicate name exists."" even though Im not connected to a network and it also shows a massage saying "limited or no connectivity" whats worst is I cant access other website such as pldtplay.com(philippine game servers) and I also cant sign in on my yahoo MESSANGER. is there something wrong with my PC? can anyone help...?get superantispyware run it in safe mode(along with any other protections) and dl hijackthis and post log, it might take more then one postthanks, I think Ill try that my browser(firefox and internet explorer both have the same problems) has a big space on the bottom part of it which is very annoying since i cant see most of the contents of a website.Got a screen shot of this big space? Quote i reformat every 3 months and my computers are doing fine.Why would you do that UW?because i like to make sure i don't have anything. and i like a fresh start several times during the yearQuote Got a screen shot of this big space?well I've already reinstall firefox just like what unlovedwarrior suggested and the bottom thing was gone. but the other bug are still there. I'm still wondering if frequent re-formatting can damage a hardrive... MAYBE I'll try to find some other source. but if anyone know something fell free to post hereNo frequent formatting wont damage a hard drive. It is no DIFFERENT than other write operations a hard drive perform. |
|
| 3560. |
Solve : Oh My God... Incredibly Evil Virus PLEASE HELP? |
|
Answer» Ok, well yesterday night whilst I was on MSN Messenger.. and suddenly the internet stopped working although Windows Vista said it was online.... so I tried opening Windows Media Player to listen to some music from my library and I got an error message saying "wmplayer.exe not FOUND" followed by various messages saying that "explorer.exe" not found and others which I cannot remember.... So I thought best thing to do would be restarting the computer.. as soon as I clicked on restart I got a message saying "SystemUI.exe not found" followed by a blue screen... Now each time I boot before I even have a chance to press F8 it tells me Boot\BCD not found and restarts.... constantly. What is it you want to accomplish here... Most importantly retrieving my data.... I know how to do a clean start. I would hook up that drive as a slave in a working machine...run a virus scan on the drive, actually all your protection apps...you have a well balanced arsenal there BTW. Then copy/burn the data you need from that HDD and do a full format on it. It should then be clean enough for a clean install. p,s. You may want to add AdAware and Spybot to your package... p.s.s. Before copying /using any of that data on the new build re-scan the CD just in case.Quote from: patio on July 17, 2007, 02:16:05 PM I would hook up that drive as a slave in a working machine...run a virus scan on the drive, actually all your protection apps...you have a well balanced arsenal there BTW. That is exactly the problem.... it is a laptop >_ About 10 bucks at any computer store...lets you connect a laptop HDD to any desktop machine with an available IDE connection. Handy for quicker backups as well.Quote from: patio on July 17, 2007, 04:40:34 PM Then grab one of these... I NEVER knew that existed... I'll go to PC World and to the small shop next 2 my house later to find out if they got them. Thank you so much you are a real life saver =)As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3561. |
Solve : Can a keylogger log your clipboard?? |
|
Answer» I've recently become paranoid after I fell victim to a keylogger last week having a very important password stolen and decided to manually copy and paste my passwords from a notepad document from then on. Might be important to note that since that time I had NEVER typed the password, EVEN to initially create it. Thought I was safe and was surprised to have the same password stolen again. I have run hijackthis, avg, trojan remover, trendmicro online scan, adaware, and win security task manager(actually a safe program believe it or not) and my system turned up clean. I even ran them all in safe mode to be sure. I have a router and use the xp FIREWALL as well. I just don't get it. The only possible way that that password could have been stolen again is if the keylogger is somehow recording my clipboard, which I have began deleting after I paste the password. Is this possible? Is there any way to prevent it happening in the future?can you post the hijackthis log for us to look at?Quote from: endezeichen on August 23, 2007, 12:41:58 AM The only possible way that that password could have been stolen again is if the keylogger is somehow recording my clipboard, which I have began deleting after I paste the password. Is this possible?Yes Quote from: endezeichen on August 23, 2007, 12:41:58 AM Is there any way to prevent it happening in the future?Get rid of the keylogger. As unlovedwarrior said a hijackthis log would be good place to start. Sorry, I didn't post my hijackthis log because I didn't think it would be necessary. I've done extensive cleaning with many programs as well as manually. This really is one heck of a trojan. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:23:21 AM, on 8/23/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Just took a nice look into this one and noticed there was a bogus exe in the folder that was not recognized by google or licensed. Deleted the whole folder, could care less about winmsngr... that could be what I had missed O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: NOD32 Kernel Services (NOD32kren) - Nero AG - (no file) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 2626 bytes Thanks You could have just uploaded the file to http://www.virustotal.com/, it can tell you, from numerous scanners whether a file is malcious or not..Do you download warez by any chance? One thing you can try... Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. GO ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls. You could also try running a full-system scan with SUPERAntiSpyware in Safe Mode. I'm not sure how much this will help, though. When it comes to this sort of breach of security, I think it's best to back up all important personal files (not programs; download them again later) and then reformat. Keyloggers can be pretty sneaky and even when you remove one, it's sometimes hard to trust that your computer truly is clean again.Well I must say, combofix is a pretty interesting and useful program. Never even heard of it so thanks for that. Got a bit weary when zonealarm told me it was launching cmd.exe...that was a high risk alert. Did a little reading up and apparently combofix was infected a few months ago. I just assumed that was a clean version and the cmd.exe part was just part of the process. Oh yeah- Wwwwinnnantispyware... the most annoying piece of crap I've ever had on my computer. Apparently I didn't get rid of it as I thought I did. C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor C:\Program Files\Common Files\curity~1 C:\Program Files\Common Files\winantispyware 2007 C:\Program Files\Common Files\winantispyware 2007\err.log C:\Program Files\Common Files\WinAntiSpyware 2007\err.log C:\Program Files\Common Files\winantispyware 2007\WAS7Mon.exe C:\Program Files\Common Files\WinAntiSpyware 2007\WAS7Mon.exe C:\Program Files\Common Files\ystem~1 C:\Temp\1cb C:\Temp\1cb\syscheck.log C:\Temp\fse C:\Temp\fse\tmpZTF.log C:\WINDOWS\scurit~1 C:\WINDOWS\system32\aeksree.dll C:\WINDOWS\system32\configs C:\WINDOWS\system32\driver C:\WINDOWS\system32\drivers\ApiMon.sys C:\WINDOWS\system32\drivers\fopn.sys C:\WINDOWS\system32\f02WtR C:\WINDOWS\system32\F2 C:\WINDOWS\system32\F3 C:\WINDOWS\system32\H1 C:\WINDOWS\system32\mcroso~1.net C:\WINDOWS\system32\mcroso~1.net\M?crosoft.NET\ C:\WINDOWS\system32\msnav32.ax C:\WINDOWS\system32\V1 C:\WINDOWS\system32\winpfz32.sys C:\WINDOWS\system32\wtsicomsv.exe C:\WINDOWS\system32\zxdnt3d.cfg C:\WINDOWS\uninstall_nmon.vbs C:\WINDOWS\wr.txt ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) -------\LEGACY_CMDSERVICE -------\LEGACY_FOPN -------\LEGACY_NETWORK_MONITOR -------\LEGACY_NET_AGENT -------\LEGACY_WINDOWS_OVERLAY_COMPONENTS -------\fopn -------\Net Agent -------\Windows Overlay Components ((((((((((((((((((((((((( Files Created from 2007-07-23 to 2007-08-23 ))))))))))))))))))))))))))))))) 2007-08-23 13:4351,200--a------C:\WINDOWS\nircmd.exe 2007-08-23 09:22d--------C:\DOCUME~1\ED903B~1.ED-\vw 2007-08-23 09:21d--------C:\Program Files\Visual IP Trace 2007 2007-08-23 07:28512--a------C:\ScanSectorLog.dat 2007-08-23 07:195,664--AHS----C:\WINDOWS\system32\drivers\fidbox2.dat 2007-08-23 07:191,720,352--ahs----C:\WINDOWS\system32\drivers\fidbox.dat 2007-08-23 07:19d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\MailFrontier 2007-08-23 07:0775,512--a------C:\WINDOWS\zllsputility.exe 2007-08-23 07:074,212---h-----C:\WINDOWS\system32\zllictbl.dat 2007-08-23 07:0711,264--a------C:\WINDOWS\system32\SpOrder.dll 2007-08-23 07:071,087,216--a------C:\WINDOWS\system32\zpeng24.dll 2007-08-23 07:07d--------C:\WINDOWS\system32\ZoneLabs 2007-08-23 07:06d--------C:\WINDOWS\Internet Logs 2007-08-23 04:50d--------C:\WINDOWS\CSC 2007-08-21 04:46d--------C:\DOCUME~1\ED903B~1.ED-\AIMPro 2007-08-21 04:45d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\AIMPro 2007-08-21 04:45d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\acccore 2007-08-21 04:305,632--a------C:\WINDOWS\system32\ptpusb.dll 2007-08-21 04:30159,232--a------C:\WINDOWS\system32\ptpusd.dll 2007-08-21 04:3015,104--a------C:\WINDOWS\system32\drivers\usbscan.sys 2007-08-21 01:37d---s----C:\DOCUME~1\ED903B~1.ED-\UserData 2007-08-19 00:52d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Ahead 2007-08-19 00:37d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Simply Super Software 2007-08-18 21:16d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\Ventrilo 2007-08-17 19:59d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\WinRAR 2007-08-17 19:57d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\vlc 2007-08-17 08:15d--------C:\DOCUME~1\ED903B~1.ED-\APPLIC~1\uTorrent 2007-08-16 15:201,310,720--ah-----C:\DOCUME~1\ED903B~1.ED-\NTUSER.DAT 2007-08-16 13:47d--------C:\WINDOWS\system32\ActiveScan 2007-08-16 03:426,588--a------C:\WINDOWS\system32\bcbeg.ini.ren 2007-08-16 03:426,473--a------C:\WINDOWS\system32\bcbeg.bak1.ren 2007-08-16 03:42243,296--a------C:\WINDOWS\system32\gebcb.dll.ren 2007-08-15 11:536,536--a------C:\WINDOWS\system32\prutv.ini.ren 2007-08-15 11:536,421--a------C:\WINDOWS\system32\prutv.bak1.ren 2007-08-15 11:4852,750--a------C:\WINDOWS\system32\lqdsrngo.exe 2007-08-15 11:4843,542--a------C:\WINDOWS\system32\gebabxw.dll 2007-08-15 11:48192,582--a------C:\WINDOWS\system32\qwinrmdt.exe.ren 2007-08-15 11:48d--------C:\WINDOWS\system32\tmps9 2007-08-15 11:48d--------C:\WINDOWS\system32\ICdll 2007-08-15 11:48d--------C:\WINDOWS\system32\chkconfig 2007-08-15 11:48d--------C:\DOCUME~1\NETWOR~1\APPLIC~1\NetMon 2007-08-05 22:51d--------C:\DOCUME~1\ADMINI~1\APPLIC~1\Simply Super Software 2007-08-05 22:11d--------C:\Program Files\Trend Micro 2007-08-05 21:557,021--a------C:\WINDOWS\system32\ijkmp.ini.ren 2007-08-05 21:556,507--a------C:\WINDOWS\system32\ijkmp.bak1.ren 2007-08-05 21:34d--------C:\WINDOWS\system32\appmgmt 2007-08-05 20:10d--------C:\Program Files\MagicISO 2007-08-05 19:541,404,928--a------C:\WINDOWS\system\nvcpl.dll 2007-08-05 19:07d--------C:\DOCUME~1\ed\APPLIC~1\Help 2007-08-05 19:05d--------C:\Program Files\Security Task Manager 2007-08-05 19:05d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan 2007-08-05 18:5377,312--a------C:\WINDOWS\system32\ztvunace26.dll 2007-08-05 18:5375,264--a------C:\WINDOWS\system32\unacev2.dll 2007-08-05 18:5369,632--a------C:\WINDOWS\system32\ztvcabinet.dll 2007-08-05 18:53162,304--a------C:\WINDOWS\system32\ztvunrar36.dll 2007-08-05 18:53153,088--a------C:\WINDOWS\system32\UNRAR3.dll 2007-08-05 18:53d-a------C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP 2007-08-05 18:53d--------C:\Program Files\Trojan Remover 2007-08-05 18:53d--------C:\DOCUME~1\ed\APPLIC~1\Simply Super Software 2007-08-05 18:53d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Simply Super Software 2007-08-05 18:37786,432--ah-----C:\DOCUME~1\ADMINI~1\NTUSER.DAT 2007-08-05 18:206,467---hs----C:\WINDOWS\system32\efhkj.bak1 2007-08-05 04:0189,088--a------C:\WINDOWS\system32\atl71.dll 2007-08-05 04:01499,712--a------C:\WINDOWS\system32\msvcp71.dll 2007-08-05 04:01348,160--a------C:\WINDOWS\system32\msvcr71.dll 2007-08-05 04:011,060,864--a------C:\WINDOWS\system32\mfc71.dll 2007-08-05 03:346,466---hs----C:\WINDOWS\system32\ttutv.bak1 2007-08-05 03:29169,147--a------C:\WINDOWS\TTC-4444.exe.ren 2007-08-05 03:29d--------C:\Temp 2007-08-05 03:2840,183--a------C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe.ren 2007-08-05 03:28d--------C:\DOCUME~1\ed\APPLIC~1\s?stem32 2007-08-02 23:00d--------C:\Program Files\Lavasoft 2007-08-02 23:00d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft 2007-07-30 23:16d--------C:\DOCUME~1\ed\AIMPro 2007-07-30 22:47d--------C:\DOCUME~1\ed\APPLIC~1\AIMPro 2007-07-30 22:47d--------C:\DOCUME~1\ed\APPLIC~1\acccore 2007-07-30 22:46d--------C:\Program Files\Common Files\Nullsoft 2007-07-30 22:46d--------C:\Program Files\AIM 2007-07-30 22:46d--------C:\DOCUME~1\ed\APPLIC~1\AIM 2007-07-27 20:56d--------C:\WINDOWS\ShellNew 2007-07-27 20:56d--------C:\Program Files\AutoIt3(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-08-23 13:4516292--ahs----C:\WINDOWS\system32\drivers\fidbox.idx 2007-08-23 13:451508--ahs----C:\WINDOWS\system32\drivers\fidbox2.idx 2007-08-20 22:39---------d--------C:\Program Files\World of Warcraft 2007-08-20 21:07---------d--------C:\Program Files\Realtek 2007-08-19 01:38---------d--h-----C:\Program Files\WindowsUpdate 2007-08-18 20:27---------d--------C:\Program Files\uTorrent 2007-08-17 19:59359040--a------C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL 2007-08-17 19:59359040--a------C:\WINDOWS\system32\drivers\TCPIP.SYS 2007-08-16 02:1514656--a------C:\WINDOWS\gdrv.sys 2007-08-15 12:16---------d--------C:\Program Files\AC3Filter 2007-08-10 15:2116384000--a------C:\WINDOWS\RTHDCPL.exe 2007-08-10 13:524603904--a------C:\WINDOWS\system32\drivers\RtkHDAud.sys 2007-08-05 20:1812528--a------C:\WINDOWS\system32\drivers\secdrv.sys 2007-08-03 13:221826816--a------C:\WINDOWS\SkyTel.exe 2007-08-02 23:00---------d--------C:\Program Files\Common Files\Wise Installation Wizard 2007-07-30 19:1992504--a------C:\WINDOWS\system32\cdm.dll 2007-07-30 19:19549720--a------C:\WINDOWS\system32\wuapi.dll 2007-07-30 19:1953080--a------C:\WINDOWS\system32\wuauclt.exe 2007-07-30 19:1943352--a------C:\WINDOWS\system32\wups2.dll 2007-07-30 19:19325976--a------C:\WINDOWS\system32\wucltui.dll 2007-07-30 19:19203096--a------C:\WINDOWS\system32\wuweb.dll 2007-07-30 19:191712984--a------C:\WINDOWS\system32\wuaueng.dll 2007-07-30 19:1833624--a------C:\WINDOWS\system32\wups.dll 2007-07-26 18:061191936--a------C:\WINDOWS\RtlUpd.exe 2007-07-26 17:09520192--a------C:\WINDOWS\RtlExUpd.dll 2007-07-20 00:2936864--a------C:\WINDOWS\system32\dxinputdll.dll 2007-07-20 00:19---------d--h-----C:\Program Files\InstallShield Installation Information 2007-07-19 01:34---------d--------C:\Program Files\Guitar Pro 5 2007-07-17 00:32---------d--------C:\Program Files\Axon Data 2007-07-13 17:17---------d--------C:\Program Files\Ventrilo 2007-07-10 00:08---------d--------C:\Program Files\Common Files\Ahead 2007-07-10 00:07---------d--------C:\Program Files\Nero 2007-07-09 00:052722--a------C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin 2007-07-09 00:048972--a------C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin 2007-07-06 21:44---------d--------C:\Program Files\RivaTuner v2.02 2007-07-06 20:40---------d--------C:\Program Files\GIGABYTE 2007-07-06 18:13---------d--------C:\Program Files\Common Files\Blizzard Entertainment 2007-07-05 11:07315392--a------C:\WINDOWS\HideWin.exe 2007-07-05 11:06---------d--------C:\Program Files\Common Files\InstallShield 2007-07-05 10:580-rahs----C:\MSDOS.SYS 2007-07-05 10:580-rahs----C:\IO.SYS 2007-07-05 10:580--a------C:\CONFIG.SYS 2007-07-05 10:580--a------C:\AUTOEXEC.BAT 2007-07-05 10:58---------d--------C:\Program Files\microsoft frontpage 2007-07-05 10:56---------d--------C:\Program Files\Movie Maker 2007-07-05 10:56---------d--------C:\Program Files\Common Files\MSSoap 2007-07-05 10:55---------d--------C:\Program Files\Windows NT 2007-07-05 10:55---------d--------C:\Program Files\Online Services 2007-07-05 10:55---------d--------C:\Program Files\MSN Gaming Zone 2007-07-05 06:50---------d--------C:\Program Files\Common Files\SpeechEngines 2007-07-05 06:50---------d--------C:\Program Files\Common Files\ODBC 2007-07-05 00:38---------d--------C:\Program Files\QuickTime 2007-07-04 23:36---------d--------C:\Program Files\VideoLAN 2007-07-04 23:22---------d--------C:\Program Files\XviD 2007-06-28 16:442165760--a------C:\WINDOWS\MicCal.exe 1997-10-24 13:2025088--a------C:\WINDOWS\inf\regl3acm.exeDoes anyone know of a keylogger that can log a copy & pasted password? I don't know of one, the log usually comes up as Ctrl C and Ctrl P with no further detail. Could you be getting directed to a malicious website and pasting your password there? This is a common problem when clicking on links that COME in emails, very common with banking sites but they play it down because they don't want to admit they're being ripped off. I have personally reported 2 such misdirections to 2 different banks and neither of them even acknowledged my email. They're running scared. |
|
| 3562. |
Solve : I've had these trojans for awhile, but my computer is the same.(resolved)? |
|
Answer» I have about 4 or 5 trojan viruses that I can't REMOVE which really pisses me off. But the thing is my computer has been running the same and nothing seems wrong with it. And I've had these trojans for a couple of months. I'm trying to remove them. |
|
| 3563. |
Solve : wat is qwiz?? |
|
Answer» ok so its the LAST time IM at my cousins and my older cousin mike has something on his startup shield we found wen he just got spy sweeper is anyone FAMILIAR with this program? i know what to do its just that i dont feel safe deleting this programqwix seems to be legit, did you Google it? |
|
| 3564. |
Solve : Please help me i think its a virus.? |
|
Answer» OK i recently was surfin the web and some how i picked up something. I know its not good but it keeps tellin me that i have a virus on my computer but its not my anti-virus program which is mcafee. it keeps putting pop ups of different anti-virus programs and other sites. I have scaned a million times and dont know what to do. Please help as fast as you can.Hi, I think I have the same or a similar problem to you. I was browsing the internet and TRIED to view a video, of an advert, that I need for a research project, I had to download some SOFTWARE to view it. When I did I got next to the clock a new icon, that occassionally sends a message about a system alert about spyware. When I click on the icon it takes me to a webpage for virusprotectpro. I have norton ANTIVIRUS and have scanned my computer but it says my computer is clean, but I cannot remove this icon. When I first try and go online it normally takes me to bbc.co.uk but now it takes me to a security page, saying my computer is at risk and I should download anti-spyware software. I am not sure what is causing all of this but I would like it to stop, if someone could help me it would be appreciated.ok monkeynuts please start your own thread in this section with as much detail as possible, computer specs, symptoms, protection programs( anti-virus and other programs like that.. silence, we need more info on your computer, like OS( what windows do you have?) what scans did you do? did you do them in safe mode? can you post a hijackthis LOG for us to look at also.To avoid confusion, I'm locking this thread. Please refer to the one containing your logs. |
|
| 3565. |
Solve : spywarebomb? |
|
Answer» how do i get rid of this THING, every two days seems to show up and dont know which software to kill it for good i hope lol Go ahead and post a HijackThis log and we'll take it from there.Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 1:33:04 PM, on 7/14/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\hmsam\Local Settings\Temporary Internet Files\Content.IE5\M72V9DV4\HiJackThis_v2[1].exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ca.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O4 - HKLM\..\Run: [eTrust PestPatrol Active Protection] "C:\Program Files\CA\eTrust PestPatrol\PPActiveDetection.exe" O4 - HKLM\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /QS O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1182927150374 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182927172195 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u1-windows-i586-jc.cab O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx O17 - HKLM\System\CCS\Services\Tcpip\..\{7345C513-0818-48BD-A4B4-8AC56A09D709}: NameServer = 204.239.167.3,204.239.167.13 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic Professional 6\IoloSGCtrl.exe O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: Performance Logs and Alerts (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: WMI Performance Adapter (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe -- End of file - 4794 bytes Quote from: hmsam on July 13, 2007, 12:00:01 PM have xp home, with system mechanic 6 pro , adaware pro, etrust pestpartol 5, registry mechanic, ashampoo - photo commander, antispyware, winoptimizer & burning studio 6, ms office 2003 pro, aol/yahoo/windows live messengers, winamp & limewire pro I notice you have Limewire Pro. Did you PURCHASE this? Regardless, downloading files off P2P networks is highly risky and not advised. You should probably uninstall this software so that you are not affected again. Also, none of the software you have sounds like an AV, correct me if I am WRONG but it is advised, as I am sure Chris will tell you to get - AVG Anti-Virus Free. (Direct .exe Link).Your log looks clean to me. Perform a scan online with Panda ActiveScan and post a log here. Also, download SUPERAntiSpyware and Spybot - Search & Destroy, update them and scan with them in Safe Mode (one at a time!). Let us know the results of your scans. DeltaSlaya is right...I can't tell you to get rid of it, but you might want to reconsider using LimeWire. The program itself isn't considered malicious, but some of things you download through this client may be unsafe, and are likely contributors to your infection. Many downloads are also considered illegal, as they infringe on copyright laws. Quote from: DeltaSlaya on July 13, 2007, 06:37:08 PM Also, none of the software you have sounds like an AV, correct me if I am wrong but it is advised, as I am sure Chris will tell you to get - AVG Anti-Virus Free. (Direct .exe Link).Actually, they already have Kaspersky, which is a respectable anti-virus. Personally, I prefer AVG, but what they have is sufficient, so there's no need. They could certainly go for some better anti-spyware, though.Sorry, it's just that their AV wasn't mentioned here: Quote have xp home, with system mechanic 6 pro , adaware pro, etrust pestpartol 5, registry mechanic, ashampoo - photo commander, antispyware, winoptimizer & burning studio 6, ms office 2003 pro, aol/yahoo/windows live messengers, winamp & limewire pro and yea now that I look it indeed is in their HJT log.No worries. They probably forgot to mention it. hmsam, do you update Kaspersky and scan with it on a regular basis?it updates every three hrs and scans constantly by itself, because of kaspersky's antihacker makes it scans from the attacks of the helken attacks scans full on friday mornings spybot does not work, never tried superantispyware as mentioned above oh i also installed the cleaner professiona from moosoft, found nothing tooTry removing SpywareBomb in Safe Mode and then scan with System Mechanic since it seems to be able to detect the program. If it still exists, you should also delete C:\Program Files\SpywareBomb, as well as the various files listed here... http://www.emsisoft.com/en/malware/?Adware.Win32.SpywareBomb Use Pocket KillBox if you have to. Once you've done all of this, try the Panda ActiveScan and post your results.RogueRemover is supposed to remove spywarebomb, it on their list. If it's returning after a couple of days then you should review your downloading habits as antivirus & antispyware programs won't protect you from rogue programs or pups.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3566. |
Solve : Rustock.gen!C virus? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.0 (BETA) |
|
| 3567. |
Solve : VIRUS named GONrong.ALP?? |
|
Answer» ok so i was on the internet with my cousins computer and a window pops up saying know dude we cant do a thing like we get to black thing thingy but u cant do anything To be perfectly honest, I have no idea what you're saying. Like patio said...we need more info, as well as coherent sentences.forget it hes out a good 1000 bucks cus of this viruses Incoherent gibberish. Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3568. |
Solve : Winantispy2007 downloaded to my computer without my permission? |
|
Answer» You still have a couple of bad entries showing up... You appear to have a PurityScan infection. Copy everything inside the quote box below (starting with dir) and paste it into Notepad. Go up to File > Save As... and click the drop-down box to change the "Save As Type" to "All Files". Save it as findfile.bat on your Desktop.I'm sorry there wasnt anything in the notepad file I did it but it came up empty. After fixing the others here is the hijack log. Logfile of HijackThis v1.99.1 Scan saved at 9:48:31 PM, on 7/21/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Apoint\Apntex.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\vsnpstd2.exe C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe C:\Program Files\Pando Networks\Pando\pando.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Raynelle\My Documents\my programs\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: CafeMom Toolbar - {8151A608-00FB-4D5C-8B8D-40E239E32A42} - C:\Program Files\CafeMom Toolbar\cmtb.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall O4 - HKLM\..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [EasyLinkAdvisor] "C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" /startup O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\pando.exe" /Minimized O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll O9 - Extra 'Tools' menuitem: IE7pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IE7pro\IE7pro.dll O9 - Extra button: (no name) - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll O9 - Extra 'Tools' menuitem: CafeMom Toolbar - {07DB8C18-9FD9-4e43-AF16-043E44D89768} - C:\Program Files\CafeMom Toolbar\cmtb.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - OPTIONS group: [INTERNATIONAL] International* O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) - http://help.rr.com/Foundrysdccommon/download/tgctlar.cab O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab O16 - DPF: {A93D84FD-641F-43AE-B963-E6FA84BE7FE7} (LinkSys Content Update) - http://www.linksysfix.com/netcheck/67/install/gtdownls.cab O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AOL CONNECTIVITY Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe I seem to be getting IE pop ups like a myspace celebrity profile and I won this crap, but I dont even have IE open.. I use Mozilla firefox. AND I have the popupblocker on IE set at block ALL popups.. In the add/remove programs list I have windows internet exlporer 7 and IEpro7 entries... is this the same thing? I also have programs that have no size on it? Im sorry I keep posting UGHH now I am getting pop ups in firefox.... something like system doctor.com your computer is under attack! get help now! You could be getting the popups through the messenger service which would indicate that your windows is not uptodate. If this is the case then update your windows or disable the messenger service. Start>Settings>Control Panel>Admin Tools>Services>Messenger...Disable. Did you run the scans I suggested, all 4 of them?I am now.. sorry.. the ROGUE remover wiped out a bunch of things that said winanitspy2007. but i'm still getting the pop up. ewido is running, and so is panda active scan. I'm getting a question from zone alarm to allow a generic hos process for win32 services to accept internet connections.. its svchost.exe???/Okay...look in C:\Program Files for a ?racle folder. The question mark is a wildcard, which means it could start with any letter. So, the folder could be called Tracle, Iracle, or (most likely) Oracle. This folder needs to be deleted. If you find more than one folder with such a name, let me know before you do anything. Did you try this suggestion from Fed... Quote from: Fed on July 21, 2007, 09:14:35 PM You could be getting the popups through the messenger service which would indicate that your windows is not uptodate.You can also try Shoot The Messenger. As for ZoneAlarm...it may be a legit request, but you might want to read through this thread... http://www.computing.net/security/wwwboard/forum/272.html Quote from: nellenaz on July 21, 2007, 09:00:46 PM In the add/remove programs list I have windows internet exlporer 7 and IEpro7 entries... is this the same thing? I also have programs that have no size on it?This is IE7Pro... http://www.ie7pro.com It's an add-on for IE7. You don't need it, but it's not malicious. Also...not all programs list their filesizes. Are any of these programs suspicious?By the way, here is some info for those programs you listed earlier... Digital Content Portal (Comes with some Dell computers. Some consider it to be spyware, but it doesn't appear to be malicious. Can be removed if you don't want it.) EarthLink Setup Files (Can be removed if you have no interest in EarthLink.) f Get HI speed Internet! (Not sure what this is. Probably related to FlashGet. Should be able to remove safely.) Macromedia Flash Player (You should keep this.) Microsoft .NET Framework 1.1 (You might want to upgrade to 2.0.) Microsoft .NET Framework 1.1 Hotfix (KB8928366) (Are you sure that's the right number? I can't find info on this exact hotfix.) Microsoft COMPRESSION Client Pack 1.0 For windows (This is safe.) Microsoft Plus! Digital Media Edition Installer (This is safe, but you don't need it.) Microsoft Plus! Photo story 2 I.E Microsoft User-mode driver Framework feature Pack 1.0 (This is safe. Keep it if you want it.) NetZero Installer (You can remove this if you have no interest in NetZero.) PhotoClick (Not sure about this one. Could be related to this.) RealPlayer Basic (Media player that probably came with your computer. It's safe.) (Safe.) Sonic DLA (Safe, but not free.) Sonic RecordNow! Audio (Safe, but not free.) Sonic RecordNow! Copy (Safe, but not free.) Sonic RecordNow! Data (Safe, but not free.) Sonic Update Manager (Safe.) WebCyberCoach 3.2 Dell (Came with Dell. Should be safe.) Windows Installer 3.1 (KB89353) (This is safe.) Windows Media Format 11 runtime (Part of Windows Media Player. You should keep this.) Windows Media Player 11 (You should keep this.) Apple Software Update (Safe. Probably came with your Apple Mobile Device.) IE7Pro (IE7 add-on. Safe.) Learn2 Player (Uninstall Only) (Bloatware installed by AOL; often comes with Dell computers. It's not malicious, but you don't need it.) Conexant D480 MDC v.9x Modem (Modem driver. Might want to keep this.) Digital Line Detect (Comes with Dell; used to be considered spyware. Should be safe, but you don't need it.) AOL Coach Version 1 (build:20040229. 1 en) (AOL bloatware. Not malicious, but you don't need it.) AOL Connectivity Services (Automatically reconnects you if you lose your AOL connection.) Apple Mobile Device Support (Comes with the latest versions of iTunes. If you don't have an iPhone, then you don't need this.) Viewpoint Media Player (More AOL bloatware. Technically not malicious, but I usually advise removing it.) Windows Desktop Search 3.01 (Search tool. You don't need it, but it's safe, and might be useful.) Well I ran ALL the programs Fed suggested, coupled with what Chris told me and I seem to be in the clear. I didnt have a ?acle folder, but i did see something like that deleted with one of the programs. I'm going to run all of the programs again Roguerunner, AVG Free Ccleaner panda active scan superantispyware ewido online and spybot and see what they come up with again how often should I run these programs? And thank you Chris for all the information on those programs.. I'm going to be deleting a LOT today.. Quote from: CBMatt on July 22, 2007, 04:04:32 AM By the way, here is some info for those programs you listed earlier... it wasn't!! it is KB928366 somehow and 8 got added.. I was c/p from microsoft onenote. so probably happened then. AVG Free came up clean!! Will keep you updated. Oh and the messenger service was already disabled. oh and no none of the programs were suspicious, I just didnt know what they were. Thanks guys!!! You're lifesavers!!! Don't forget to keep your Windows uptodate and create a new restore point.So, no more popups, then? Excellent. Like Fed says, you should clear your restore points and create a new one... 1. Go to Start > Programs > Accessories > System Tools > System Restore 2. Click on System Restore Settings. 3. Check Turn off System Restore and click OK. 4. Restart your computer. 5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK. 6. Create a new restore point and close the program. System Restore will now be active again. If you would like to learn more about System Restore, go here. Also, I see that your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. Once you have installed the latest version, you should remove any older versions of Java. For more info on infections and how to stay clean, please read through this guide.As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3569. |
Solve : My connection is unstable.? |
|
Answer» Hi everyone, Hi patio, thx for replying. And each DSL filter is installed in the right direction? Please don't ask me how I know this makes a difference. Hi, Well in the past, like 1 year ago, i've had the same KIND of problems with my connection...I thought it was some trojan downloader that was using my connection to the max...so I just formated. But now this unstability came back. This week I should be able to call my ISP and try to do that line test. But just to make sure, I would need ur help to find out is there is any junk running on my comp with a HJT scan or ne other program. I'm not sure my computer is healthy right now... This help would be greatly appreciated from your part. Thx for ur time again.Run all your protection apps in safemode and then post back with the results and a HijackThis log... The Resident Experts will be along shortly. Make sure to list what you ran and the results,,,FORMATTING wipes the drive clean, allowing you to do a fresh install of Windows. If you formatted, then you shouldn't have to worry about malicious infections. But if you would still like us to take a look at an HJT log, you're free to post it. EDIT: Nevermind, I just re-read your post. When you said "I just formatted" I thought you meant today. Go ahead and follow patio's advice.Due to lack of feedback, I am closing this topic. If you are the ORIGINAL poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3570. |
Solve : Agh help please!? |
|
Answer» Hey all, this is my first post here, im HOPING to et some answers |
|
| 3571. |
Solve : storm worm?? |
|
Answer» And if you THINK you might be infected, you may want to POST a HijackThis log.Due to lack of feedback, I am closing this topic. If you are the original POSTER and you would like this topic to be re-opened for any REASON, PM me or another moderator and it can be arranged. |
|
| 3572. |
Solve : reset all cookies reset every ie startup? |
|
Answer» all protection programs have different database and different names for the same infection. those might have found it but couldn't remove it or just quantined it. superantispyware as a nice vundo database along with other infections. and some infections just need specialty tools to remove them completelyWell, your main infection was Vundo. I'm not sure why VundoFix didn't pick it up...it should have recognized the infection because it's not a new version. PERHAPS it was old enough to not be supported. I will see if I can get an ANSWER from the creator. Anyway...although you had Vundo, I don't think it was the one changing your settings. You also had an IE hijacker, which I believe was causing the problems you described. In addition to these, you had a couple of infections that I can't identify. |
|
| 3573. |
Solve : Spybot? |
|
Answer» I recently tired to download Spybot on to my laptop and it went through then told me that I need to have to adminstrator password which is myself, and when entered it STILL didn't go through, so I couldn't FINALIZE the download, what should I do?which browser are you using? |
|
| 3574. |
Solve : Safemode lockout? |
|
Answer» I downloaded Embarq online security software,I did not disable My Windows XP Firewall prior installing the other firewall,now I do not have any icons or start menu and my safe MODE is a dark screen.how do i disable one of those firewalls,without being able to acces safe mode and get to add and remove programs.login to your pc, and when you arrive at your iconless and taskbarless desktop, PRESS ctrl+alt+del and add NEW task 'explorer.exe' and see if you can access add/remove programs from there.I tried explore.exe to no avil,Ispent 45 min.with an embarq IT and ET in TASKMANAGER,without any results.hmm....INSTEAD of task manager...try pressing start button + r to bringup the run menu. then type explorer.exe |
|
| 3575. |
Solve : Trojan Downloader on XP...Mega Problems? |
|
Answer» Combofix Part II *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-01-12 21:3863128---------C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 01:07] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46] "HostManager"="C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe" [2006-09-25 20:52] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" "nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C "tscuninstall"=%systemroot%\system32\tscupgrd.exe [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29] [HKEY_LOCAL_MACHINE\SYSTEM\currentcontrolset\control\safeboot\minimal\aawservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Trent Berger^Start Menu^Programs^Startup^Anapod Manager.lnk] path=C:\Documents and Settings\Trent Berger\Start Menu\Programs\Startup\Anapod Manager.lnk backup=C:\WINDOWS\pss\Anapod Manager.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG] BCMSMMSG.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster] C:\Program Files\Blubster\Blubster.exe SILENT [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /installquiet [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] AutoRun\command- E:\autorun.exe Contents of the 'Scheduled Tasks' folder 2007-06-15 06:39:50 C:\WINDOWS\tasks\AppleSoftwareUpdate.job 2007-07-04 05:51:53 C:\WINDOWS\tasks\MP Scheduled Scan.job ************************************************************************** catchme 0.3.914 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-04 02:30:50 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-04 2:32:14 C:\ComboFix-quarantined-files.txt ... 2007-07-04 02:32 --- E O F ---Hijack This Logfile of HijackThis v1.99.1 Scan saved at 2:35:58 AM, on 7/4/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Documents and Settings\Trent Berger\Desktop\HijackThis(2).exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dell.com/ O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AOL CONNECTIVITY Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe Your HijackThis log looks clean to me. ComboFix picked up quite a few infected files, WinAntiVirus in particular. Even after running the scans, are you still experiencing PROBLEMS? I noticed that you have Blubster installed on your computer. According to reviews, it hosts a lot of risky downloads (like all file-sharing programs) and it seems to cause a fair amount of system instability. On top of that it is bundled with third party adware. You don't have to get rid of it, but if I were you, I would. You can read a little about it here. Also, I found this in your ComboFix log... C:\Program Files\Kap.GRETests Are you at all familiar with this? It appears to be related to Jersey Cow Software, but I can't find any actual information on it. As for the programs you have downloaded...although you don't have to, I would advise keeping the anti-spyware programs. Unfortunately, there's not one program that can detect everything, so it's good to have a few. And the ones you have are some of the best. However, you don't need all of them...but you should have two at the very least. I would also suggest keeping CCleaner. It's very handy and you should run it a couple of times each WEEK to help tidy things up a bit. Once we are done here, you're free to get rid of HijackThis and ComboFix if you wish. You can delete the logs at any time. Once you post them here, there's no need for them on your computer.Thanks again, a few questions. 1) What can I do to clean up my infected files and programs? -You stated combo fix found a lot of files, and that I have the GRE program and blubuster. -How can I get rid of these and get my computer fixed? 2) Why is it I keep every few days getting the same viruses found again on symnatec? -Is there anything I can do to fix this thing once and for all? 3) The computer is better, but not 100%. -I am most concerned about deleting all iffy programs AND -The combofix infected files -Reappearing virusesComboFix removes all infected files. If they keep coming back, then there's definitely something else going on. Go ahead and run the program again and post another log. And I hate to make you get another program, but I think you should download and save Blacklight to your desktop: Double-click fsbl.exe then accept the agreement and click on Scan. Once it's complete, click on Next. You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers). Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe" As for Blubster...you should be able to uninstall it through Add/Remove Programs. You should be able to do the same with Kap.GREsts, but I'm not sure what it might be called. Perhaps we can take a look at the programs installed on your computer. Go ahead and open up HijackThis. Click on "Open the Misc Tools SECTION" and then "Open Uninstall Manager". From there, click on "Save list" and save the Notepad file to your desktop. Open that file and paste the contents here.1) Combofix Log Part I "My Name" - 2007-07-06 11:29:57 - ComboFix 07-07-03.9 - Service Pack 2 ((((((((((((((((((((((((( Files Created from 2007-06-06 to 2007-07-06 ))))))))))))))))))))))))))))))) 2007-07-04 02:2351,200--a------C:\WINDOWS\nircmd.exe 2007-07-02 02:54d--------C:\Program Files\CCleaner 2007-06-30 15:0110,872--a------C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-06-28 04:221,060,864--a------C:\WINDOWS\system32\mfc71.dll 2007-06-15 02:44d--------C:\Program Files\iTunes 2007-06-15 02:44d--------C:\Program Files\iPod 2007-06-08 16:04d--------C:\Program Files\Lavasoft 2007-06-08 16:04d--------C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft 2007-06-08 16:03d--------C:\Program Files\Common Files\Wise Installation Wizard (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-07-06 14:47:38--------d-----wC:\Program Files\Symantec AntiVirus 2007-07-04 16:25:5217,634----a-wC:\WINDOWS\system32\nvModes.dat 2007-07-02 03:31:594,755----a-wC:\WINDOWS\mozver.dat 2007-06-30 05:42:23--------d-----wC:\DOCUME~1\TRENTB~1\APPLIC~1\Wal-Mart Digital Photo Manager 2007-06-30 04:50:34--------d-----wC:\Program Files\Google 2007-06-21 23:35:29--------d-----wC:\Program Files\America Online 9.0 2007-06-15 06:42:27--------d-----wC:\Program Files\QuickTime 2007-06-15 06:39:49--------d-----wC:\Program Files\Apple Software Update 2007-06-11 20:21:02--------d-----wC:\Program Files\Common Files\AOL 2007-06-04 19:18:489,344----a-wC:\WINDOWS\system32\drivers\NSDriver.sys 2007-06-04 19:17:028,320----a-wC:\WINDOWS\system32\drivers\AWRTRD.sys 2007-06-04 19:14:566,272----a-wC:\WINDOWS\system32\drivers\AWRTPD.sys 2007-05-25 19:47:21--------d-----wC:\Program Files\Kap.GRETests 2007-05-16 15:12:02683,520------wC:\WINDOWS\system32\inetcomm.dll 2007-04-25 14:21:15144,896------wC:\WINDOWS\system32\schannel.dll 2007-04-18 16:12:232,854,400----a-wC:\WINDOWS\system32\msi.dll 2007-04-17 02:47:3633,624----a-wC:\WINDOWS\system32\wups.dll 2007-04-17 02:45:541,710,936----a-wC:\WINDOWS\system32\wuaueng.dll 2007-04-17 02:45:48549,720----a-wC:\WINDOWS\system32\wuapi.dll 2007-04-17 02:45:42325,976----a-wC:\WINDOWS\system32\wucltui.dll 2007-04-17 02:45:36203,096----a-wC:\WINDOWS\system32\wuweb.dll 2007-04-17 02:45:2892,504----a-wC:\WINDOWS\system32\cdm.dll 2007-04-17 02:45:2053,080----a-wC:\WINDOWS\system32\wuauclt.exe 2007-04-17 02:45:2043,352----a-wC:\WINDOWS\system32\wups2.dll 2007-04-13 19:19:527,680----a-wC:\WINDOWS\system32\lsdelete.exe 2007-04-13 17:31:03103,984----a-wC:\WINDOWS\system32\AOLDial.dll ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] 2006-01-12 21:3863128---------C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-20 01:07] "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46] "HostManager"="C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe" [2006-09-25 20:52] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-01 16:51] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56] "Aim6"="C:\Program Files\AIM6\aim6.exe" [2006-11-07 11:29] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" "nlhr"=RunDll32.exe %SystemRoot%\System32\AdvPack.Dll,LaunchINFSection %SystemRoot%\inf\nlite.inf,C "tscuninstall"=%systemroot%\system32\tscupgrd.exe 2) ComboFix Log Part II [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Trent Berger^Start Menu^Programs^Startup^Anapod Manager.lnk] path=C:\Documents and Settings\Trent Berger\Start Menu\Programs\Startup\Anapod Manager.lnk backup=C:\WINDOWS\pss\Anapod Manager.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG] BCMSMMSG.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blubster] C:\Program Files\Blubster\Blubster.exe SILENT [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /installquiet [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E] AutoRun\command- E:\autorun.exe Contents of the 'Scheduled Tasks' folder 2007-06-15 06:39:50 C:\WINDOWS\tasks\AppleSoftwareUpdate.job 2007-07-06 14:50:01 C:\WINDOWS\tasks\MP Scheduled Scan.job ************************************************************************** catchme 0.3.914 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net Rootkit scan 2007-07-06 11:32:08 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Completion time: 2007-07-06 11:32:42 C:\ComboFix-quarantined-files.txt ... 2007-07-06 11:32 C:\ComboFix2.txt ... 2007-07-04 02:32 --- E O F --- 3) Whenever I do ComboFix -Internet Explorer icon automatically is downloaded onto my desktop. -Why? Is this a problem? 4) FSBL downloaded -Scanned, no problems -Log 07/06/07 11:41:59 [Info]: BlackLight Engine 1.0.64 initialized 07/06/07 11:41:59 [Info]: OS: 5.1 build 2600 (Service Pack 2) 07/06/07 11:41:59 [Note]: 7019 4 07/06/07 11:41:59 [Note]: 7005 0 07/06/07 11:42:05 [Note]: 7006 0 07/06/07 11:42:05 [Note]: 7011 1580 07/06/07 11:42:05 [Note]: 7026 0 07/06/07 11:42:06 [Note]: 7026 0 07/06/07 11:42:08 [Note]: FSRAW library version 1.7.1022 07/06/07 11:46:11 [Note]: 2000 1012 07/06/07 11:46:11 [Note]: 2000 1012 07/06/07 11:46:11 [Note]: 2000 1012 07/06/07 11:46:11 [Note]: 2000 1012 07/06/07 11:47:28 [Note]: 7007 0 5) Hijack This Logfile Logfile of HijackThis v1.99.1 Scan saved at 11:48:10 AM, on 7/6/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Program Files\BitLord\BitLord.exe C:\Documents and Settings\Trent Berger\Desktop\HijackThis(2).exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://dell.com/ O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1154149194\ee\AOLSoftware.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe 6) I months ago thought I deleted all of kaplantests and bluebuster. I can not find it on add/remove. -Why is it not deleted when I already thought it was done -Is there anything I can do to finish? 7) Do I need to save and keep the logs of ComboFix, FSBL, and HiJack This or may I delete? When I download music, not often I -Go to isohunt, download torrent with bitloard -Would you call this safe and is there anything I can do to safeguard? -Should I run a cleaner after? Thanks.Everything looks clean to me. You may want to give the Outerinfo remover a try. I have my suspicions, but we're running out of options, and it might work... http://www.outerinfo.com/howto.html ComboFix might be making a change to the registry that causes the IE icon to appear on your desktop. I don't have a definite answer for this, but I've seen it before and I wouldn't be concerned. If you already removed those programs, then they may have just left some files behind. Most programs will still leave something behind, even after you've uninstalled it. You can go ahead and delete the logs. And yes, you should scan those downloads. In fact, you should can ALL downloads once they're on your computer.Alright 1) I downloaded the program, it says everything is deleted. 2) According to you do you think my computer is safe for the time being? Knock on wood it is running fine. 3) What do you think the problem was or how did it become? 4) Do you have a recommendation on what I can do to keep it safe from now on, should I keep -Symnatec anti-virus active -AVG spyware active -Have Ad aware, spybot search and destroy, ewido spyware as backups -HiJack this, ComboFix, and CCleaner all stay on the computer and run everything once a week? Is this a good a plan or do I need to add anything or delete? Hijack this and Combofix, should those be run only when necessary not regularly? 5) Should I encounter a problem in the future, what can I do to make sure if I must reformat I have everything and don't lose material? Thanks.If your problem is gone and stays that way, then I have no reason to think you need to worry about anything. There are many ways to get infected. My guess would be that you downloaded something that installed third party software without your knowledge. It's always a good idea to read the EULA before installing anything. EULAlyzer is a helpful program... http://www.javacoolsoftware.com/eulalyzer.html To learn more about how you may have been infected and for even more prevention tips, read Tony Klein's protection article. Personally, I'm not a fan of Symantec/Norton and would suggest replacing it with AVG Free. However, if you are happy with it and wish to keep it, then that's fine. Your anti-spyware programs are all good and should be kept. AVG Anti-Spyware is a very good program, but unfortunately, once the trial runs out, the resident shield is disabled. Because of this, I think Spybot would be better as your active anti-spyware. But as long as you perform regular scans, it won't make much of a difference. With all of these backups, you've got a good arsenal. You should keep CCleaner and run it at least once a week. I run it everyday, but that's just my preference. HijackThis and Combofix should only be run when needed again. I would suggest keeping them someone on your computer, though. If you encounter further problems, the best thing to do is update your protection programs and then scan with each one in Safe Mode. If your problem still persists, then you can post another HijackThis log and ask for assistance. If it ever gets to the point where you need to reformat, you should back up all of your important data (pictures, documents, media) onto CD's. There are loads of free burning programs out there. It's usually advised to simply re-download software rather than backing it up. This is entirely up to you, of course. If you have any other questions, I'll be happy to answer them to the best of my ability.1) Thank you very much for your time and helpfulness. I really appreciate your continued interest and responses to my serious questions. 2) I'll review the links on the EULA analzyer plus the protection. 3) As far as further things to do, my AVG anti spyware trial ran out. -What does this mean, it still automatically boots up on my computer and says I am "now" protected against 864,XXX threats, yet the icon is now black and white as opposed to colored. Is it actually working and protecting me or not and is there any use in keeping it active? 4) When I run the CCleaner, it deletes about 19.5 mb of files each time, is this normal? -Additionally when I run "scan for problems" the same problems appear, again should this be of worry? 5) How do you download material onto CDs that allow them to be "backed up" if reformatted -Internet browser settings Desktop icons -Programs -Documents -Pictures -Music? Thanks.1. You're very welcome. It's my pleasure to help out when I can, and I'm glad to be of service. 3. This is what I was referring to in my last post when I said that the Resident Shield will be disabled. AVG Anti-Spyware is still fully functional after the trial runs out. However, the live scanning no longer works. This means that it doesn't scan incoming files and you have to perform scans manually. The same goes for updates; it will no longer update automatically, so you have to go to the Update tab and do it yourself. The program is still very useful, but I would suggest keeping Spybot active instead, and have AVG as your backup when you perform routine scans. 4. Depending on the connection you have, this is probably normal for CCleaner. Especially if it's set to also scan Temporary Internet Files. I'm on a slow dial-up connection and I tend to get about 6 to 12 MB in a day. Of course, this depends on your activities. I just performed a scan and included my Temporary Internet Files (which I only do about once a week), and it added on an additional 95 MB. Make sure you click on Run Cleaner each time. As for the registry scan...what issues keep coming up? Are you clicking on Fix selected issues? 5. For backing up info onto CD's, you first need to make sure you have a CD-R/RW drive. Typically, the front of the CD drive will say something about Compact Disc ReWritable. Another thing you will need is burning software. CDBurnerXP Pro is a decent program. Lastly, you need blank CD-R/RW discs. These days, you can get 50 for about $15. Burning programs are usually fairly self-explanatory (select the files you want and the program to copy them), but if you need help, let us know.Thanks again. I have in the past downloaded music and burnt it on to CD, it is right to assume then I have the necessary components on my computer to back up information, is it really any different? What do you, simply click save to CD, and the once reformatted download it from the CD? Thanks.Yes, it's a lot like burning music. But instead of burning a music CD, you're burning a data CD. The process is essentially the same, though. And so is the equipment. And yes, after reformatting, you simply insert the CD's and take the data off. Personally, I think an external hard drive would be easier and more reliable, but they're also a bit more expensive. |
|
| 3576. |
Solve : 3 Antiviruses - Will they work together?? |
|
Answer» Sorry if this is in the wrong place, i just thought since this was about viruses and malware... |
|
| 3577. |
Solve : new start up entry? |
|
Answer» My pc has been running slow for a while after start up. I checked the start floder and found a new entry ZSSnp211.exe. Can any body help with info on this please .Thanks.Quote from: Richenstony on AUGUST 09, 2007, 02:35:01 AM http://www.majorgeeks.com/downloadget.php?id=5554&file=10&evp=4122712c2af084c815e5fd4f2b249d83Post the log for us to have a look at tedder, ZSSnp211.exe is a file often ASSOCIATED with Bigdog/Vimicro, who make various products, the most common being webcams. Although they mainly cater to the Chinese market, they're not exclusive to the area. I'm not 100% sure exactly what this particular file does, but I believe it is your webcam DRIVER. It shouldn't be anything malicious. You can try disabling it, but it may cause your webcam to not function properly. That's about the best ANSWER I can give you. However, I'm fairly confident that you don't have anything to worry about. But if you wish, you may still post a HijackThis log. |
|
| 3578. |
Solve : Trojan Horse Removal?...? |
|
Answer» Well I got careless of what I was downloading so now I am stuck with Advertisment Pop-ups, my computer starts extreamly slow, and I think it is hidden. When I do a virus scan with AVG Free I delete the INFECTED files but when I am connected to the internet the Trojan DOWNLOADER downloads all the same viruses/trojans that I deleted, same thing with the adware (Which I use Spybot Seek & DESTROY) is there a way where I can delete all these viruses/trojans without reinstall Windows? Any help would be apperiated.DLoad install update and run AVG Anti-Spyware which is also free...it's more designed for removing trojans which it seems you have... If i were you, i'd purchase some antivirus software. I'd recommend Norton Internet Security, and Win Antivirus Pro.AVG Free is easily superior to these programs. In fact, we often advise removing Norton. And we always remove WinAntiVirus Pro because it's basically considered an infection.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3579. |
Solve : avg process? |
|
Answer» every time I try to connect to net the avg update process takes place is this normal , taI'm not sure if that is the AVG default or not but I have my auto update turned off because I'm on dialup & prefer to update when it suits me.How LONG has this been happening? How often do you connect to the internet? I'm guessing it's probably just a coincidence. AVG updates PRETTY often, which could be the cause. You could try TURNING off the automatic updates, although I wouldn't really suggest doing so.It's a normal running process...if you click on Schedule in the main PANE and select properties below you can set the time at which AVG updates daily. |
|
| 3580. |
Solve : strange files? |
|
Answer» Hi. Please excuse me because I've never posted to any forum before. Remove all those programs, I think one of em is actually spyware itself... Ignore this advice. Update and run the protection programs you have in safemode. To enter safemode tap F8 repeatedly after turning the machine on and before you see the Windows splash screen. Let them fix what they find. Then DLoad and install HijackThis. Install it in it's own directory not the Desktop. Run a scan with it. DO NOT let it fix anything yet. Save the log as a text file and post it here. It may take 2 or 3 posts to include the entire log. |
|
| 3581. |
Solve : CPU usesage reads 100%? |
|
Answer» Lately I have had to do a restore on my computer every other day. Seems that my computer cpu usage jumps up to 100%. After the restore it goes down to 28% and my computer functions OK. Could this be due to a virus? I run AVG anti virus on my system. |
|
| 3582. |
Solve : V:15A 2121 Aueno5 12 Do you know what this is?? |
|
Answer» I have a blue field in my left hand CORNER of my screen. It has V:15A 2121 Aueno5 12 in that field. Since I have had the message I find that when my screen goes to the screen saver I get flashing bright lights instead of the screen saver. When you look at the desk top items and go to click on ONE it is like the message is above it on the computer screen. I need help this is driving me crazy! I am SORRY if this has been posted some where else. I am new to this web site.Could you give us a screenshot? Hit the Print Screen key and go to Start > Programs > Accessories > Paint. Upload the picture to a site such as PhotoBucket and post the link here. Also, what OS do you have?Due to lack of feedback, I am CLOSING this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. |
|
| 3583. |
Solve : Registry Entry? |
|
Answer» The following is appearing in my registry, I have know idea where it came from and I cant delete it.
Other than that, your log looks pretty clean. However, you do have this... O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE It's related to RealTek. Technically, it's considered spyware, but it isn't malicious. You don't have to remove it, but if you wish, I can tell you how. Once you have run LSPFix, update your anti-virus program. Then download SUPERAntiSpyware and update that. Reboot in Safe Mode and scan with each program, one at a time. Then restart and update us on how things are running. Also...are there any keys inside of that registry entry?Thanks so far for your help. I have done all that you have outlined above and yes there are other keys in this problem I would like to get rid of. HKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer HKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer\Recent File ListHKEY_CURRENT_USER\Software\Ó¦ÓóÌÐòÏòµ¼Éú³ÉµÄ±¾µØÓ¦ÓóÌÐò\HViewer\Settings Can you explain to me how to delete the above without having to re format again. CheersOkay...I'm thinking two things. Either you have Hadith Viewer installed on your computer, or you have an infection (at this point, I suspect VX2). The strange characters make think the former might be a possibility, as Arabic wouldn't show up properly in the registry. Do you have Hadith Viewer installed on your computer? Check your Add/Remove Programs list (look for anything that might relate to the name HViewer). If it's there...did you install it? And if so, where did you download it from? I don't believe the program is malicious, but many sites hosting it are known for having risky downloads. If you do NOT have Hadith Viewer installed, then follow these instructions... Download CCleaner (install without Yahoo! toolbar) and configure it according to this guide. Run the Cleaner and Issues. Download and install the latest version of Ad-Aware. If you have an older version, choose to uninstall it when prompted. After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run. Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now". Close Ad-Aware, if it is CURRENTLY open. Download the VX2 Cleaner 2.0 Plug-in from Here
Go ahead and post back with an update on how things are running.Cheers Mate. I will be offline for a few days and I will let you know how I get on.Alrighty, we'll leave the light on for you.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3584. |
Solve : virus software cant remove on windows update? |
|
Answer» i have this contra virus software tring to get us to buy it weird thing is it is comming throgh our windows update icon and we CANT seem to get it to stop and it is bothering the way we use the computer when the message comes up on our computer that our system has been infected we already have virus software what can i do please anyone that can help it is real bothersomeyou might be infected with smitfruad.. what OS and other protections do you have? i have this contra virus software tring to get us to buy it weird thing is it is comming throgh our windows update icon and we cant seem to get it to stop and it is bothering the way we use the computer when the message comes up on our computer that our system has been infected we already have virus software what can i do please anyone that can help it is real bothersome Hi all, After a long time not visiting the forum, where I apologise for, I'm back. @doitinachevy : What antivirussoftware are you using ? Hopefully not Norton or Mcafee. Do you have any antispyware tools installed ? If yes : which ones ? Quote from: unlovedwarrior on July 25, 2007, 08:16:16 AM thanks ChrisNo problemo. I agree that this sounds like SmitFraud. doitanechevy, please FOLLOW the link in unlovedwarrior's post and then post back with a HijackThis log and an update on how things are going.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a NEW Topic with information about your computer and your problem. |
|
| 3585. |
Solve : Win32 DNS Changer,Zlob DNS Changer? |
|
Answer» Hi All,I'm back again.After following advice on here,I use (amongst other things) Spybot search & destroy.It has pinpointed the spyware as in the topic title.When I click the fix problems button it says they're fixed but another scan shows they are still there.I did a general GOOGLE search for both,The win32 one showed up on a french site but GOOGLES translation didn't help much! The zlob one showed a couple of sites to fix the PROBLEM but the spyware changed the site & diverted me away from it! |
|
| 3586. |
Solve : MP3 software virus? |
|
Answer» HI I've tried to delete this mp3 software that my uncle installed from my computer using Add or remove but it wouldn't let me. My anti-virus picked a few GENETIC trojan from that software. I deleted it's folder in program files. But in Add or remove it's still there. Please help... Thankyou Here's my HJT log: Logfile of HijackThis v1.99.1 Scan saved at 4:22:21 PM, on 7/25/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\AGRSMMSG.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Common Files\AOL\1125001301\ee\aolsoftware.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Veoh Networks\Veoh\VeohClient.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\cidaemon.exe c:\program files\common files\aol\1125001301\ee\aexplore.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\HJT\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimtoday.aim.com/today/aimtoday.adp R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage/ R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {B339E38A-22DD-4425-92C2-3C15F9643F4B} - C:\WINDOWS\system32\vtutu.dll (file missing) O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll (file missing) O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125001301\ee\AOLSoftware.exe O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 4.0\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 4.0\aoltb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {00001024-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter24 Class) - http://download.netmarble.com/web/nmstarter/NMStarter24.cab O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.3.102.cab O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab O16 - DPF: {89981B1D-07DA-43C3-9770-06C51E7E5DCE} (NostaleWebStarter Control) - http://game.nostale.com/sso/NostaleWebLauncher.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netmarble.com/kdefence/kdfense8237.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab O16 - DPF: {F7899FAE-51C9-4EF5-B98C-A64997635235} (GSPRunGame Class) - http://www.playinfinity.net/cab/WindyGSPAx.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exewhats the software name? have you tried in safe mode?? get Ccleaner and run the cleaner then go to tools on the left hand side. and see if you can uninstall it from there. If not then report back with any error messages. if you can then run the issues scan also on the left side above tools, save when prompted to and make SURE you save somewhere where you will remember. the issues scan a couple of times to make sure your registery is cleaned up good. also what protection programs are you usingScan with HijackThis and check the following entries... O2 - BHO: (no name) - {B339E38A-22DD-4425-92C2-3C15F9643F4B} - C:\WINDOWS\system32\vtutu.dll (file missing) O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab Close all other windows and click on Fix Checked. You've had a past Vundo infection, so you may want to follow the below instructions, just to be on the safe side... 1. Download VundoFix and save it to your desktop. 2. Run VundoFix and click on Scan For Vundo. 3. Once it's done SCANNING, click on Remove Vundo. 4. When it prompts you to remove the files, click on Yes. 5. Your desktop will go blank as it's removing files. Don't worry, this is normal. 6. It will prompt you to restart your computer, so click OK. 7. When your computer is turned back on, your problem should be gone. 8. The program normally produces a Vundofix.txt file. Please locate this file and paste the contents in your next post. And then, just to be thorough... 1. Download VirtumundoBeGone and save it to your desktop. 2. Reboot into Safe Mode. 3. Once you are in Safe Mode, run VirtumundoBeGone and follow the instructions. 4. Exit when it has finished and reboot back into normal mode. 5. The program normally produces a VBG.txt file. Please locate this file and paste the contents in your next post. Also...I see that your Java is out of date. You'll want to correct this quickly, as it will help provide further protection for you. To do so, go here and click on Free Java Download. You will be given instructions on what to do next. You should update your AVG and scan with it in Safe Mode. Do that and follow unlovedwarrior's instructions and let us know how everything's running.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3587. |
Solve : found some virus on my computer, help? |
|
Answer» Hi, I just ran a hijack VIRUS scan on my computer and found some virus. I am clueless as to how to remove them. Can someone PLEASEEEEEEEE help me. I definitely need a knight in shining armor for this one . Thanks a mil. Download, install & update...Did you install SP1? You HijackThis log still shows you as not having any Service Packs installed. It also still shows a Vundo infection. If VundoFix isn't catching it, then you should try ComboFix... Download ComboFix and save it to your desktop. Run the program and read its disclaimer (it's fairly short) and make sure you really pay attention to what it says. Follow the prompts and when finished, it will produce a log at C:\ComboFix.txt. Go ahead and post that here. Note: Don't click on the window while it's running; this may cause stalls. Also, it is very very important that you have SP1 installed! Without it, you'll be terribly vulnerable to more infections.Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3588. |
Solve : Something weird really ,? |
|
Answer» Uhm well I got this message, and i dont KNOW what the *censored* to do.. please help me :> |
|
| 3589. |
Solve : internet exeplorer keeps poping up? |
|
Answer» ok this happens when im ONLINE and sometime offline my pc which is a sony OS windows Xp home edition serviuce pack 2........ |
|
| 3590. |
Solve : Outlook Express - can't open any links? |
|
Answer» When I receive an email I can't open links. Ex: Kohl's sends an ad and says "start shopping" and I click and go no where. |
|
| 3591. |
Solve : Help I downloaded and now have problems? |
|
Answer» Please help I downloaded defender pro on my computer and nothing but problems so I uninstalled and reinstalled norton. I currently have norton antivirus only!!! And I searched through the forums and found some free SPYWARE and such but when I scan my computer it says that it fixed 5 of my 441 errors please help !!!!!And I forgot to say that my computer is running really slow and it keeps freezing up on me . I was wondering if there is SOMTHING else I am to do after I deleated it?Time for a MAJOR cleanup. See here... Thank-you for your help I downloaded AVG but I went to spybot and downloaded it ..." Did you download AVG anti-virus, or spybot, or both.... or what? Your statement is unclear. Dusty said, " .... install AVG Free anti-virus ..." Quote and it said I have 1024 bugs and pay his amount I went to it straight from your link??? I thought it was free Please help am I doing somthing wrong? Did you go to this page? : http://free.grisoft.com/doc/1 Look for where it says, "Anti Virus" and "Free of charge" I hope that helps. I can assure you that Spybot is free, here are the links to the usual cleaning tools. CLEANUP Ccleaner (During install, uncheck the Yahoo Toolbar option) (After install, SET Options>Advanced> 'Uncheck the 48 hour box') ANTI SPYWARE Adaware Spybot S&D ANTI VIRUS AVG Free (After install, set Options to 'scan all files') ANTI TROJAN Ewido for W2K & XPDue to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3592. |
Solve : Will this help someone help me?? |
|
Answer» I hope someone can read this and help me out because i dont know what i'm doing. |
|
| 3593. |
Solve : MatCash F? |
|
Answer» I have a Virus on a different computer that's named Matcash F., should i use HIJACKTHIS to get rid of it? I'm using Microsoft win xp sp2.DLoad and run Stinger in safemode with System Restore turned off... |
|
| 3594. |
Solve : Virtual Memory Minimum is low? |
|
Answer» By the way, you should get yourself a firewall. You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.Hi CBMatt |
|
| 3595. |
Solve : Symantec Antivirus 10? |
|
Answer» Hi there, I'd install the Symantec Antivirus 10 Corporate Edition on a computer that runs Windows XP, but I have some clue about it, because it has been INSTALLED the SQL Server database manager, and I don't know why, because the old VERSION doesn't install it. Please help me with this because it makes that the cumputer turns slowly. |
|
| 3596. |
Solve : i dont know what it is...? |
|
Answer» almost three months past, my old HD say goodbye to me (got damaged and did not leave anything to me) Your infection looks pretty bad. I'm not sure how much we can do for you as far as cleaning it goes. You should update your protection and scan with it in Safe Mode (not Normal Mode). THANK you very much for your reply here. First thing first i can put here almost what you ask by tomorow (coz im at work and no internet in my home) some i can answer: windows.1 im not sure when this folder birth in my c drive Windows- i have this folder in my c drive OS- only one, its Xp SP2 i will follow all your instruction then i will post tomorow thanks again...I had this same problem a long time ago. the way i fixed it i had to reformat my computer. You can always do that but as you said you dont wana loose everything :SI don't want to have to resort to a reformat just yet, but it may come down to it. When you try the above and post back with your results, I'll take a look, but be prepared to backup your data.also can you do the hijackthis in normal mode after scans?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3597. |
Solve : clicked random .cn php link? |
|
Answer» Sorry for not showing this forum thread an eye for the last couple of days I had a holiday, well the AVG scan in safe mode found no threats so I guess I am clear |
|
| 3598. |
Solve : Explorer being assaulted by trojan? |
|
Answer» His virus's consumed him ...... and soon the WORLD..... |
|
| 3599. |
Solve : malware scans did not find much about "Assert Failed"? |
|
Answer» I got the "ASSERT FAILED" and ddcmigrate.exe Application Error - these two alerts come up as SOON as the boot completes. I click OK a couple times and they GO away... |
|
| 3600. |
Solve : removing virus as power user? |
|
Answer» Dell Dimension 2400 desktop |
|