Announcement Banner
UNSOLVED

darth jed

updated

21 years ago

DJ

darth jed

12 Posts

0

635

March 1st, 2006 13:00

pls review this

hi there. someone pls help me out. can't open my windows firewall and norton detects a torjan virus in my system but cant remove it.
 
here's my HJT log:
 
Logfile of HijackThis v1.99.1
Scan saved at 12:06:39 AM, on 2/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Common Files\Stardock\SDMCP.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\SYSTEM32\lptask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\DELLSU~1\DSAgnt.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\winstall.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://support.dell.com/support/index.aspx?c=us&l=en&s=dhs
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://download.yahoo.com/dl/installs/ymsgr/ymsgrins.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.dlsu.edu.ph:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;
F2 - REG:system.ini: Shell=explorer.exe                                                                                                    "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O1 - Hosts: 62.189.6.78 _sip._tls.sip1.callserve.com
O1 - Hosts: 62.189.6.78 _sip._ssl.sip1.callserve.com
O1 - Hosts: 62.189.6.79 _sip._tls.sip2.callserve.com
O1 - Hosts: 62.189.6.79 _sip._ssl.sip2.callserve.com
O1 - Hosts: 62.189.6.85 _sip._tls.sip5.phoneserve.com
O1 - Hosts: 62.189.6.85 _sip._ssl.sip5.phoneserve.com
O1 - Hosts: 62.189.6.86 _sip._tls.sip6.phoneserve.com
O1 - Hosts: 62.189.6.86 _sip._ssl.sip6.phoneserve.com
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
O2 - BHO: (no name) - {397D7D63-816E-4ECF-8761-775C932C5CF1} - C:\WINDOWS\iDonate.dll
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [LPtask] C:\WINDOWS\SYSTEM32\lptask.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DellSupport] "C:\PROGRA~1\DELLSU~1\DSAgnt.exe" /startup
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Dell\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1120277955783
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123124262179
O17 - HKLM\System\CCS\Services\Tcpip\..\{44311DBA-922B-417F-9773-46615C6605E6}: NameServer = 203.172.25.21 202.163.239.2
O17 - HKLM\System\CS1\Services\Tcpip\..\{44311DBA-922B-417F-9773-46615C6605E6}: NameServer = 203.172.25.21 202.163.239.2
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Common Files\Stardock\mcpstub.dll
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O20 - Winlogon Notify: ssldr - C:\WINDOWS\SYSTEM32\ssldr32.dll
O20 - Winlogon Notify: wancp - C:\WINDOWS\SYSTEM32\wancp.dll
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINDOWS\system32\dcom_14.dll
O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - C:\WINDOWS\system32\baefnnel.dll (file missing)
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Ethernet Packet Service (npacketservice) - Nokia - C:\WINDOWS\system32\npacketsvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation  - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 
  • RKinner

    2 Intern

    •

    5851 Posts

    366

    0

    Posted March 1st, 2006 18:00


    I recommend that you do the following so you will have an electronic copy of the instructions since you will need to have Internet Explorer closed during most of the fix.

    Select the instructions: Put your mouse at the top left corner of my post then hold down the left button and drag it down to the bottom of the post. 
    Copy the instructins to your clipboard: Ctrl + c (or Edit, Copy). 
    Start notepad:  Start, Run, notepad, OK
    The cursor will be in notepad now so just Ctrl + v (or Edit, Paste) to paste the instructions into the notepad. 
    Save the file:  File, Save As, (navigate to your desktop), fix, OK

    You should now have a file called fix on your desktop which you can open by double clicking.

     

    Get DelDomain.inf from:
     
    http://www.mvps.org/winhelp2002/DelDomains.inf  and then right click on it and Install. 

     


    Download and install ccleaner.exe from http://www.ccleaner.com. Don't let
    it clean anything yet. 

    Download the killbox:

    http://www.bleepingcomputer.com/files/killbox.php

    Unzip it to your desktop but don't run it.

    You will need to turn off Spybot's teatimer or just uninstall Spybot until we finish.  It will keep Hijackthis from working.

    I am not sure of the effect of your lptask.exe program on this fix.  The writeup I read on it says it protects
    and encrypts certain folders.  We will try it without uninstalling it first.

    Shutdown and Restart and Boot into Safe Mode by tapping the F8 key when you see the PC
    maker's logo.
    Keep tapping until it tells you it is going to Safe Mode or you see the Safe
    Mode menu. Select the top option. Log in as your usual login or you won't find the programs you put on the desktop
    and some of the entries we want to remove will not appear in HijackTHis.

    Run HijackThis and just do a Scan only. Check  then Fix Checked the following:
     
    O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
    O2 - BHO: (no name) - {397D7D63-816E-4ECF-8761-775C932C5CF1} - C:\WINDOWS\iDonate.dll
    O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL
    O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\1.bin\IMESHBAR.DLL

    F2 - REG:system.ini: Shell=explorer.exe                                                                                                    "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
    O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
    O20 - Winlogon Notify: ssldr - C:\WINDOWS\SYSTEM32\ssldr32.dll
    O20 - Winlogon Notify: wancp - C:\WINDOWS\SYSTEM32\wancp.dll
    O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINDOWS\system32\dcom_14.dll
    O21 - SSODL: SysTray.Exgl - {636821FC-6F5C-2f1b-B164-E67214F678E2} - C:\WINDOWS\system32\baefnnel.dll (file missing)
    O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)


    If you are not in the Phillipines then also check these two:
    O17 - HKLM\System\CCS\Services\Tcpip\..\{44311DBA-922B-417F-9773-46615C6605E6}: NameServer = 203.172.25.21 202.163.239.2
    O17 - HKLM\System\CS1\Services\Tcpip\..\{44311DBA-922B-417F-9773-46615C6605E6}: NameServer = 203.172.25.21 202.163.239.2


    Run ccleaner.exe, uncheck everything on the first page except the two entries
    with Temporary and then Run Cleaner.

     

    Without leaving Safe Mode see if you can get norton to run a full scan of your system.  When it finishes let Microsoft AntiSpy do a full scan too (look under scan options).


    Run killbox.  Open Options and check Remove Directories
    Where it says Full Path of File to Delete you need to type or copy (Hightlight and Ctrl + c)
    and Paste (move to the killbox and place the cursor in the box and Ctrl + V):

    C:\WINDOWS\SYSTEM32\doser.exe


    Then check the Delete on Reboot box then the red button. 
    It will say:  File Will Be Removed On Reboot, Do you want to reboot Now.
    Tell it NO.  (If it can't find it that's OK just go on to the next one)
     
    Repeat for:
     
     C:\WINDOWS\SYSTEM32\msupdate32.dll
    C:\WINDOWS\SYSTEM32\ssldr32.dll
    C:\WINDOWS\SYSTEM32\wancp.dll
    C:\WINDOWS\system32\dcom_14.dll
    C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe

    Let it reboot after the last one.  Hijackthis should remove most of these but sometimes it can't so I am letting killbox verify that they are gone.


    Reboot into regular mode.  Make a new HJT log and post it as a reply.

    Ron

     

     

  • darth jed

    12 Posts

    366

    0

    Posted March 5th, 2006 14:00

    hi there.

    i dont know what u mean by

    "Get DelDomain.inf from:

    http://www.mvps.org/winhelp2002/DelDomains.inf and then right click on it and Install."

    when i click on the link all i see is this
    "
    ; DelDomains.inf © 11-28-04 | Revised 01-15-06
    ; Created by: Mike Burgess Microsoft MVP
    ; http://mvps.org/winhelp2002/
    ;
    ; Warning: Deletes all entries in the Restricted & Trusted Zone list
    ; http://mvps.org/winhelp2002/restricted.htm
    ;
    ; Revised to include the EscDomains key
    ;
    ; To execute this file: in Explorer - right-click (this file)
    ; Select Install from the Menu.
    ; Note: you will not see any onscreen action.

    [version]
    signature="$CHICAGO$"

    [DefaultInstall]
    DelReg=DelTemps
    AddReg=AddTemps

    [DelTemps]
    HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
    HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
    HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
    HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
    HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains"

    ; Recreate the keys to avoid a restart

    [AddTemps]
    HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
    HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains"
    HKCU,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
    HKLM,"Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges"
    HKCU,"Software\Microsoft\Win
    "
  • RKinner

    2 Intern

    •

    5851 Posts

    366

    0

    Posted March 6th, 2006 02:00

    Do not use the left mouse button.  right click on it and you will get a menu.  One of the options is install.    (Unless you have reversed the mouse buttons because you are left handed).
     
    Ron
  • darth jed

    12 Posts

    366

    0

    Posted March 6th, 2006 13:00

    Did everything you said. Here's my new HJT log. I still can't open Windows Firewall though.

    Logfile of HijackThis v1.99.1
    Scan saved at 11:37:29 PM, on 3/6/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Dell\Bluetooth

    Software\bin\btwdins.exe
    C:\Program Files\Common Files\Symantec

    Shared\ccSetMgr.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Common Files\Microsoft

    Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\RegSrvc.exe
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec

    Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec

    Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec

    Shared\Security Center\SymWSC.exe
    C:\Program Files\Common Files\Stardock\SDMCP.exe
    C:\WINDOWS\system32\ZCfgSvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\1XConfig.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\SYSTEM32\lptask.exe
    C:\Program Files\Common Files\Symantec

    Shared\ccApp.exe
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\Spybot - Search &

    Destroy\TeaTimer.exe
    C:\PROGRA~1\DELLSU~1\DSAgnt.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Yahoo!\Messenger\YPager.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Default_Page_URL = http://www.dell.com
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://red.clientapps.yahoo.com/customize/ie/defaults

    /sb/ymsgr6/*http://www.yahoo.com/ext/search/search.ht

    ml
    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Start Page =

    http://support.dell.com/support/index.aspx?c=us&l=en&

    s=dhs
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Default_Page_URL = http://www.dell.com
    R1 - HKLM\Software\Microsoft\Internet

    Explorer\Main,Search Bar =

    http://red.clientapps.yahoo.com/customize/ie/defaults

    /sb/ymsgr6/*http://www.yahoo.com/ext/search/search.ht

    ml
    R1 - HKCU\Software\Microsoft\Internet

    Explorer\SearchURL,(Default) =

    http://red.clientapps.yahoo.com/customize/ie/defaults

    /su/ymsgr6/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection

    Wizard,ShellNext =

    http://download.yahoo.com/dl/installs/ymsgr/ymsgrins.

    exe
    O1 - Hosts: 62.189.6.78 _sip._tls.sip1.callserve.com
    O1 - Hosts: 62.189.6.78 _sip._ssl.sip1.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._tls.sip2.callserve.com
    O1 - Hosts: 62.189.6.79 _sip._ssl.sip2.callserve.com
    O1 - Hosts: 62.189.6.85 _sip._tls.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.85 _sip._ssl.sip5.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._tls.sip6.phoneserve.com
    O1 - Hosts: 62.189.6.86 _sip._ssl.sip6.phoneserve.com
    O2 - BHO: (no name) -

    {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
    O2 - BHO: (no name) -

    {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - (no file)
    O2 - BHO: DriveLetterAccess -

    {5CA3D70E-1895-11CF-8E15-001234567890} -

    C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4}

    - C:\Program Files\MSN

    Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: CNisExtBho Class -

    {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program

    Files\Common Files\Symantec

    Shared\AdBlocking\NISShExt.dll
    O2 - BHO: MSNToolBandBHO -

    {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program

    Files\MSN Apps\MSN Toolbar\MSN

    Toolbar\01.02.5000.1021\en-us\msntb.dll
    O2 - BHO: NAV Helper -

    {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program

    Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Web assistant -

    {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program

    Files\Common Files\Symantec

    Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: MSN -

    {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program

    Files\MSN Apps\MSN Toolbar\MSN

    Toolbar\01.02.5000.1021\en-us\msntb.dll
    O3 - Toolbar: Norton AntiVirus -

    {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program

    Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [PCMService] "C:\Program

    Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [Apoint] C:\Program

    Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program

    Files\Intel\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [gcasServ] "C:\Program

    Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [UserFaultCheck]

    %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program

    Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [HotKeysCmds]

    C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [dla]

    C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor]

    C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [LPtask]

    C:\WINDOWS\SYSTEM32\lptask.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common

    Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program

    Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [DellSupport]

    "C:\PROGRA~1\DELLSU~1\DSAgnt.exe" /startup
    O8 - Extra context menu item: &Yahoo! Search -

    file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: E&xport to Microsoft

    Excel -

    res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Send To &Bluetooth -

    C:\Program Files\Dell\Bluetooth

    Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Yahoo! &Dictionary -

    file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps -

    file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS -

    file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

    Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console -

    {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

    Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Yahoo! Services -

    {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

    Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research -

    {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

    (WUWebControl Class) -

    http://update.microsoft.com/windowsupdate/v6/V5Contro

    ls/en/x86/client/wuweb_site.cab?1120277955783
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}

    (MUWebControl Class) -

    http://update.microsoft.com/microsoftupdate/v6/V5Cont

    rols/en/x86/client/muweb_site.cab?1123124262179
    O17 -

    HKLM\System\CCS\Services\Tcpip\..\{44311DBA-922B-417F

    -9773-46615C6605E6}: NameServer = 203.172.25.21

    202.163.239.2
    O17 -

    HKLM\System\CS1\Services\Tcpip\..\{44311DBA-922B-417F

    -9773-46615C6605E6}: NameServer = 203.172.25.21

    202.163.239.2
    O18 - Protocol: ms-help -

    {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program

    Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: widimg -

    {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} -

    C:\WINDOWS\System32\btxppanel.dll
    O20 - Winlogon Notify: igfxcui -

    C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: MCPClient - C:\Program

    Files\Common Files\Stardock\mcpstub.dll
    O20 - Winlogon Notify: Sebring -

    C:\WINDOWS\System32\LgNotify.dll
    O20 - Winlogon Notify: wancp - wancp.dll (file

    missing)
    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM,

    Inc. - C:\Program Files\Dell\Bluetooth

    Software\bin\btwdins.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) -

    Symantec Corporation - C:\Program Files\Common

    Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) -

    Symantec Corporation - C:\Program Files\Common

    Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation

    (ccPwdSvc) - Symantec Corporation - C:\Program

    Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) -

    Symantec Corporation - C:\Program Files\Common

    Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: InstallDriver Table Manager (IDriverT)

    - Macrovision Corporation - C:\Program Files\Common

    Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. -

    C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Macromedia Licensing Service - Unknown

    owner - C:\Program Files\Common Files\Macromedia

    Shared\Service\Macromedia Licensing.exe
    O23 - Service: Norton AntiVirus Auto Protect Service

    (navapsvc) - Symantec Corporation - C:\Program

    Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Intel NCS NetService (NetSvc) -

    Intel(R) Corporation - C:\Program

    Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Ethernet Packet Service

    (npacketservice) - Nokia -

    C:\WINDOWS\system32\npacketsvc.exe
    O23 - Service: RegSrvc - Intel Corporation -

    C:\WINDOWS\System32\RegSrvc.exe
    O23 - Service: Spectrum24 Event Monitor

    (S24EventMonitor) - Intel Corporation -

    C:\WINDOWS\System32\S24EvMon.exe
    O23 - Service: SAVScan - Symantec Corporation -

    C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) -

    Symantec Corporation -

    C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: SmartLinkService (SLService) - Smart

    Link - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Symantec Network Drivers Service

    (SNDSrvc) - Symantec Corporation - C:\Program

    Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec Core LC - Symantec

    Corporation - C:\Program Files\Common Files\Symantec

    Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec

    Corporation - C:\Program Files\Common Files\Symantec

    Shared\Security Center\SymWSC.exe
  • RKinner

    2 Intern

    •

    5851 Posts

    366

    0

    Posted March 6th, 2006 21:00

    Start, Run, Services.msc, OK then look for the Application Layer Gateway Service (alg).  If you find it then double click on it and verify that the Startup Type: is set to Automatic.  If it isn't then change it to Automatic and then Apply.  START the service.  Does it start?  If not does it say why?

     

    Ron

     

  • darth jed

    12 Posts

    366

    0

    Posted March 7th, 2006 09:00

    tried that too but windows security settings still reports that windows firewall is turned off.

    when i manually try to enable windows firewall (Start - Control Panel - Windows Firewall), its says "Due to an unindentified problem, Windows cannot display windows firewall setting".

    in the windows security center window. it says that Norton Internet Security is installed, but its status is unknown.
    Note: Windows does not detect all firewalls. When i click on recommendations it says that i try to open manually via the Window Firewall in the Control Panel.
  • RKinner

    2 Intern

    •

    5851 Posts

    366

    0

    Posted March 7th, 2006 14:00

    Were you able to find and start the service as I suggested?  Was it disabled?

    If you insist on the XP firewall then Start, Run, eventvwr.msc, and select System and look for red marked errors.  Doubleclick on them then copy the text by pressing the bottom of the three buttons and then move to a forum reply and Edit, Paste.  Repeat for any different events since your last reboot.  Repeat for Applications.

    However, why don't you forget about getting XP's firewall to work and try installing the free version of Zone Alarm?


    http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads

    It's better than the XP firewall since it does not have the preprogrammed holes and it works in both directions.

    When you install it, decline the free trials and demos.  You just want the free version.  Do allow it to preset up for Internet Explorer.

     

    As for Norton, the usual fix is to uninstall it and reinstall.  They do have a program that supposedly helps to get it to work:

     

    http://symantec.com/techsupp/home_homeoffice/index_ts.html

    Is this a trial subscription or one that you have paid for?

    If it's a trial you might just uninstall it and download one of the free antivirus programs for now.

     Avast! and AVG are both good and free for home use.

    http://www.avast.com/eng/download-avast-home.html

    http://free.grisoft.com/doc/2/lng/us/tpl/v5

    Just one antivirus at a time.

    Ron

  • darth jed

    12 Posts

    366

    0

    Posted March 8th, 2006 00:00

    a big thank you for all your help.

    my friends have also recommended that i forget about windows firewall and use zone alarm instead. guess it'll have to do, until this school term finishes so i can reformat my laptop. hehe.

    thanks again.