

InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
4651. |
Solve : Computer Running Slow/Infected?? |
Answer» Hi, |
|
4652. |
Solve : ADW_MARKETSCO.D? |
Answer» I have had this on my computer for a couple of months and can't get rid of it. It is QUARANTINED through Trendmicro with ACCESS denied, but everytime I scan or use the INTERNET it pops up. You posted in a wrong section, so repost at "Computer Viruses and Spyware" forum, but before you do so, download HijackThis: http://majorgeeks.com/Trend_Micro_HijackThis_d5554.html |
|
4653. |
Solve : I Need help with something easy...Grey Box in on desktop? |
Answer» I need help with a small problem... I have a random grey box that takes up the center of the desktop...I dont know how to fix this but it COVERS up the center of the wallpaper and it won't go away...any help would be great...Can you post a SCREENSHOT? |
|
4654. |
Solve : New at this, have virus I think? |
Answer» Computer keeps shuting down. Can be on a program & it keeps turning off & restarting by itself. Tried system suite 6 & it just shut off, did not good. What are your suggestions?What is "system suite 6"? What is "system suite 6"? Take a look at their website: http://www.v-com.com/product/SystemSuite_Home.html I've never heard of this program before.assuming you are using windows XP or Vista, I will recommend you do system restore. If you can boot into windows and use computer before shut down/restart PROBLEM happens, then do system restore in windows. Otherwise, go into safe mode and do system restore there. If system restore fixes problem, then you are set. If system restore is useless, then you got a problem. For antivirus, I recommend you use avast or avg if you want a free program that does just basic antivirus detection and updates. Or you can get yourself a paid subscription SERVICE like norton or kaspersky or SOMETHING trendmicro.Quote from: Broni on November 06, 2007, 04:42:52 PM What is "system suite 6"? System Suite 6 is suppose to be a anti virus, PC recovery, spyware removal& maintenance program from Walmart. It Has norton( last yrs.version), don't know what kind of firewall, but it does have one. Windows XP. Won't stay open enough to get much information for you, but I appreciate your time in helping me.Quote Won't stay open enough to get much information for youI'm SORRY to hear that. Will your computer stay up in Safe Mode (restart, and keep tapping F8 KEY)? |
|
4655. |
Solve : kernel change? |
Answer» dell DIMENSION 4600; 2.8 cpu, 2.5 gb ram, 80 gb drive, windows xp home version 2002-service pack 2 avg 7.5, avg anti-rootkit, spybot-search&destroy, lavasoft-ad-aware 2007, comodo firewall pro, comodo boclean, clamwin antiivirus, ccleaner when i run a avg scan i get this message at the top of the page; under file- kernel32.dill; under result/infection- change; under path- c:\windows\system.32\kernel32.dill and yet, avg said no threats found. avg is a free program and has no support help. i have tried to find out through avg forums just what is meant by; " kernet32.dill change c:\windows\system.32\kernel32.dill" but no LUCK. i am not having any problems that i know of. i have run/ran all of the above programs and all seems to be ok. but if anybody can tell me what the message means i sure would be thankful. tazpaigeIf all other AV programs detect nothing, then it is most likely a false positive.Don't worry, AVG is simply notifying you of a change in the file. This is normal. I get the same thing when I scan too.I disagree... AVG Free has TONS of support including the Forums...your issue is mentioned there quite frequently. It is a harmless system change and happens every TIME you scan. How much time did you spend at the Forums ? ? |
|
4656. |
Solve : Best of the Best of the Best.....lol? |
Answer» I am looking for the best FREE antivirus PROGRAM i can GET....i just got my computer running again (thanks to This site...Broni Mainly) and i need protection....any recommendations would be greatly appreciated. |
|
4657. |
Solve : Security toolbar 7.0 pop up, malware pop ups and online security center? |
Answer» I have windows xp, zone alarm firewall Spybot search and destroy AVGfree antivirus Spycatcher Spyblaster AVG Anti-spyware 7.5 Hijackthis Rogueremover and something called spynomore I've ran everything and still I am getting pop ups like my computer is infected, please download these great programs.. I say no all the time but continue to get pop ups it has slowed my computer down tremendously Here is the Hijack file Logfile of HijackThis v1.99.1 Scan saved at 8:00:45 PM, on 11/6/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\PROGRAM Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\wuauclt.exe C:\DOCUME~1\Raynelle\LOCALS~1\Temp\20071159532_mcinfo.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\SpyCatcher\Protector.exe C:\Program Files\SpyCatcher\Scheduler daemon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Corel\Corel Paint Shop Pro Photo XI\Corel Paint Shop Pro Photo.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Program Files\Download Direct\DLD.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Pando Networks\Pando\pando.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Raynelle\LOCALS~1\Temp\Rar$EX01.192\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\jpizpxhc.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe" O4 - HKLM\..\Run: [a8a5bd45] rundll32.exe "C:\WINDOWS\system32\triawdss.dll",b O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Raynelle\LOCALS~1\Temp\20071159532_mcinfo.exe /insfin O4 - HKLM\..\Run: [SpyCatcher Reminder] C:\Program Files\SpyCatcher\SpyCatcher.exe reminder O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Startup: Scheduler.lnk = C:\Program Files\SpyCatcher\Scheduler daemon.exe O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher\Protector.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - AppInit_DLLs: secuload.dll,wbsys.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe I'll take a look..Download VundoFix: http://www.atribune.org/content/view/24/2/ * Double-click VundoFix.exe to run it. * When VundoFix re-opens, click the Scan for Vundo button. * Once it's done scanning, click the Remove Vundo button. * You will receive a prompt asking if you want to remove the files, click YES * Once you click yes, your desktop will go blank as it starts removing Vundo. * When completed, it will prompt that it will reboot your computer, click OK. Note: It is possible that VundoFix encountered a file it COULD not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot. POST new HJT log.I did the vundofix and also did superantispyware.. and got rid of all the other spyware things except for Spybot S&D. now the only THING that shows up is the icons on the desktop that say Online security guide and live safety here is the HJT file Logfile of HijackThis v1.99.1 Scan saved at 11:19:39 PM, on 11/6/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\DOCUME~1\Raynelle\LOCALS~1\Temp\20071159532_mcinfo.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Apoint\Apntex.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\analyzeThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing) O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {9B5DD2A2-F390-4C04-853D-6678B55DCADC} - C:\WINDOWS\system32\vtsrs.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [a8a5bd45] rundll32.exe "C:\WINDOWS\system32\triawdss.dll",b O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Raynelle\LOCALS~1\Temp\20071159532_mcinfo.exe /insfin O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe" O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: urqnljh - urqnljh.dll (file missing) O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe Good... Let me see...In your previous log, you had this: O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\jpizpxhc.dll which was causing your pop-ups. It's gone. Now, we have to do some HJT cleanup... ... 1. Print this post out, since you won't have an access to it, at some point. 2. Download, and install Spybot (if you don't have it) from here: http://www.safer-networking.org/en/download/index.html 3. Close all windows, except for HJT. 4. Put a checkmark next to following HJT entries: - O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing) - O2 - BHO: (no name) - {9B5DD2A2-F390-4C04-853D-6678B55DCADC} - C:\WINDOWS\system32\vtsrs.dll (file missing) - O4 - HKLM\..\Run: [a8a5bd45] rundll32.exe "C:\WINDOWS\system32\triawdss.dll",b - O4 - HKLM\..\Run: [msci] C:\DOCUME~1\Raynelle\LOCALS~1\Temp\20071159532_mcinfo.exe /insfin - O4 - HKLM\..\Run: [winshow] "C:\WINDOWS\winshow.exe" - O20 - Winlogon Notify: urqnljh - urqnljh.dll (file missing) 5. Click on "Fix It" button. 6. Restart your computer in Safe Mode (F8) 7. Run Spybot (click on updates, first), and fix WHATEVER it asks you to fix. 8. Open Windows Explorer. Go Tools>Folder Options, put a checkmark next to "Show hidden files, and folders". 9. Delete following files (if they still exist): - SpyCatcher folder from C:\Program Files\ 10. Turn off System Restore. 11. Restart in Normal Mode. 12. Turn System Restore on. 13. Run HJT again, and post back its log back here.Logfile of HijackThis v1.99.1 Scan saved at 12:17:15 AM, on 11/7/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\Program Files\analyzeThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Digital Line Detect.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe I have a question on the one in red.. Do I need to delete this also?Congratulations Your HJT log is perfectly clean ...and NO, to answer your question. MSOXMLMF.DLL is legit M$ Office file: http://support.microsoft.com/dllhelp/?dlltype=file&l=55&alpha=MSOXMLMF.DLL&S=1&x=16&y=9 How are your computer issues, now?they are nonexistent lol.. Thanks for the help!!!I'm glad to hear it You're welcome. |
|
4658. |
Solve : AVG Anti-Virus keeps saying kernel32.dll has "changed" on each XP start-up.? |
Answer» HI folks, I have AVG anti-virus (http://free.grisoft.com/) and when it does its daily scheduled SCAN (which is normally when when I turn the PC on for the first time that day) it always says that kernel32.dll has "changed". It doesn't say it's infected or damaged or anything, just that it's changed. Is this an issue? Thanks in advance for your help, my system SPECS are: asus a8n-e athlon64 3500+ venice 1gb ram geforce 7800gt oc windows xp home Nevermind, apparently it's ok.That's normal with AVG. Probably an update either from MS or AVG itself. Antivirus doesn't KNOW the difference between good and bad changes so sometimes you get things like that. It is just doing what it is supposed to and alerting you to a change. Hope this helps.It will do this EVERY time it scans...it's normal and not an issue. |
|
4659. |
Solve : Vundo Problem? |
Answer» I just downloaded it from a very same source, and it worked. It took some 30 sec with "Combofix is preparing to run" screen, before disclaimer window opened.Ok so I deleted my prior version and downloaded it again. When I click run on Combofix the same thing happens. I get a "C:\ . " command prompt box. I did get a short flash of the C:\ box being paused. No disclaimer shows, not even after 5 minutes. Yes I thought it was strange that Combofix didn't work either...But whenever I've seen it used on other posts, someone is instructing a person to create a text file and drag it into Combofix. That is part of combofix, but not the part we needed. Lets do this please How To Create An Uninstall List 1. Start HijackThis 2. Click on the Misc Tools button 3. Click on the Open Uninstall Manager button. 4. Click on the Save list button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. 5. Save it to your desktop. 6. Add the uninstall_list.txt in the next post. Ok I was able to delete everything manually from that online scan. Here's the results from Hijack This. Everything looks benign to me. Ad-Aware SE Personal Adobe Acrobat - Reader 6.0.2 Update Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Flash Player 9 ActiveX Adobe Reader 6.0.1 Alt-Tab Task Switcher Powertoy for Windows XP Apple Mobile Device Support ArcSoft Software Suite Audible Download Manager Broadcom Management Programs Dell Digital Jukebox Driver Dell Media Experience Dell Solution Center Dell Support 5.0.0 (766) DivX Web Player EPSON Copy Utility EPSON EIC CX5400 EPSON Photo Print EPSON Printer Software EPSON Scan EPSON Smart Panel ESET Online Scanner GTA2 HijackThis 1.99.1 Image Resizer Powertoy for Windows XP Intel(R) 537EP V9x DF PCI Modem Intel(R) Extreme Graphics Driver Internet Explorer Default Page Internet Explorer Q903235 iPod for Windows 2006-01-10 iPod mini 1.0 for Windows User Guide iPod mini Software Updater 1.0 iPod Updater 2004-11-15 iTunes Jasc Paint Shop Photo Album Java 2 Runtime Environment, SE v1.4.2 Logitech Camera Driver Logitech QuickCam Software MathPlayer McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft Data Access Components KB870669 Microsoft Encarta Encyclopedia Standard 2004 Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office XP Small Business Microsoft Picture It! Express 9 Microsoft Picture It! Library 9 Microsoft Windows Journal Viewer Modem Event Monitor Modem Helper Modem On Hold Mozilla Firefox (2.0.0.9) MSN MSN Encarta Plus Support Files MSNFans Live Winks 1.0 MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) QuickTime Registry Mechanic 5.2 Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893066) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Shockwave Skype 2.5 Sonic DLA Spybot - Search & Destroy 1.4 Spyware Doctor 3.8 Symantec Technical Support Web Controls Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Verizon Online Control Pad Viewpoint Manager (Remove Only) Viewpoint Media Player Windows Backup Utility Windows Defender Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Format Runtime Windows Media Player 9 Hotfix [See KB885492 for more information] Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WinRAR archiver WordPerfect Office 11 Workrave 1.8.3 You didn't post HJT log itself.Viewpoint products are known to cause problems. 1) Press ctrl-alt-delete (all at once) to open Task Manager. 2) Click on the Processes tab and search for VIEWMGR.EXE, if its found, click on it and then click End Task to CLOSE it 3) Click on Start, Control Panel, Add/Remove Programs 4) Uninstall all of the following programs associated with Viewpoint Viewpoint Manager (Remove Only) Viewpoint Media Player 5) Close the Add/Remove Programs and Control Panel 6) Restart your computer == Then post a fresh HijackThis log Tell us how things are now.Also, you have Symantec Technical Support Web Controls Uninstall this also. I would the recommend running the Norton Removal Tool to ensure all Symantec products are gone.It never hurts to be thorough Logfile of HijackThis v1.99.1 Scan saved at 7:52:09 PM, on 11/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\wdfmgr.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\System32\hkcmd.exe C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Program Files\Logitech\Video\CameraAssistant.exe C:\WINDOWS\system32\ElkCtrl.exe C:\WINDOWS\system32\taskswitch.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Dell\Media Experience\PCMService.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\msiexec.exe C:\Documents and Settings\Mik\Desktop\AntiVirus Folder\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" O4 - HKLM\..\Run: [EPSON Stylus CX5400] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2G1.EXE /P19 "EPSON Stylus CX5400" /O6 "USB001" /M "Stylus CX5400" O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe Thanks again The log does not show any malware. Are you still having any problems? Go to add/remove programs and uninstall Quote Java 2 Runtime Environment, SE v1.4.2Reboot the computer and then navigate to www.java.com and download the latest version of Java JRE 6 update 3 Outdated VERSIONS of Java are entry points for malware. Let us know how things are now. I checked the McAfee detection log, and I haven't had a vundo notice since I uninstalled the icons that were left on my desktop/favorites. False alarm, but maybe good to know that Vundofix and Vundobegone do not remove the desktop icons. I'm glad you mentioned the Java. I saw that on other sites. I'll fix it. The last part that was puzzling me was this error message that I get when I go from normal to safe mode: "An access error was returned while attempting to change a service. You may need to log in using an administrator account to make the specified changes." The puzzling part is that I'm always in the admin account (although after this I'm going to start using a guest account w/out admin priviledges). I have XP... some sites say it's a XP bug, and others say I need to REINSTALL windows. It seems like it's just a notification, and I can still switch from normal to safe mode effectively. I'm just worried b/c on Wikipedia, Vundo is said to modify winlogon..... If you consider it a risk, let me know. Otherwise I'll close out this log w/ a clean computer. THANKS!!!!!! Quote An access error was returned while attempting to change a service Mine does the same thing when going to safe mode from msconfig. No worries. Check out this article from Tony Klein for continued safety: So how did I get infected in the first place? Safe surfing! |
|
4660. |
Solve : How To run a log? |
Answer» I KNOW I've done it before a long time ago,but I can't remember how. an someone tell me how to run a LOG on my computer? Thanks.I know, that you're asking about HJT log. |
|
4661. |
Solve : Virtumonde win32 sneaky ****? |
Answer» Ok, I've been BATTLING this virus for a couple weeks now. 1. Check the box next to YES, I accept the Terms of Use.It's definitely not a false positive. I have downloaded s&d and adaware from lavasoft and they have both flagged multiple copies of randomly named dll's all existing in the system32 path. The program that is downloading virtumonde after my "successful" removal is the win32.conhook.trojan. I succesfully removed both of these with both s&d and adaware, after this I went to the pandasoftware website to make sure I got rid of all traces of these two, but while the scan was taking place nod32 popped up again to tell me 4 new copies of the dll's had been created in the same system32 folder. Here are some of the files that were flagged: C:\WINDOWS\system32\awtqnkh.dll C:\WINDOWS\system32\awtuvuv.dll C:\WINDOWS\system32\jkkkhgd.dll C:\WINDOWS\system32\khffcbx.dll C:\WINDOWS\system32\mljgfdd.dll C:\WINDOWS\system32\silkyeqk.exe C:\WINDOWS\system32\tzlfe.exe C:\WINDOWS\system32\wvusrqo.dll C:\WINDOWS\system32\wvuvvwx.dll This virus is driving me crazy!!! 1. Download VirtumundoBegone : http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe 2. Now reboot into Safe Mode. 1. This can be done tapping the F8 key as soon as you start your computer 2. You will be BROUGHT to a menu where you can choose to boot into safe mode. 3. Select safe mode with networking using your arrow keys on the keyboard and then press enter. 4. When you computer reaches the desktop make sure you log in as the same user which you had performed the previous STEPS, 3. Once you are logged into safe mode, double-click VirtumundoBeGone.exe file you just downloaded and follow the instructions. 4. Exit when it has finished, and reboot back to normal mode. Awesome! That process worked a treat, thank you VERY MUCH!! :D:D:DI'm glad, it did |
|
4662. |
Solve : The virus won't delete!!? |
Answer» I have 2 infected files that i can try to delete. The first will delete, but as soon as the SECOND one is deleted, they come back!! what do i do? the last thing I want to do is download something else without knowing exactly what it isYes hijackthis contains trojans , worms , and a whole lot of addware . www.google.com - all you had to do was ask google , and not make yourself out to be a complete twat by saying that . Quote from: TonyRichens on December 02, 2007, 09:10:46 PM Yes hijackthis contains trojans , worms , and a whole lot of addware . That's a little inappropriate and uncalled for. Please refrain from saying such things in the future. We're here to help people, not make them feel bad about what they know or don't know about computers.Tony...c'mmon...quaxo is right. PM him, if you don't like him. Not here, in the open. |
|
4663. |
Solve : can someone check this hijack this log plz?? |
Answer» I'm having some trouble with ie: wondering if its a virus etc hope you can help me! so: heres my hijack this log This command will immediately initiate the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem. You may need the Windows disk to complete the process. http://www.updatexp.com/scannow-sfc.htmltried it- looked good for a few mins but the error came up again... Have you tried re-installing IE6 or upgrading to IE7 ? ? Do you have any of the .NET frameworks installed ? ? They will be listed in Add/Remove.Did you try to delete IE temp files through Windows Explorer: C:\Documents and Settings\username\Local Settings\Temporary Internet Files Sorry for my link. It was actually intended for Win 95 |
|
4664. |
Solve : How do I configure AVG to just scan my C drive only?? |
Answer» I know I can I do "Scan Selected Drives" for a manual scan but for the AUTOMATIC scans I've been trying to figure out how to set it to just scan my C drive only and then I would scan all the drives once a month.The free version is limited on the scheduled scan settings. |
|
4665. |
Solve : Virus "See who Blocked or Deleted you on MSN? |
Answer» HI there We have done everything recommended and still appear to have the issue. Can someone please look at this logfile and advise us what to do next. No that is only one step. There are three logs that are requested to be added as attachments. I tried to add them as attachments, they wouldnt post because they are in notebook format....Then they just need to be changed to Text (.TXT) format. Go to Start > Run > type Notepad.exe and press Enter Copy them from wherever you have them and paste to notepad and SAVE the notepad file to the desktop. Then you can add them as attachments. |
|
4666. |
Solve : Cannot open files directly.....? |
Answer» Hi I am running on Win XP with AVG Antispyware and WINDOWS Defender protecting.... |
|
4667. |
Solve : Is this a virus or trojan?? |
Answer» I noticed a few days ago that my Norton's ANTIVIRUS icon had disappeared from the notification area of the task bar. I tried restarting it from the Start menu but it wouldn't run. |
|
4668. |
Solve : Help needed immediately!!? |
Answer» ALRIGHT so yesterday I was enjoying my desktop PC and then I WENT to work this morning when I got up It has a message on the screen saying " Disk Read Error push Crtl+Alt+Del to restart". I don't know what the crap happened it was working last night with no problems can anyone shed some light on the subject?I hope, some Mod will move this to appropriate forum... Anyway... Quote I got up It has a message on the screen saying " Disk Read Error push Crtl+Alt+Del to restart"...and??? Your computer INFO needed.Its a P4 1.6ghz 128mb ram 120gb hard driveQuote I got up It has a message on the screen saying " Disk Read Error push Crtl+Alt+Del to restart"Kenter, Which operating system Me, XP, Vista ? Have you left disk in machine from previous night? Might be trying to read on bootup. CHECK and remove if you have. |
|
4669. |
Solve : Browser hijack, restrictions applied, possibly because a website I visited? |
Answer» Hi,
Then use this one and post the log from it. Trend Micro Housecall Scan for Firefox 1. Click Scan Now. It's Free 2. Read and put a Check next to Yes, I accept the Terms of Use 3. Then click Launch HouseCall Wait for the Java-Based Housecall Kernel Test 4. Click Starting Housecall and wait for the updates to finish. 5. Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button. * It will download the latest scan engine and pattern files. When the definitions have been downloaded, the scan will start. * Please wait while HouseCall scans your system… * Once the scan is complete, it will take you to the summary page. 6. Under Cleanup options choose Clean all detected infections automatically 7. Click the Clean now>> button. 8. When presented with a notification According to your instructions, all detected infections were cleaned..., click OK * The Housecall log is saved to C:\Documents and Settings\UserName\.housecall6.6\log Add the log as an attachment in the post along with the SUPERAntiSpyware log and the new HijackThis log. These are the sort of scans that really use up my ISP's data allowance. I noticed that the modem lights where blinking wildly. I hope you don't get mad because I asked this, but since most sites are compatible with Opera, WOULD it be OK if I just keep using Opera? I don't use IE anymore. In fact, I've being planning to uninstall IE.If you are having problems with the online scans do to your ISP then you can hold off on it. In fact it is better that we know you have download limits and such so we can try to work AROUND that. But the SUPERAntiSpyware scan should not have that problem. Have you gotten that log?Sorry, I forgot about that. Next reply will have a SUPERAntispyware log if I can find it.* To retrieve the removal information please do the following: + After reboot, double-click the SUPERAntiSpyware icon on your desktop. + Click Preferences. Click the Statistics/Logs tab. + Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. + It will open in your default text editor (such as Notepad/Wordpad). + Save the notepad file to your desktop by CLICKING (in notepad) "File" "Save As" * Save the log somewhere you can easily find it. (NORMALLY the desktop) * Click close and close again to exit the program. * Please add the log as an attachment along with a new HijackThis log in the next post.Here are the SUPERAntispyware and HijackThis log files. [saving space - attachment deleted by admin]Open HijackThis and place a check mark next to R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Serial99.com Close all windows and click Fix checked. Are you still having any problems?No problems. Thanks!! Won't download any keygens/warez again. |
|
4670. |
Solve : “Brave Sentry – BS 2.0” Windows XP Professional? |
Answer» Currently I am experiencing a problem with a Dell Insprion 600M laptop, operating system Windows XP Professional. The problem began yesterday evening during which my desktop background became black and stated, “Your computer is in Danger. Windows Security center has detected spyway/adware infection! It is strongly recommended to use special antispyware tool to prevent data loss.” Seconds later a balloon appeared in the lower left hand corner, which stated, “Your computer is infected. Windows has detected spyware infection. It is strongly recommended to use special antispyware tool to prevent data loss. Windows will now download and install the most up-to-date antispyware for you. Click here to protect your computer from spyware.” After which a box appeared “Brave Sentry – BS 2.0” and began scanning my computer for potential damages, listing different malwares (Trojan X Download, Win Desktop, Hotbar toolbar, Keenvalue/Perfect NAV, Internexus Dialer, Gatordone, etc.) and the threats (severe, high, etc.) they posed. Not ever encountering this problem I let the program run. After the program detected about 27 possible threats the scan stopped and the “remove threat” button appeared. In clicking on the “remove threat” button, another box appeared titled “BS Evaluation Version Warning” underneath the title there was a brief paragraph, which stated “This version of BS is for evaluation purposes only. The REMOVAL feature is disabled. You may scan your PC to locate malware threats. To be able to remove threats found you should purchase a license.” Under the paragraph were two buttons the first being “purchase licenses” and the second being “continue evaluating.” Below the two buttons there was a sentence that read “BS activation, if you have already purchased a licenses please enter the activation code below.” Underneath the statement the third button being “Activate BS Now!” Since this issue began, I am unable to connect to the Internet even when the computer is directly plugged into the MODEM and/or the wireless router is used. The computer however, detects the wireless router, which it states is giving off a strong signal. Lastly, there is another box which appears and is titled “Warning!” with the sentence “Get free *censored* now!” along with two buttons “OK” and “Cancel.” If at all possible, I would greatly appreciate someone assisting me with this problem. Welcome aboard Thank you very much for assistance, I really appreciate it. I just seem to have one tiny problem and that is I can not get on the internet from my dell laptop. Since this issue began, I am unable to connect to the Internet even when the computer is directly plugged into the modem and/or the wireless router is used. The computer however, detects the wireless router, which it states is giving off a strong signal. The laptop only has internet explorer on it and everytime I click the desktop icon a blank page comes up and states it can not find the server. I am just not sure what to do from here I understood the directions you send regarding the malware, I am just not sure how to download that link when using an iBook and not the computer that is having the problem. I hope you can help me with this and once again I thank you for your help.That file to download is only little bit over 1MB, so you can put it on floppy, and transfer it to your XP computer.I just download the file that you suggested onto my MAC ibook when trying to run the program to fully install it and download onto a cd to transfer it to the PC however, when trying to run the program it opens up my itunes for some odd reason and then I can not find it in my itunes. I also tried to insert the cd-r to the iBook and manually move the icon off the program to the cd-r to burn the cd which work. However, when I placed the cd-r into the PC directions in French appeared and translated to roughly the program is missing files do you want to continue to install. In hitting yes, there was another box that came up and where cancel appeared (in French) and closed (in French) as the two options. Trying both of them nothing happened. Are there any other ways to fix this problem?Quote when trying to run the program to fully install itThis is Windows program, you can't run it on mac. Just burn that file to CD. That's it.I downloaded the program you suggester placed it on a cd-r inserted the cd-r with the program into the other laptop (PC) and there is an alert that comes up in French stating that there is a problem with the program it is missing files and when you continue with the installation it shuts you out. Is there any thing else I can do I tried installing the program onto 4 different cd-r's and still nothing. Considering the spyware that is in the computer ... is that the problem with why the internet is not working from the PC Laptop???Quote Considering the spyware that is in the computer ... is that the problem with why the internet is not working from the PC LaptopVery possible. Try to restart your laptop in Safe Mode, and see if you can install/run from there.I ran/downloaded the program into the PC laptop in safemode. It was success through all the steps except for a few. However, a red Norton AntiVirus box appeared titled, Alert: Malicious Script Detected and below it stated Object: FileSystem Object Activity: Create TextFile, Your computer is halted and needs to do something about this script File: C:\WINDOWS\SYSTEM32\GETVALUE.vbs, What do you want to do? and just below there is a drop down box with these following options 1. Stop this script (recommended), 2. Allow this activity once, 3. Allow the entire script once, 4. Quarantine this script, 5. Authorize this script. Then there is an option button stating okay. I tried to allow the entire script option and as well as the allow this activity once and another Norton AntiVirus box came up titled Alert: Malicious Script Detected and below it stated Object: FileSystem Object Activity: Create TextFile, Your computer is halted and needs to do something about this script File: C:\Documents and Settings\logan pepchinski\SmitfraudFix\ScanDNS.vbs then when I chose the same option again the desk cleaning comes up ... cleans then the Registry cleaning prompt comes up where I enter Y (yes) and enter. After which a rapport - Notepad appears as well as another box which is Titled Desktop, Windows is running in safe mode. This special diagnostic mode of Windows enables you to fix a probelm which may be caused by your network or hardware settings. Make sure these settings are correct in Control Panel, and then try starting Windows again. While in safe mode, some of your devices may not be available. To proceed to work in safe mode, click yes. If you prefer to use System Restore to restore your computer to a previous state, click not. Then there are the two buttons below with yes and no. In clicking yes nothing happens afterwards there is no box counting down or any of the other things. Also, while waiting after a box titled Warning Get free *censored* now appeared with the two buttons below 1. okay (highlighted) and 2 cancel. There is something wrong here. Did you print out my instructions? This program HAS to be run from Safe Mode. In Safe Mode, Norton CAN NOT run. When you said Safe Mode, did you actually see SAFE MODE text in all four corners of your screen?Yes, and the desktop back is black ... It is def. in safe mode. Do you have Norton icon in taskbar?I ejected the cd-r which had the program on it and then the Norton AntiVirus box did not appear however, the box titled Desktop, Windows is running in safe mode. This special diagnostic mode of Windows enables you to fix a probelm which may be caused by your network or hardware settings. Make sure these settings are correct in Control Panel, and then try starting Windows again. While in safe mode, some of your devices may not be available. To proceed to work in safe mode, click yes. If you prefer to use System Restore to restore your computer to a previous state, click not. Then there are the two buttons below with yes and no. In clicking yes nothing happens afterwards there is no box counting down or any of the other things. |
|
4671. |
Solve : Is this a virus?? |
Answer» I use Windows XP HOME Edition SP2. Also most likely if it is a virus you wouldn't see it on your desktop, unless the guy who made the virus is retarded. lol LOL. I GUESS so. |
|
4672. |
Solve : Across his cheek... (Virus?)? |
Answer» Hello Everyone |
|
4673. |
Solve : Killbox.exe trojan? |
Answer» A couple of DAYS ago my AVG detected & removed (TROJAN horse BackDoor Hupigon3.XKF) from my computer. |
|
4674. |
Solve : c:\windows\system32\proper.exe? |
Answer» sn12.mailshell.net has to do with AVG antivirus (I think), why it is suddenly popping up I am not sure. maybe check the settings in AVG. Or even check for updates. |
|
4675. |
Solve : Possible Virus - HJT log? |
Answer» Hello, My brother isn't really having problems with his computer but I think he has a virus. |
|
4676. |
Solve : Using the 'read first' instructions..? |
Answer» Click Here for the installer. I need to update the instructions. Things have changed with the download since they were originally created.Here is the hijack log... Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:34:19 PM, on 12/14/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe C:\Program Files\COMODO\Firewall\cmdagent.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\COMODO\Firewall\cfp.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Metacafe\MetacafeAgent.exe C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.valp.net/ O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user') O4 - GLOBAL Startup: Adobe Reader SPEED Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe O4 - Global Startup: Metacafe.lnk = C:\Program Files\Metacafe\MetacafeAgent.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?11622 37926812 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE -- End of file - 6964 bytesYou are running two antivirus and two firewalls. This just causes system conflicts and slowdowns. Kaspersky AVG Comodo Either use AVG and Comodo or just Kaspersky. Open HijackThis and select "Do a system scan only" then place a check mark next to: O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file) Now close all browser windows and click "Fix checked" Other then that the log looks fine. It was the site advisor I once tried and subsquently removed. Are there any more McAfee items in the log? I found out what it was because Spybot pops up a warning that something or someone is attempting to make a change in the registry. Am I supposed to learn from some library how to identify what each item in the log is? There are some more 'unknown entries' later in the log. EF. I scanned and removed #3. Spybot popped up warning me an attempt is being made to change the registry. I let it happen. Spybot ID'd it as McAfree 'site advisor' I once tried and removed. Is there anymore McAfree entries in the log? Is there a library one goes too to learn how to ID all the entries? There are more 'unkown' items later at the end of the log. Google is the best library there is for searching out entries in the HijackThis log. I don't see any other entries from McAfee. Did you take care of the multiple AV and Firewalls? I don't care for Tea Timer and keep it off. I want AVG free a/v and Comodo f/w; Lavasoft and Spybot plus the "read first" list of protections you provided to stay at this time. So I should check every item that has the recognizable words "symantec or kaspersky" in the log and selecting them for 'fix'? I think you've tried to get me thinking on my own to take action but the first instructions out of the mouths of babes was, you better know what your doing in Hijack before you just make changes.Go to add/REMOVE programs to uninstall Kaspersky and anything to do with Norton or Symantec. Anything else installed is OK to keep, but HijackThis should be used with caution. Here is a tutorial on how to read the entries. But still, don't remove anything you have not researched first. How To Analyze HijackThis Logs To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? As per your instructions I read the articles and requested support from "Spywareinfoforums' to REVIEW and recommend anymore changes to my Hijack log. I'll let you know what happens. EF. The folks over at SWI reviewed my HiJack This log and reported no defects. I wish they would have been able to answer my questions regarding some items still in the log that shared a name of a previously removed process like Symantec but are still present. So far I have a clean bill of health and want to thank you for what you have taught me. I presume; in the interest of learning, there is no where else to look to see if any other malware is hiding anywhere because we have completed a full diagnostic check? Just let me know if there is anything else I could learn. I wish I could learn how to identify malware. Is that something taught in IT school? Merry Christmas and I hope your weather is better this coming New Year. |
|
4677. |
Solve : problem here!? |
Answer» i have remove a trojan NAMED brontok using avast and when every time i start my computer there is always a sign saying that windows cannot find eksplorasi.exe. Is there any way i can remove it? thanks1. Run free online scan at: http://housecall.trendmicro.com/ |
|
4678. |
Solve : Please help my interenet explorer is infected? |
Answer» My computer got infected i do have an antivirus but i think it happen while downloading music, thank you for your help in advance |
|
4679. |
Solve : trojans trojans and more trojans (new topic)? |
Answer» See my avg will have a pop-up saying it detected this TROJAN. I VAULT it then wipe it from my comp. Then in a day or two there ends up being a few more. It ends up being about 3 trojans per week. |
|
4680. |
Solve : Plz recommend a good virus program Thank!? |
Answer» Can someone plz RECOMMEND me a decent virus program. One that will not slow up my browsing so much and that can ALLOW me to play games uninterrupted. THANKS!I use AVG, it's good and best of all free If you go with AVG, which I recommend, as well, don't forget to uninstall your current AV, first.Thanks! free is good, but will this work with Vista home 32bit.Yep.Thanks! I really APPRECIATE the help given in these forums. |
|
4681. |
Solve : help me retrieve my email ad? |
Answer» i dont know what happened.... im not using any public computers ... one day i tried to open one of my email ad, i cannot open it. it says i have an invalid password. there are important files there. how can i retrieve my password/email ad? anyone COULD help me PLEASE?Can you explain what you mean by "e-mail ad"? The only ad I know of is an advertisement. my email ad Quote and that uput the correct letters Everybody needs to use the correct spelling of words and not text talk in help forums. The consequences could be severe (crashed computer) if we misinterpret what is being said. |
|
4682. |
Solve : What are the worstadmost threatening worms, or viruses?? |
Answer» Doing a report for school. I just want to know what the names are so that I can research them.Typically, we don't help with homework here. You've been around here long enough now to know how it works. I think you're giving him too much credit...It's the Holidays...i'll be back to Normal soon. |
|
4683. |
Solve : Personal Security Center Malware/Spyware? |
Answer» About a week ago I foolishly opened up a suspicious .exe file that I knew I shouldn't have, but what's done is done. My Norton didn't quite stop it so now I have this spyware known as "Personal Security Center." There is a small icon in the taskbar that occasionally pops up with a message warning me I am unsafe. I followed another guide to try to remove the program to no avail, so I came here! I've always gotten help here so I hope I can receive it again! Here's a post of my HJT Log. (Note: I've scanned multiple times with Windows Defender, Norton, Spybot Search & Destroy and Ad-aware. Still nothing has helped. I've always tried using smitfraud in safe mode but still nothing.) |
|
4684. |
Solve : Windows Vista SLOW HELP: Scan Logs? |
Answer» I posted my concerns in the Windows section of this forum and I was advised to go through the recommended scanning procedures. Here is my original message: Hi! I have a Dell Inspiron 1501 with Windows Vista Home Premium with AMD Turion(tm) 64 X2 Mobile Technology TL-60 2.00 GHz 1918 MB RAM 32-bit OS.I have done all the required scans & here are the logs: [saving space - attachment deleted by admin]The logs do not show any malware. We can fix a few empty entries with HijackThis. Open HijackThis and select Do a system scan only and place a check mark next to: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Close all windows except for HijackThis and click Fix checked Your Java is out of date LEAVING your system vulnerable. Older versions have vulnerabilities that malware can use to infect your system. Updating Java: * Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. * Check for any item with Java Runtime Environment (JRE or J2SE) in the name. ** The latest version is Java 6 Update 3. Remove all other entries. * Click the Remove or Change/Remove button. * Repeat as many times as necessary to remove each of the Java versions. * Reboot your computer once all Java components are removed. * Download the latest version of Java Runtime Environment (JRE) 6[/color] * Click the Free Java Download button. * Click the Download Now button. * When the Software Installation dialog box opens. Click on the Install Now button. * Follow the prompts to complete installation. There are 13 in instances of McAfee running in the services. this could be part of the problem. Is McAfee a paid version? There are free lightweight alternatives which provide equal or sometimes better protection to paid versions. Also running are unnecessarily are: InstallShield Update Service InstallShield Update Service Scheduler Adobe Reader Speed Launcher] QuickTime Task iTunesHelper Cacheman Let us know if we can help out with anything. Thank you very much! I have followed all of your instructions. Concerning McAfee, I've known that it uses a lot of memory, but I am hesitant to uninstall it. It came installed on my computer. Should I uninstall it & use another program? Thanks again for the BIG help!That is up to you, but I would. The popular choice here is AVG Antivirus and Comodo Firewall. Both free.Thank you very much! One side note, is it ok for me to uninstall the programs used to create the logs LIKE HijackThis or should I keep them?Yes you can delete any logs and uninstall HijackThis if you wish. HijackThis can cause damage if used improperly. SUPERAntiSpyware is free and good to use now and then to make sure nothing has crept in. To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place? Thank you very much! I found an installation disc for McAfee that came with my computer so I have uninstalled it & installed the programs that you have recommended. & something shocked me when I uninstalled McAfee: it cleared 50 GB from my hard drive! No WONDER I was having problems! But thank you so much! It's nice to find REAL solutions, not excuses like "it must be a virus so restore your computer to factory settings." So thank you so much! This is a lifesaver! If I have any other concerns, I will definitely come here. Thank you for your time & dedication!Your welcome, I'm glad it worked!Nicely Done evilfantasy and thanx for posting back with the results jfoulk2... We love SUCCESS stories here !Quote from: patio on December 07, 2007, 06:11:28 PM Nicely Done evilfantasy and thanx for posting back with the results jfoulk2... We really should have our own reality series. |
|
4685. |
Solve : Got the Trojan.win32.agent.akk,How do I get rid of it?? |
Answer» I GOT the Trojan.win32.agent.akk virus. Two questions. I have Mcafee 2007. HOw did it make it past it and why does it not detect it and get rid of it for me. How can I get rid of it?How it got in I don't know. HOw did it make it past it and why does it not detect it and get rid of it for me. The problem lies in your PREVIOUS statement... Quote I have Mcafee 2007. You're using subpar software. When you get that computer situated, I would suggest getting AVG, Spybot - Search & Destroy, and SUPERAntiSpyware. |
|
4686. |
Solve : More than one antivirus on a system? |
Answer» Hello Sir/Madam, Its possible, everything is possible,Please, do NOT post anything (I'm sorry) stupid.Broni is correct...more than one A/V program and they will bang heads and create conflicts as they are both fighting to do the same thing. Some AV programs have even been known to report another AV as a threat. However there is more to this than meets the eye. There are different forms of threats out there that need to be addressed with different protection applications. There is no one program that will do it all. That being said here is a rundown. Anti-Virus Avast AVG Select only one... Spyware Spybot SEARCH and Destroy Adware AdAware Trojan and Anti Malware AVG Anti-Spyware aSquared Select only one. And last but not least there are some online scanners you can always run as well: Online Scanners. All the above listed are FREE. Select one from each category and DLoad and install them. Remember to update and scan regularly...just having them installed will NOT protect you.Quote There is no one program that will do it all.Just to EXPAND this... While running ONE default ANTIVIRUS, and it detects something, or it doesn't DETECT anything, but you feel, there is something wrong with your computer, there are plenty, free, on-line scans, which should be used as crossrefrence.Look Up... Oooops....broni is right! different A/V has different capability. some A/V cannot detect a virus but other A/V can do. it is quite good if we scan using different A/V one at a time.Quote from: tommy gusack on December 04, 2007, 09:42:53 AM Its possible, everything is possible, I'll never UNDERSTAND why you're still allowed to post. |
|
4687. |
Solve : Network Issues? |
Answer» I'm having a LOT of problems CONNECTING to the internet through the ethernet. I think I have it narrowed down to something in the background is using a lot of the signal. The sending and RECIEVING rate goes up by 50 each second on my dial up connection. In no time I'm up to 800,000. On the ethernet connection it shows only sending info and 0 recieving. I forgot to mention that some have suggested I have a virus and go the trendmicro and run a scan. I only have dial up and I can't get it to download. Can anyone GIVE me any suggestions.I've tried to load the PANDA scan. I only have dial-up capability and I think it downloaded and started the scan, 3 hours later it hadn't progress much. I forgot to mention that some have suggested I have a virus and go the trendmicro and run a scan. I only have dial up and I can't get it to downloadWhy? HouseCall plug-in is a very small file (62KB). You can download, and install it in no time, even with dial-up. |
|
4688. |
Solve : critical problem help please? |
Answer» oh i m fade up of my pc problem i tried a lot of antivirus but no one is working.... Travel Here and follow the instructions and we'll see if we can get you fixed up...That's mot the whole log, it wasn't a full scan and we need the other two as well. |
|
4689. |
Solve : Screen flashes, taskbar goes to the top, what do I do?? |
Answer» It is a windows screen saver, the one with the 3D pipes. Just making sure, it's not 3rd party screensaver. But when I run my computer in Safe Mode it is fine. It's just when I run it in normal mode that it messes up. This is because in Safemode Windows is using a generic driver to run the HARDWARE...therefore it is either a driver issue or the actual card going bad as evilfantasy suggested...That's it.Ahh, well I'll just deal with it for a while longer then until I get a NEW computer. Thanks for all of the help! |
|
4690. |
Solve : help pls? |
Answer» hi all...ive installed spybot -search&destroy.. |
|
4691. |
Solve : PWS-WoW? |
Answer» Hi All, |
|
4692. |
Solve : Problems with Spybot? |
Answer» After installing the latest Spybot Search & Destroy update, I started getting Bad URL warnings on sites I never had problems with before...I uninstalled Spybot for now. Should I re-install an older version or can I get the same protection with AVG Anti Spy & forget about Spybot. I'm sure the problem is with the update or it was one *censored* of a coinsidence? should I even bother re-installing SpybotI'd give it a shot, just for the heck of finding out, if those pop-ups will show up again, if TeaTimer is NOT installed. Since you have AVG Antispyware running, as real time protection, you really don't need TeaTimer to be running. Also, yes, you can run as many antispyware programs, as you want. You ran ONLY ONE, antivirus, and firewall.Seperately is fine...Anti-Virus apps have the most problems with banging heads...this isn't true in your current protection package. Personally i didn't like Tea-Timer very early on and have never used it since.Me neither.Have re-installed Spybot (without Tea Time). So far so good. No warnings or pop-ups. If feel much better now. Thanks for all your advice, you guys are AWESOME! Szpixman Good |
|
4693. |
Solve : I get an error message, windows cannot find 'SSCVIHOST .exe'..? |
Answer» I get an error message everytime i turn on my computer. the FIRST thing appears at my DESKTOP is, |
|
4694. |
Solve : Spyware Blaster 3.5.1 vs. FireFox? |
Answer» Every time I try to enable protection for FireFox, Spyware Blaster will crash !!! |
|
4695. |
Solve : Slow computer again? |
Answer» I posted a hijack log on this forum many times and people say everything is fine with my computer. Lately my computer starts slow and takes a long time until it loads. Then when it loads up the programs that I start work fine, no problem there. The only problem is the boot up process anytime I boot up the computer. Is there any other program that i can use to post my computer process and startup application that are running and maybe anyone in the forum might help me solve my problem. Here is the hijack log in case : |
|
4696. |
Solve : virus maybe?? |
Answer» this is all hjt brings up
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1017A80C-6F09-4548-A84D-EDD6AC9525F0}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{1017A80C-6F09-4548-A84D-EDD6AC9525F0} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1017A80C-6F09-4548-A84D-EDD6AC9525F0}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}\ not found. ========== COMMANDS ========== File move FAILED. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully Error: Unable to interpret <[clearrestorepoints]> in the current context! [EMPTYTEMP] User: 12gage ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: AppData User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: ZERO KEWL ->Temp folder emptied: 252962 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 14333152 bytes ->Apple Safari cache emptied: 0 bytes ->Opera cache emptied: 0 bytes ->Flash cache emptied: 589 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 526570 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 14.00 mb OTL by OldTimer - Version 3.2.8.1 log created on 07092010_094341 Files\Folders moved on Reboot... File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. File\Folder C:\Windows\temp\TMP000000481196ED7C082D2C6D not found! Registry entries deleted on Reboot... hjc found and terminated: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666 R3 - URLSearchHook: (no name) - FBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)ill post the eset when its completed..... |
|
4697. |
Solve : Unable to update Microsoft Windows or get to Microsoft Update? |
Answer» Please help? |
|
4698. |
Solve : having a problem with Miccrosoft Security Essentials? |
Answer» for some unknown reason it seems to have stopped working. Usually, it automatically downloaded updates throughout every day but a few days ago I realized that I hadn't noticed the PROGRAM's icon in the lower right corner of my screen for a few days time. today I re-started my computer but still didn't see the program's icon so i opened the program's interface window and found it said it was switched off. i tried restarting it but it would start and gave an error message. I went into the control PANEL to try to restart it but it still wouldn't start so I uninstalled the program and reinstalled a copy I had gotten from their website today (which may be a different copy than was previously INSTALLED). Now the program still won't start, won't update. I don't understand the problem. If it matters, I also have Online Armor program installed. I often don't know what is "safe" or not safe and so if something pops up while I'm working and I wasn't trying to open or install something then I usually block it.You don't have to be on-line for your computer to be getting updates on a lot of different programs. Is it possible that you're blocking the updates? Have you added any security programs lately that would conflict with MSE?Thanks for your reply I think I might have fixed the problem. I turned off the Online Armor and then was able to turn on and update Microsoft Security Essentials. I guess there must have been a conflict with Online Armor that it wasn't letting the other program operate PROPERLY |
|
4699. |
Solve : AV Security Suite + can't run programs? |
Answer» Thanks. It will take me a while to run these various scans of course, just one question in the meantime though: when should I reboot back to normal mode? I'm still in safe mode right now.Try MBAM in Normal Mode, at least.OK, RAN all of the scans and back in normal mode now. No sign of any trouble so far, everything on the system appears to be working fine. Here are the LOGS, as you'll notice MBAM found some malware but SAS and ESET came up totally clean after that (except for a bunch of tracking cookies that SAS found).
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows 7 (UAC is enabled) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Security Center service is not running! This report may not be accurate! Windows Firewall Enabled! ESET Online Scanner v3 Norton Internet Security WMI entry may not exist for antivirus; attempting AUTOMATIC update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java(TM) 6 Update 15 Out of date Java installed! Adobe Flash Player 10.0.42.34 Adobe Reader 9.3.3 ```````````````````````````````` Process Check: objlist.exe by Laurent Norton ccSvcHst.exe ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7). Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations AntiSpyware
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
4700. |
Solve : Comcast log in page? |
Answer» I have a laptop that I use to SURF the web occasionally and I do so by pinging off a public site. One day I woke up and "Comcast" LOG in for customers or technicians was the only thing my computer will display. To make more weider, I don't have Comcast. I tried to restore and I got the IE cannot display web and then just like magic poof there is the Comcast log in page and it will not go AWAY. Any suggestions? I believe I have IE7 and WINDOWS XP. Please help. |
|