Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

I've been Hijacked!


  • This topic is locked This topic is locked
7 replies to this topic

#1 Keys

Keys

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 19 November 2005 - 08:04 PM

I downloaded something loaded with multiple infections. (virus, spyware, adware). (oops)
I cleaned up all I could find with Mcafee, Ad-Aware and Spybot S&D.

All 3 of them now report no problems....except that I still have a problem.
Internet explorer opens a new window every 5 minutes trying to display
various web sites.

Any help would be much appreciated. Thanks.

Here's my log:

Logfile of HijackThis v1.99.1
Scan saved at 8:20:29 PM, on 11/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINXP\System32\inetsrv\inetinfo.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINXP\Explorer.EXE
C:\WINXP\system32\taskmgr.exe
C:\Internet\PopUpKiller\PopUpKiller.EXE
C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Internet\DU Meter\DUMeter.exe
C:\Utilities\YAC\yac.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Utilities\SpyBot\SpybotSD.exe
C:\Utilities\SpyBot\TeaTimer.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Utilities\RegEdit\RegCrawler\rcrawler.exe
C:\WINXP\REGEDIT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINXP\system32\NOTEPAD.EXE
C:\WINXP\system32\notepad.exe
C:\UTILIT~1\WINZIP8\winzip32.exe
C:\Utilities\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iwon.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [PopUpKiller] C:\Internet\PopUpKiller\PopUpKiller.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DU Meter] C:\Internet\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKCU\..\Run: [Skype] "C:\Internet\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Utilities\SpyBot\TeaTimer.exe
O4 - Global Startup: YAC.lnk = C:\Utilities\YAC\yac.exe
O8 - Extra context menu item: &Highlight - C:\WINXP\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINXP\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINXP\WEB\selsearch.htm
O8 - Extra context menu item: Download Using &BitSpirit - C:\Internet\BitTorrent\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Programs\Office2K\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: I&mages List - C:\WINXP\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINXP\WEB\frm2new.htm
O8 - Extra context menu item: Zoom &In - C:\WINXP\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINXP\WEB\zoomout.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .001: C:\Program Files\Internet Explorer\PLUGINS\npzzatif.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://myvpn.ford.c...oterisSetup.cab
O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F126} - http://www.swiftview...a_stat_libs.cab
O20 - Winlogon Notify: RunOnce - C:\WINXP\system32\k044lahq1d4e.dll
O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} - C:\WINXP\system32\phohcfjn.dll (file missing)
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - C:\WINXP\system32\gjcojjde.dll (file missing)
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINXP\system32\ieebgplc.dll (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXP\system32\nvsvc32.exe

    Advertisements

Register to Remove


#2 Keys

Keys

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 20 November 2005 - 10:45 AM

Ok, after spending many hours studying the problem, the obvious line is: O20 - Winlogon Notify: RunOnce - C:\WINXP\system32\k044lahq1d4e.dll I ran l2mfix, but it didn't work. (I didn't try the beta option 6) Correct me if I'm wrong, but here is what I found: 1. The hijacker adds a registry entry to run its process at bootup. 2. The process monitors the registry entry and puts it back any time it is deleted or changed. 3. The process is somehow hidden and can not be terminated. 4. The process's dll file is protected (in use) and can not be deleted. Here is what I did: I booted from the WinXP install CD to a DOS prompt. This avoids loading anything from the harddrive. Since the hijacker process is now not running, we can delete the randomly named dll file (k044lahq1d4e.dll). I also deleted several other files with the same creation date: srvklist.exe krnatcha.dll wzhisn.dll guard.tmp wpa.dbl I think the last one (wpa.dbl) might be an ok file since it showed up again later. I booted up normal and was then able to delete the reg. entry (and it didn't come back) Finally: the random iexplorer windows are now gone. :) Does anybody see anything that I might have missed ? Thanks.

#3 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 20 November 2005 - 11:51 AM

Hello Keys, welcome to the TC. You had more bad guys then what you fixed. Post a new HJT log.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#4 Keys

Keys

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 20 November 2005 - 12:20 PM

Here's my latest log:
Are the missing files listed in lines: O21 good files or bad files?

Logfile of HijackThis v1.99.1
Scan saved at 1:08:55 PM, on 11/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINXP\System32\inetsrv\inetinfo.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Internet\PopUpKiller\PopUpKiller.EXE
C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Internet\DU Meter\DUMeter.exe
C:\Internet\Skype\Skype.exe
C:\Utilities\SpyBot\TeaTimer.exe
C:\Utilities\YAC\yac.exe
C:\WINXP\system32\taskmgr.exe
C:\WINXP\regedit.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Utilities\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iwon.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [PopUpKiller] C:\Internet\PopUpKiller\PopUpKiller.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DU Meter] C:\Internet\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKCU\..\Run: [Skype] "C:\Internet\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Utilities\SpyBot\TeaTimer.exe
O4 - Global Startup: YAC.lnk = C:\Utilities\YAC\yac.exe
O8 - Extra context menu item: &Highlight - C:\WINXP\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINXP\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINXP\WEB\selsearch.htm
O8 - Extra context menu item: Download Using &BitSpirit - C:\Internet\BitTorrent\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Programs\Office2K\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: I&mages List - C:\WINXP\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINXP\WEB\frm2new.htm
O8 - Extra context menu item: Zoom &In - C:\WINXP\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINXP\WEB\zoomout.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .001: C:\Program Files\Internet Explorer\PLUGINS\npzzatif.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://myvpn.ford.c...oterisSetup.cab
O16 - DPF: {7DD62E58-5FA8-11D2-AFB7-00104B64F126} - http://www.swiftview...a_stat_libs.cab
O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} - C:\WINXP\system32\phohcfjn.dll (file missing)
O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - C:\WINXP\system32\gjcojjde.dll (file missing)
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINXP\system32\ieebgplc.dll (file missing)
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXP\system32\nvsvc32.exe

#5 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 20 November 2005 - 12:29 PM

You need To disable TeaTimer, or it can stop the fix.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
5) Restart your computer.



I suggest you do this:


Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Use Add/Remove Programs and remove: If listed.
PopUpKiller



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iwon.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

O4 - HKLM\..\Run: [PopUpKiller] C:\Internet\PopUpKiller\PopUpKiller.EXE

O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab

O21 - SSODL: SysTray.Exys - {7368D5FC-6F5C-4f5b-B964-E67214F67852} - C:\WINXP\system32\phohcfjn.dll (file missing)

O21 - SSODL: SysTray.Excn2 - {1722ECFF-4356-4f5b-B534-E67294FE75E9} - C:\WINXP\system32\gjcojjde.dll (file missing)

O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINXP\system32\ieebgplc.dll (file missing)


Close ALL windows and browsers except HijackThis and click "Fix checked"



Restart in Safe Mode:
Restart your computer.

Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.



delete these files if listed:
C:\WINXP\system32\phohcfjn.dll
C:\WINXP\system32\gjcojjde.dll
C:\WINXP\system32\ieebgplc.dll



Open C:\Windows\Prefetch\ Delete ALL files in this folder.



Do this also if these Temp Folders are part of your OS.

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.


Next navigate to the C:\Documents and Settings\(EVERY LISTED PROFILE USER)\Local Settings\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#6 Keys

Keys

    New Member

  • New Member
  • Pip
  • 4 posts

Posted 20 November 2005 - 01:35 PM

Ok, I did all that you asked.

Note:
1) iwon.com was my original home page.
2) I installed popupkiller myself, but I have now removed it since iexplore has the build-in blocker.
3) There is one Temp file that I can not delete: 102-4205503-4852952[1].
It says it can't read from the source file or disk.

Thanks for the help.

Logfile of HijackThis v1.99.1
Scan saved at 2:31:31 PM, on 11/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Internet\DU Meter\DUMeter.exe
C:\Internet\Skype\Skype.exe
C:\Utilities\YAC\yac.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINXP\System32\inetsrv\inetinfo.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINXP\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Utilities\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iwon.com/
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINXP\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DU Meter] C:\Internet\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKCU\..\Run: [Skype] "C:\Internet\Skype\Skype.exe" /nosplash /minimized
O4 - Global Startup: YAC.lnk = C:\Utilities\YAC\yac.exe
O8 - Extra context menu item: &Highlight - C:\WINXP\WEB\highlight.htm
O8 - Extra context menu item: &Links List - C:\WINXP\WEB\urllist.htm
O8 - Extra context menu item: &Web Search - C:\WINXP\WEB\selsearch.htm
O8 - Extra context menu item: Download Using &BitSpirit - C:\Internet\BitTorrent\BitSpirit\bsurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Programs\Office2K\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: I&mages List - C:\WINXP\Web\imglist.htm
O8 - Extra context menu item: Open Frame in &New Window - C:\WINXP\WEB\frm2new.htm
O8 - Extra context menu item: Zoom &In - C:\WINXP\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINXP\WEB\zoomout.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINXP\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .001: C:\Program Files\Internet Explorer\PLUGINS\npzzatif.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://myvpn.ford.c...oterisSetup.cab
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINXP\system32\nvsvc32.exe

#7 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 20 November 2005 - 01:38 PM

Good Job :thumbup:


Log looks good :D

Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Click Start> My Computer, select the Tools menu and then Folder Options, after the new window appears select the View tab…]
This time select the: Restore Defaults
Select: Apply, and click OK




If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 


#8 LDTate

LDTate

    Grand Poobah

  • Root Admin
  • 57,211 posts

Posted 23 November 2005 - 03:46 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

The forum is run by volunteers who donate their time and expertise.

Want to help others? Join the ClassRoom and learn how.

Logs will be closed if you haven't replied within 3 days

 

If you would like to paypal.gif for the help you received.
 

Proud graduate of TC/WTT Classroom

 

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users