Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Jul 23 2008, 01:53 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 23-July 08 Member No.: 80,459 Operating System: XP |
ISP is a Verizon DSL account and everything works from/to a desktop PC
Following day, 7/24, ran a Live CD session of Ubuntu 7.01 and using Firefox browser was able to access Internet. Evolution e-mail program also worked. Being a stubborn old coot, Icould not give up on the problem. On a second (closer) perusal of the Hijack log print out, I spotted the following item: O2 - BHO: WormRadar.com IE SiteBlocker.NavFilter - ... I re-ran HijackThis and "fixed" the item by deleting it. Still could not access the Internet! In a related post, I saw a comment to disable Zone Alarm. That did the trick. With access to the Intenet, I Googled "free firewalls for Windows XP" and ended up with Comodo Firewall Pro - a free program for personal use. Installing Comodo required removing Zone Alarm using its "uninstall" file. All seems fine now, although I still suspect that there is a nasty remaining somewhere in the system. This forum has been a great help and thanks to all the volunteers and users. Lee This post has been edited by LeeAlex: Jul 24 2008, 05:57 PM
Attached File(s)
|
|
|
|
Jul 26 2008, 02:17 PM
Post
#2
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,037 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Hello LeeAlex
Welcome to the Whatthetech Malware Removal Forum Your version of Hijackthis is extremely outdated and not showing us everything, drag it to the trash and download and install the latest version by Trendmicro, copy and paste it into this thread, do not attach it. Download Trendmicros Hijackthis to your desktop.
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. |
|
|
|
Jul 31 2008, 08:34 PM
Post
#3
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 23-July 08 Member No.: 80,459 Operating System: XP |
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:54 PM, on 7/31/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\BCMSMMSG.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe D:\Utilities\Firewall\Comodo\Firewall\cfp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe D:\Utilities\Firewall\Comodo\Firewall\cmdagent.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Internet Explorer\iexplore.exe D:\Utilities\RapidRes\RapidRes.exe D:\Utilities\Spyware\HiJack\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Utilities\Firewall\Comodo\Firewall\cfp.exe" -h O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1197388793329 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll C:\WINDOWS\system32\guard32.dll O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - D:\Utilities\Firewall\Comodo\Firewall\cmdagent.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 4712 bytes As you can see, I have done as you suggested. Meanwhile, I found out the problem was a WinXP patch -KB951748 July 8, 2008 that interfered with Zone Alarm. My solution was to uninstall Zone Alarm, replacing it with Comodo Firewall Pro; IMHO a better free utility. Thanks for the help. This post has been edited by LeeAlex: Jul 31 2008, 08:44 PM |
|
|
|
Aug 1 2008, 04:11 AM
Post
#4
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,037 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Good Morning,
Yep, the windows updates messed with internet access with users who had Zone Alarm installed, glad you got that figured out. It was just that one update that did that, the rest are fine. Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank. You can run this cleaner written by one of our own malware fighters to clean out all the temp files and such that could be clogging your system down Please download ATF Cleaner by Atribune to your desktop.
The rest of your log looks clean, no malware or viruses that I can see
Safe Surfn Ken |
|
|
|
Aug 12 2008, 11:07 AM
Post
#5
|
|
![]() SuperHelper Group: Malware Expert Posts: 7,037 Joined: 3-December 04 From: Darien, Connecticut Member No.: 19,436 Operating System: Win Xp Home SP3/ Vista Home Premium SP1 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
15 | LyndaV | 150 | Today, 04:44 PM Last post by: LyndaV |
|||
![]() |
33 | Kathys | 216 | Today, 04:27 PM Last post by: Kathys |
|||
![]() |
4 | ExocetMissile | 28 | Today, 03:13 PM Last post by: ExocetMissile |
|||
![]() |
3 | NyankeeC | 30 | Today, 12:46 PM Last post by: NyankeeC |
|||
|
Time is now: 21st November 2008 - 06:00 PM |