Tech Problem Aggregator

Possible virus causing trouble with gameguard

Q: Possible virus causing trouble with gameguard

Hi I'm not sure if this should be posted in the games section, but it seems more like a virus is causing an issue in this case.

When I run Iris online, a new mmorpg which uses gameguard hack protection, nothing else but the game can connect to the internet. Prior to gameguard loading I can use either browser (IE or firefox) and they work absolutely fine.

However this all stops after I load the game, yet I can still connect to the game and it runs, but nothing else can connect to the internet despite being able to ping websites and that works and the internet says it is connected but never loads a page.

One or two times however I could run the browser and load sites fine whilst playing Iris and gameguard was running then too, but these times are rare and often when i close the game, the browsers stop working.

This only happens on this one game using gameguard, other times in the past playing other mmos with the same hack protection it worked fine. A simple way to fix this would be to stop playing the game, but it's a really fun game! Also another reason why I'm concerned and want to get to the bottom of this issue is no one else i spoke to on the game has this problem so it must be something wrong with my computer which I would like to fix.

I have avg spybot ad-aware malwarebytes webroot spy sweeper and have scanned my pc a few times and found nothing that could be causing this. If it is a network problem I would like some help figuring out how to fix it too!

Also, after i restart my computer the internet works as normal until next I try to run this game again.

So if anyone can help, please do and I would really appreciate it!
Here is the hijack this log from when the internet does work, if you need one for after i run gameguard (and hence when the internet doesnt work, let me know!):

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:03:26 PM, on 27/11/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18975)
Boot mode: Normal

Running processes:
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.iprimus.com.au
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=54896" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iprimus.com.au
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157" target="_blank" class="invilink">http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.iprimus.com.au:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.iPrimus.com.au;speedtouch;dsldevice;speedtouch.lan;dsldevice.lan;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.31.*;198.18.1.*;192.168.*;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - {472734EA-242A-422b-ADF8-83D1E48CC825} - (no file)
O1 - Hosts: ::1 localhost
O1 - Hosts: 216.107.241.2 aion.patcher.ncsoft.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] "%ProgramFiles%\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [IgfxTray] "C:\Windows\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\Windows\system32\hkcmd.exe"
O4 - HKLM\..\Run: [HDAudDeck] "C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe"
O4 - HKLM\..\Run: [Ad-Watch] "C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] "C:\Program Files\Microsoft Works\WksSb.exe" /AllUsers
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG10\avgtray.exe"
O4 - HKLM\..\Run: [Persistence] "C:\Windows\system32\igfxpers.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\EROProj.dll
O13 - Gopher Prefix:
O15 - Trusted Zone: http://list1.111222.cn
O15 - Trusted Zone: http://kan.pps.tv
O15 - Trusted Zone: http://list1.pps.tv
O15 - Trusted Zone: http://tvguide.pps.tv
O15 - Trusted Zone: http://vodguide.pps.tv
O15 - Trusted Zone: http://list1.ppstream.com
O15 - Trusted Zone: http://notice.ppstream.com
O15 - Trusted Zone: http://xml1.ppstream.com
O15 - Trusted Zone: http://xml2.ppstream.com
O15 - Trusted Zone: http://xml3.ppstream.com
O15 - Trusted Zone: http://list1.ppstream.net
O15 - Trusted Zone: http://list1.ppstv.com
O15 - Trusted Zone: http://list1.ppstv.net
O15 - ESC Trusted Zone: http://list1.111222.cn
O15 - ESC Trusted Zone: http://kan.pps.tv
O15 - ESC Trusted Zone: http://list1.pps.tv
O15 - ESC Trusted Zone: http://tvguide.pps.tv
O15 - ESC Trusted Zone: http://vodguide.pps.tv
O15 - ESC Trusted Zone: http://list1.ppstream.com
O15 - ESC Trusted Zone: http://notice.ppstream.com
O15 - ESC Trusted Zone: http://xml1.ppstream.com
O15 - ESC Trusted Zone: http://xml2.ppstream.com
O15 - ESC Trusted Zone: http://xml3.ppstream.com
O15 - ESC Trusted Zone: http://list1.ppstream.net
O15 - ESC Trusted Zone: http://list1.ppstv.com
O15 - ESC Trusted Zone: http://list1.ppstv.net
O17 - HKLM\System\CCS\Services\Tcpip\..\{B9BA7AF7-E34C-475F-96F7-E15BC47D1D0B}: NameServer = 203.134.24.70,203.134.26.70
O18 - Protocol: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASWLSVC - Unknown owner - C:\Windows\System32\ASWLSVC.exe (file missing)
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgfws.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\Windows\system32\Pen_Tablet.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

--
End of file - 9051 bytes


Also, here are the DDS results (the attach file is attached also) :
DDS (Ver_10-11-27.01) - NTFSx86
Run by User at 22:08:12.87 on Sat 27/11/2010
Internet Explorer: 8.0.6001.18975 BrowserJavaVersion: 1.6.0_20
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.61.1033.18.2046.794 [GMT 11:00]

SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG10\avgfws.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WTablet\Pen_TabletUser.exe
C:\Windows\system32\Pen_Tablet.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\User\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.iprimus.com.au
uDefault_Page_URL = hxxp://www.iprimus.com.au
uInternet Settings,ProxyOverride = *.iPrimus.com.au;speedtouch;dsldevice;speedtouch.lan;dsldevice.lan;10.*;172.16.*;172.17.*;172.18.*;172.19.*;172.20.*;172.21.*;172.22.*;172.23.*;172.24.*;172.25.*;172.26.*;172.27.*;172.28.*;172.29.*;172.30.*;172.31.*;198.18.1.*;192.168.*;*.local
uInternet Settings,ProxyServer = proxy.iprimus.com.au:8080
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: Encarta &Researcher: {9455301c-cf6b-11d3-a266-00c04f689c50} - c:\program files\common files\microsoft shared\reference 2001\EROProj.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [Windows Defender] "%ProgramFiles%\Windows Defender\MSASCui.exe" -hide
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [HDAudDeck] "c:\program files\via\viaudioi\vdeck\VDeck.exe"
mRun: [Ad-Watch] "c:\program files\lavasoft\ad-aware\AAWTray.exe"
mRun: [Microsoft Works Portfolio] "c:\program files\microsoft works\WksSb.exe" /AllUsers
mRun: [AVG_TRAY] "c:\program files\avg\avg10\avgtray.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {9455301C-CF6B-11D3-A266-00C04F689C50} - {9455301C-CF6B-11D3-A266-00C04F689C50} - c:\program files\common files\microsoft shared\reference 2001\EROProj.dll
Trusted Zone: 111222.cn\list1
Trusted Zone: microsoft.com
Trusted Zone: microsoft.com\download
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: pps.tv\kan
Trusted Zone: pps.tv\list1
Trusted Zone: pps.tv\tvguide
Trusted Zone: pps.tv\vodguide
Trusted Zone: ppstream.com\list1
Trusted Zone: ppstream.com\notice
Trusted Zone: ppstream.com\xml1
Trusted Zone: ppstream.com\xml2
Trusted Zone: ppstream.com\xml3
Trusted Zone: ppstream.net\list1
Trusted Zone: ppstv.com\list1
Trusted Zone: ppstv.net\list1
Trusted Zone: security_PPStream.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
TCP: {B9BA7AF7-E34C-475F-96F7-E15BC47D1D0B} = 203.134.24.70,203.134.26.70
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg10\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: msencarta - {74D92DF3-6D9D-11D1-8B38-006097DBED7A} - c:\program files\common files\microsoft shared\reference 2001\MSREF.DLL
Handler: msero - {B0D92A71-886B-453B-A649-1B91F93801E7} - c:\program files\common files\microsoft shared\reference 2001\msero.dll
Handler: msref - {74D92DF3-6D9D-11D1-8B38-006097DBED7A} - c:\program files\common files\microsoft shared\reference 2001\MSREF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
Hosts: 216.107.241.2 aion.patcher.ncsoft.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.avg.com/route/?d=4cdf036f&v=6.010.006.004&i=23&tp=ab&iy=&ychte=au&lng=en-GB&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\[email protected]\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\[email protected]\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\[email protected]\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg10\toolbar\firefox\[email protected]\components\xpavgtbapi.dll
FF - component: c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\[email protected]\components\YomikataDictionary.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\programdata\nexonjp\ngm\npNxGameJP.dll
FF - plugin: c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{d2d536a0-b6fc-11d5-9d10-0060b0fbd8ac}\platform\winnt_x86-msvc\plugins\NPseallaunch.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Extension: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Extension: DownThemAll!: {DDC359D1-844A-42a7-9AA1-88A850A938A8} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Extension: SealWeb Launcher: {d2d536a0-b6fc-11d5-9d10-0060b0fbd8ac} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{d2d536a0-b6fc-11d5-9d10-0060b0fbd8ac}
FF - Extension: Rikaichan: {0AA9101C-D3C1-4129-A9B7-D778C6A17F82} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{0AA9101C-D3C1-4129-A9B7-D778C6A17F82}
FF - Extension: Japanese-English Dictionary for rikaichan: {6D898772-AD34-4c16-86BB-9DE787A5DEA0} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{6D898772-AD34-4c16-86BB-9DE787A5DEA0}
FF - Extension: Rikaichan Japanese-English Dictionary File: [email protected] - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\[email protected]
FF - Extension: Quick Locale Switcher: {25A1388B-6B18-46c3-BEBA-A81915D0DE8F} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{25A1388B-6B18-46c3-BEBA-A81915D0DE8F}
FF - Extension: Furigana Inserter: [email protected] - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\[email protected]
FF - Extension: HTML Ruby: {e10bc159-aa26-41d8-aa24-65de9464ca5a} - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\{e10bc159-aa26-41d8-aa24-65de9464ca5a}
FF - Extension: Furigana Inserter Dictionary: [email protected] - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\[email protected]
FF - Extension: BarTab: [email protected] - c:\users\user\appdata\roaming\mozilla\firefox\profiles\fhvnwi68.default\extensions\[email protected]
FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Extension: AVG Safe Search: {3f963a5b-e555-4543-90e2-c3908898db71} - c:\program files\avg\avg10\Firefox
FF - Extension: AVG Security Toolbar em:version=6.010.006.004 em:displayname=AVG Security Toolbar em:iconURL=chrome://tavgp/skin/logo.ico em:creator=AVG Technologies em:description=AVG Security Toolbar em:homepageURL=http://www.avg.com >: [email protected] - c:\program files\avg\avg10\toolbar\firefox\[email protected]

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-11-14 64288]
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 29808]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2010-7-12 54112]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-9 299984]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-21 21504]
R2 avgfws;AVG Firewall;c:\program files\avg\avg10\avgfws.exe [2010-11-9 3229728]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-11-10 6127184]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-9-23 1375992]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-4-4 1153368]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-3-7 3032360]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2007-9-18 36112]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2010-11-25 1201640]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 27216]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2008-11-19 250880]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg10\toolbar\ToolbarBroker.exe [2010-11-14 517448]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-9-23 15264]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 u2kg54;BUFFALO WLI-U2-KG54 Wireless LAN Adapter Service;c:\windows\system32\drivers\rt2500usb.sys [2010-9-12 139904]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2009-3-7 15144]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 RelevantKnowledge;RelevantKnowledge;c:\program files\relevantknowledge\rlservice.exe /service --> c:\program files\relevantknowledge\rlservice.exe [?]

=============== Created Last 30 ================

2010-11-25 05:34:07 -------- d-----w- c:\program files\Fiddler2
2010-11-25 02:42:17 -------- d-----w- c:\program files\MSSOAP
2010-11-25 02:42:17 -------- d-----w- c:\program files\common files\MSSoap
2010-11-25 02:41:46 1563008 ----a-w- c:\windows\WRSetup.dll
2010-11-25 02:41:45 -------- d-----w- c:\users\user\appdata\roaming\Webroot
2010-11-25 02:41:45 -------- d-----w- c:\program files\Webroot
2010-11-25 02:41:45 -------- d-----w- c:\progra~2\Webroot
2010-11-25 02:34:10 -------- d-----w- c:\progra~2\PC Tools
2010-11-24 00:31:44 7680 ----a-w- c:\program files\internet explorer\iecompat.dll
2010-11-19 02:46:07 -------- d-----w- c:\progra~2\NVIDIA Corporation
2010-11-18 02:24:43 -------- d-----w- C:\GamesCampus
2010-11-16 08:50:02 -------- d-----w- c:\program files\DriveiQ
2010-11-14 01:31:25 -------- d-----w- c:\users\user\appdata\local\AVG Security Toolbar
2010-11-13 21:59:00 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-11-13 21:58:57 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-11-13 21:53:41 -------- d-----w- c:\users\user\appdata\local\Sunbelt Software
2010-11-13 21:30:23 -------- d-----w- c:\progra~2\AVG Security Toolbar
2010-11-13 21:28:03 -------- d-----w- c:\windows\system32\drivers\AVG
2010-11-13 21:17:20 -------- dc-h--w- c:\progra~2\{E961CE1B-C3EA-4882-9F67-F859B555D097}
2010-11-13 09:56:03 57960 ----a-w- c:\windows\system32\OpenCL.dll
2010-11-13 09:56:03 5473896 ----a-w- c:\windows\system32\nvwgf2um.dll
2010-11-13 09:56:02 813672 ----a-w- c:\windows\system32\nvgenco322030.dll
2010-11-13 09:56:02 14899816 ----a-w- c:\windows\system32\nvoglv32.dll
2010-11-13 09:56:02 10084360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-11-13 09:56:00 888424 ----a-w- c:\windows\system32\nvdispco322050.dll
2010-11-13 09:55:58 4837480 ----a-w- c:\windows\system32\nvcuda.dll
2010-11-13 09:55:58 2912360 ----a-w- c:\windows\system32\nvcuvid.dll
2010-11-13 09:55:58 2666600 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-11-13 09:55:55 13019752 ----a-w- c:\windows\system32\nvcompiler.dll
2010-11-13 09:55:03 -------- d-----w- c:\program files\NVIDIA Corporation
2010-11-13 06:24:57 -------- d-----w- c:\program files\Defraggler
2010-11-13 05:35:39 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{c2eb7694-9499-4be3-97ad-7999b33dde57}\mpengine.dll
2010-11-13 03:49:45 871484493 ----a-w- c:\program files\USA_Client_101029.exe
2010-11-13 01:28:40 -------- d-----w- c:\users\user\appdata\roaming\LolClient
2010-11-13 00:42:37 -------- d-----w- c:\program files\Disk1
2010-11-11 00:29:13 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2010-11-09 11:20:58 299984 ----a-w- c:\windows\system32\drivers\avgtdix.sys

==================== Find3M ====================

2010-10-18 23:41:44 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-10-16 18:55:00 1719912 ----a-w- c:\windows\system32\nvapi.dll
2010-10-16 18:55:00 10023528 ----a-w- c:\windows\system32\nvd3dum.dll
2010-09-23 07:46:08 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-09-13 13:56:41 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-08 06:01:28 916480 ----a-w- c:\windows\system32\wininet.dll
2010-09-08 05:57:18 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-09-08 05:57:05 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-09-08 05:56:53 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-09-08 05:56:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-09-08 05:04:36 385024 ----a-w- c:\windows\system32\html.iec
2010-09-08 04:26:46 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-09-08 04:25:15 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2010-09-06 16:20:29 125952 ----a-w- c:\windows\system32\srvsvc.dll
2010-09-06 16:19:06 17920 ----a-w- c:\windows\system32\netevent.dll
2010-08-31 15:46:37 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 15:46:37 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-31 15:44:31 531968 ----a-w- c:\windows\system32\comctl32.dll
2010-08-31 13:27:38 2038272 ----a-w- c:\windows\system32\win32k.sys

============= FINISH: 22:09:34.27 ===============

More replies
Answer Match 62.58%

Hi my computer was attacked by Vundo Trojan recently and I used SUPERAntiSpyware Professional Trial Version to get rid of it. This program did manage to detect and delete some files and I have the logs saved, but IE 7 does not function at all. Also, the computer is functioning at a slower rate than before the virus. I don't know if this IE 7 is causing the trouble or the virus.

I found these instructions for IE 7 problems on this site and followed them and am posting my results.(in red are the directions I followed)

[COLOR="Red"] Please do this:


Produce a list of IE add ons

* Click Here to download StartUplist. Save it to your desktop.
* Extract the files.
* You should now have StartupList.exe double click on it.
* Wait until it is complete.
* Right click on Browser Helper Objects (BHO), click on Save Node and all sub nodes as.. then when the save box appears type in BHO.txt and click Save.
* Now right click on ActiveX Objects, click on Save Node and all sub nodes as.. then when the save box appears type in ActiveX Objects.txt and click Save.
* Then right click on Internet Explore toolbar, click on Save Node and al l sub nodes as.. then when the save box appears type in IE toolbars.txt and click Save.
* Last one, right click on Internet Explore buttons/tools, click on Save Node and all sub nodes as.. then when the save box appears type in IE buttons.txt and click Save.


Open up the folder where Startuplist.... Read more

A:Virus causing trouble with IE 7

In addition to the above mentioned problem, I noticed that when I click on Add/Remove Programs(in the Control Panel) I get a message that says:

Windows cannot find 'C:\WINDOWS\system32\rundll32.exe'. Make sure you typed the name correctly, and then try again. To search for a file, click the start button, and then click Search.

1 more replies
Answer Match 56.28%

i really have no idea what to do about this one... malwarebytes didnt find it i did the full scan and the fast scan (both after most recent update).
i got hijackthis but i really dont wanna mess with it alone..

a friend suggested the use of combofix (did that but it didnt seem to change anything..).

ohh forgot to mention - it only happens when im trying to run an online game through the ijji reactor, gameguard loads and than it finds this virus and the shutdown thingy start (with 60sec timer) bcuz of "c:\windows\system32\services.exe" and some others.

sry for the messy post, thx allot in advance.

A:Gameguard finds a virus and begins "system shutdown"

--bump--, running on winXP 32 bit pro

1 more replies
Answer Match 48.3%

My 2nd computer recentaly stopped booting up as of late, the fans would spin for a seconed then shut down. Fearing the worst I removed all hardware (video card, ram, etc...) It still did the same thing. However I noticed that whenever I squezzed the wires going into the board, right before they got to the plug (20 pin connector) the computer would start to boot. When I used another power supply the motherboard booted up like regular. My question is, is their a way to fix the PSU i'm not in a good postion to buy another.

Thanks
 

A:PSU wires causing trouble

Don't be too sure that this a PSU problem. I had this same symptom on a little HP and when I wiggled the 20/24 pin input at the board it would boot. Then it wouldn't boot until I did it again. I tried another PSU and it worked for quite awhile. Then it wouldn't boot one day and after I wiggled the wires etc., it booted again. The 2nd PSU (seemed) to fix the problem until that one needed to be wiggled also. In other words, the problem could be at the socket on the board, not the power supply.
 

10 more replies
Answer Match 48.3%

hello
first of all im sorry if this is the wrong section
my problem: my windows 7 starts to a black screen, everything is booting up everything is fine but it doesnt get shown on the monitor. this started happening yesterday when all of a sudden the screen turned black and i was forced to restart and then shutdown pc because it started with black screen . if i remove the power cable from the monitor and put it back in the screen shows up but only for like a second
can you please help?

A:i think the monitor is causing trouble

You could be correct - go to the samsung site and see if it is still under warranty - if so explain the problem and see if you are eligible for a new monitor or free repair of the old one. I had the exact same problem with my viewsonic and it was under warranty and fixed and posted both ways for zero dollars.

6 more replies
Answer Match 48.3%

Hey everyone,

Recently I?ve been having an annoying piece of spyware which I cannot seem to get rid of. It?s called frmpop and it?s a blank-screen icon, only revealed by alt-tabbing and it keeps pushing all programs to the bag as if I?d alt-tab to it. It appears to happen during the first 10 minutes after I start my computer, but it?s bleeping annoying as it is. It's not supposed to happen so I want to get it out.

So far I?ve ran McAfee, Ad-aware, SuperAntiSpyware, and Spybot S&D, but neither have been able to pick it up and destroy it. I?m running a Windows XP computer with Firefox.
By the way, I?ve never run a HJT log, but it seems like it?s requested a lot, so if it?s needed I?m going to need some instructions too.

Any help would be greatly appreciated, thanks in advance!

A:Frmpop Causing Trouble

Please download SDFix by AndyManchesta and save it to your desktop.alternate downloadWhen using this tool, you must use the Administrator's account or an account with "Administrative rights"Double click SDFix.exe and it will extract the files to %systemdrive%(this is the drive that contains the Windows Directory, typically C:\SDFix). DO NOT use it just yet.Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".Open the SDFix folder and double click RunThis.bat to start the script.Type Y to begin the cleanup process.It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.Press any Key and it will restart the PC.When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.Once the desktop icons load, the SDFix report will open on screen and also save a copy into the SDFix folder as Report.txt.Copy and paste the contents of Report.txt in your next reply.-- If this error message is displayed when running SDFix: "The command prompt has been disabled by your administrator. Press any key to continue..."Plea... Read more

9 more replies
Answer Match 48.3%

HP Pavilion g7 1227nr.  Had to replace hard drive.  Have done so and have downloaded repair disks supplied by HP.  I have updated drivers and HP updates. Computer will not except wireless connection driver from HP.  Computer shows running Rralink RT5390 802.11b/g/n WiFi Adapter.  Have downloaded appropriate drivers from HP but computer refuses to recognize digital signature.  Also seems issue with Microsoft Virtual WiFi Miniport Adapter which showed up after download of 192 updates from Microsoft.  I can conntect to wifi using external D link but internal does not even show in network.
 
After 192 updates received blue screen showing the following.  Same issue that caused replacement of HD in first place.
 
Problem signature:
  Problem Event Name: BlueScreen
  OS Version: 6.1.7601.2.1.0.768.3
  Locale ID: 1033
 
Additional information about the problem:
  BCCode: 1000007e
  BCP1: FFFFFFFFC0000005
  BCP2: FFFFF880051B3A83
  BCP3: FFFFF8800359A168
  BCP4: FFFFF880035999C0
  OS Version: 6_1_7601
  Service Pack: 1_0
  Product: 768_1
 
Files that help describe the problem:
  C:\Windows\Minidump\082415-78733-01.dmp
  C:\Users\Sandra\AppData\Local\Temp\WER-93803-0.sysdata.xml
 
 
Please let me know where to go from here.

A:New HD but drivers are causing trouble! Help

Hi siminu2,
 
You mention that you had been receiving this issue blue screen error prior to replacing the hard drive. Is there another thread on the forum that might give me some insight to the issues before you changed hard drives?
 
I did a quick google search of that BCCode and it correlates to an invalid memory read error. This could be either because you have a bad memory module. Have you tried running memtest86 yet? You can download memtest here and burn it to a DVD.

more replies
Answer Match 48.3%

Hi,
My dad's pc has very poor performance on its internet connection. Its fastest download speed is about 90 kilobytes per second.  Even after upgrading our download speed ot 8 megabits per second, his pc still barely acheives 90 kilobytes per second. All of our other PCs have good download speeds.  Also, web browsing in Firefox makes the PC run slowly. Although the PC is about 8 years old, it was able to handle web browsing easily about two months ago. Due to all of these issues, my dad can't do any work on his computer. Is this being caused by some kind of malware? Thanks in advance.

A:Is malware causing trouble for this PC?

Download Minitoolbox - http://www.bleepingcomputer.com/download/minitoolbox/
Start the application.Set ticks everywhere.Click GO button.After is done a log will appear.Save and attach it here.

14 more replies
Answer Match 48.3%

Hi!
I need to be walked through how to get rid of this file or whatever needs to be done to get rid of this adware. But it is slowing down my computer as well as casusing lots of popups. Here is the

Logfile of HijackThis v1.99.1
Scan saved at 9:57:51 PM, on 3/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Kg\command.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\Personal Firewall\MpfService.exe
C:\PROGRA~1\McAfee\SpamKiller\MSKSrvr.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\hvnzomz.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\CRW\shwicon.exe
C:\Program Files\inKline Global\PC Booster\pcbooster.exe
C:\Program Files\McAfee\QuickClean\Plguni.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program File... Read more

A:Toolbar888 is causing big trouble

16 more replies
Answer Match 47.88%

I made the mistake of letting my little brother use my computer, and he got on IE and Firefox and downloaded God knows what. I've managed to delete most of the crap, but there are a few DLLs and misc. files hanging around that I can't delete.

Now it's taking longer to get on Firefox (I don't even touch IE anymore!) and I'm having pop-ups here and there and slow loading. Nothing major but I want to stop it now before it gets worse. I've already run Kaspersky Online Scanner and downloaded HijackThis so I'm ready to go if someone can help me out. :)

A:Suspicious DLLs causing trouble?

BUMP and some more information. The problem has gotten worse. The DLL files continue to multiply in my system32 folder, along with small .exe files. Using Firefox, I have random ads replacing images in the webpages I visit. Some pages no longer come up at all, but only at certain times. It's very random.

It's also affecting Windows Explorer, slowing things down and being very glitchy.

After running Kaspersky it only found one infected file with a trojan called not-a-virus:AdWare.Win32.SuperJuan.clf, but I'm sure there's something else causing trouble...

17 more replies
Answer Match 47.88%

Right and left click of my Y50 notebook not working smoothly..i was using an external mouse for past 6 months and when i started using my smart pad i found this one tottaly horrble.Especially the right and left clicks..Its not soft at all ..i have to apply a lot of preassure to my Smart pad for making right click work which is not fair.When i went through the net there are lot of people experiancing the same problem but i coudnt find a solution for this problem.Please get me a solution .I no more want an external mouse with my Laptop...Please Help

More replies
Answer Match 47.88%

Hello,
Recently I was infected with the Alureon trojan, which caused me much greif. However, after running MaleWareBytes several times, as well as installing and running AVG, I seemed to have removed all traceable parts of the trojan. All of my computer seems to be running normally, save for one very important thing: The Internet.

Now, I automatically assumed that it was either a firewall or a DNS problem. So first I disabled all of the firewalls which produced no effect. I then pinged google.com and received a response, so I'm relatively certain that it is not a DNS issue. It appears, though, to be intermittent, as sometimes on browsers the pages will load and sometimes they will not. I have tried reinstalling both google chrome and firefox, and it also had no effect.

I have dismissed the issue as an ISP problem, as I have two routers connected with separate wireless broadcasts, and one of them works and one of them does not. Both are managed by the same ISP, and unfortunately it's the faster one that does not work.

I think it would also be worth mentioning that my iPhone, when connected to the problematic router, receives internet just as intermittently as the computer, so I'm assuming it's not my computer that is infected.

The last thing I could possibly think was that it was my router that was infected, and if that truly is the case, I have absolutely no idea what to do apart from buying a new router.

A:Alureon causing trouble with internet

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Due to the restrictions on Windows 7, all tools should be started by right-click > Run as Administrator

------------------------------------------------------

We want all our members to perform the steps outlined in the link I'll give you below, before posting for assistance. There's a sticky at the top of this forum, and a
Quote:




Having problems with spyware and pop-ups? First Steps




link at the top of each page.

------------------------------------------------------

Please follow our pre-posting process outlined here:

http://www.techsupportforum.com/f50/...lp-305963.html

After running through all the steps, you shall have a proper set of logs. Please post/attach the logs in your next reply.

If you have trouble with one of the steps, simply move on to the next one, and make note of it in your reply.

------------------------------------------------------

2 more replies
Answer Match 47.88%

I use an Acer Veriton 7200D using Windows XP Professional SP1, bought a Labtec USB Webcam and installed it, it works and I thought everything was fine until I noticed all the icons on the sys tray have disappeared, the only one left was the Labtec camera icon.

Second thing I noticed was when I want to see MY COMPUTER, it shows up nothing, the only thing showing was a torch saying "searching", so I deinstalled the whole thing and get system retore to get my icon and MY COMPUTER back.

I then installed the camera on my daughter's machine which uses WIndows XP home and it was all right. Anybody has any idea what is going on with mine?
 

A:Labtec Webcam causing trouble

i thought so
 

1 more replies
Answer Match 47.88%

I've recieved multiple viruses (probably through a security hole in java as I noticed the java icon started at time of infection). Virus types I've recieved.

trojan.Downloader
Rogue.Multiple.H
Trojan.FakeAlert
Trojan.Agent
Trojan.TDSS
Alureon-BY
Alureon-BX
Alureon-CD
Rogue.SystemSecurity
Hijack.Userinit

I have used Avast, Malwarebyes, unhackme, avg antirootkit and GMER to try to solve this problem. I understand that at this point getting my computer 100% clean is not something that can be accomplished with any certainty and that I should probably reformat and reinstall. However I wish to do whatever that can be done to solve without reformatting the computer even with that fact in mind.

I have successfully cleaned many of the viruses of the computer and at this point am not getting any hits from multiple scans. GMER does not detect any rootkit activity and the last files of Alureon seem to have been removed.

I am pretty certain there is still virus activity due to these symptoms...

If I connect to the internet the computer tries to access numerous sites probably trying to download more viruses.
On startup the computer takes lots of time "configuring network connections", probably viruse related.

Here are the requested scans. Please Help

DDS (Ver_09-06-26.01) - NTFSx86
Run by security1 at 12:59:40.84 on Sat 07/18/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.894.525 [GMT -7:00]

AV: Trend Micro Of... Read more

A:Alureon or other rootkit still causing trouble (I think)

hi,

sorry for delay, no shortage of posters. Still need help, reply to my post.

You use a proxy to access the internet?

you can delete this .exe out of the Windows Temp:
IB51B.EXE

1 more replies
Answer Match 47.88%

Norton 10 alerted to the backdoor trojan, it was missed by hijack, spybot and hitman pro 3.5. Emsisoft picked up a bloodhound. malwarbytes also picked up trojan on the first scan, after that any further scans show nothing. My computer tech who's no longer available had combofix run and it quarantined disk.sys.vir and 31793ws9.dll.vir all of which only show up on norton scans as quarantined while the other programs show clean. Emsisoft is the only active program that is blocking the redirects at the moment, which is still going on. I ran through the list here and everything went smoothly except for gmer, I tried twice and in both cases about 2hrs in to the scan the computer restarts. a full system scan with any of the programs takes about 3~5 hrs, not anything new just seems like a loong time. I've also attached the norton screen shots if help full. norton update also hangs at 99% the last good virus definition was 3-18-11 rev 19.

In the middle of trying to post this on that laptop, firefox no longer connects to the web, signal is good with connection according to radio. no alert from any of the virus programs, just constant searching to blankness. posting now from another laptop.

.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Scott at 1:00:24.35 on Fri 03/25/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1026 [GMT -7:00]
.
AV: Emsisoft Anti-Malware *Enabled/Updated* {0F8591BB-342B-44... Read more

A:backdoor.tidesrv.!inf causing trouble

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will ap... Read more

22 more replies
Answer Match 47.88%

Hi I'm having problems when I run vuze on vista it works for a while and intermittenly causes networking errors. Sometimes it says that the network is marked as hidden and other times it claims my password is incorrect. Restarts typically fix this problem, but makes downloading larger files a pain since I can't download over night do to my network card not working. I'm using a Belkin N1 card with a Belkin N1 router.

More replies
Answer Match 47.88%

I've looked thru the forums but have not been able to find the answer to this question so here goes, hope I'm not asking a repeat.

I have a Orinoco RG1000 with a DSL connection. Everything is working fine on 2 laptops and a desktop unit. The problem is that about every 5 minutes I get a message that pops up telling me that "one of more wireless networks are available" and I have to keep choosing my network and reconnecting to it. The other network that is available must be a neighbors linksys system. How do I stop the computers from seeing this network and asking me if I want to connect to it? Each time it sees it, I loose connection to my RG until I select it again.

I have gone to the Wireless Connection Properties dialog box in XP and put my network first in the preferred list and have deleted the "linksys" network from that list but that doesn't help any.

I do have a cordless phone, but it is the 5.8 MHz version, I have heard that 2.4 MHz phones can cause troubles.

Anyone have an idea?

Thanks
 

A:other available wireless networks causing trouble

6 more replies
Answer Match 47.46%

Man is my problem complicated.....it started about a month ago, but i wasnt here for half of that month, so i didnt use my computer:

-I think this started when my bro was downloading something from ares. Afterwards, my internet started failing, and i eventually didnt have any more internet. I scanned my computer with trend micro anti-virus 2007, it found nothing, but i guess its because its expired, heh, trust me, i tried it a lot. I also scanned with spy sweeper and it found nothing either, its expired too. Then programs started acting weird, some startup programs didnt start up, and then spy sweeper didnt want to sweep.

-My computer started going slower, and the worst part is that everytime i try to shut down my computer in normal mode after i log in into an account, i get a blue screen.Sometimes, when i try to open up a program, nothing happens, i try 5 more times and still nothing! Also, i just found out that if i plug in an xbox 360 controller, another blue screen pops up, what the heck man! Also, when i click on a link in google, it sends me somewhere else, but if i go back by clicking the back button twice, and press on the same link again, it works.

-I cant connect to the internet in normal mode(i dont know if i already said that before). I can only get in the internet through safe mode with networking. Ive got windows vista by the way, when i check my network's status, it tells me its on a limited network. I contacted my internet provider, and they couldnt h... Read more

A:Gaaaah! Im Infected! And It's Causing Lots Of Trouble!

Note: My printer doesnt want to respond either.......

2 more replies
Answer Match 47.46%

Hi,
Recently Norton Anti-virus started showing me that the Trojan Winctrl32.dll has been detected on my computer and it was unable to delete it.
I did some research on it but unable to find a solution only other than getting a professional help. I have never used the HJT which i believe will be needed for even the first step to get some help. So i read about it and download the .exe file from Trend Micro Inc. website.

Now should i just run it like any other installer or do i need to do anything different?
Then comes the real part that how to take care of the actual culprit the Winctrl32.dll?
I need help as i don't want to format and rebuild this computer.
Thanks

 

More replies
Answer Match 47.46%

Hello! Earlier this week, I got a nasty case of the Antimalware Doctor and AVE spyware programs. I got it cleaned out using rkill and Malwarebytes... or so I thought. I still randomly am getting thing popping up, and both Malwarebytes and AVG Free (note that my old version of McAfee Virus Scan doesn't work, though it is still installed) are finding random infections of trojans and spyware. I suspect there's a rootkit somewhere, so I need your help finding it! Here is my DDS log:DDS (Ver_10-03-17.01) - NTFSx86 Run by Janice at 14:15:38.38 on Thu 04/15/2010Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.703.164 [GMT -4:00]============== Running Processes ===============C:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\WINDOWS\system32\svchost.exe -k WudfServiceGroupsvchost.exesvchost.exeC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\WINDOWS\system32\spoolsv.exesvchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:\Program Files\a-squared Free\a2service.exeC:\Program Files\Network Associates\VirusScan\avsynmgr.exeC:\Program Files\Apoint\Apoint.exeC:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exeC:\Program Files�... Read more

A:Former Anitmalware Doctor / AVE infection, still causing trouble

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.We need to create an OTL ReportPlease download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.In the custom scan box paste the following:CODEnetsvcsmsconfigsafebootminimalsafebootnetworkactivexdrivers32%systemroot%�... Read more

23 more replies
Answer Match 47.46%

Hey All,
Apologies in advance if this is a bit long winded, but I'm struggling to reconstruct the events that have led to what appears to be a fairly serious problem.

I suspect my trouble started about the 15th of March (Today being Apr 6 09) when I upgraded from AVG 7x? to AVG 8.5. on an XP Home edition machine. Sorry if I can't be more specific, but I just noticed a general slow down and what seemed quirky behavior that was initially all too easy to dismiss . At any rate, long about March 28th (a little over a week ago) AVG did detect a Trojan, and supposedly quarantined it. Fair enough... but over the course of the last week I began to notice that AVG was taking 8-9 hours to complete a scan without ever finding much, but a few cookies. It was then that I started thinking it might be time to look for another AV program. I decided to try Avast on a new machine I've been driving for 8-10 hours per day for the last few weeks, with it in mind to replace AVG on all seven of the other computers in the house -- IF Avast worked-out to my liking. Meanwhile, on a brief visit to the machine in question, I noticed an alert of some or other infected.dll being quarantined. Once again I didn't think much of it, and went back to work at the new machine. Later, on a subsequent visit to the problem machine (where I run all my email etc.) I noticed that my preferred code editor (crimson) could not be started owing to a missing dll, with an alert that re-installing might r... Read more

A:missing Mystery dll causing all kinds of trouble!

Index % of PCs with item Code Data
1 0.0% O16 {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
2 0.0% O16 {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
3 0.0% O16 {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
4 0.0% O16 {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab
5 0.0% O16 {72C9EA8F-8965-40C2-ABAD-D460A5815F86} (hostCntrlIE Class) - http://host.oddcast.com/hostClientIE.cab
6 0.0% O16 {F73BE1F4-82AA-4405-AB81-FAFB5A122359} (SiteBuilderEditor Class) - http://store02.prostores.com/storeadmin/utilities/pssbedit.cab
7 0.0% O16 {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
8 0.0% O16 {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1188522133171
9 0.0% O16 {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1188522730858
10 0.0% O16 {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
11 0.0% O16 {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - ht... Read more

3 more replies
Answer Match 47.46%

This is the first time in a while I have had trouble removing something from someones computer. I've used several different programs to try and detect it but they come up with nothing. I've used Ewido, AVG and trojan hunter. I have to run trojan hunter again because it found some .dll attatched it an exe called lhp.exe I think but the scan got cut off. It wasn't the same .dll causing problems with the winlogin. I have deleted the file but it comes back with a different name. It also changes its name every time windows is restarted. I will highlight it in bold.

Logfile of HijackThis v1.99.1
Scan saved at 12:07:47 PM, on 12/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:... Read more

A:Trouble removing .dll attached to winlogin causing pop ups

9 more replies
Answer Match 47.46%

I've recently started university and I got a brand new laptop for it. I was using it earlier today when it crashed for seemingly no reason before simply switching off, no shutdown sequence or anything like that. I should add that it hasn't crashed before. I didn't think too much of it but when I switched it back on I got a message saying that system information was missing, in total I think there were 4 things, product key, product configuration, serial number and product number. Of course, this ended up with the system telling me my copy of Windows 7 wasn't genuine but I put the key back in and this message has now disappeared, but the other messages are still there.
The other thing that was wrong was that I couldn't connect to the internet through a wired connection, only a wireless connection. When I try to connect through a wired connection I get a message saying "Local Area Connection has an invalid IP address" or something to that effect.
So I have two questions. 1. How do I re-enter all this information that's apparently gone missing and 2. Why can I only connect to the internet wirelessly?

Thanks for any help you can give.

A:Laptop randomly crashed, causing trouble

Hi and welcome to TSF have you tried system restore,you can also try a repair
http://www.sevenforums.com/tutorials...up-repair.html do you have any error flags in device manager ie yellow ! or red Xs,have you looked in the eventviewer to try to find some info on your issue,please first answer the questions and check for error flags and info before trying anything else

6 more replies
Answer Match 47.04%

I have windows Xp on my computer. I have a computer game called "Zues: master of olympus". Everytime i play it i get a message that says:

win32k.sys-Address BF8F3E67 base at BF800000,DateStamp 3db4ad9d

or

win32k.sys-Address 13F8E2CAF base at BF800000, DateStamp 3db4ad9d
PLEASE ANY HELP WILL BE APPRECIATED
 

A:Zeus: Master of Olympus: win32k.sys-causing trouble HELP!!!

6 more replies
Answer Match 47.04%

Been tracking down an odd glitch in HDTV playback.
the glitch I now remember only started after I plugged in the NIC Intel Pro 1000

I think it has to do with IRQ 16 being shared between those 2 devices.

other than pulling the NIC, how can I force these to use a distinct IRQ?

in the bios, PNP OS is set to no.
If I set to yes, will windows then be able to force a change?

A:IRQ shared between video card and gigabit NIC causing trouble

I dont think you can actually force a device to use a distinct irq per say. If one device is conflicting with the other; i would say go in to the windows settings like you have shown above in the image; and select let windows choose the settings(not sure what it says exactly as i havent been in there in quite some time) But i believe it will have the word automatic in it and if it will let you; choose that setting then reboot when it asks you to. EDIT: Also; You could try completely uninstalling the NIC; rebooting; and letting windows reinstall it and hopefully that will clear things up

5 more replies
Answer Match 47.04%

pop-ups and slowness....please help if you can...thanks
Logfile of HijackThis v1.99.1
Scan saved at 5:19:32 PM, on 2/25/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Progr... Read more

A:Solved: win xp malware-winfixer,winantivirus and others causing trouble

11 more replies
Answer Match 47.04%

First I want to say that the drive works without problems at the correct speed. The problems come upon disconnect. I also want to to stress that USB 2.0 discs are working flawlessly.

If I use safe eject and the look in the device manager I get an error 47 saying that it has been shut down but not disconnected, it also says I can rectify it by disconnecting and reconnecting but this does not work. If I do so the drive will not be recognized.

The enclosure has a power switch. After a safe eject I have tried both pulling the USB cable while power is still on and also going the other way by first shutting the power down. In both cases the error 47 shows in device manager. When this happens the CPU load goes up to about 20% and stays that way when it before was around 0 at idle.

If I reboot the drive reconnects and I have no problem with it unless I try to safely eject it again.

Sometimes I get a BSOD when shutting down the computer(I want to stress that it so far only happens during shutdown).

I downloaded a small program that could read the crashdump and it blames the Etron host controller.
Does anybody have any experience with this?

A:External USB 3.0 drive causing trouble in device manager.

I had a similar problem awhile back what I did to resolve it was went to my laptops manufacture website and downloaded
the latest driver for the usb that solved the problem .

2 more replies
Answer Match 47.04%

i am getting real annoying popups that keep appearing on my machine from all sorts of websites like crazygirls and WinAntivirus and others that i do not know and have never heard of. this is really annoying me and would really appreciate if anybody could help.
 

A:winrar, crazygirl and other popups causing trouble (read!)

prestorock said:

Hello, before i ask i would like to mention i cant understand in depth computer details so you may have to explain how to do something to me if its hard.

I keep getting pop ups when i visit sites and even when im not even online. I have just reformatted my computer a month ago because of a virus with the same symptoms (WinAntiVirus, i didnt install it jsut kept getting popups) Even when i had never installed or downloaded anything it just popped up on my computer. Please help!

Oh and i run Windows XP SP2 and Norton AntiVirus. Im also 13 but my father taught me alot about the computer and i apperantly am capable of doing more than my mother can (HA!). She also just bought the Norton subscription after i reformatted so i wouldnt get it again but it stil does.

Another thing i hav enoticed is that my cookie settings keep going down to Accept all cookies. Even after i set it to Block all cookies.

Please help! I do not wish to reformat again! (I can also get my dad to do the regestry things and others that could potentionaly destroy my computer.Click to expand...

i'm having the same problem, could someone please help me!!

HJT log:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 21:38:52, on 24/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:... Read more

3 more replies
Answer Match 47.04%

Hi,
Recently my computer has been running slowly, applications are taking up to 10 seconds to start and firefox/internet explorer take ages to load sites. So after running Hijackthis, i noticed an oddity in the log... 'hwxkor32.dll' . A quick search on google showed this was some kind of virus/malware. I've tried multiple methods to remove it, including safemode/delete, command line unregistering, and adaware (which didn't find it) but it's still there. Anyway, I believe this dll is the source of my problems but here is the log just to make sure...
Logfile of HijackThis v1.99.1
Scan saved at 5:26:58 PM, on 9/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
... Read more

A:Trouble removing a problem DLL causing slow performance

16 more replies
Answer Match 47.04%

Hi

Last night, I clicked on a link provided by Google search which redirected me to random websites and crashed my laptop. When my laptop rebooted, there was a "internet security" icon sitting on my desktop which had not been there previously. I did a system restore and then ran a full scan with both Symantec and MBAM. Symantec was able to delete everything it caught. So did MBAM. After restarting my laptop and re-running MBAM however, it kept re-catching a Trojan.Agent svchost.exe. I've restarted and re-run MBAM multiple times, but the svchost.exe never seems to go away. I'm not sure what to do.

The virus seems to only redirect links I click from a Google search. It doesn't do anything if I search from a different engine. Also, it seems it has rendered my Google Chrome unusable.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421
Run by Bee at 14:06:04 on 2012-03-12
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3891.1834 [GMT -4:00]
.
AV: Symantec Endpoint Protection *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Symantec Endpoint Protection *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\syst... Read more

A:Trouble with svchost.exe, causing Google links to redirect

Good evening. Download aswMBR.exe from here and save it to your Desktop. Double click the tool to run it. When prompted "Would you like to download latest Avast! virus definitions?" click No . Click the Scan button to, well, start the scan - obvious really! Once the scan reports "Scan finished successfully" click Save log. On my system it offers to save it to the Desktop, which may or may not be it's default behaviour, but it's as handy a place as any. You'll also see a file called MBR.dat appear as well - this is a backup that it created, just in case it's needed. Keep it handy for now.I'd like the contents of aswMBR.txt in your next reply, if you'd be so kind.

17 more replies
Answer Match 45.36%

Forgive the long detailed post. I've read many forums solving my own problems, but this time I need to post. On Nov 7 I managed to download something that infected my computer. Since then I've been fighting it. I know TDSS and Brastk were on there though I no longer see references to those that I know of. I've successfully run HJT, MalwareBytes, CCleaner, AdAware (old version), and AdAware 2008 to clean out a lot but I still have some major issues.

Running Windows XP SP3, HP computer

Problems:
1. Browser hijacked. When I search from Yahoo and click on a link there, redirected via go.,yahoo.com to some junk page. Sometimes if type direct link I want it works, but I cant get to many spyware, adware, malware, rootkit cleaner pages (page not found). Sometimes if I use the IP address instead of DNS name it works. I also cant get to many forum help pages. I got to this site's main page by IP address but cant click links. So right now I am typing this from another computer.

2. Programs I managed to download (mostly in Safe with Networking), are only somewhat successful, even in Safe Mode. a. HJT always works, and I'll attempt to post log next.
b. Ad Aware 2008 I downloaded and ran a few times. But for some reason, even though I selected English, the options are in another language. And though it originally found 36, I chose wrong option to disinfect. Then later it only found 2 and disinfected them (one looked like a search helper). Now, whenever I run it, it hangs... Read more

A:Browser hijacked and probably more causing trouble even running detection programs in Safe Mode

I tried to post HJT log but got rejected as it's older version. Well, I cant install the new one. I downloaded it, but the installer wont run in safe mode. Neither will RootKit Revealer. I will try them next time I go to Normal Mode. I am currently running AVG Anti-Spyware which detected some things already.

4 more replies
Answer Match 44.94%

Hello.I came home from work today and noticed that my computer was running much slower than normal. I noticed a new shortcut on the desktop and asked my son what it was.He had installed a game called Shaiya earlier in the day. A program called GameGuard was also automatically installed with the game. After looking into both of these subjects it seems that the GameGuard program is problematic for many people and I am now assuming that it is what has made the sudden change in my computers speed. It also seems that uninstalling the programs is difficult and involves manually modifying registry items. I am not comfortable doing this and I am posting this topic to get some professional help. The only other info in this forum I could find on this topic mentioned needing to post a HJT log so that is what I am doing here.Below I have pasted the following txt files per the instructions in the forum intro. I hope I have done this right.1. Kapersky scan results.2. DSS results 13. DSS results 2.Thanks in advance for your help and I look forward to hearing from you.--------------------------------------------------------------------------------KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, June 10, 2008 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Wednesday, June 11, 2008 02:24:21 Records in database: 849818--------------------------------------------------------------------... Read more

A:Gameguard

Welcome to the BleepingComputer Forums. Since it has been a few days, please post a new HijackThis log. Thank you for your patience.If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

14 more replies
Answer Match 44.94%

hello so there is this gameguard application for games basically any game using GamGuard protection when I press to launch it says "GameGuard initial error please kill any other conflict apps and restart the game" do you have any ideas?

Thank you waiting for answer
 

A:GameGuard

http://www.gameguard.co.kr/eng/FAQ_500.htm

Try this maybe...
 

1 more replies
Answer Match 44.94%

anyone know how to fix the gameguard 104 error? I needa restart my computer everytime i close the game. =/ its pretty annoyin
 

More replies
Answer Match 44.1%

This is a heads up for anyone playing games that run Gameguard, such as Maplestory Mabinogi or Gunbound.
For anyone who read my thread a few days ago, my computer was crashing during gameplay of a few games, Maplestory most notably. The probably was diagnosed as and agreed apon by the responses as a Graphics Card overheat error, which concerned me as it hasn't happened before. I may now have found the problem, to which I would like to inform my fellow gamers.

The problem started when my girlfriend's brand new computer started having the same issue last night out of the blue. I decided to scour the web for possible problems with the game. I found a thread somewhere describing an error with gameguard BSODing when there was a critical error in the program. Doing more homework, I found out that gameguard's error handler is tied right into the kernal process of windows and activated a BSOD instead of crashing just the game. Wondering what could have possibly done that, I decided to check gameguard's website WHEN I remembered: I have other gameguard games.

I uninstalled them all(including maplestory) did a system search for gameguard anything and manually deleted it. Ran CCleaner to get rid of leftover files(probably was unneccesary). Redownloaded Maplestory and ran the program. It's been running(and still is) error free for the last hour and a half(twice as long as I've made it in the last 3 weeks). I was gonna try it on my girlfriend's compute... Read more

More replies
Answer Match 44.1%

I get it when I play ANY game using Gameguard, such as Soldier Front or Maple Story..

It tells me to close the application causing the problem. What am I supposed to do?
 

A:Gameguard error 114?

12 more replies
Answer Match 44.1%

:Hello,Well when i play a free mmo game like flyff and gunbound then i try to logg in and after i log in either 30 secs or 1 min later it shutsdown and i have to restart my computer after this happens. This only happens when then game uses nprotect gameguard. please help
 

More replies
Answer Match 44.1%

guys i have like 2 weeks wit this error i cant fix it.
i play soldier front when is loading the game appear this message
"game guard initialization. try rebooting nd executing the game or close
the program considered colliton"

ps: i shut down my firewall reinstall again the game no works.
os: win xp
 

A:error gameguard 114

i dunno....maybe you have a file on your computer it doesn't like.....try scanning your computer for viruses......if you have a file that may look like a virus, as several hacks do so, sometimes anti-cheat systems will cut you off.

or you may have an external process it may not like...

i really don't know otherwise...
uninstall...
manually make sure all lthe files are deleted
and reinstall
..... i dunno otherwise.
 

1 more replies
Answer Match 44.1%

Read the title... enough said. I'm just curious how many people have thought "YES! NO MORE HACKERS IN *insert game here*!" Then, there are still thousands of hackers. The games I play, like Gunz, Gunbound, and Soldier Front are filled with hackers. Even Rakion. GameGuard does absolutely nothing... post your ideas here!
 

A:nProtect GameGuard

6 more replies
Answer Match 44.1%

As of yesterday any games that have Game Guard do not work. They all give me error message 114.

The games I play with gameguard are Grand Chase and Gunz. I have contacted my ISP, Dell and the game providers via help desk. My ISP and Dell said it was the game, Gunz said it was my computer, I haven't recieved a response from Grand Chase.

Now, I have tried all solutions I have found on the internet. I do not have a firewall. Nothing has changed since the day before yesterday on my computer. It happened over night basically, when my computer wasn't even on.

I do have AVG anti-virus, however that NEVER caused this before. I've been playing this games along side AVG for a long time. I even have AVG disabled when I play, it still doesn't work.
It is really frustrating me, and honestly I am really tempted to throw this computer out my door.
 

A:GameGuard Error 114

I would try contacting the game provider..........

and then again you could get bumped up to a level 3 tech that still knows less than you lol
 

2 more replies
Answer Match 44.1%

ok so you've heard of gunz etc etc and how while launching Gunz.exe it also starts up gameguard.exe anti hacking prevention system created by ijji to well...prevent hackers, now dont say to shut down gamguard cause u cant run gunz without it. Anyways they've jsut recently upgraded gameguard because of some bugs etc, and ever since over 70% of gunz players have been experiencing FPS lag. now heres the link of the gunzfactor forum. its just to give u an overview of the main program, (already linked to the main thread about it) and everyone has already mention that it isn't the CPU of video card its something with the gameguard anti-virus, but maybe you guys might know?

link: http://www.gunzfactor.com/forums/f43..._lag_come.html

thanks again xD

More replies
Answer Match 44.1%

So when I play games like CrossFire... well online games that has to do with Gameguard it doesnt work! Can someone HELP ME!
HERE'S WHAT HAPPENS(CrossFire and this happens on other MMO's to) : First I start the game, then wait for it then then the GameGuard BOX pops up. It tell's that gameguard is Loading. Then AFTER the box dissappears, THIS another box appears's saying nothing. No text or anything, the only option i could do is "OK". So I press "OK" and It leads me to the gameguard website saying an error (114) occured! I've try EVERYTHING (suggestion) it says to do but NONE of them WORK!
SO PLEASE HELP!!! THX

 

More replies
Answer Match 44.1%

I'm trying to play Trickster Online. It has never worked since I installed it a few weeks ago and their tech support never answered my email. It has this anti-hacking software called nProtect Gameguard. You have to go through its updating process in order to play. The problem is I keep getting error 380 and so it exits. Every guide I find is in bad English (nProtect is Korean) and doens't tell you how to fix it. I'm not using a proxy or anything. Can anyone help me out?
 

A:GameGuard error 380

Look at this forum maybe they can help you out.
http://flyff.gpotato.com/phpbb/viewtopic.php?t=2977&start=225&sid=f4b64f3f8ddfdf2e5e0d146edce05e4f
 

1 more replies
Answer Match 44.1%

Hi hi.So I play ijji's Gunz: The Duel. I tried playing Exteel (both of which games use Nprotect GameGuard). Exteel's gameguard would always come up with an error message, and as such, I couldn't play the game. So I gave up on it, and went back to Gunz. It seems the Gunz gameguard was overwritten with the Exteel gameguard, as the same error message now occured whenever I tried to play Gunz.So I uninstalled Exteel, reinstalled Gunz, deleted GameGuard, only to find that GameGuard is, in fact, a rootkit, and all that technical stuff is beyond me.So I deleted the GameGuard that installs with Gunz, knowing that upon trying to play the game, it would re-download and reinstall (with the hopes of re-overwriting Exteel's gameguard), but it came up with an error message saying:"GameGuard initialization error. Try rebooting and executing the game or close the program considered to cause a collision."Basically, I want to be able to play Gunz: The Duel again, without formatting my computer.Here are my DSS Logs:Deckard's System Scanner v20071014.68Run by Brian Collins on 2008-04-13 12:18:17Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------Successfully created a Deckard's System Scanner Restore Point.-- Last 5 Restore Point(s) --75: 2008-04-13 04:18:32 UTC - RP852 - Deckard's System Scanner Restore Point74: 2008-04-12 08:23:15 UTC - RP851 - Syst... Read more

A:Gameguard Clash

Hello WyreZI apologize for the delay in response as we get overwhelmed at times but we are trying our best to keep up.If you have since resolved the original problem you were having would appreciate you letting us know. If not please perform the following below so I can have a look at the current condition of your machine.Thanks and again sorry for the delay.Please download Deckard's System Scanner (DSS) and save to your Desktop.alternate download siteDSS will do the following:Create a new System Restore point in Windows XP and Vista.Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.Check some important areas of your system and produce a report for an analyst to review.Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.You must be logged onto an account with administrator privileges when using.Close all applications and windows.Double-click on dss.exe to run it and follow the prompts.If your anti-virus or firewall complains, please allow this script to run as it is not
malicious.When the scan is complete, two text files will open in Notepad:main.txt <- this one will be maximizedextra.txt <- this one will be minimizedIf not, they both can be found in the C:\Deckard\System Scanner folder.Please copy (Ctrl+C) and paste (C... Read more

2 more replies
Answer Match 44.1%

Hi guys, I recently started playing Trickster Online again and was upset to find out that their version of nProtect GameGuard won't let me use internet browsers while it's running. I was hoping someone would be able to help me out and I hope this problem is fixable. Thanks in advance, and by the way I'm using my laptop.
 

A:GameGuard on Vista

http://global.nprotect.com/GGP_download/index.php?user_lang=en

hope this helps you

its the website for it where you should be able to download the program and update the game files from there (if its anything like battlefield 2 and punkbuster)

I dont play the game nor any games that use it but from what i see thats what I gather
 

1 more replies
Answer Match 44.1%

hi all the problems i have occur with game gaurd on such games as albatross18,and rakion.

as for both of these games there was a time when i was able to play them, then gradualy i started to get errors and no longer could play.

rakion loads up the nprotect/gameguard then acts like its going to start but i get no screen or anything.then when i try to run it again it says "the game is overlapped,or gamegaurd is already in execution.Please try again after you terminate the game" or this "this is game guard initilization error.please try again after you re-boot or close any other program that may be coliding" well ive checked and the game isnt running, and no processes of the game or gameguard are running,and i also cant find anything that would colide with it.. some people said it might be spyware of some sort,but i scanned with 3 different programs and im clean according to them.

any help is appreciated thank you
 

More replies
Answer Match 44.1%

i got some problems regarding with my online game with is RANONLINE which has game guard, the game guard keeps giving me error 100 as i search at internet they sey it is a VIRUS thats why i came up in here. i had removed and installed the game many times, i had scanned my pc using norton, then which to avira but still problem exist. then i found this combo fix and run it. then it gives me the log after combo fix has finished. BUT still problem exist. please help me. i don't know what to do..

A:GAMEGUARD ERROR 100

Hello, Welcome to BleepingComputer.I'm nasdaq and will be helping you.If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.===Please DownloadTDSSKiller.zip>>> Double-click on TDSSKiller.exe to run the application.Click on the Start Scan button and wait for the scan and disinfection process to be over.If an infected file is detected, the default action will be Cure, click on Continue
If a suspicious file is detected, the default action will be Skip, click on Continue
If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) to your desktop. Double click the aswMBR.exe to run it Click the "Scan" button to start scan. Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANTPlease post the contents of that log in your next reply.There shall also be a file on your desktop named MBR.dat. Righ... Read more

2 more replies
Answer Match 44.1%

Ok, so I go into any game with nProtect GameGuard (FlyFF, ijji Gunz) and I get the same two errors when GameGuard tries to Authenticate.

"Program Error
GameMon.des.exe has generated errors and will be closed by
Windows. You will need to restart the program
An error log is being created."

"GameGuard execute error : 114
GameGuard initialization error. Try rebooting and executing the game or close the program considered to cause a collision."

Now of course the first thing I do is restart the program, then reboot and try again, after that didn't work I closed all other applications that I could, when that failed I looked around and found out it could be a virus, used Spy Sweeper and cleared 3 trojans that AVG didn't know existed, and I still get the errors when I try to start the game.

My drivers are up to date, I've turned off my Anti-virus, I've remade accounts, and yet it still doesn't run.

I've played before, so I know the games work, but here are my specs anyways.

------------------
System Information
------------------
Time of this report: 8/27/2007, 14:18:53
Machine name: PARADYME-UHL9Y8
Operating System: Windows 2000 Professional (5.0, Build 2195) Service Pack 4
Language: English (Regional Setting: English)
System Manufacturer: INTELR
System Model: AWRDACPI
BIOS: Phoenix - AwardBIOS v6.00PG
Processor: Intel(R) Pentium(R) 4 CPU 3.20GHz (2 CPUs), ~3.2GHz
Memory: 1024MB RAM
Page File: 430MB used, 2030MB available
Window... Read more

More replies
Answer Match 44.1%

Yea, I get that whenever I try to play a game involving GameGuard (mainly Ijji games).
Any ideas?
 

A:Gameguard error 114?

11 more replies
Answer Match 44.1%

my computer recently got a virus or worm or malware or something...anyways there was a huge amount of pop ups and executables going off, I shut down windows and they haven't reemerged, but there is about a 50% drop in speed.

Running Windows XP Pro SP3

Heres what I scans I ran(thorough scans)
-Avast
-Symantec Antivirus(installed after lag remained and removed avast)
-Spybot Search and Destroy
-A-Squared Free
-CCleaner

basically when I ran any of the above(excluding CCleaner) it turned off my computer...I booted up in Safemode and tried the scans again, and it shuts down at some point during the scan....im guessing its a virus that shuts down the computer when scanned....so any hints? I don't really want to reinstall Windows, since I got this CD Key cheaply from my school, but its only a one time install key supposedly....Im guessing this is possibly a bad worm, since my computer is semi-laggy...and I tried installing WoTLK and it took 2 hours to do on a machine I bought 1 year ago which was considered high end then

HijackThis log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:13:03 PM, on 11/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEn... Read more

More replies
Answer Match 44.1%

Hi Tech Guys,

I don&#8217;t usually have problems using my laptop but recently I&#8217;m experiencing this weird case where at some point of the anti-virus scan, my laptop will unexpectedly shutdown thus not completing the scan. I&#8217;m also experiencing frequent random shutdowns over the last month.

A week ago I noticed that my AVG free 8.5 scheduled everyday scan was not being completed. I usually leave my laptop open and running before I go to work in the morning. The everyday scan is scheduled at 12noon and upon returning home, I&#8217;m always surprised to see my laptop shutdown-ed. When I hit the power button, the screen will say something like the system experienced unexpected shutdown and I will just choose the start windows normally option.

I then decided to change my anti-virus program to ESET Smart Security 4 free trial (and will eventually buy it depending on its performance) but I&#8217;m still experiencing the same problem.

Earlier today, I also decided just to run nothing but the anti-virus program and at around 86% of the scan, my laptop suddenly shutdown. So I&#8217;m guessing it is something being detected by the anti-virus program but cannot be cured/removed just by a normal scan.

By the way my laptop is HP Pavilion dv6000, Windows Vista Home Premium 32-bit OS, Intel Core 2 1.60 GHz and 1G RAM. Below please see the HJThis! Log.

Any help would be greatly appreciated on this very annoying and troublesome bug. Thank you very muc... Read more

More replies
Answer Match 43.68%

all of the free mmorpg's i have downloaded that use nprotect gameguard are crashing after giving this message:

---------------------------
GameGuard.des - Application Error
---------------------------
The instruction at "0x458c3be8" referenced memory at "0x5f05001e". The memory could not be "read".

Click on OK to terminate the program
---------------------------
OK
---------------------------

help??
 

A:nProtect GameGuard crashing

7 more replies
Answer Match 43.68%

DDS (Ver_09-03-16.01) - NTFSx86
Run by Santero Famiglia at 12:08:38.85 on Sun 05/03/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.367 [GMT 8:00]

AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Genius\ioCentre\gAutoPan.... Read more

A:Need Help. The GameGuard is not working properly.

I dont know if this is a addtional information, but when I start my PC, before the Windows logo there appear a two choice: Microsoft Windows Recovery console and Microsoft XP Media Center Edition(this is the highlighted one). it automatically choice the highlighted for 1-2 secs mabye.

3 more replies
Answer Match 43.68%

I try to launch the game and it was fine then when it try to start it pop up 380 error and http://www.gameguard.co.kr/gameguard/faq/eng/FAQ_3xx.html I tried to reinstall but it didn't work. I have two laptop and both have the same problem I dont know if it was a network problem or not. please help me fix the problemT_T
 

More replies
Answer Match 43.68%

Hi!

I am new here and I have a problem. I have recently installed Cabal Online and after playing it I noticed something was not right. After trying to find a solution I have decided to uninstall the game and forget about it but then I found out on the internet that GameGuard, which this game uses, is a rootkit and thus a threat to my and my computer's security. I read you have to manually remove it from the computer so I followed some instructions. I deleted the GameGuard folder after uninstalling the game and I also found npptnt2.dll and nppt9x.vxd files but I can't find the place in registry all those people on the internet mentioned. Is it possible that there is nothing left of GameGuard? How big a threat is GameGuard really? Can you please help or give information or something? You would make a guy's life easyer

P.S. I believe that when I found this site & forum I found a goldmine. I bet there is a lot of good information here

A:How Can I Completely Remove Gameguard?

If there is a "rootkit" on your computer, the best chance of finding it and removing it is by posting a Hijack This log.Post a Hijack This log in the Hijack This Forum by following the directions in the link below. DO NOT post the log in this forum.http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/

1 more replies
Answer Match 43.68%

Hello,

A couple of weeks ago, I installed wolfteam on my computer, started playing and when I finish playing and get back to the desktop, I cannot open any programs anymore, cannot open my computer or anything. When I double click icons, nothing happens.

I thought it was the game, so I uninstalled and reinstalled with the same problem.

Yesterday, I downloaded 2 new games, Huxley and Pandora saga, both games and wolfteam all come with gameguard. And all these games now do the same thing when I close them. So I guess the problem was not with wolfteam, but rather with gameguard, maybe I'm just jumping to conclusions...

I have over 50 games installed on my computer, online and single player games, and the only 3 games that use gameguard give me this problem.

I did not try uninstalling gameguard and reinstalling because im not sure if I would have to redownload and reinstall the whole games by doing that, Huxley is 4GB, I do not want to redownload if not necessary.

So to repeat myself, the problem is that I cannot open any programs, or windows or do anything anymore on my computer after I close the games. My desktop is there, everything is normal, I can open the start menu, but that's about it.

I tried to attach my Dxdiag file, but it wouldn't let me, so let me know what info you need on my computer other than what I will give...

------------------
System Information
------------------
Time of this report: 8/8/2009, 01:16:42
Machine name: FASHION-FREAK
Oper... Read more

A:Issue with games with gameguard...

11 more replies
Answer Match 43.68%

I am sick and tired of this worthless security software. I used to play Mabinogi, a Korean MMO from Nexon, and of course they use that infernal GameGuard BS. Fool that I was, I tolerated its presence since I liked the game more than most. Well, trust me, I paid for it. Who knows how much it has altered the registry.

Worse, it has disabled my keyboard! I use Vista and a Logitech Wave Keyboard. Once in a while, Mabinogi fails to load up and I see a white screen instead of the title. My mouse works but my keyboard is disabled and I have to do a hard reboot. Upon reboot, it still doesn't work. I switch the USB to another port... voila, it works. But it will never work for that previous port again!

I didn't suspect anything until it happened a second time. Now I have two ports on my PC that refuse to work with my keyboard. Any other device works fine, just not the keyboard. This is BS of the highest degree.

I can only guess that it has modified my registry in some way, but I don't even know where to begin. Can anyone help me recover the use of my two USB ports for the keyboard?
 

A:GameGuard killing my keyboard and USB

I've since uninstalled Mabinogi, deleted the GameGuard folder, deleted the two hidden files it inserted into my system folder and deleted a registry key to no avail. Someone has suggested that GameGuard is using an "input hook", which I've never heard of.
 

1 more replies
Answer Match 43.68%

So here's this game Ran Online and I have Windows 8 Pro 32-bit.

I always get this error saying that there are programs that conflict with gameguard. I already allowed the game and the gameguard.des and gamemon.des in windows defender and firewall. And I also allowed the entire drive.

So any idea what would these programs be that conflict with game guard?

Thanks in advance.

A:Windows 8 Gameguard Error

I am assuming Game Guard is anti-cheat software for the game just like S4 League's xtrap.

It is dangerous to allow the whole drive and I recommend you undo that. The bad news you can't do anything until they update Game Guard to work with Windows 8

Similar case happen with xtrap and within a month they updated to allow Windows 8.

I am assuming and I don't know Game Guard is thinking your cheating because it only checks the approve OS in its definitions list and windows 8 is not on it.

You can probably sent a email to the company or post on their forums or send a ticket to get them to make a small update to add Windows 8 as a approve OS

I think the actual game runs fine if it ran in Windows 7 just the anti-cheat software needs a update.

The Ticket page:
RAN WORLD : The Frontier of Ran Online

Forum page:
RAN WORLD : The Frontier of Ran Online

Check there.

2 more replies
Answer Match 43.68%

So i went to play maplestory last night and well it did not work my internet connection was excellant but the game would not connect it would not even show the adveirtisment. I installed and reinstalled but that did not work in case my comp has not been updated but i have an acer aspire 5100 vista

Plz Help
 

More replies
Answer Match 43.68%

Ok so i was playing this game called 2moons for about a month it was awesome and i got addicted to it. its kinda like WOW but free. so anyway, one i clicked the launcher and it did nothing for awhile then a error poped up and said connection error. i was like ok w/e and tried again the same thing happened. so i decided to just play a different game. and i tried to log into it (Gunz Online hosted by ijji.com) and it came up with a connection error as well it said "Gameguard execute error 380 failed to connect to gameguard update server. please try again later or check personal firewall settings" so i tried again later (1.5 weeks now) and im still getting that message. i did some research on this to try and fix the problem all the sites i went to said to turn off my firewall while playing the game so i turned it off and i still get the same msg. they also said to delete gameguard and when u run the game again it will update it and ull b fine. that also didnt work. I would be really really greatful if some1 knew how to fix this and tell me. thanks!
 

A:gameguard error 380 (2 moons)

14 more replies
Answer Match 43.26%

Hello

First of all i need to let you guys know that i am not very computer literate. So any technical computer talk may stump me. When i start my computer and log on to my account, i get a message saying that the module c:\windows\system32\guserohu.dll couldn't be found, i scanned my computer with ad aware and managed to detect one by the name of win32.adware.virtumonde/c.

After i removed it and restarted my computer, i get the same kind of message but this time it isn't guserohu, it's now c:\windows\system32\himesuvo.dll And another thing, my anti-virus software, windows live onecare, keeps turning off it's automatic update and after repeated turning the auto update on and on again for like 2 hours, the program closes. After that i can't manually start it. It says to restart my computer and i did, still keeps closing automatically. I'm fully convinced that it is a virus. i get pop ups on my internet browsers too, whether i am using internet explorer or google chrome.

But it is my fault, i was er.... downloading some ummmm "things" and my computer got infected :( . Also, i do not have a boot cd or windows installer disc. 1 more thing i have to add, when i first realised that something was wrong, i immediately scanned with windows live onecare (strangely it was working then) and removed 2 viruses, i can't find records of it in my onecare program and i don't remember the names. I did this before what i stated in the above paragraphs

Here are th... Read more

A:My anti virus keeps shutting down, convinced it is a virus causing it

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

------------------------------------------------------

Please visit this webpage for download links, and instructions for running ComboFix:

http://www.bleepingcomputer.com/comb...o-use-combofix

* Ensure you have disabled all antivirus and antimalware programs so they do not interfere with the running of ComboFix.

Right click system tray icon > on main page click Change Settings > click Viruses and Spyware Tab > Tick "Off" radio button > Apply and OK.

Also either have to disable Firewall, or approve one of CF's files, or RC won't install for XP

Firewall Tab > Off > OK

------------------------------------------------------

Please post the C:\Combo... Read more

11 more replies
Answer Match 43.26%

Well, this computer is about 2 weeks old, and whenever i try to play games that use gameguard, gameguard gets to the point were it exits, and the game is supposed to load up, but when gameguard exits, my computer freezes up, completely, i cant do anything on it, i have to manually re-boot it using the power button. ~_~

More replies
Answer Match 43.26%

Each time I start up a game that uses GameGuard, my PC BSODs before the actual game is loaded.
The BSOD that seems to occur when it happens is 0x000000D6 and the file that causes it is dump_wmimmc.sys.

I have tried uninstalling the games and re-installing them, which does not fix the BSOD.

A:BSOD playing game that uses gameguard

Hi fuzzah,

Your logs show dump_wmimmc.sys:


Code:

*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
Use !analyze -v to get detailed debugging information.
BugCheck D6, {fffff980613b7000, 1, fffff88008438124, 0}
Unable to load image \??\C:\Program Files\PHANTASYSTARONLINE2
\pso2_bin\GameGuard\dump_wmimmc.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for dump_wmimmc.sys
*** ERROR: Module load completed but symbols could not be loaded for dump_wmimmc.sys
Faulting Driver: dump_wmimmc.sys
Related to GameGuard: Usually buried deep in a game's folder structure.
For example: C:\gPotato\GV Online Eg\GameGuard\dump_wmimmc.sys

Suggested Action:

I suggest removing any games that utilize Gameguard from your system.
The developers didn't store the driver in the proper place (C:\Windows\System32\drivers)
nor did they name it using a normal convention:
(the dump_ prefix is usually reserved for copies that the OS makes of storage drivers in case of a crash)

As Gameguard is integrated into the games, this is the only remedy to stop the BSOD's.

I would also suggest to remove Advanced System Care 6 and Free Windo... Read more

9 more replies
Answer Match 43.26%

I'm posting here because I'm not getting any response on the Virus Malware board. I play an online game from GamesCampus, and I had to install Gameguard. I constantly get error messages from AVG.
avwsc.exe encountered a problem and needs to close
Exception in modul AVGNT.EXE
I turned off Avira while I play this game, but I still get booted out of a game all of a sudden, with error messages from Gameguard. I tried several solutions from gameguard and nothing seems to correct this problem. Initially I thought I had a virus, which I still don't know. Then I thought it may be a conflict with my antivirus. Now I am so frustrated and don't know where to turn to figure this out. My girlfriend has the same set up as me, Avira free, and gameguard, and she plays the same game but has never had this problem. The only difference is she has ZoneAlarm firewall, and I'm using Wins firewall.

I am attaching the DxDiag report.
Thank you I hope someone can help.
 

More replies
Answer Match 43.26%

I just switch from windows 7 ultimate to windows 8 pro, my problem is I can't run ragnarok online and every time I open ragnarok online the gameguard always has a problem.. It says gameguard error 114.. Any update on this? Any fix?

A:gameguard error 114 can't run ragnarok online

I don't think GameGuard has updated their anti-cheat system to work with Windows 8 yet.

2 more replies
Answer Match 42.84%

I got this recently
i have tried to change UAC, redownload gameguard, turnoff anti-virus and turnoff firewall and i still don't have any clue how to solve this problem
Problem Event Name:    BEX64
  Application Name:    GameMon64.des
  Application Version:    2015.10.15.1
  Application Timestamp:    56205b36
  Fault Module Name:    nvinitx.dll
  Fault Module Version:    9.18.13.2702
  Fault Module Timestamp:    521fbdfc
  Exception Offset:    000000000000d88d
  Exception Code:    c0000417
  Exception Data:    0000000000000000
  OS Version:    6.1.7601.2.1.0.256.1
  Locale ID:    3081
  Additional Information 1:    4d78
  Additional Information 2:    4d786dbd8016c944ddbb1e4ed4cbc217
  Additional Information 3:    000f
  Additional Information 4:    000fd2bb259f66c51b9642e16359ca20

thanks in advance to those tried to solve this problem

More replies
Answer Match 42.84%

It all started last night, Some of my google searches (not all) get re-directed and any game i try to run that uses GameGuard (anti cheat program) wont load. All this happened after i went to download Americas Army 3 from their site last night. Ran all scans (SpyBot, AVG, and AdWare) and nothing showed up. I also noticed, my System Restore is on, but all my Restore points are gone! You guys helped me before....let do it again!

Here's my DDS.txt


DDS (Ver_09-05-14.01) - NTFSx86
Run by Shane at 13:00:08.90 on Mon 06/22/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.1852 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\syst... Read more

A:Searches re-directing, GameGuard wont load

Hello and Welcome to TSF.

Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant notification by email, then click Add Subscription.

Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.

------------------------------------------------------

One or more of the identified infections is a backdoor trojan.

This type of infection allows hackers to remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.

If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?

------------------------------------------------------

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper.

----... Read more

2 more replies
Answer Match 42.84%

Any time I'm playing Rose i'll be able to play fine for an hour or so and then suddenly i get an error. It closes out the game and has a pop-up that says Gameguard Initialize Error 230. Don't know if this helps but im using Zonealarm and i didnt know if i had to add a Gameguard file to my firewall possibly? Not sure, just looking for some help because its frustrating.
 

More replies
Answer Match 42.84%

Im 19 years old, i live in massachussetts, and im fairly good managing a computer.
Recently, ive been having this problem with GameGuard. Gameguard is a program used to prevent hacking, using 3rd party programs in a game etc. Ive downloaded 2 different kinds of games that have gameguard. the first is darkeden. Darkeden is a low memory, not very good graphics kind of game. Im running a Dell pent4 2.66ghz 512 ram Nvidea GeForce FX 4200 - 128. Whenever i try and start this game, after Nguard runs, it brings me to a blue screen of death, every time. It gives me the error 0x0000008e. This is supposedly a graphical error. maybe hardware isnt installed properly and whatnot. Ive tried a lot of different things to try and correct this problem. Ive come to the conclusion it is not my graphics card. Ive reinstalled the driver.. updated .. everything. Now lets move on... bear w/ me for a second. I also play another game called Lineage 2 w/ a few buddies on a private server. This game puts my graphic driver to its limits. Still runable tho.... Now letss move onto the other game. The other game is called Silkroad Online. I just downloaded this game and found that it has Nguard on it. This game also gives me the same error. If i can run a game that creates much more graphics, why wouldnt i be able to play this. Ive come to that maybe theres something wrong with some other part of my computer... To try and correct this, i turned off write debugging information. Now all that happens when i tr... Read more

A:Gameguard Blue Screen Of deaths Issue

9 more replies
Answer Match 42.42%

Hello, Past 1 Year, I've had a problem. Sometimes When I play game that uses Gameguard, Pictures of the character/Font/Etc disappears/Reappears. If I have play games with another different kind of Anti hacking system, There would be no disappearing font/Character/bars.

Screenshot

Shot at 2007-07-20

This screenshot there's a disappearing Charcarter

http://img404.imageshack.us/my.php?image=maple0007dl9.jpg

Blur Bar

http://img149.imageshack.us/img149/3866/maple0003pg7.jpg

Disappearing
 

More replies
Answer Match 42.42%

I think the gameguard error is also associated with the rootkit avg found but cannot remove. The rootkit changes name when I restart my computer. Also if any of you have an idea about the gameguard error: default setup error, close programs that confilct or restart the computer.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:47 AM, on 12/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Cerience\RepliGo\RepliGoMon.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ThreatFire\TFTray.exe... Read more

More replies
Answer Match 42.42%

So after not playing for awhile I decided to redownload everything and after that I got a problem.

(Excluding the fact DC is now owned by GC and my lvl 50 account was deleted >.>)

After you press play and it goes through Nguard and does it's normal installation of files as soon as that opens windows 7 comes up with the error you usally get when application stops working.

"Nguard Game Launcher has stopped working, Attempting to fix and find solutions"

It does not do this anymore but it does come up with the image I have said with the error 3221225477.

Just to inform some of you who do not know what NGuard/GameGuard is, it is a game protection application that is ran to PREVENT hacking the game so it's not the game that doesn't work it's the NGuard/GameGuard that is not updating or causing something to stop. Again this is something that's force-runned via game start this is the problem I am having not with Drift City the game.

Now I don't know whether Windows is stopping it or it's not updating properly I'm not sure.

Something in Windows 7 is causing the program to stop processing.. Has anyone else had this same problem specifically and fixed it?

P.S (Checked Nguard Stickies for this and didn't find the error discussed correct me if I'm wrong)

I'd really like to play this again but this is stopping me from playing..

Until this is fixed I can't play DC or GUNZ

I have submitted threads on nu... Read more

A:GameGuard Execute Error: 3221225477 (Drift City)

I fixed it all i had to do was disable uac!!!!!!!!!!!
 

1 more replies
Answer Match 42.42%

Hi, you guys helped me save this computer from a string of really annoying BSODs a year ago and it's been great since, although I can't seem to find the actual thread. Anyway I've been trying to play this game, Phantasy Star Online 2

However, every time I try to start it and GameGuard finishes initializing/updating, I get a BSOD. The actual BSOD that pops up doesn't say the actual error message, but from BlueScreenView, it says PAGE_FAULT BEYOND_END_OF_ALLOCATION.

This is a BSOD that can be reproduced every time I start the game, although I recently did a system restore to before GameGuard was installed and thus deleted the later mini-dumps, but I still have one from an earlier attempt 11 days ago. Other than the PSO2 BSODs, this computer has had zero problems, especially when playing other games like Warframe and Path of Exile.

I can kinda guess and say that GameGuard is to blame, but I'd like an expert opinion on what is behind these BSODs, and if possible, try and get this game working so I can play.

EDIT: I forgot to mention that I was able to play this game on this same PC when it had Vista, before I upgraded to Windows 7.

A:BSOD when starting Phantasy Star Online 2. GameGuard?

Code:
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************

Use !analyze -v to get detailed debugging information.

BugCheck CD, {fffff98017ed1000, 1, fffff80002cce7bb, 0}

*** WARNING: Unable to verify timestamp for dump_wmimmc.sys
*** ERROR: Module load completed but symbols could not be loaded for dump_wmimmc.sys

Could not read faulting driver name
Probably caused by : dump_wmimmc.sys ( dump_wmimmc+24c5b )

Followup: MachineOwner
---------
This is a known problem with GameGuard on Windows 7 & 8. I recommend uninstalling the game as there is no known fix.

Info:
Driver Reference Table - dump_wmimmc.sys

2 more replies
Answer Match 42%

Hello, i just reinstalled windows 7; first i installed all my apps, and later on the windows updates : before that, no issue at boot, but after : between "windows starting" and the appearence of the logon screen, the screen stays black for while. This a known issue with the logitech "unifying" receiver. I'm just trying to find out WHICH of the "security update" is causing this.. Perhaps someone here knows?

A:Windows update causing trouble with "unifying" receiver

I'm not awate of any relationship between these receivers and updates - and to be honest, can't really see why there should be.
The latest Logitech software update appears to be 2010 vintage - perhaps you should check each connected device and see if there are more recent drivers available for them. It may simply be that this device forces detection early in the boot process which would normally be carried out at a later stage - thereby causing this apparent slowdown

What happens if you unplug the device before boot, and plug it in later?

3 more replies
Answer Match 42%

Hi normally my internet works fine, that is I can connect to pages and they load without trouble in both firefox and internet explorer or anything else that uses the internet.

However, I recently downloaded a new game called IRIS online which uses a hack protection called gameguard which apparently acts like a rootkit.

Now whenever I run the game, it will connect to the game but restricts anything else that uses the internet from working. So when the game is running, I can ping sites and still get a response as the internet is still connected, but pages never load in internet explorer or firefox until I reboot the computer.

A reboot fixes it and there is nothing else that is wrong with my connection (afaik) other than that when gameguard runs, nothing else wants to work.

Apparently other people are fine with gameguard and it doesn't affect them at all so I'm looking for some help as to why it stops my internet from working!

If anyone could help I'd greatly appreciate it thanks

here are my ipconfig/all results if needed:

Microsoft Windows [Version 6.0.6002]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.

C:\Users\User>ipconfig/all

Windows IP Configuration

Host Name . . . . . . . . . . . . : User-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : lan

Ethernet adapter Local Area Connection 3:
... Read more

A:Solved: Internet connected but won't load pages after gameguard starts

How did u fix this problem as i have the same
 

3 more replies
Answer Match 41.58%

Hey guys, always when I play a game which GameGuard has been put to prevent hacks, it always comes up with this Windows Host Process Error. When GameGuard launches, an error pops up and says "Host process has stopped working and will close". The game still works but I'm wondering if this is a problem. It seems nothing is affected by this error, however I would still like to get rid of it because it basically spams my event log with a bunch of error logs. I am running Windows Vista Home Premium.
 

A:Host Process For Windows Services Has Stopped Working - GameGuard Problem

6 more replies
Answer Match 41.16%

Hello,I seem to have contracted a virus or malware of some description that generates fake, "Your Computer may be infected" - type alerts in my Windows taskbar and attempts to install a fake antivirus onto my pc called XPShieldSetup.exe. It also causes advertising popup, though this is fairly rare (once or twice an hour, max).I am running Windows XP, Service Pack 3, and I have Trend Micro PC-cillin Internet Security 14 for antivirus software. I have also turned on Windows firewall, as per the instructions on this site.My antivirus program detects an infected file called C:\WINDOWS\SysNotifier.exe, and classifies it as something called "Mal_FakeAV-9". It Quarantines this file repeatedly, but it always comes back, even if I manually drag it to the Recycle Bin.I have run HijackThis and attached a copy of the log file it created.Thanks in advance for your help. Here is my hijackthis log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:27:32 PM, on 4/28/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16827)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\Ati2evxx.exeC:&#... Read more

A:Malware of some sort causing ad popups, fake virus alerts, trying to install fake anti-virus, etc -- HijackThis log attached.

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the resul... Read more

4 more replies
Answer Match 41.16%

the other day I was downloading something from sharebee.com when i got a popup from the site. the popup's address was a sketchy looking ".info" site and the page was blank except for a small box in the middle. I figured that this was an infected page so i did a google search on it and it showed up as containing "antivirus2008" virus on some diagnostic site that i do not remember... shortly after this page loaded my computer became really sluggish to the point where i couldnt do anything. so i restarted it.

then i saw somethin i've never seen before. a red window showed up on screen before windows loaded saying that "Trend Chipaway Virus has detected a boot virus on your hard disk" and won't let me load up windows. I tried to boot anyway, but when i click on my username it just logs me right back off. I tried to boot it in safe mode, and it also logged me right off immediately. It tells me to insert a bootable floppy disk, which i do not have. I do however have an xp disk. I put that in my disk drive and tried to reinstall windows. I chose to do a repair installation, and it went through the first part of the installation and rebooted. then the setup screen came up and it went through the "collecting information" "dynamic update" and "preparing installation" portions, however once it got to the installing windows section i recieved a fatal error saying "An error has been encountered that prevents Setup from co... Read more

A:boot virus causing "trend chipaway virus" message. can't log on, reinstall hangs AH!!

nothing huh.

3 more replies
Answer Match 41.16%

Hi. Um, I have a virus that's causing lag, but it only happens in games, like counter strike and world of warcraft, ms in wow is going over 300, even more, and usually it was 40 - 60 and latency in counter strike is changing all the time, it goes from 20 - 800 and back, it's annoying. I possibly have another virus, since I was getting some messages, like when I start a program, little window pops out and it says "This is not valid win32 application" and program doesn't open, I'll tell you what does it say exactly when it happens again. I'm also getting blue screen of death, something like this: http://jmobley123.files.wordpress.com/2008/10/blue-screen-of-death1.jpg
It doesn't happen a lot, but it does, at least 3 times in 24 hours. Note: That bsod screenshot isn't mine, dunno, maybe there's some difference. I didn't really read the whole thing when it happened to me, but I'm guessing it's the same...

My system:
Windows Xp Professional, 2002
Service Pack 3

I don't know if this is needed for this to be fixed, but here's the hjt log...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:44:22 PM, on 12/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WIN... Read more

A:Virus causing lag :|

8 more replies
Answer Match 41.16%

Hi folks,

I've been running this harddrive on my pc for a few years ... i installed the win98se OS from my licensed cd, a few months after xp came out, i bought an xp upgrade and upgraded my pc to xp. I went through the validation process and everything. Now all of a sudden, I replace the batteries in my keyboard, reboot my pc and get a msg saying 'You may be a victim of software counterfeiting' ... I've searched here to see if there was a new virus and noticed each time you see those words, the thread is closed. I don't know who else to ask, I KNOW this is a legal version of windows, I've bought and installed everything from the windows cds and validated it. It has been a legal copy from the time I installed it. How can this happen (what could have changed it?) and what can I do to fix it? Please post here or msg me. Thanks for any help you might be able to provide.

Btw, I'm currently in the process of running a virus scan just to check the pc out.

Edit: AVG has finished a complete scan with no threats found. Ran AdAware and Spybot as well, everything appears to be clean.
 

A:Can a virus be causing ... ?

Just wanted to let you know in case you ever run across this yourself.

While making coffee this morning, I was going over the sequence of events when switching the batteries on my keyboard. I remembered that the button I have to push on the keyboard to sync it to the wireless controller had the letters ch1 and ch2. I re-sync'd the keyboard hoping it would choose the original ch setting, booted up the pc and now I have no windows validation problem at all!

Thanks for looking at this though.
 

1 more replies
Answer Match 41.16%

Hi Everyone-

I believe I've picked up some sort of virus that is forcing new advertising pop ups every time I am using Internet Explorer (ver 10). Each time I click on a link, a new window opens with a random ad. Also, websites I normally frequent now have links in certain areas which will bring me to an ad if I click on it (see below).

I believe I picked up the virus after being directed to an add on site while using a program called Audacity.

I also ran Avast with no luck.

Thoughts?

A:Virus causing new pop up ads in IE?

iPaul626, You might want to take a look at your tools in IE, Select Manage Add-On's and your browser highjacker might be there.
Or you could download the free Malwarebytes at https://www.malwarebytes.org/
and run it in the full scan mode.
It might not be what they call a Virus but in reality a browser hijacker..

Rich

9 more replies
Answer Match 40.74%

HI everyone!

My husband was on facebook when suddenly "Antivirus 8" came up on the screen. He told me he closed it and all hell broke loose. He started Malwarebytes and the laptop just shut down.

I've been trying for 3 days now to get it to stay on long enough to scan. Sometimes I can get it to stay on for 10 minutes in safe mode/safe mode with networking and other times I cant get past the Welcome screen. It restarts, I choose safe mode, log-in and get BSOD. The main error I get is DRIVER_IRQ_NOT_LESS_OR_EQUAL. I have also seen BAD_POOL_CALLER and SYSTEM_SERVICE_EXCEPTION although I've only seen that once or twice.

Anyone know what I can do? Its a Gateway MS2274 with Windows Vista Home Premium.

Thanks!

A:Virus causing BSOD?

Hello, let's try to scan like this. If not we have other ways. Reboot into Safe Mode with Networking How to enter safe mode(XP/Vista)Using the F8 MethodRestart your computer. When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu. Select the option for Safe Mode with Networking using the arrow keys. Then press enter on your keyboard to boot into Safe Mode. >>>> Download this file and doubleclick on it to run it. Allow the information to be merged with the registry.RKill....Download and Run RKillPlease download RKill by Grinler from one of the 4 links below and save it to your desktop.

Link 1
Link 2
Link 3
Link 4

Before we begin, you should disable your anti-malware softwares you have installed so they do not interfere RKill running as some anti-malware softwares detect RKill as malicious. Please refer to this page if you are not sure how.
Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
If nothing happens or if the tool does not run, please let me know in your next replyDo not reboot your comp... Read more

1 more replies
Answer Match 40.74%

I'm running Windows XP (5.1.2600 Service Pack 3).
The problem I'm having is: Internet Explorer windows are popping up without having anything open, sometimes a gray box pops up stating "Congratulations You Have Won..." and when I do a Google search the results redirect to some shopping sites.

I have Antivir, Spyware Dr. & Search and Destroy but nothing seems to help.

As instructed please find my DDS output below (additional files are attached). Any help would be greatly appreciated!




DDS (Ver_10-12-12.02) - NTFSx86
Run by John at 9:46:02.70 on Wed 03/02/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.1734 [GMT -8:00]

AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {F85E8EC8-FFA4-00EB-0D24-347CA8A3377C}
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {804E5358-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *Enabled/Updated* {804E5358-FFA4-00EB-0D24-347CA8A3377C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\syst... Read more

A:Virus causing havoc

Hi and welcome to TSF.

I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible.

You may wish to subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

Please be patient with me during this time.

19 more replies
Answer Match 40.74%

I'm sure I have some kind of bug but have not been able to remove it. It is causing continuous internet explorer popups that can only be stopped by closing IE through task manager. I've ran avast antivirus, malwarebytes, and Spybot S&D which are all scanning clean at this point, but the problem persists. Below are the DDS logs and Root Repeal log. Please help!
DDS (Ver_09-10-26.01) - NTFSx86
Run by Michele at 9:08:15.38 on Tue 11/10/2009
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_17
Microsoft? Windows Vista? Home Basic 6.0.6002.2.1252.1.1033.18.1525.491 [GMT -5:00]

AV: avast! antivirus 4.8.1296 [VPS 090124-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: avast! antivirus 4.8.1296 [VPS 090124-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:�... Read more

A:Virus causing IE popups

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. Please include a clear description of the problems you're having, along with any steps you may have performed so far.Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.Please download OTL from following mirror:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the button.Two reports will open, copy and paste them in a reply here:OTL.txt <-- Will be openedExtra.txt <-- Will be minimizedIn the upper right hand corner ... Read more

2 more replies
Answer Match 40.74%

Thank you for your help. I have what seems to be multiple viruses which have hijacked my search results and today a screen came up that said if you have not seen this screen turn off your computer and reboot in safe mode. It also said something about BIOS (?) dump. I rebooted computer in safe mode which it is in now. I also have Norton which gave me a security warning and displayed this in security history:

&#65279;Category: Unresolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action,Path - Filename
1/8/2011 2:42 PM,High,mouclass.sys (Backdoor.Tidserv.I!inf) detected by Virus scanner,Manual Removal Required,Review risk details on Symantec Web site.,c:\old hard drive\c\windows\system32\drivers\mouclass.sys
1/8/2011 2:38 PM,High,a0126218.sys (Backdoor.Tidserv.I!inf) detected by Virus scanner,Manual Removal Required,Review risk details on Symantec Web site.,c:\old hard drive\c\system volume information\_restore{47e7117b-18f3-4a10-b47c-105bed1bff9b}\rp96\a0126218.sys
1/8/2011 1:48 PM,High,mri.exe (Trojan.Gen.2) detected by Virus scanner,Attention Required,Remove this Security Risk now.,e:\mri.exe
I followed the instructions for preparation for posting and the three logs are as follows:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:08:15 PM, on 10/25/2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe... Read more

A:Virus Causing Problems

16 more replies
Answer Match 40.74%

Hi, could someone please take a look at my hijackthis report. I have an Acer Aspire 5735, running Vista home premium, AVG free anti virus, malwarebytes, and superantispyware - i have run all these but problem still persists. Two days ago i couldn't log onto windows with my user profile, i was issued with a temp profile, so i decided to do a complete recovery to factory settings - thats when my problems started, first i used Acers erecovery console and it couldn't fully install, it stalled, so i tried again using the back up recovery discs i made when i purchased the laptop, again it stalled at the same point, i have tried a few more times and still no luck.

I can still get onto the internet, and have a limited windows setup (i can't get windows updates at all), but now when i go on the internet, i keep getting redirected to random sites, and getting virus warnings all the time.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:49:26, on 26/03/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel... Read more

More replies
Answer Match 40.74%

Hey folks, I am normally very, very careful about who and what is on my pc. Well, I got stupid, I'll admit it. (Yet, unless pressed, I won't admit how.) Can you PLEASE help me get my XP back? I truely hate Vista. (Dual Boot System)

HJT LOG:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:20: VIRUS ALERT!, on 6/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Logitech\LCD Manager\lcdmon.exe
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDClock.exe
C:\Program Files\Common Files\Logitech\LCD Manager\Applets\LCDMedia.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
F:\FRAPS STUFF\FRAPS.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\b... Read more

More replies
Answer Match 40.74%

Recently as of last week i have had multiple Bsod crashes with different stop codes on my laptop. the most common one is stop code 116. additionally my screen is not functioning properly as there are yellow and blue pixels left behind if either the mouse pointer moves or the window changes.
 
i believe this to be a virus because i haven't made any hardware changes recently. the laptop when attempting to start normally gets to the password screen then crashes so i have been using it in safe mode with networking.
 
i have scanned the computer with malwarebytes but it did not find any problems
 
any help or advice would be much appreciated
 
thanks
Jez

A:Virus causing Bsod ?

Please download MiniToolBox  , save it to your desktop and run it.
 
Checkmark the following checkboxes:
  List last 10 Event Viewer log
  List Installed Programs
  List Users, Partitions and Memory size.
 
Click Go and paste the content into your next post.
 
Also...please Publish a Snapshot using Speccy - http://www.bleepingcomputer.com/forums/topic323892.html/page__p__1797792#entry1797792 , taking care to post the link of the snapshot in your next post.
 
Louis

8 more replies
Answer Match 40.74%

I seem to have some virus or malware that has hi-jacked my outlook address books and is sending out e-mails. They do not appear in my sent file in outlook. I discover it has happened when it finds several addresses that are bad and they get returned to me. I have tried Avast, Norton security, malwarebytes and spybot S&D. They don't not find anything. Any ideas?

A:Virus causing e-mails to be sent out

Welcome aboard They do not appear in my sent file in outlookHow do you know, some bad email had been sent then?

1 more replies
Answer Match 40.74%

this thing hit my computer and i am having problems getting it back to working right, it is a pain in the a$$ to get programs to work and i keep getting this stupid win 7 anti spyware window that keeps popping up.

her is all the info logs i could run,
GMER didn't find anything.

Tech Support Guy System Info Utility version 1.0.0.1
OS Version: Microsoft Windows 7 Home Premium , 64 bit
Processor: Intel(R) Core(TM)2 Quad CPU Q8200 @ 2.33GHz, Intel64 Family 6 Model 23 Stepping 10
Processor Count: 4
RAM: 8191 Mb
Graphics Card: ATI Radeon HD 4350, 512 Mb
Hard Drives: C: Total - 701070 MB, Free - 238834 MB; D: Total - 14331 MB, Free - 1854 MB;
Motherboard: PEGATRON CORPORATION, Eureka3, 1.01, MS1C96R52003078
Antivirus: AVG Anti-Virus Free Edition 2011, Updated and Enabled

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:46:48 PM, on 4/6/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal

Running processes:
C:\Users\Will\AppData\Local\jlb.exe
C:\Users\Will\Desktop\HijackThis.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Li... Read more

More replies
Answer Match 40.74%

Hello - hoping someone can help. Home computer with multiple accounts, running Vista (HP Pavilion). When I log in under my wife's account (she is the primary user), I'm unable to search for updates, nor am I able to get new definitions for Spyware. When I try to open IE or start Spyware, the computer reboots. When I log in and don't do anything, it will reboot within a minute or two.
I am able to open IE or run Spyware under a different account, but only with limited access (unable to run a full scan with Spyware or check for new Windows Updates). DDS log is below. I had to run this after booting in safe mode - I am not able to log into the primary account and execute anything..

Thanks in advance - Baroo

DDS (Ver_09-07-30.01) - NTFSx86 MINIMAL
Run by Angela at 15:42:28.98 on Mon 09/07/2009
Internet Explorer: 8.0.6001.18702
Microsoft? Windows Vista? Ultimate 6.0.6001.1.1252.1.1033.18.990.590 [GMT -7:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Spywar... Read more

A:Virus Causing Reboot?

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Foll... Read more

2 more replies