Announcement Banner
UNSOLVED

Rob9202

updated

21 years ago

R

Rob9202

10 Posts

0

550

November 19th, 2005 20:00

Winfixer Problem

I have followed ur primary directions for the Hi-Jack thing, but it's kinda vague whether we should post here or not... so I am just to be sure.
 
I already have the Hijackthis.log notepad ready to go... and I do have that O2 file you spoke about in the forum link here  -----> http://forums.us.dell.com/supportforums/board/print?board.id=si_hijack&message.id=16923  
 
This is just a repeated quote of the vagueness.
 
"

If you don't see such a line, then STOP HERE... either you don't have WinFixer, or you have a different variation of it....  and in these cases, you should now post your Log in the HiJackThis forum in order to obtain individualized assistance:  http://forums.us.dell.com/supportforums/board?board.id=si_hijack

If you're running Windows 95, 98, 98SE or ME, then STOP HERE... the fix described below is only for Windows XP and Windows 2000  "

^^^ not sure weather you mean to "go below" or "go to forums" or both.^^^^

 

Anyway... my hijackthis.log notepad is copied below with the 02 file

Also... ?--Is my IP address below---?.... if it is I would rather you not pay attention to that... you could say i'm perinoid when it comes to viruses.

 

Logfile of HijackThis v1.99.1
Scan saved at 6:34:59 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\sstray.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Free Surfer\fs20.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\jkhhf.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
O16 - DPF: {8F24DE00-0D66-4F93-9405-3F21E97AEE99} - http://esb.alcena.com/ESBAdultInstaller.ocx
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} - http://webpdp.gator.com/4/download/hdplugin_1018_bundle43v2d26.cab
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} - http://www.spybouncer.com/downloader/downloader.ocx
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/winfixer.com/www/pages/scanner/WinFixerScannerInstall.cab
O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
O20 - Winlogon Notify: jkhhf - C:\WINDOWS\system32\jkhhf.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

... I made it easy to find

If you know how to get rid of anything else useless, that would be nice also.

This is my second time posting becuase my other post is on the 7th page and I feel you have forgotten it... so plz answer this time... My mom has a dell and it may be infected soon so I need to find out how to get rid of this now!

 
Thank you for your time and concern,
Rob.

Message Edited by Rob9202 on 11-11-2005 05:58 PM

Message Edited by Rob9202 on 11-12-2005 10:53 AM

Message Edited by Rob9202 on 11-12-2005 10:54 AM

  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    225

    0

    Posted November 20th, 2005 11:00

    Sorry if your earlier post was overlooked... we're just so overwhelmed here.... especially by WinFixer.
     
    there's a new, simpler fix that we're recommending now:

    Download [but do *NOT* yet run] FixVundo from

    http://securityresponse.symantec.com/avcenter/FixVundo.exe

    [we'll have you run it later]

    Note: If you have previously download this file on another occasion, please download it again, to be absolutely sure you have the most current version.

    ********************

    Next, download VirtumundoBeGone from:

    http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

    * Save it to your Desktop
    * Close all running programs (including your Internet Browser)
    * Double-click VirtumundoBeGone.exe on the desktop
    * Follow the directions as indicated

    please be advised that this program will generate a "BLUE SCREEN OF DEATH"... this is an expected/necessary part of the process, so don't be surprised when it happens.

    just reboot if your system "jams"

    *********************

    After rebooting, it's now time to run FixVundo (which you had downloaded earlier).

    Make sure all other programs, including your Internet Browser, are closed.

    Double-click the FixVundo.exe file to start the removal tool.

    Click Start to begin the process, and then allow this tool to run.

    Important: Do not launch any new applications while the tool is running!

    Reboot your computer.

    Run the FixVundo removal tool again to ensure that the system is clean.

    *********************

    It's now time to report back to us:

    VirtumundoBeGone generated a "log" file of its own, which it should have placed on your Desktop... please REPLY to this thread, and copy/paste the VirtumundoBeGone log back here, along with your latest HJT log.

     

  • Rob9202

    10 Posts

    225

    0

    Posted November 20th, 2005 16:00

    The VirtumundoBeGone was a txt file looking like VBG.txt, hope it's the same one your talking about...

     

    VBG.txt

     


    [11/20/2005, 11:10:55] - Starting Process...
    [11/20/2005, 11:10:55] - Looking for Browser Helper Object [MSEvents Object]
    [11/20/2005, 11:10:55] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
    [11/20/2005, 11:10:55] - 2: {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - REALBAR
    [11/20/2005, 11:10:55] - 3: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - ST
    [11/20/2005, 11:10:55] - 4: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - CNisExtBho Class
    [11/20/2005, 11:10:55] - 5: {B313D637-F405-4052-AC37-E2119AB3C8F8} - MSEvents Object
    [11/20/2005, 11:10:55] - Found MSEvents Object!
    [11/20/2005, 11:10:55] - File location: C:\WINDOWS\system32\jkhhf.dll
    [11/20/2005, 11:10:55] - Attempting to kill C:\WINDOWS\system32\jkhhf.dll
    [11/20/2005, 11:10:55] - Terminating Process: RUNDLL32.EXE
    [11/20/2005, 11:10:55] - Terminating Process: IEXPLORE.EXE
    [11/20/2005, 11:10:55] - Disabling Automatic Shell Restart
    [11/20/2005, 11:10:56] - Terminating Process: EXPLORER.EXE
    [11/20/2005, 11:10:56] - Suspending the NT Session Manager System Service
    [11/20/2005, 11:10:56] - Terminating Windows NT Logon/Logoff Manager
    [11/20/2005, 11:10:56] - Re-enabling Automatic Shell Restart
    [11/20/2005, 11:10:56] - Renaming C:\WINDOWS\system32\jkhhf.dll -> C:\WINDOWS\system32\jkhhf.dll.vir
    [11/20/2005, 11:10:56] - File successfully renamed!
    [11/20/2005, 11:10:56] - Removing Registry references to {B313D637-F405-4052-AC37-E2119AB3C8F8}
    [11/20/2005, 11:10:56] - Adding Internet Explorer Protection (Kill ActiveX) for {B313D637-F405-4052-AC37-E2119AB3C8F8}
    [11/20/2005, 11:10:56] - Removing Winlogon Notify Entry: jkhhf
    [11/20/2005, 11:10:57] - BHO list has been changed! Starting over...
    [11/20/2005, 11:10:57] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
    [11/20/2005, 11:10:57] - 2: {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - REALBAR
    [11/20/2005, 11:10:57] - 3: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - ST
    [11/20/2005, 11:10:57] - 4: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - CNisExtBho Class
    [11/20/2005, 11:10:57] - 5: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - MSNToolBandBHO
    [11/20/2005, 11:10:57] - 6: {BDF3E430-B101-42AD-A544-FADC6B084872} - CNavExtBho Class
    [11/20/2005, 11:10:57] - Finished searching for [MSEvents Object]
    [11/20/2005, 11:10:57] - Finishing up...
    [11/20/2005, 11:10:57] - Enabling Automatic Reboot on STOP Error.
    [11/20/2005, 11:10:57] - Attempting to Restart via STOP error (Blue Screen!)

    [11/20/2005, 13:01:07] - Starting Process...
    [11/20/2005, 13:01:07] - Looking for Browser Helper Object [MSEvents Object]
    [11/20/2005, 13:01:07] - 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class
    [11/20/2005, 13:01:07] - 2: {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - REALBAR
    [11/20/2005, 13:01:07] - 3: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - ST
    [11/20/2005, 13:01:07] - 4: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - CNisExtBho Class
    [11/20/2005, 13:01:07] - 5: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - MSNToolBandBHO
    [11/20/2005, 13:01:07] - 6: {BDF3E430-B101-42AD-A544-FADC6B084872} - CNavExtBho Class
    [11/20/2005, 13:01:07] - Finished searching for [MSEvents Object]
    [11/20/2005, 13:01:07] - Nothing found! Exiting.

     

    FixVundo.log

     

    Symantec Trojan.Vundo Removal Tool 1.4.0

    C:\System Volume Information: (not scanned)
    Trojan.Vundo has not been found on your computer.

     
    New HJT file
     
    Logfile of HijackThis v1.99.1
    Scan saved at 1:29:19 PM, on 11/20/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\sstray.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Free Surfer\fs20.exe
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
    O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
    O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} - http://launch.gamespyarcade.com/software/launch/alaunch.cab
    O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} - http://download.websearch.com/Dnl/T_50188/QDow_AS2.cab
    O16 - DPF: {8F24DE00-0D66-4F93-9405-3F21E97AEE99} - http://esb.alcena.com/ESBAdultInstaller.ocx
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} - http://webpdp.gator.com/4/download/hdplugin_1018_bundle43v2d26.cab
    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
    O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} - http://www.spybouncer.com/downloader/downloader.ocx
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/winfixer.com/www/pages/scanner/WinFixerScannerInstall.cab
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
     
     
    Thank you very much, I just would like to know how to get rid of any unnecessary stuff like XXX toolbar that I have never seen.  I have not looked at porn for years and I don't use most of those 016 files if u could tell me how to get rid of them that would be fantastic.
     
    Thank you again for your time and concern,
    Rob.
     
  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    225

    0

    Posted November 20th, 2005 17:00

    Looks like VirtumundoBeGone successfully deactivated the bad WinFixer/Vundo file... have you noticed any difference, in terms of WinFixer popups, and overall system speed/performance?

    ********************************

    As for the  XXXtoolbar  entries that you no longer want to keep around:

    Run HiJackThis. Place a check-mark in the box in front of each of the lines:

     

    O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab


    O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_adult.cab


     

    [Feel free to check-off any of the other    O16    entries that you would also like to remove... but do *NOT* try this removal technique for any other grouping of  HJT entries, unless you are specifically advised to do so!!   O16 are Active-X controls, which may be freely/simply removed, at will.... and will be re-installed, automatically, should you ever visit that site again.]

    Click on FIX CHECKED. Close HiJackThis. Reboot. And then generate/post another log.

     

    At that point, I'm gonna try to ask someone else to step-in, to determine additional problems (if any) that you might have. Please be advised that we're very "understaffed" at the moment, so I can't make any guarantee as to when (or even if) the next helper will arrive.

     

    Good luck.

  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    223

    0

    Posted November 20th, 2005 18:00

    i see you removed some of the O16's, including the xxxtoolbars...  might as well also take care of [check, and FIX CHECKED] the following, which appears to be WinFixer related:

     

    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/winfixer.com/www/pages/scanner/WinFixerScannerInstall.cab

  • Rob9202

    10 Posts

    225

    0

    Posted November 20th, 2005 18:00

    Thank you very much, my computer runs substantially smoother and no more WinFixer pop-ups.
     
    Logfile of HijackThis v1.99.1
    Scan saved at 3:18:14 PM, on 11/20/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\sstray.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Free Surfer\fs20.exe
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Documents and Settings\Owner\Desktop\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: REALBAR - {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - C:\PROGRA~1\COMMON~1\Real\Toolbar\realbar.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
    O9 - Extra 'Tools' menuitem: Free Surfer - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - C:\Program Files\Free Surfer\FS20.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
    O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} - http://www.spybouncer.com/downloader/downloader.ocx
    O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/winfixer.com/www/pages/scanner/WinFixerScannerInstall.cab
    O16 - DPF: {FF0C042C-98E9-4C36-B2EC-E21FDFDCEF75} (InstallCtl Class) - http://download.redswoosh.net/Installer/104/rsinstaller.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
  • RKinner

    2 Intern

    •

    5851 Posts

    223

    0

    Posted November 21st, 2005 22:00

    Get rid of this one too.  Spybouncer is on the rogue spyware list.  (Not to be trusted.)

    O16 - DPF: {F48EAB92-8BCE-4C77-BE98-D10060BD8590} - http://www.spybouncer.com/downloader/downloader.ocx

     

    Otherwise log is OK. except adobe and java (JRE) are both out of date.  If you use them you should upgrade to the latest versions.  If not remove them.  Is your firewall running?

    Ron

    Make sure you have System Restore running (toggle it off and On today to get rid of any bad stuff it may have retained)
    and then you can just go back to an earlier time if you hit a bad site.

    http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/systemrestore.mspx

    One way to make this more obvious is to check everything in your current HijackThis and Add to Ignore List then set up Hijackthis to run at boot and to show you if it finds anything new.

     
    To avoid going to a bad site you might want to install IE-SpyAd and SpywareBlaster and make the other changes recommended at:.
    http://www.mvps.org/winhelp2002/restricted.htm
    I used to recommend Spybot's Immunize system but have recently learned it is not as good as the one at:
    http://www.mvps.org/winhelp2002/hosts.htm

    Never hurts to do one of the free on line scans from Panda or Trend.  They take a while but are pretty good.
    www.pandasoftware.com/activescan/activescan.asp?
    http://housecall.trendmicro.com/
    In addition to Microsoft AntiSpy
    http://www.microsoft.com/athome/security/downloads/default.mspx
    I like to run Spybot S&D. 
    http://www.safer-networking.org/en/download/index.html
    Also like to run AdAware once in a while. 
    http://www.lavasoftusa.com/software/adaware/


     

  • Rob9202

    10 Posts

    223

    0

    Posted November 22nd, 2005 02:00

    Wow, thank you very much, yes I wasn't sure if that winfixer site was a deletion site or something so I'll get rid of that.  And same with the spyware stuff, I thought that was bad but wasn't sure.  I am always very confused on what is good for your computer and what is bad... cuase there is like....

     

    Spyware

    Adware

    Spybouncer

    Gamespy

    Spy(everything)

    My friend even once showed me a spy something program which is quiet scary to look at because all you need is someone's I-P address and it functioned as a hacking program to do basically anything to their computer, from the "matrix Black screen" to opening someone's C: drive.  If you want I could find out excactly what it is called, unless you already know.

    ****Suggestion Notice**** for those uneducated people like me, you should make a section to the Dell website that shows a well orginized list of certain programs that are considered unreliable and potentially dangerous.  The only way I find out about them is from gaming forums and I obviously do not trust the validaty of that resource.  A Hazardous Programs to your Computer page on the Dell site would help tremendously because people can trust this site.  Unless you already have these postings It's just a recommendation.

    Last thing I have to say is... I have a program that is called EMS free surver mk II, basically it is a very strict pop up blocker.  So my question is, one day a long time ago I was deleting files that I thought were unnecessary and I accidently deleted the english patch or something, and every time I load my computer a notice comes up that says "free surfer mk II english pact not working" or something like that, and I just click ok.  Is there away to remove this program from my computer and maybe re-download it?  My friend put it on to prevent pop-ups but I don't use it anymore since it has no writing (english) on it.

    Thanks again,

    -Rob.

    Message Edited by Rob9202 on 11-21-2005 10:26 PM

  • ky331

    5 Journeyman

    •

    15627 Posts

    •

    45058 Points

    223

    0

    Posted November 22nd, 2005 10:00

    RE:  your request for "a well orginized list of certain programs that are considered unreliable and potentially dangerous"... a great place to start is:
     
    The Spyware Warrior List of Rogue/Suspect Anti-Spyware Products & Web Sites   by Eric L. Howes
     
     
     
    ***************************************************
     
    I'll now offer you my "standard" list of FREE security programs.... and i'm sure Ron has a lot to suggest as well...
     
    there are several aspects to internet security... and you need to have protection in each of these areas:

    windows critical/security updates

    anti-virus (worms/trojans &etc)

    anti-spyware

    firewall

    (not as critical as the above, but probably desirable) pop-up blocker

     

    Please note that a security SUITE may offer you some combination of the above.... in this case, you only have to "add-on" those features that it doesn't already have.

     

    Here more information [including FREE recommendations] on each category... 

    ************

    Windows critical/security updates are made available the 2nd Tuesday of each month, and should be installed as soon as possible.   If you've set-up AUTOMATIC updates, that's optimal; but if not, you can manually obtain them, in Internet Explorer, by clicking on TOOLS, and then WINDOWS UPDATE

    *********

    Anti-Virus:  You should have ONLY ONE passive/RESIDENT anti-virus running on your system, which is set to load/run automatically every time you boot-up your PC, and which continually monitors your files/e-mails, in real-time, as you download/install/open/run them.  In contrast, feel free to visit as many of the "online scanners" that you have the time/patience to play with. 

    Regardless of which product you choose/use, it is critical that you continue to update its definition/reference files... I strongly advocate this be done every time you log onto the internet.

    [Norton and McAfee are certainly the big "names" here].  FREE products include:

    grisoft/AVG:  http://free.grisoft.com/doc/Get+AVG+FREE/lng/us/tpl/v5  then, click on the avg71free...  link near the bottom of the page

    or

    avast!  http://www.avast.com/eng/avast_4_home.html

    i've been using avg (first version 6, then version 7) for a few years now, and have been very satisfied with it.   i personally haven't tried avast!, but  many people in the virus/spyware forum are very pleased with it as well.

    ************

    Anti-Spyware programs:  In contrast to an anti-virus, you can [in fact, SHOULD] use/combine SEVERAL anti-spyware programs.  The following, all FREE, can all be run together, without conflicts... so get as many as you want... even all of them.
     
    In all cases, make sure you continue to UPDATE these programs (their "definition" or "reference" files) on a regular basis (i would suggest weekly) before scanning.
     
    Ad-Aware SE Personal 1.06     http://majorgeeks.com/Ad-Aware_SE_Personal_d506.html
     
     
    Microsoft Anti-Spyware Beta [for win 2000 and winXP --- will *NOT* run on win98/98se nor winME ]
     
    [somewhat more specialized, but can't hurt to have] CWShredder 2.19:   http://majorgeeks.com/Trend_Micro_CWShredder_d3019.html
     
    There's also a somewhat-overlooked,  but (in my opinion) really great product called Win-Patrol http://www.majorgeeks.com/WinPatrol_d3380.html
     
    *********
     
    Firewall:  As with anti-virus, you want to be running ONLY ONE firewall at a time.
     
    Windows XP SP2 has a built-in firewall... just be sure to turn it on.   It's only a "one-way" firewall... if you want stronger/two-way protection, you can consider [again, among the FREE products]::
     
     
    or
     
     
    ********
     
    popup-blocker  [ You don't need all of these; any one should work]:

    Windows XP SP2 also has a built-in popup blocker option available there.... just make sure you've turned it on.

    Alternatively, there are several free popup blocker programs available, including the following:
    1) Yahoo Toolbar offers a popup blocker
        Note:  you can download this [with or] without their Anti-Spy feature.
      I believe other Toolbars (perhaps Google) also offer popup blockers... you can do the research.
     
    or
     
    2) 12Ghosts popup killer
       note:  i believe their popup blocker (by itself) is [still] free... you do NOT have to buy their entire suite.
     
    ***********
     
    Finally, there's also the matter of common-sense " SAFE-SURFING" --- you can save yourself a lot of problems if you do your best to keep away from certain categories of sites, like pornography, and  [any illegal] music downloads [just to name two key categories].
  • RKinner

    2 Intern

    •

    5851 Posts

    223

    0

    Posted November 22nd, 2005 12:00

    To  uninstall freesurfer just do Start, Control Panel, Add/Remove Programs and look for EMS FreeSurfer Mk II then uninstall it.

    To just turn it off or if the uninstall doesnnot work: run HijackTHis and check this line:

    O4 - HKLM\..\Run: [freesurfer] C:\Program Files\Free Surfer\fs20.exe

    the Fix Checked.

    The download is a bit hard to find.  This is a program that I use too but it has been replaced with a newer version which doesn't work as well for me.  It originally came from:

     

    http://www.kolumbus.fi/eero.muhonen/FS/Downloadfsc.htm

    but if you want the old version I think you can get a zip copy at:

     

    http://www.dslreports.com/r0/download/407445~ed342ec680f1a062a4ece3f90f655181/FreeSurfer21026.zip

     

    Ron
  • Rob9202

    10 Posts

    85

    0

    Posted December 19th, 2005 21:00

    I am having trouble running my spybot search and destroy program that you had me download.  The program seems to freeze every time I click on... search for updates.  Spybot says it is "trying to search for updates, if the icon below has not begin annimated, you have to wait because it may take a while to connect to the internet."  The only problem is, it doesn't ever annimate... what do i do to fix this problem?