InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 4551. |
Solve : Virtumonde is taking over!!!!!! HELP!!!!!!? |
|
Answer» So here is whats going on. I scaned my computer with Spy sweeper, Ad-Aware, Spybot S&D and even Norton Anti-Virus. All of them detect it but cant seem to remove it. Even though it says that it got removed from my computer. All the pop-ups that are caused by it are overwhelming and my computer is practically unusable..............What should I do??? |
|
| 4552. |
Solve : Quaxo has been hijacked.? |
|
Answer» Quaxo done f'ed up. Someone (a trusted person)...Attached were two pictures...I went to open oneYou'll never do it again, won't you? Two main reasons: 1. Even, if a sender appear to be your FRIEND, it's not necessary the case. Bad guys have a lot of ways to fake email addresses. 2. Even, if a sender IS your friend, he/she may be infected, and don't know about it. Said that... ALWAYS scan any attachment with your AV program BEFORE opening it. I'll check now, what you have there.You have Trojan-Spy.Agent.204 Also, you need to update your Java. Your version is one notch old. Uninstall any older version through Add\Remove. You're using beta version of HJT. In your next post, use current version: http://www.snapfiles.com/get/hijackthis.html 1. Print this post out, since you won't have an access to it, at some point. 2. Close all windows, except for HijackThis. 3. Put a checkmark next to the following HijackThis entries: - O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) - O4 - HKUS\S-1-5-19\..\Run: [msnsc] C:\WINDOWS\system32\msnsc.exe (User 'LOCAL SERVICE') 4. Click on "Fix checked" button. 5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts) 6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders". 7. Delete following files/folders (if present): - msnsc.exe from C:\WINDOWS\system32 8. Turn off System Restore: - Windows XP: 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore". 5. Click Apply. 6. When TURNING off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. - Windows Vista: 1. Click Start. 2. Right-click the Computer icon, and then click Properties. 3. Click on System Protection under the Tasks COLUMN on the left side 4. Click on Continue on the "User Account Control" window that pops up 5. Under the System Protection tab, find Available Disks 6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:") 7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this. 8. Click OK 9. Restart in Normal Mode. 10. Turn System Restore on. 11. Run HijackThis again, and post back its log back here.Well, I knew she was sending them to me. Hotmail sees the attached pictures as just that, pictures. Something piggybacked the download though when I went to open one though. It's weird and hard to explain exactly what happened. Depending on what AVG finds tonight and how hard it is to remove, I might actually record a video (I have a screen to video capture program) of what it's doing just so I can stop the video and see exactly what all it does and what it downloaded.I doubt it was piggybacked....jpg's and other photo formats can easily be manipulated to carrry a malicious payload these days.I installed that Java update at one point, but after I did, Java stopped working properly so I went back down. Might of just been a bad update, I'll try again. Thanks for the help Broni. I've got to get some sleep now, but I'll carry on with this first chance I get tomorrow.Non-beta version log attached (prior to cleaning). Starting with your instructions now, will post back after I've finished. [file cleanup - saving space - attachment deleted by admin]All instructions followed. Post-cleaning HJT log attached. [file cleanup - saving space - attachment deleted by admin]Nice, and clean. How is your home page?Firefox is still nice and clean, never got changed from about:blank After resetting IE's homepage to about:blank, it hasn't been changed again. Thanks for the help, mate. I really appreciate it. They really should require more virus knowledge on the CompTIA A+ Certification. It's mostly Windows, Windows errors, and hardware... not much about what to do when you get screwed with a virus.Good, good. I guess, you had just small treat. |
|
| 4553. |
Solve : I have viruses and dont know what to do?? |
|
Answer» with regards to the regseeker back up the box was not checked so therefore it did not make backups of the stuff i deleted (silly me) |
|
| 4554. |
Solve : rediculously slow PC? |
|
Answer» Hi... |
|
| 4555. |
Solve : Please help!??? |
|
Answer» I have tried and tried to delete a program called SPYWARE TERMINATOR,unsuccessfully...I have tried evry method i can think of,including downloading a program,going into EXPLORE and trying to remove the folder,KEEPS saying is protected or is being used???..I am left to believe that this fing program is spyware itself! I think that depends on what Spyware Terminator it is Correct. Spyware Terminator used to be considered a rouge application as they were partnered with crawler inc. They have since cleaned up their act and have taken steps to correct the past. But this doesn't mean that the download was from a legit source (there is a free and paid version) which could explain the problems. You need to run the removal steps and post the logs so we can see what is wrong.Quote there is a free and paid versionWhere is the paid version? It is just the corporate version that is paid. My fault.... I haven't kept up with the saga in a while but there is a conversation with the PRODUCT manager of Spyware Terminator and the owner of MGs HERE that gives a good insight as to what the program is all about. And the different versions. Thanks.Thanks to everyone who REPLIED .I followed your advice and was able to remove the junk from my pc! Thanks a million!Thanx for the Update Deerpark and evilfantasy. patio. |
|
| 4556. |
Solve : Its Back.? |
|
Answer» Open Windows Explorer. Does this sound like I am "out of the woods"?It looks like. Sometimes, we forget to check very simple, and basic thing, like home page address. I'm glad, it worked Quote By the way Broni, would it be coincidence that both this problem + the Trojan dilemma would happen at virtually the same time? Or could the virus somehow have been attached to the Brit URL?It's hard to say. I checked that site, and it's LEGIT, and clean, but with bad guys, you never know what ways they use to get to your computer. I wish, more problems had such a simple solutions...LOL |
|
| 4557. |
Solve : Stealth Virus?? |
|
Answer» The BBC has put out a warning about a stealth Virus (See link below) Will scanning with AVG ANTI Rootkill find this virus? (As well as using AVG Anti virus) I don't have a problem with it at the moment, but if infection can be avoided I would prefer that! Computers running Windows XP, Windows Vista, Windows Server 2003 and Windows 2000 that are not fully patched are all vulnerable to the virus.That vulnerability was taken CARE of with SP2 for XP and SP4 for Win2K. Their info is also slightly incorrect IDENTIFYING it as an MBR virus....it is a rootkit but not an MBR virus.Thank you for that info. ONE less thing to be concerned about! |
|
| 4558. |
Solve : SQL Slammer virus? |
|
Answer» Yes, I have McAfee firewall and yes my Windows XP firewall is off.I need new HJT log.Here's the new HJT log: I got a pop-up which gave a choice of "yes" and "no". I clicked on "yes" which was fix or remove what was checked. I hope that was correct.You did fine. Quote There were a bunch of folders: WINDOWS, iPOD, WINAMP, etc. and some other individual files, but I did not see ANY individual .exe files.That's fine. It looks like HJT took care of it. Anyway, your HJT log is clean. Any other problems?I'm glad HJT is clean. I'll let you know if the SQL Slammer message from my firewall returns. Thanks for your help. Quote my firewall gave me another SQL Slammer attack messageMost likely, your firewall just informed you, that it prevented some attack. If so, there is nothing to worry about. So I got another pop-up saying SQL SLammer tried to infiltrate. When it does that, I click on "block" on my firewall dialog box. I thought this pop-up meant my machine was INFECTED. Maybe it's not. I guess my question is: why, after having my computer for several years, would I suddenly start getting these SQL Slammer messages from my firewall? Isn't the whole point of a firewall to block all the stuff out there trying to get in? In which case: why don't I get pop-ups from all kinds of stuff all the time trying to get into my computer? Only the SQL Slammer shows up OK. Let's put it to rest. Quote I thought this pop-up meant my machine was infected.No, your firewall just informed you of a TRY. If you're about to infected, your AVG would kick in, and tell you. Personally, I have those warning messages turned off, because it's a waste of time. |
|
| 4559. |
Solve : AD-Aware SE updates? |
|
Answer» Hello Forum. Every time I run Ad-Aware SE free edition I get a message TELLING me that my definitions are old. Today it said 16 days old. Do you want to update now? I say yes , it connects and it says there are no updates to download. I faithfully updated them every Monday. But now, everytime I go to update they say there are no updates. Should I remove the program and then reinstall or is it true that there are no updated definitions right now. I have WIN XP , IE 6.0, lots of disk space. Everything else is updated. AVG etc. I tried Spybot but it doesn't PERFORM as well as Ad-Aware. Is anyone else having this problem with Ad-Aware SE? Any help would be appreciated. ThanksThe SE version is being phased out this month and will no longer have updates...travel to their SITE and DLoad and install the new Free Edition. is it always better to have both?Yes. Often, one will pick up stuff, missed by the other. |
|
| 4560. |
Solve : hi_jack_this_log? |
|
Answer» here is the log file for dr.web and a new hjt log.
Let me know how everything is now.Hi, everything looks pretty good from where i'm sitting. I know it took a while to find a solution, and again, I thank you for your help. you are the best. If I need your assistance in the future, would it be ok if i emailed you or should i look for you on "the computer forums.com"? Have a GREAT evening!! Solotekk
Closing steps....... Please download OTMoveIt2 by OldTimer 1. Double click OTMoveIt2.exe to launch it. 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)[/list] When finished exit out of OTMoveIt2
Let us know if anything else comes up. I will. Thanks a million. keep kewl...... |
|
| 4561. |
Solve : Ad-aware and avira anti-virus? |
|
Answer» Hey All, No virus found in this incoming message. www.free.grisoft.comWillyW, Thanks for the info even though I'm a bit LATE! The working of the Ad-aware and Avira anti-virus wasn't the problem, they both do still work, but the sites now provide NO support, updates. I switched over to AVFree for anti-virus and Sypbot SEARCH and destroy. They are both support updating for Win98se and seem to work.Some of us are just not sure about the next step like to win2000 which I use at work and like, just cann't afford to take the home computer to the next step. Thanks again!!!!! greg Quote from: gehammack on January 28, 2008, 01:31:47 PM WillyW, Yep. That's why I included the stamp from an email - to show that AVG is up-to-date supported. Quote I switched over to AVFree for anti-virus and Sypbot search and destroy. They are both support updating for Win98se and seem to work.Some of us are just not sure about the next step like to win2000 which I use at work and like, just cann't afford to take the home computer to the next step. You're welcome. I too would like to be able to do some other things computer and software wise - but, until it is affordable, we do with what we have. |
|
| 4562. |
Solve : buying spyware protection? |
|
Answer» hello, I was wondering if anyone COULD recomened a good anti spyware program with good real time protection. Its hard to trust sites with reviews, they all seem to be selling it as well. Save your hard-earned, see here. |
|
| 4563. |
Solve : drwtsn32.exe What is it really.? |
|
Answer» I tried to do my own reading and learning and there is enough SITES that have endorsements both negative and positive. |
|
| 4564. |
Solve : Odd virus? Spyware? I dont know what this is!?!?? |
|
Answer» Ok, when I go to search in Google, you know that "list" of previous searches that pop up? Sometimes I have spam in there! And its always horrible and perverted things. They look like random keywords. Just out of curiosity, are you talking about windows Auto complete?Either what solotekk suggested or. Look at the search settings and turn off suggested searches. (I think that is what it's called) |
|
| 4565. |
Solve : hggff.exe problem? |
|
Answer» Maybe you ran a SCAN, but you didn't save it to a new log. After you click on "Scan" button, scan runs, and when it's done, "Scan " button changes to "Save log" button, which you have to click in order to save new log. |
|
| 4566. |
Solve : Problem with Windows UpDates and Norton Anti Virus 2007, help? |
|
Answer» I have WINDOWS Xp and use Norton Anti Virus 2007. When I turn OFF the Automatic Updates for Windows XP, my NAV alerts me that to use NAV updates, I must TURN ON Windows back to automatically receive Windows Updates. Why would NAV have and CONTROL over Windows XP Updates?NAV, LIKE any anti-virus, locates security RISKS. If your not UPDATING Windows, you could be missing out on some important fixes and updates. Therefore it is telling you to fix the problem. Atleast, that what I think. |
|
| 4567. |
Solve : Need new computer security, help.......? |
|
Answer» I just bought a NEW Dell computer a few months back which came with 90 days of free Norton security, on our last computer we had McAfee. My 90 days are just about up and I'm not SURE if I should just renew with Norton or install the new McAfee. Would anyone know if there is a big diffrance in protection between these two, or if one is better than the other? |
|
| 4568. |
Solve : accidentaly delete usefull registry file? |
|
Answer» dear all members...sorry if my english very poor...i have a problem with my office laptop.. last week i had clean my laptop who infected with w32.rajump.. i had scan and clean the virus with regrun ( reanimator) program.. but after all viruses had been delete from my system...i still have a big new problem..in the below is the kind of problem that i had : 1) i cannot enable my system restore because the system restore tab is missing 2) no start menu at my desktop 3) i cannot copy or paste any file i think all that happen is because i had accidently delete usefull registry file that infected with the rajump virus...so what can i do now...please help me...i don't want to format my laptop.. i hope...all of you can help me to solve my problem...thanksYou may try to access System Restore from command line. Open Task Manager (CTRL+ALT+DEL), click on New task, type in: %systemroot%\system32\restore\rstrui.exe Click OK.Quote from: Broni on January 08, 2008, 09:07:45 PM You may try to access System Restore from command line.i had done this...the error is appear....."system restore is not able to protect your computer.Please restart your computer, and then run system restore again"... i had restart my system and the same message appear again..why ??Open Task Manager (CTRL+ALT+DEL), click on New task, type in: services.msc Scroll down to System Restore If its STATUS is Stopped, RIGHT click on it, and click Start Right click again, click Properties, and pick AUTOMATICALLY from drop-down menu.Quote from: Broni on January 08, 2008, 09:50:18 PM Open Task Manager (CTRL+ALT+DEL), click on New task, type in: the startup type is already automatic. i also cannot view properties from this page. still cannot solve the problemQuote i had scan and clean the virus with regrun ( reanimator) program..See, this is the problem with some unknown programs. Often, they mess things up even more... Do you have Windows CD, or Recovery CD?Quote from: Broni on January 08, 2008, 11:26:41 PM Quotei had scan and clean the virus with regrun ( reanimator) program..See, this is the problem with some unknown programs. Often, they mess things up even more... i have windows cd...but this laptop need recovery cd..i did'nt have it...laptop model is hp COMPAQ nx6330. system winXp service pack 2.Quote i have windows cd...but this laptop need recovery cdI don't understand.Quote from: khairul on January 08, 2008, 11:46:36 PM i have windows cd...but this laptop need recovery cd..i did'nt have it...laptop model is hp compaq nx6330. system winXp service pack 2. Even if HP tells you to use the recovery CD, you still don't need to use it. I USED the normal Windows XP CD-ROM, and I didn't have problems. HP telling you to use the recovery CD? Scratch that, the botched application will probably mess up your computer anyway. And if it does, HP won't help you.ok fren...thanx for ur info...but it still problem.....which is? |
|
| 4569. |
Solve : Question w/ New Please read this before requesting help.? |
|
Answer» EF. I am about to coach another newbie throught your process, I see its been updayed. |
|
| 4570. |
Solve : MRU's (Maxinum Receive Unit)? |
|
Answer» Should I be concerned with these? I really don't understand what they are, and do they affect your computer to which I should obtain some sort of protection?Quote MRU lists contain information such as the names and/or locations of the last files you have accessed. They are located ALL OVER your registry, and for almost ANY FILE type. By looking at these MRU lists, someone could determine what files you opened/saved/looked at, what their file names were, and MUCH more! (And, in many cases, the lists are displayed in drop-down menus automatically.) Javacools MRU BlasterAnother note. Using CCleaner will get most if not all of the MRUs. You can use MRU blaster after CCleaner for a second "opinion", but I don't think MRU blaster has been updated in a while so I would have more faith in CCleaner. Yep CCleaner is great option for getting rid of your MRUs. Here's a download link and a setup guide. Just FYI... Maximum Receive Unit is something else entirely and not something you need to worry about. The ACRONYM you're worried about is Most Recently Used.Nice catch, Deerpark Thanks EVERYONE, very helpful. |
|
| 4571. |
Solve : Broni, when you get a chance...? |
|
Answer» I'm online with an old friend. She doesn't speak English, so I'm posting for her. I'm online with an old friend.Is she as good looking, as your girlfriend?....LOL I'll take a look.There are quiet a few things there. Couple of questions, though.... I can't see any firewall running. Is she using Windows firewall? Is True Internet Co., Ltd. her ISP? Now... 1. Run free ESET Online Scanner at: http://www.eset.com/onlinescan/ Note: This Scanner is for Internet Explorer Only 1. You will notice that the "Start" button is grayed out. Place a check mark at "Yes, I accept the Terms of use". The "Start" button will become visible. Click on it. 2. If it wants to install an ActiveX component allow it 3. You will be asked to install an ActiveX, click the "Install" button (Note: If you have a Firewall install you may have to approve the installation) 4. Once ActiveX control is installed click on the "Start" button to initialize the scanner 5. After initialization is complete uncheck\untick "Remove found threats" 6. Check\tick "Scan unwanted applications" 7. Click the "Scan" button 8. Once the scan is done, you will find a log in C:\Program Files\esetonlinescanner\log.txt Post ESET's log. 2. Download SUPERAntiSpyware Free for Home Users: http://www.superantispyware.com/ Print these instructions out. * Double-click SUPERAntiSpyware.exe and use the default settings for installation. * An icon will be created on your desktop. Double-click that icon to launch the program. * If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: http://www.superantispyware.com/definitions.html.) * Close SUPERAntiSpyware. Restart computer in Safe Mode. To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; pick Safe Mode; you'll see "Safe Mode" in all four corners of your screen * Open SUPERAntiSpyware. * Under "Configuration and Preferences", click the Preferences button. * Click the Scanning Control tab. * Under Scanner Options make sure the following are checked (leave all others unchecked): o Close browsers before scanning. o Scan for tracking cookies. o Terminate memory threats before quarantining. * Click the "Close" button to leave the control center screen. * Back on the main screen, under "Scan for Harmful Software" click Scan your computer. * On the left, make sure you check C:\Fixed Drive. * On the right, under "Complete Scan", choose Perform Complete Scan. * Click "Next" to start the scan. Please be patient while it scans your computer. * After the scan is complete, a Scan Summary box will appear with POTENTIALLY harmful items that were detected. Click "OK". * Make sure everything has a checkmark next to it and click "Next". * A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu. * If asked if you want to reboot, click "Yes". * To retrieve the removal information after reboot, launch SUPERAntispyware again. o Click Preferences, then click the Statistics/Logs tab. o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. o If there are several logs, click the current dated log and press VIEW log. A text file will open in your default text editor. o Please copy and paste the Scan Log results in your next reply with a new HijackThis log. * Click Close to exit the program. Post SUPERAntiSpyware log. 3. Post new HijackThis log.Actually, until about an hour ago she wasn't running anything, not even virus protection which is how she ended up like this in the first place. True is her internet company, yes. Same as mine. Oh, just for you, Broni haha WOW! I feel like flying, already....LOL Get her Comodo, before you do anything else, because we may be fixing things over, and over.Actually, she IS single Willl do about ComodoQuote Actually, she IS singleIt sounds promising...heheheHey Broni, she's having trouble getting through the instructions. Not sure why. She's bringing it by the shop tomorrow, I'm gonna fix it myself.I wish, I was closer to HELP her....hehehehaha Well, it's here now. Two viruses infecting 6 files. She has what she needs off of it, so she just wants me to wipe it and reinstall. I guess that's what I'll do.Reinstalled everything. Up and running clean. Thanks for the help.Nice Bird... Quote Nice Bird...You dirty, old MAN....LOLYeah, I was just thinking 'which bird?' hahaha |
|
| 4572. |
Solve : Wierd Half Virus? |
|
Answer» Hi, I have Windows XP Pro SP2 with all updates applied. |
|
| 4573. |
Solve : SPYWARE QUESTIONS...? |
|
Answer» This chart is interesting. This chart is interesting. Consider the source...every co. out there has their own set of charts.VERY good point. lol, You just made me feel like a n00b. This is likely much more accurate. Independent comparatives. http://www.av-comparatives.org/Not my intent by any means EF... I'll dig out my link to one of the best comparitive sources after i go have a Guinness... Seeya in a few.Quote Not my intent by any means EF... No worries, we all need wake UPS now and then. I had one or two other good independent comparatives links but have misplace or am just not seeing them. (I really need to organize my bookmarks once again) sweet!! hey...i have a QUESTION but don't know if it's VIRUS related...it has to do with user ACCOUNTS and the msgina.dll file not allowing me to change how users log on and off. May i send you the print screen at your gmail acct? solotekkSure, go for it.thx.. Gotta wrap them in {img} {/img} tags. Make the {} this [] ok...let's see if i can do this |
|
| 4574. |
Solve : I did the HJT a few months ago and everything was great but? |
|
Answer» R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ How often should I run the cleaner?Once a month should be OK, but in your case....put those *censored* itchy finger into some ice before installing some crap again....LOL Now...I propose, you start new topic about your separate problem. It'll bring more people attention.okey dokey oh computer guru!!! LOL!!!Not yet. I need some more posts to become "guru".....LOL |
|
| 4575. |
Solve : Two icons on the Desktop (Windows Update, Help and Support Center)? |
|
Answer» There are these two icons on the desktop (namely, Windows Update and, Help and Support Center). I can't delete them. And when I deleted the two icons, they never appeared again.It doesn't matter, because, you have serious Vundo infection (plus COUPLE more things), so you better follow my instructions.Okaay... Done. [file cleanup - saving space - attachment deleted by admin]It looks MUCH better. Run HJT again. Checkmark following entries: - O2 - BHO: {8d45c8d0-bd61-c87a-f9a4-05cc3e512e02} - {20e215e3-cc50-4a9f-a78c-16db0d8c54d8} - C:\WINDOWS\system32\ichqovkb.dll (file missing) - O20 - Winlogon Notify: winuns32 - winuns32.dll (file missing) Click "Fix checked" button. Restart computer. Post new HJT log.Okay. Sorry for the laaaate reply... The internet here died. (Darn wi-fi antenna). Anyway... Log attatched. [file cleanup - saving space - attachment deleted by admin]You're clean. Happy computing |
|
| 4576. |
Solve : malware help plz? |
|
Answer» i have malware on my computer i keep poping up advertisment is the anyway to stop |
|
| 4577. |
Solve : Not sure what I have or how to remove it.? |
|
Answer» Hello everyone! Im new to the forum but read the faq and have the attached logs as needed. Im getting an error message everytime i open a program that the image file for the program is missing. I also am noticing a very slow system. I know its a terrible description of what is happening but its really All I know as of this point. Thanks for the Help in Advance - JT everytime i open a program that the image file for the program is missingPlease post exact error message. Now... Print out these instructions as we will need to close every window that is open later in the fix. Download VundoFix: http://www.atribune.org/content/view/24/2/ * Double-click VundoFix.exe to run it. * When VundoFix re-opens, click the Scan for Vundo button. * Once it's done scanning, click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, your desktop will go blank as it starts removing Vundo. * When completed, it will prompt that it will reboot your computer, click OK. Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot. After reboot.... 1. Download VirtumundoBegone (http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe) and save it to your desktop. 2. Now reboot into Safe Mode. 1. This can be done tapping the F8 key as soon as you start your computer 2. You will be brought to a menu where you can choose to boot into safe mode. 3. Select safe mode with networking using your arrow keys on the keyboard and then press enter. 4. When you computer reaches the desktop make sure you log in as the same user which you had performed the previous steps, 3. Once you are logged into safe mode, double-click VirtumundoBeGone.exe file you just downloaded and follow the instructions. 4. Exit when it has finished, and reboot back to normal mode. Let me know, if any of the above programs found anything. Post new HijackThis log.Error Messge is as Follows: "The Application or DLL C:\WINDOWS\system32\sol323.txt is not a valid Windows image. Please check this against your installation dikette."Just this particular file looks suspicious, and that's why I asked you to run two other programs. Don't forget to update your Java.Great, will do but have to wait until I get to the office in order to print and do it properly. Ill repost when I'm done Thanks - JTCool...NEITHER Program found anything. Ill attach log as soon as its done Thanks - JThere is log - JT [file cleanup - saving space - attachment deleted by admin]1. Print this post out, since you won't have an access to it, at some point. 2. Close all windows, except for HijackThis. 3. Put a checkmark next to the following HijackThis entries: - O20 - AppInit_DLLs: C:\WINDOWS\system32\sol323.txt - O20 - Winlogon Notify: awtqq - C:\WINDOWS\system32\awtqq.dll (file missing) - O20 - Winlogon Notify: awvts - C:\WINDOWS\system32\awvts.dll (file missing) 4. Click on "Fix checked" button. 5. Restart your computer in Safe Mode (keep tapping F8 key, when your computer starts) 6. Open Windows Explorer. Go Tools>Folder Options>View tab, put a checkmark next to "Show hidden files, and folders". 7. Delete following files/folders (if present): - sol323.txt file from C:\WINDOWS\system32 8. Turn off System Restore: - Windows XP: 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore". 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. - Windows Vista: 1. Click Start. 2. Right-click the Computer icon, and then click Properties. 3. Click on System Protection under the Tasks column on the left side 4. Click on Continue on the "User Account Control" window that pops up 5. Under the System Protection tab, find Available Disks 6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:") 7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this. 8. Click OK 9. Restart in Normal Mode. 10. Turn System Restore on. 11. Run HijackThis again, and post back its log back here.Ok all those steps are done, I dont seem to be getting the error now here is log - JT [file cleanup - saving space - attachment deleted by admin]The log is clean. I'm glad, the error is gone. I recommend... 1. Download, and install CCleaner: http://www.ccleaner.com/ 2. Read CCleaner instruction from here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleanerGreat Broni Thank you so much im downloading CC now - JTCool |
|
| 4578. |
Solve : using 2 antivirus softwares? |
|
Answer» guys, my friend said that, i can use 2 antivirus in my desktop to be sure that i am secure from viruses. at first, i guess he got a point there but i am not sure if his advice is recommended or not? |
|
| 4579. |
Solve : anti-virus software wont turn on...? |
|
Answer» I'm running Windows Vista and neither my CA antivirus software nor my SpySweeper software will turn on or allow me to do a sweep. I was using an internet based scanner to scan my system but then my computer froze and after about 5 MINUTES and a couple of CTRL ALT DEL's later I got back to the login screen with a message that said security error and again my comp was frozen. Any help would be GREATLY appreciated. Oh and one more thing... I'm not sure if this could be related, but after browsing my file I found a suspiscious folder labled Acceleration Software that seems to contain a bunch of random files and some mock anti-virus software. I tried to delete it but was told I needed permission... So I tried to change the permissions and told I wasn't able to... So I tried to change the owner and was once again, you guessed it, wasn't able to... HELP ME!!!Go here and read post 1 and do the steps in post 2. MSXML Parser Do you have administrative rights on the computer or is it a limited account? I don't see any malware in the log but there is an entry to fix with HJT. Open HijackThis and select Do a system scan only. Place a check mark next to the FOLLOWING entries: O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-3/ZwinkyInitialSetup1 .0.1.0.cab Close all windows except for HijackThis and click Fix checked. Exit Hijackthis. --------------- When running antispyware/antivirus programs or updates on Vista you have to run it as an Administrator. Right-click the program icon or file that you want to open, and then click Run as administrator. Click here >> More Information on Administrator Accounts Let me know if this helps.It's an administrative log on so I assume I should have all the rights to run whatever I want, but it's very possible that I could be wrong. I do have another question though, Could the Trojan that Dr. Webb found and apparently removed be causing my anti-virus software not to turn on?Could the Trojan that Dr. Webb found and apparently removed be causing my anti-virus software not to turn on? Possible but I don't think so. Have you tried to update the programs by right clicking them and selecting Run As Administrator? I would like to run another scan to DETERMINE where we are at. It will take a while to run so please be patient. Run CCleaner before you start it. Use the Kaspersky Online Scanner
a) Run or b) Complete the scan? I fixed the link for Kaspersky, sorry about that.No I haven't tried it safe mode, but i will after I run the scanner you suggested in the previous post...I tried to post the Kasperky Report but it won't let me because it's too long... It didn't find anything, but it skipped quite a few files because they were "locked"... If you want the report we'll have to find a different way for you to get it... And do you think I should still run the scans in safe mode and if so which scans should be ran? |
|
| 4580. |
Solve : Best Firewall Protection?? |
|
Answer» Dzien dobry Broni, |
|
| 4581. |
Solve : Newer versions of Norton? |
|
Answer» I have a question about Norton Antivirus. I am currently USING the 2005 version of the software. Would it be wise to UPGRADE to the 2008 one now, or is it unneccessary? Can 2005 be used for a couple more years yet, or will there SOON be a time when it is unusable? |
|
| 4582. |
Solve : ESET Online scan; Update error (108)? |
|
Answer» Hello again, |
|
| 4583. |
Solve : Hacktool.Rootkit Strikes Back? |
|
Answer» It sounds like the updates did their job. you recommending me to reformat my thumb drive just to get rid of the dummy Autorun.inf folder? No, it sounded as if you didn't want to use the flash disinfector. So I mentioned that a reformat would be the next alternative. Without doing one or the other you will be infecting everything you plug it in to. Maybe I misunderstood what you had said. Welcome back ...and welcome to you, evilfantasy, since you're online now I want to use Flash_Disinfector if it protects my thumb drive and pc's from being really infected, and as I understand it's the job that the program is doing, am I right and is there any more details that I can get of it?You can Google Flash Disinfector, but the information I gave in the instructions is probably more then you will easily find in a search. Most of the time the directions are for a link to download it and to plug it in when prompted. The author of the tool sUBs is one of the most respected members of the malware fighting community. He doesn't release much information on his tools. If he did then the bad guys would quickly figure out a way to exploit their use in removal and they would not be as effective. Do you know what these are? That One.exe xstart.exe RealClip.exe If so then the logs look fine. Although the 1.99 version of HijackThis is the old version and the use of the new 2.02 version are suggested. Both machines Java is out of date. Your Java is out of date leaving your system vulnerable. Older versions of Java have vulnerabilities that malware can use to infect your system. Go to >> http://java.sun.com/javase/downloads/index.jsp On the Sun Java page scroll to the 4th download Java Runtime Environment (JRE) 6 Update 4 to install the new version. Next go to add/remove programs and remove all older versions. Then go to C:\Program Files\Java and delete the old folders. Be sure to keep jre1.6.0_04 Cleanup:
then hit Enter. [/LIST]The above procedure will:
This is a good time to clear your infected system restore points and establish a new clean restore point:
Let us know how everything went. Thanks, again, evilfantasy. That One.exe is a code name for Hijack This (said that before: someone tipped that rootkits may hide themselves from HJT and suggested renaming it; and I'm considering dowloading a fresh copy of it); xstart looks familiar but forgot what it was (I think it was a system tray manager, it's uninstalled, but the registry value seems still hiding so I've manually deleted it using Regseeker and everything went just fine); and RealClip is a clipboard enhancer that works for me. I've done all fixes suggested by you, and it all went as planned, and here's the HJT reports. [file cleanup - saving space - attachment deleted by admin]Everything looks fine now. This is a good time to clear your infected system restore points and establish a new clean restore point:
Here are some great tools to help you keep from getting infected again. Spybot Search & Destroy - A safe and effective spyware scanner. * Official Spybot Tutorial * Spybot FAQ AVG Anti-Spyware Free EDITION - Very reliable with a high detection rate. * AVG Anti-Spyware User Manual SpywareBlaster - SECURE your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also STOP certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * SpywareBlaster Tutorial Comodo BOClean - Stops trojans and many more malicious attacks. Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. * Click here for a list of free firewalls. * Why would I consider a third party firewall? UPDATE UPDATE UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. * Help with Windows updates Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Let us know if anything else comes up. |
|
| 4584. |
Solve : Comodo 3 Basic Setup Issues? |
|
Answer» Interesting reading...In all farness...His ReplyOK you GUY's, I hope you have this all settled. I try my best to learn about you alls advise and put it to use. No, there is only one version of CFP and that is the free version. The issue here is how you choose to install it. During the install you have to choose between Advanced Firewall and Basic Firewall. If you choose the advanced firewall you get the whole protection package, if you choose basic firewall you get just that... a basic firewall. Even if you have installed CFP in basic firewall mode you can still activate the advanced part later on by enabling Defense+. |
|
| 4585. |
Solve : Please Help: Can't Shake The Vundo!!? |
|
Answer» ComboFix 08-01-17.3 - Louie 2008-01-17 0:02:42.2 - NTFSx86
Next post Dr. Web CureIt logProcess.exe;C:\Documents and Settings\Louie\Desktop\SmitfraudFix;Tool.Prockill;; restart.exe;C:\Documents and Settings\Louie\Desktop\SmitfraudFix;Tool.ShutDown.11;; iTunesHelper.exe.vir;C:\QooBox\Quarantine\C\Program Files\iTunes;Trojan.MulDrop.10006;Deleted.; jusched.exe.vir;C:\QooBox\Quarantine\C\Program Files\Java\jre1.6.0_03\bin;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; qttask .exe.vir;C:\QooBox\Quarantine\C\Program Files\QuickTime;Trojan.MulDrop.10006;Deleted.; backup-20080115-172114-558-PowerReg Scheduler V3 .exe.vir;C:\QooBox\Quarantine\C\Program Files\Trend Micro\HijackThis\backups;Trojan.MulDrop.10006;Deleted.; backup-20080115-172114-736-PowerReg Scheduler V3 .exe.vir;C:\QooBox\Quarantine\C\Program Files\Trend Micro\HijackThis\backups;Trojan.MulDrop.10006;Deleted.; backup-20080115-172114-921-PowerReg Scheduler V3 .exe.vir;C:\QooBox\Quarantine\C\Program Files\Trend Micro\HijackThis\backups;Trojan.MulDrop.10006;Deleted.; hggff.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Trojan.MulDrop.10006;Deleted.; instsrv.exe.vir;C:\QooBox\Quarantine\C\WINDOWS\system32;Tool.SrvRunner;; Process.exe;C:\SDFix\apps;Tool.Prockill;; A0000006.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP1;Trojan.MulDrop.10006;Deleted.; A0000007.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP1;Trojan.MulDrop.10006;Deleted.; A0000008.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP1;Trojan.MulDrop.10006;Deleted.; A0000018.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP2;Trojan.MulDrop.10006;Deleted.; A0000019.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP2;Trojan.MulDrop.10006;Deleted.; A0000020.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP2;Trojan.MulDrop.10006;Deleted.; A0000024.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000026.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000027.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000028.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000029.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000030.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000031.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000032.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000033.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000034.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000035.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000036.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000037.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000038.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000039.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Trojan.MulDrop.10006;Deleted.; A0000040.exe;C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP3;Tool.SrvRunner;; Process.exe;C:\WINDOWS\system32;Tool.Prockill;; I think you are in the clear. Please download ATF Cleaner by Atribune. ATF Cleaner.exe Make sure that all browser windows are closed.
Post a new Hijackthis log Let me know how everything is now.I think we did it! Startup was amazingly fast. hggff.exe is no longer there after reboot. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:47:54 PM, on 1/17/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\S24EvMon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\System32\QCONSVC.EXE C:\WINDOWS\System32\RegSrvc.exe C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\TpKmpSVC.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\TpShocks.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\WINDOWS\MXOALDR.EXE C:\WINDOWS\system32\RunDll32.exe C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\Program Files\Swarmcast\swarmcast.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://local.swarmcast.net:8001/proxy.pac O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [TP4EX] tp4ex.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe O4 - HKLM\..\Run: [UpdateManager] "c:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: Epson printer Registration.lnk = D:\Drivers\E_reg\EPSONREG.EXE O4 - Startup: swarmcast.lnk = C:\Program Files\Swarmcast\SwarmcastLauncher.exe O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O11 - Options group: [JAVA_IBM] Java (IBM) O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) CORPORATION - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing) O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe -- End of file - 8280 bytes Final steps. Time to do some cleanup and secure the work you have done.
Here are some great tools to help you keep from getting infected again. Spybot Search & Destroy - A SAFE and effective spyware scanner. * Official Spybot Tutorial * Spybot FAQ AVG Anti-Spyware Free Edition - Very reliable with a high detection rate. * AVG Anti-Spyware User Manual SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * SpywareBlaster Tutorial Comodo BOClean - Stops trojans and many more malicious attacks. Use a Firewall - It can not be stressed enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. * Click here for a list of free firewalls. * Why would I consider a third party firewall? UPDATE UPDATE UPDATE!!! - If you do not have automatic updates enabled then visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. * Help with Windows updates Learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Let us know if anything else comes up.Almost forgot. Check out this tutorial to install the Recovery Console http://www.bleepingcomputer.com/tutorials/tutorial117.html |
|
| 4586. |
Solve : Issues updating the Trend Micro Scan? |
|
Answer» I receive an error message when trying to Update the Anti VIRUS "Unable to connect to server. There may be a problem with the server or Network." |
|
| 4587. |
Solve : Windows System Folders like ProgramFiles and MyDocuments are duplicated? |
|
Answer» Windows System Folders like ProgramFiles and MyDocuments are duplicated in the same location.. Please help to fix this! |
|
| 4588. |
Solve : CCleaner New? |
|
Answer» The latest build of CCLEANER has been released...available Here... I spotted it on another Forum...CCleaner has yet to inform me of an update. Same here, my usual rounds........I need something to take up more of my time... I'm starting to think the last girlfriend wasn't so bad after all... But she was a redhead and we all know how challenging that is...Ahh but the benefits of overcoming the CHALLENGES with redheads..................Quote I'm starting to think the last girlfriend wasn't so bad after all...quaxo has really pretty one for you... |
|
| 4589. |
Solve : How we can remove worm virus?? |
|
Answer» I have a windows XP OS. |
|
| 4590. |
Solve : C:Windows\system32\mljgg.exe? |
|
Answer» HI i just got rid of a load of virus's and now when I start my PC this message keeps appearing saying that this FILE is missing. C:Windows\system32\mljgg.exe I tried to do a SEARCH for it in the REGISTRY but no luck any suggestions. I am a novice where this type of stuff is concerned so would appreciate the help.Quote Hi i just got rid of a load of virus's But not all of them. Read post 1 and 2 in this thread Post the logs so we can get rid of the rest of it. |
|
| 4591. |
Solve : .tmp files in my c drive (and other problems)..? |
|
Answer» mysteriously, like 5 bazillion .tmp files appeared in my C Drive (like directly in it) - and also in my Documents folder. |
|
| 4592. |
Solve : Anywhere to get Norton antivirus cheap?? |
|
Answer» We gave our SON a laptop for Christmas and it came with a 30 day subscription to Norton Antivirus. The copy I have of Norton does not run on his laptop. Does anyone know where I can get a free/cheap copy of Norton? Forget about Norton and try AVG instead. |
|
| 4593. |
Solve : where can i get antivirus/spyware updates?? |
|
Answer» im USING zonealarm internet SECURITY SUITE 7. i WANT to download latest antivirus/spyware updates...where could i get it??Zonealarm should do this automatically. I don't BELIEVE Check Point provides updates you can download manually. |
|
| 4594. |
Solve : Fake Rootkit Tool? |
|
Answer» Quote A URL link to a Trojan posing as a copy of the Trend MICRO RootkitBuster is CURRENTLY being spammed in the wild. Full Story Kudos to QMan.Thanks Patio and QMan, I will be passing this one along.You're Welcome...the screenshot is identical to TrendMicro and most would be fooled by this. These crooks will stoop to anything it SEEMS... |
|
| 4595. |
Solve : Unable to upload/attach files? |
|
Answer» Quote Now if only you'll do my Visual Basic homework for me...Are you a female?...... ......Just KIDDING...LOLSo is everything in order now? Can you UPLOAD again? If you haven't already done so, you should download a copy of AVG free for virus protection.Yeah, everything is A-OK now, and my homework is in one time! I'll download the AVG, too. Thanks again for all the help!Wait a second. Aren't you using MCAFEE Security Center, which includes antivirus?It was one of those free 1-year installations that came with the computer, but I didn't pay to renew it.Then, you need to uninstall it. Ues removal tool: http://service.mcafee.com/FAQDocument.aspx?id=107083&lc=4105 rather, then Add\Remove. After that... 1. Download, and install CCleaner: http://www.ccleaner.com/download/builds. GET "Slim" version. 2. Read CCleaner instruction here: http://www.jahewi.nl/ccleaner/ccleaner.html, and run CCleaner Finally, post new HijackThis log for us to see what leftovers you have. |
|
| 4596. |
Solve : Weird virus with no name in local settings/temp? |
|
Answer» I did a system RESTORE to DECEMBER 17th and can now install CCLEANER. I'm gonna run it nowCool. Since you rolled back, don't forget about Windows updates.Yep, ALREADY installed them. Thanks. |
|
| 4597. |
Solve : windows_installer? |
|
Answer» i just started RECEIVING multiple pop up windows from windows installer. I am using internet explorer 7. Windows installer 3.1 re-dist. is installed as well. I CHECKED in Services and confirmed that windows installer service is started. |
|
| 4598. |
Solve : Runscanner findings...? |
|
Answer» Yes, please.Logfile of Trend Micro HijackThis v2.0.2 |
|
| 4599. |
Solve : Spanish Speaking Voice From Speakers? |
|
Answer» About 3 months ago I was GETTING noises from my speakers like knocking at a door or a creaking or slamming door. The noises were very random and did not occur all the time. More anoying than anything. More recently I get a voice that sounds like SPANISH. Can't really identify what it is saying, but it is a brief phrase. I also can't link it to any particular OPERATION. I opened the control panels to turn off the sounds and the arrow on the screen started flashing on and off and another noise that sounded like somekind of vibration or alien death ray occured for about 10 seconds or so and then stopped. I was able to turn off all the sounds, but the voice was still present. However, when I rebooted this morning neither the voice nor any other sound has reoccured. I'm hoping that solved the problem, but it seems more likely that something is lurking on the hard drive that I just can't identify. Has anyone had a similar experience that can be of assistance?I'm thinking you have some malware that's causing it, because I've had that same kind of thing happen and once I ran several different TOOLS to clean up my computer, the weird sounds went away. Try running CCleaner. You can FIND out about it here: http://www.ccleaner.com/features |
|
| 4600. |
Solve : Real Player pain!? |
|
Answer» Since updating Real Player yesterday, Online Armor FIREWALL keeps warning me each time I open up Firefox that a dangerous program, Realplayer.exe is trying to run. I have scanned with AVG anti virus, AVG anti spyware, AVG anti rootkill, A-Squared, RemoveIt. Nothing found and I think the problem is with OA. I have marked Realplayer as "Trusted" in the program list. But still I get the warning box come up. Is there an ALTERNATIVE to Real Player that would not cause this problem, or is there something else I can do? Is there an alternative to Real Player I dont know if Real Alternative is what you would want. Real Alternative http://filehippo.com/download_real_alternative/ I use Media Monkey http://www.mediamonkey.com/ WinAmp www.winamp.com is also very good.Remove Real Player from your startup folder...it doesn't need to be there anyways... Also dis-able auto-updates in Real Player which is also useless. EF's alternative is a NICE suggestion.Thanks. I have uninstalled Real Player and downloaded and installed Real Alternative to give it a try. Just opened up Firefox and no warning!Real Player is a Real SOB, rather. |
|