Unsolved

This post is more than 5 years old

10 Posts

2237

May 2nd, 2005 20:00

McAfee Virus Scan Disabled by virus

I used stinger.exe to delete the Bagle virus' s wiwshost.  I deleted winshost.  No more viruses are detected by stinger.  Virus scan is still disabled.  I can't link to any McAfee site.  On startup, I get a message that "Some components of Active Shield are either missing or might not have been installed properly.  Please reinstall Active Shield...."
 Here's the HJT log:
 Logfile of HijackThis v1.99.1
Scan saved at 4:54:03 PM, on 5/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sm_exe.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,72/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8/McUpdatePortal.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{014A793B-BF8D-4A84-BFBE-CCC401A28CD6}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{014A793B-BF8D-4A84-BFBE-CCC401A28CD6}: NameServer = 207.69.188.187 207.69.188.186
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
 

2 Intern

 • 

5.9K Posts

May 2nd, 2005 21:00


Get a copy of winsockxpfix.exe before you do anything. This is just a safety
item in case you can't get on the internet afterwards. You just run it and
things should work OK after it reboots your system.
http://www.iup.edu/house/resnet/winfix.shtm
 
Also download and unpack Pocket Killbox.
 
 
Now shutdown and reboot into Safe Mode by tapping the F8 key when you see the PC
maker's logo.
Keep tapping until it tells you it is going to Safe Mode or you see the Safe
Mode menu. Select the top option.
 
Run HijackThis and just do a Scan only. Check then Fix Checked the following:
O4 - HKLM\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O4 - HKLM\..\Run: [sm] C:\WINDOWS\sm_exe.exe
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe

 Wait 60 seconds and repeat the scan. Did any of the above come back? IF so
leave HijackThis up and right click on the clock and select Task Manager. Then
Processes. Find Explorer.exe, right click on it and select End Process. The
desktop will disappear but HijackThis should still be there. IF you don't see
it switch to Applications in Task Manager and highlight it there then press
Switch To or just double click on it. Check and Fix Checked the above again.
Restart Explorer by Task Manager, File, New Task(Run), explorer.exe, OK.
 
Now run killbox.exe and select Tools, Delete Temp Files.
 
Reboot into normal mode and run another HijackThis log and post it.
Ron
 

 

10 Posts

May 3rd, 2005 00:00

I followed your instructions.  The "04-HKCU\..." line doesn't show up when I run Hijackthis in safe mode as Administrator, so it didn't get deleted.  The other 2 were deleted.

I'm still getting the "Some components of Active Shield..." messsage.

Here's the log afterwards:

Logfile of HijackThis v1.99.1
Scan saved at 9:22:18 PM, on 5/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,72/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptodate.com/vsc/bin/1,0,0,8/McUpdatePortal.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{014A793B-BF8D-4A84-BFBE-CCC401A28CD6}: NameServer = 207.69.188.187 207.69.188.186
O17 - HKLM\System\CS1\Services\Tcpip\..\{014A793B-BF8D-4A84-BFBE-CCC401A28CD6}: NameServer = 207.69.188.187 207.69.188.186
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

 

2 Intern

 • 

5.9K Posts

May 3rd, 2005 01:00

Run HijackThis in normal mode and check the
 
O4 - HKCU\..\Run: [winshost.exe] C:\WINDOWS\System32\winshost.exe
 
then fix checked.  I think HijackThis got the file the first time since I don't see it running.  This is just a registry entry.
 
Otherwise the log looks clean of malware.
 
There are a bunch of mcafee statements missing from the log.  This is what I usually see from McAfee:
 
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
/checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O23 - Service: McAfee.com McShield (McShield) - Unknown owner -
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc
- C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee,
Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee
Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe

You can Start then right click on My Computer and select Manage then Services and Applications then Services and check and see if there are any McAfee services (O23 in the Hijack entries) that have been disabled.  Change them back to Automatic and try to start them but if they are not there then you will have to uninstall and reinstall.
 
Ron
 
 
 
 
 
 
 

10 Posts

May 3rd, 2005 18:00

Ron,
I deleted the 04 - HKCU entry for winshost.  That worked.
 I looked at manage services and the 3 McAfee services I have (I don't have firewall) are disabled.  I tried Actions in safe mode & not, but Start, stop, pause, resume & restart are all grayed out.  Does this mean I have to uninstall & re install McAfee.
I've never uninstalled anything and the only McAfee software I have is on the Dell supplied disk "For Reinstalling Dell Tools System Software".  Will that work.  How will I get McAfee back up to date.  I still can't get to any McAfee website.  Any ideas?    Thanks.   Peg

2 Intern

 • 

5.9K Posts

May 3rd, 2005 18:00

Go back into the services area and change where it says Startup Type to Automatic then press Apply.
 
That should allow the Start button to appear.  Perhaps then things will work a bit better at the next reboot.
 
To see why you can't get to mcafee's sites try:
 
Start, Run, cmd, OK to bring up a new CMD windows.  Type:
 
nslookup download.mcafee.com
 
 
You should get an answer like the following:
 
 Non-authoritative answer:
Name:    download.mcafee.m7z.net
Addresses:  208.254.75.144, 208.254.75.145, 198.5.148.18, 206.65.191.204
Aliases:  download.mcafee.com
 
Did you?  Are the numbers the same?  IF not what did you get? 
 
Now open up Internet Explore and type in
 
208.254.75.144 and hit Enter.  Did the site appear or did you get an error message or did nothing at all happen?
 
select Tools, Internet Options, Security, Restricted Sites, Sites.  If you have entries in the list look for anything with mcafee.com or networkassociates.com and if you find any then highlight them and Remove them.  If you can't get to the Restricted Sites because it wants a password, let me know.
 
Ron
 

10 Posts

May 4th, 2005 00:00

I forgot to add that I also got the Page not found error message when I typed in the 208.254...etc. url in internet explorer.    Peg

10 Posts

May 4th, 2005 00:00

Hi,

I was able to start Security Center and Virus Scan.  When I tried to start McShield, I got:  McAfee.com McShield service error 2 :  Cannot find specified file.  My Anti Virus index is now 3.8 and Security index is 2.8.  I'm still getting the "Some components of Active Shield are either missing or might not have been installed properly.  Please reinstall Active Shield." every time I reboot.

When I used the nslookup  cmd I got the following addresses:

204.10.28.11, 208.254.75.144, 209.133.111.210, 198.5.148.18

When I typed the 208.254..etc. url in internet explorer, I get a Yahoo search on the numbers.

There are no restricted sites listed in my internet options.

I also reran the 'stinger' program to check for viruses again and it found nothing.   Peg

2 Intern

 • 

5.9K Posts

May 4th, 2005 13:00

Looks like mcAfee is  a moving target.  Just checked them this morning and they are using:
 
65.170.56.11, 65.169.170.152, 65.203.232.16, 65.170.56.10
 
Try one of them and if that doesn't work see what happens when you do Start, Run, cmd, OK and type:
 
telnet download.mcafee.com 80
 
It show go completely black with the cursor at the top.  Type: a
then give it two Enters.  If you are connecting then it should give you a whole page of garbage that starts with:
 
HTTP/1.0 400 Bad Request
Server: iPrism/v3
Mime-Version: 1.0
Date: Wed, 04 May 2005 13:34:02 GMT
Content-Type: text/html
Content-Length: 905
Expires: Wed, 04 May 2005 13:34:02 GMT
X-Squid-Error: ERR_INVALID_REQ 0
 
 
If that works then the problem is probably in Explorer somewhere.  If it doesn't work then we have to look elsewhere.  Are you using a firewall?
 
Ron

10 Posts

May 4th, 2005 18:00

Hi again,

I forgot the result of  telnet download.mcafee.com 80:

"could not open connection to the host on port 80.  Connect failed."  That's what made me remember Winsockxpfix.

10 Posts

May 4th, 2005 18:00

Hi,

Those urls don't work for me either.  I get Page cannot be found http 400 Bad Request Internet Explorer.    That's a little different from 'server cannot be found"

In your first reply you had me download Winsockxpfix.exe.  Might running that help?

I don't have a firewall - I use a dialup modem - thought it was safe.   Peg

2 Intern

 • 

5.9K Posts

May 4th, 2005 19:00

I've been reading up on your original infection.  Start HijackThis again and Open the Misc Tools Section then select Open Hosts File Manager then Open in Notepad.  Find the line that says:

127.0.0.1       localhost

Move the cursor to the beginning of the next line then scroll down to the end of the last line at the bottom of the file and hold down the shift key and click once.  This should highlight everything below the localhost line.  Press Delete.  The last line should now be:

 

127.0.0.1       localhost

 

and there should be no lines above it that do not

1. have a # at the beginning

or

2. are just blank.

 

I expect that will allow you to get to mcafee's sites again.  The bug does kill off antivirus files so you will need to reinstall something.

 

Ron

 

 

 

10 Posts

May 4th, 2005 20:00

Ron,

Thank you for staying with me.  I can now access McAfee help.  I'll try the automatic uninstall right now.  I have to go out for a while, so any manual cleanup & the reinstall will have to wait until tomorrow.

I'll post our success tomorrow (I hope.)    Thanks again... Peg

10 Posts

May 5th, 2005 01:00

Ron,

Thanks again.  I uninstalled Virus Scan & followed the manual instructions to get all the pieces.  Then I reinstalled the latest updated version.  When I ran the scan, it found & deleted one piece of Bagle in a system restore file and 2 trojans:  qhosts-1!hosts and proxy-mitglieder.  

I also learned a few things about my system in fixing this problem.    So long    Peg

 

1 Message

May 28th, 2005 14:00

My Mcafee Virus Scan has also been disabled, and it says "Compenents of active shield or missing or not installed properely" similar to that. Well it was working yesterday and now today when i boot up my computer it all of a sudden doesnt work for me. I need some information on how to fix this problem.

10 Posts

May 31st, 2005 10:00

Hi,  That's the exact problem I first noticed.  Read the early posts from Ron using HijackThis.  Someone else will have to tell you what to delete from yours.  I've copied the post that let me get to the McAfee site.  I folowed their instructions to uninstall and reinstall and it's been fine since.  Good luck.

  from Ron:  " I've been reading up on your original infection.  Start HijackThis again and Open the Misc Tools Section then select Open Hosts File Manager then Open in Notepad.  Find the line that says:

127.0.0.1       localhost

Move the cursor to the beginning of the next line then scroll down to the end of the last line at the bottom of the file and hold down the shift key and click once.  This should highlight everything below the localhost line.  Press Delete.  The last line should now be:

 

127.0.0.1       localhost

 

and there should be no lines above it that do not

1. have a # at the beginning

or

2. are just blank.

 

I expect that will allow you to get to mcafee's sites again.  The bug does kill off antivirus files so you will need to reinstall something."

No Events found!

Top