This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Losing Default Gateway Please Help

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I would greatly appreciate any help. I have been trying for two weeks now to remidy this problem.. For some reason I am losing my default gateway connection and have to repair it about every 5 minutes or so. I have spoken with Verizon and they tell me that I have a virus or some type of worm or spybot…I have scaned my computer with removers to no avail. I am posting my hijack this log…please help!!!!!!

—————————————————————————————————

Logfile of HijackThis v1.99.1
Scan saved at 12:45:10 AM, on 3/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\OO Software\CleverCache\OOCCSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\PestPatrol\PPControl.exe
C:\PROGRA~1\PestPatrol\PPMemCheck.exe
C:\PROGRA~1\PestPatrol\CookiePatrol.exe
C:\WINDOWS\System32\ltmsg.exe
C:\PROGRA~1\DAP\DAP.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Evidence Eliminator\ee.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\dell\My Documents\hijackthis\hijackthis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCTR\System\PANELS\BLANK.HTM
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCTR\System\PANELS\BLANK.HTM
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PestPatrol\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PestPatrol\CookiePatrol.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SymNetDrv\SNDMon.exe
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://*.avsim.com
O15 - Trusted Zone: *.avsim.net
O15 - Trusted Zone: *.bestbuy.com
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O CleverCache Pro (OOCleverCache) - O&O Software GmbH - C:\Program Files\OO Software\CleverCache\OOCCSVC.exe
O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe



————————————————————————————————–
Thank You
Denney958
Hello Denney, Welcome to TomCoyote forum. If you still need help I will see what I can do.

1) Please tell me what this is, probably legit just want to be sure:
C:\Program Files\OO Software\CleverCache\OOCCSVC.exe I see this information: http://www.oo-software.com/en/index.html

2) There may be CoolWebSearch infection onboard. I would like you to download, update then FIX with CWShredder at the following link. Please allow to to do it's job and post information for me if it found and removed anything.
http://www.softpedia.com/get/Internet/Popu…WShredder.shtml

3) Scan with HJT and check the box for each of these line items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCTR\System\PANELS\BLANK.HTM
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\WINDOWS\PCHEALTH\HELPCTR\System\PANELS\BLANK.HTM
(next line is corrupted Spybot S&D, I would reinstall this software)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
(next two lines, if you did not set these restrictions you may remove them)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
(next three…I suggest you never allow any programs in your trusted zone)
O15 - Trusted Zone: http://*.avsim.com
O15 - Trusted Zone: *.avsim.net
O15 - Trusted Zone: *.bestbuy.com

Close all programs but HJT and all browser windows then click on "Fix Checked:

Stay in this thread, post a new log along with the information I asked for and any comments you have.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
PSKELLY….THANKS FOR YOUR HELP..I DONWLOADED THE CWSHREDDER AND RAN IT..IT FOUND NOTHING. I RAN HJT AND CHECKED THE BOXES YOU TOLD ME TO. HERE IS MY UPDATED HJT LOG:

Logfile of HijackThis v1.99.1
Scan saved at 10:53:29 PM, on 3/23/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\OO Software\CleverCache\OOCCSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ltmsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\dell\My Documents\hijackthis\hijackthis\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PestPatrol Control Center] c:\PROGRA~1\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] c:\PROGRA~1\PestPatrol\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] c:\PROGRA~1\PestPatrol\CookiePatrol.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SymNetDrv\SNDMon.exe
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{91F0B3D9-9309-4A7A-8084-52A677E21169}: NameServer = 68.238.96.12,68.238.112.12
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O CleverCache Pro (OOCleverCache) - O&O Software GmbH - C:\Program Files\OO Software\CleverCache\OOCCSVC.exe
O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

I AM STILL HAVING PROBLEMS. I CHANGED FROM IE TO FIREFOX AND IT SEEMS TO BE WORKING OK..HOWEVER I STILL LOSE MY GATEWAY AFTER AWHILE.

THANKS
DENNEY958
Hello Denny, I inquired about this program in my first post: C:\Program Files\OO Software\CleverCache\OOCCSVC.exe and you gave me no information. Is it valid, if it is then your log is clean. Since the problem exists in both IE and Firefox, that a good sign it is not an IE problem. I would suggest you get back to Verizon and tell them you checked and they need to troubleshhot their connection. A couple of things that you can try.

1) Give me the information about the program I inquired about so I can rule it out.

2) If you are running Verizon DSL, how is your phone line? Do you have static? Are your filters in place on all telephones in the house? If one of the phones does not have a filter and someone picks it up that can cause the connection to break. Any problems Verizon has with old lines in the area could also cause the issue, hard to advise without knowing your method of connection, but if DSL check with the neighbors on the same line to see if they have issues.

3) Here are a couple of troubleshooting links:
http://www.techsupportforum.com/computer/forum/21-1.html
http://www.techsupportforum.com/archive/in…hp/t-12664.html
http://www.computing.net/networking/wwwboa…orum/23876.html
A Google search will return more information. I am a Verizon DSL client myself and while it works fairly well, I am not without problems. I feel the old lines the purchased from GTE are mostly responsible and they keep saying they are going to replace them but I do not see it happening. The difference of $30 to $50 keep me with them.

4) I see ZAPro, how long has it been onboard? I had to uninstall it from my daughters computer due to connection issues. I took her back to ZA Free and the problems went away. Something to think about.

5) Here is a free trial of TrojanHunter if you want to give it a try. HJT can not see everything and it is always possible that something is hiding from you. Worth a try.
http://www.misec.net/trojanhunter/

6) While I would not consider it until you have no issues with the computer, here is a link to information you should have before thinking about SP2:
What you should know
http://www.microsoft.com/windowsxp/sp2/sp2_whattoknow.mspx

I would also suggest a complete maintanence. I also suggest you clean out all Temp, TIF and Prefetch files. Here is a small utility that will help for that for you to look at: http://www.ccleaner.com/ I have just started using this utility on my computer and I am not sure it cleans the Prefetch folder, manual instructions are in this link: http://www.safecomputing.umn.edu/guides/tempdirectories.html

I hope some of this information helps, let me know about the software I need to identify and if it is valid, I will give you great information to keep the computer clean of malware.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Pskelley.. Thanks for getting back to me…I am using verizon DSL and all of my phone lines have the filters on them. I contacted verizon and they said it was something in my system, virus or worm. Since I switched to Firefox it seems that I only lose my conection after I have been off for awhile like overnight. I don't know it just seems to strange that I had no problems before and then bang three weeks ago this starts happening. I remember norton popping up and saying that It detected a virus and was not able to contain or delete. But when I check the norton log it shows nothing. I ran a full system scan and it found nothing. I have read a few different things about zone alarm and I am not sure if I should uninstall it and just go with the built in firewall with windows. The program you inquired about is called Clever Cache Pro and manages your memory or file cache or something. I also use OO Defrag that is awsome, both programs are made by the same company O&O. I read about these two programs in a flight sim magazine as a suggestion to improve frame rates in fs200X. As far as the sp2 issue I am really hesitant to download it. I am a big Flight Simmulator 200X player and have heard some negative things about its compatability. I will try the other things you suggest, If you think of anything else PLEASE don't hesitate to contact me! Thanks Denney958
Hey Denney, A few thoughts.

I remember norton popping up and saying that It detected a virus and was not able to contain or delete

Whoa, if they can't stop them for the $$ we pay for their protection, we are in trouble. Keep in mind there are some virus/trojans types that actually corrupt your AV and Firewall. While I am not saying this is the case, after you know your are clean a reinstallation of both might be a good idea.

I can say I have been using ZA Free for many years with no problems. I assume you pay for ZA Pro, but I would also think this issue would have had to occur at about the same time you installed ZA Pro. You could turn it off and activate the ICF and see what happens. I for one do not think the ICF in SP1 is safe and this is the reason I run ZA Free. The firewall in SP2 is supposed to be better but my jury is still out on it also. I will tell you I had to uninstall SP2 at the suggestion of a MSN Tech after four hours of trying to figure out why critical downloads would not work. She suggest a new install of windows, but since everything is running well I may never download SP2 again. I really think it is for the folks who do not know to keep av and firewall running and updates current. I do this anyway. I also thought that once folks got SP2 onboard the malware thing would slow down. Not the case, getting worse than ever. Hard to keep up with the new infections.

Clever Cache Pro: This item is not in our scan database. I would really appreciate it if you would link me to the website so I can add it to our databases. Thanks.

Keep me posted as you proceed I do have other tools in my toolbox. I hesitate to use a hatchett when we have not tried a hammer yet. I am especially interested in rather trojan hunter finds anything. HJT is a miracle where it comes to malware, but it is not calpable of seeing everything.

Good luck
Phil Skelley
Hello Denney, Yeah this junk is hard to get off the computer then it is to get on. Thanks for the information, I will pass that to the keepers of the database. Make sure you write down the exact wording, name and location, of anything the trojan hunters locate and can't delete. You should also post a new log when you post. This stuff often mutates and displays in the log, keeping an eye on the log will let us know if anything like that happens. If you get no satisfaction from the trojan scans, here is a tool you can try. This scan is not free but it does the best job of locating hidden malware and displays it in a log. We can then use other means to delete the stuff. I ran it on my computer and it does take over two hours. If you run it please post only the log at the bottom as the total log is hugh and of no use to me. Here are the instructions:

Download mwavscan, then double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.

http://www.mwti.net/antivirus/mwav.asp

Thanks…Phil

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI