# Solved: trojan - downloader- ruin and secdro.. iie explorer still acting funny

Q: Solved: trojan - downloader- ruin and secdro.. iie explorer still acting funny

I got 2 trojans past few days and though used spysweeper to remove them my internet explorer is still redircting me to pages i dont want instead of where the links should take me. i have a log from hijack this. please help me get internet explorer working properly again.

C:\Program Files\WinRAR\WinRAR.exe
Having some trouble with a trojan, I run Spysweeper and it just comes back, and it seems like My firewall settings have been changed so that I have limited Internet Access. I have Norton Internet Security 2005. Hi, can anyone help.My computer was infected with a trojan-downloader-ruin virus which was picked up by Webroot Spy Sweeper and repaired.Ever since the computer has been running slowly.Starting the computer up takes ages ,internet explorer takes ages to open and so do web pages.Can anyone help ,have run the computer in safe mode and run the clean up 4.0 program but this didnt help. Can anyone help many thanx. Marmid............ I am having problems removing Trojan-Downloader-Ruin and Trojan-Relayer-Nextpart. These are both being alternatively identified by my SpySweeper runs, and I delete them when found, but they re-instantiate themselves and I can't find the source. Please note that I had an AIM virus a few weeks ago, and thought I had removed it via AimFix and ComboFix runs (maybe not?). Any help would be greatly appreciated! Read more A:Solved: Trojan Downloader Ruin removal problem - HJT log posted 10 more replies Answer Match 88.2% The problem I'm having seems to be isolated to explorer.exe, that is that when I start the computer, not everything that is supposed to start does. For instance, the small, two monitor icon that denotes connectivity in the bottom right of the screen does not come up, and until this happens (and nothing in particular seems to cause it to happen, but rather it's suddenly "wakes up" at random) there are a number of things I cannot do: I can't use the start menu, for instance. I can't right click on anything or else Explorer locks up. Again, no specific sequence seems to be the cause of the computer snapping out of it, sometimes it doesn't do it at all. In safe mode, this problem typically does not occur, but in order to troubleshoot the possible cause I have had to go into regular mode in order to uninstall some recently installed programs. However, I have uninstalled everything I can think of that I have installed lately, and still every time I start the computer, I have this problem at least for several minutes while I perform this task or other trying to get Explorer to activate properly. I have conducted CHKDSK, ScanDisk, a full virus, spyware, ad aware sweep, to include using Windows washer to get rid of all temporary files. I have used tuneup to clean up as well as defrag the registry. I have no unnecessary or on the identified programs starting at startup (which I checked using MS config). Short of reinstalling Windows (which I would li... Read more A:Solved: Explorer acting funny at startup theseus I don't have a specific solution for you, but I can point you in the right direction. About a year and a half ago I had the same problem. I ran spyware and virus checks, defragged, and ran scandisk....but still had the problems. I remember having to download a program called HiJackThis which ran a scan of my pc and what processes were running as my pc booted up. I then posted the scan results on a forum and some techs told me what to do. The problem was some background activex controls running through IE. I hope this at least gets you started. 3 more replies Answer Match 87.36% I got two different names for a trojan yesterday and today, and after completely running your ?5 steps before posting a log? I am finding no trojan at all! I know this sounds like a good thing, but I'd like some explanation if possible. I am running WIndows XP Home. Yesterday WebRoot SpySweeper found trojan-backdoor-progdav, which I eliminated on 2-17-07 by using TetonBob?s excellent instructions. Today I re-used those instructions, but the target files were not found, so I ran SpySweeper again ? and this time it found a different problem: trojan-downloader-ruin. So I used POADB?s instructions (provided to jack5000 on 4-25-06) for removing trojan-downloader-ruin: downloaed CleanUp!, Ewido with updated database, and FixWareout; ran FixWareout online; then ran HiJackThis offline in safe mode. HJT didn?t list any of the items that jack5000 was told to delete. The file to manually delete (C:\WINDOWS\\System32\dmeue.exe) also was NOT present. Then I ran my first Panda scan. Finding none of the target files, I went to TechSupportForum?s ?5 steps before posting a log? (now realize I should?ve done first.) Took ages, but the only things found were 1 malware program (Viewpoint Media Player, which I removed in Step 1), & 7 tracking cookies (which I quarantined using Ad-Aware SE in Step 2). In Step 4 no service packs were missing ? only upgraded IE (which I never use ? I?m a Firefox user) to IE 7. After all of this, I decided to run SpySweeper again, and thi... I caught a virus somewhere along the way. I was able to run housecall and mitigate the damage, but my internet is still acting funny by not letting get to any websites. Hi, i seem to have picked up the Trojan-downloader-ruin virus. I have numerous scanners that find it, but not remove it. (ewido, avg, webroot) If i search for something on google or click on links, i'm redirected to other sites. Id be grateful for some help. i'm running win xp pro...heres my hijack this log, thanx... Read more A:Trojan-downloader-ruin Welcome to TSF Please subscribe to this thread to be notified of fixes as soon as they are posted by our Team. To do this, please click the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread". Before you begin, take a read through these instructions and download the programs that I've advised. Save the below instructions in notepad or wordpad, because you also have to work in safe mode without networking support, so this page wouldn't be available then. You should not have any browsers open during the cleaning process unless otherwise prompted. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below. Please allow yourself a few spare hours. Below are instructions for a virus scan(s) that can take longer then 2 hours. Got a trojan that won't go away. Read more A:trojan downloader ruin Hi, Welcome to TSG!! You may want to print out these instructions for reference, since you will have to restart your computer during the fix. Please download FixWareout from one of these sites: http://downloads.subratam.org/Fixwareout.exe http://swandog46.geekstogo.com/Fixwareout.exe Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items (if they appear): R3 - URLSearchHook: (no name) - {48837813-02B4-377D-088F-45B4DF12A64A} - media64.dll (file missing) O2 - BHO: (no name) - {4EDA5007-2DB0-433C-A3F5-DC7B2530E49A} - C:\WINDOWS\system32\mspq.dll (file missing) O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{0601CB66-5DD8-4281-A59C-7E27DDB6F065}: NameServer = 85.255.113.107,85.255.112.121 O17 - HKLM\System\CCS\Services\Tcpip\..\{57832EE8-F604-4A53-8DE0-B7C949BCCFEA}: NameServer = 85.255.113.107,85.255.112.121 O17 - HKLM\System\CCS\Services\Tcpip\..\{69D3D28B-286D-4FE4-B49A-51D4A22F7A18}: NameServer = 85.255.113.107,85.255.112.121 O17 - HKLM\System\CS2\Services\Tcpip\..\{0237D679-3839-4B5B-A7B3-F012C2239864}: NameServer = 85.255.113.107... Read more 1 more replies Answer Match 86.52% Hey guys, just wanted to say thanks in advance since you've solved a couple problems for me before.Today on startup, I noticed a weird file that TheCleaner said made some changes to my startup files. The file name was just numbers, it was 49674074977093.exe. I manually deleted the file, and found no traces of it using Ewido, Spy Sweeper, or Mcafee. Spy Sweeper, did however, find two Trojans, adeog and downloader.ruin, which it quarantined and deleted.Now, using Startup Inspector, I've noticed two files that were previously not there, C://WINDOWS\System32\dmcsg.exe, and C://WINDOWS/System32/dmwiu.exe. Also, my computer is running slower than hell. Using Task Manager, many of the running files are taking up a lot of memory. I ran HiJack This, but nothing out of the ordinary came up. Any clues as to what this could be? Is it just spyware? Thanks for any help....EDIT: Now SpySweeper has found Trojan.downloader.ruin again. Hey guys, just wanted to say thanks in advance since you've solved a couple problems for me before.Today on startup, I noticed a weird file that TheCleaner said made some changes to my startup files. The file name was just numbers, it was 49674074977093.exe. I manually deleted the file, and found no traces of it using Ewido, Spy Sweeper, or Mcafee. Spy Sweeper, did however, find two Trojans, adeog and downloader.ruin, which it quarantined and deleted.Now, using Startup Inspector, I've noticed two files that were previously not there, C://WINDOWS\System32\dmcsg.exe, and C://WINDOWS/System32/dmwiu.exe. Also, my computer is running slower than hell. Using Task Manager, many of the running files are taking up a lot of memory. I ran HiJack This, but nothing out of the ordinary came up. Any clues as to what this could be? Is it just spyware? Thanks for any help....EDIT: Now SpySweeper has found Trojan.downloader.ruin again. This WILL/CAN also list Legit Files, Submit them at Virustotal C:\WINDOWS\SYSTEM32\DMCSG.EXE 60,510 2002-08-29 Other suspects. Directory of C:\WINDOWS\system32 {4649D938-AEEA-437C-987E-DE0B8796BE87}.exe {3C083DDF-DEF2-43AB-9893-E21E258B2FF5}.exe {7168966C-97B2-4F08-A4F3-52A6BD5A74FB}.exe {EF8FD7D4-5DE6-4B24-8F3C-1ED0A73E874A}.exe {D65E5E25-3D70-466B-B4D7-D06639A3C7DF}.exe {527D4B4F-CA8E-4175-A622-796E5050A4AB}.exe ????? Misc files. ????? Checking for older varients covered by the Rem3 tool. 14 more replies Answer Match 86.52% When i search using google and then click link, i am redirected to another page. if i use the "back" button it doesn't work unless i scroll down three lines to the original target. If i go back and click the link three times it will take me to my target. every time i use webroot spysweeper it finds "Trojan-downlader-ruin" even though i have quarantined it many times. When i search using google and then click link, i am redirected to another page. if i use the "back" button it doesn't work unless i scroll down three lines to the original target. If i go back and click the link three times it will take me to my target. every time i use webroot spysweeper it finds "Trojan-downlader-ruin" even though i have quarantined it many times. Performed disk cleanup. -- HijackThis (run as NORTHRUP.exe) -------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:24:39 PM, on 4/7/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16609) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\t... Read more A:trojan-downloader-ruin bump bump 10 more replies Answer Match 86.52% Seems like I picked up this little nasty. My Norton does not see it but Spy Sweeper does. When I try to delete it, it just comes back. How the heck do get rid of this? Thanks for looking. \ James A:Trojan-downloader-ruin 16 more replies Answer Match 85.26% With help from you guys over the weekend I was able to get rid of Juan (Vundo ?) but now have spy sweeper reports: Trojan-downloader-ruin detected. I have checked the forums and found several that I've looked into. One from Seaz with MFDnNC helping him/her out. With help from you guys over the weekend I was able to get rid of Juan (Vundo ?) but now have spy sweeper reports: Trojan-downloader-ruin detected. I have checked the forums and found several that I've looked into. One from Seaz with MFDnNC helping him/her out. I would like to ask one of the monitors to look through the two files attached earlier just to make sure nothing is missed. Thanks for you assistance and I will check back tomorrow morning for any posts. Meanwhile I will turn off System Restore and shutdown. Look like Vundo is keeping you guys busy. Hope everyone has as good as luck or better removing it as I did - with your help of course! Thanks HogWild 3 more replies Answer Match 85.26% I'm fixing a computer for a friend and she has a trojan by the looks of it. Any help would be appreciated. Hi everybody, this is my first post here. I've been using the search feature a great deal, and while I've found several very similar problems I've found no definitive answers. Heres the deal. Very recently(about 2-3 weeks ago at most) My CD-RW drive started acting up. It is a Mitsumi CR-48X5TE. I have the latest drivers/updates for it. Read more A:Trojan-Downloader-Ruin Removal Hiya Are you still having this problem? If so, can you do the following: Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application. Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Download and scan with SUPERAntiSpyware Free for Home Users Double-click SUPERAntiSpyware.exe and use the default settings for installation. An icon will be created on your desktop. Double-click that icon to launch the program. If asked to update the program definitions, click "Yes". If not, update... Read more 3 more replies Answer Match 84.42% Hi, my search results on Yahoo or Google are repeatedly redirected to alternate websites when I click on them. I have went through all 9 steps in the preparation guide topic on this forum, but the issue remains. Below is the results of recommended software scans and HJT log. I greatly appreciate any help you can provide to remove this bug. Hi, my search results on Yahoo or Google are repeatedly redirected to alternate websites when I click on them. I have went through all 9 steps in the preparation guide topic on this forum, but the issue remains. Read more A:Trojan-downloader-ruin / Zlob.dnschanger Welcome to the BleepingComputer HijackThis Logs and Analysis forum cmeadorMy name is Richie and i'll be helping you to fix your problems.Please disable Spybot S&D?s protection,or it will interfere.You can enable it after you're clean.Open Spybot and click on 'Mode' and check 'Advanced Mode'.Click on 'Tools' in bottom left hand corner.Click on the 'System Startup' icon.Uncheck 'Teatimer' box and/or uncheck 'Resident'.Click the 'Allow Change' box.Then, check next to the computer clock to see if the icon for Spybot is still there.If it is, right click it and choose 'exit Spybot-S&D Resident'.Restart the computer.If you find you're experiencing problems disabling Spybot's Tea-Timer,follow the info in the link below:http://www.russelltexas.com/malware/teatimer.htmPlease disable SpySweeper,or it will interfere.You can enable it after you're clean.* Open Spy Sweeper and click on Options > Program Options and uncheck "load at windows startup".* On the left click "shields" and then uncheck everything there.* Uncheck "home page shield".* Uncheck "automatically restore default without notification".* Exit the program.* (When we are done, you can re-enable it using the same steps but this time reverse them.)Please download OTMoveIt by OldTimer,save it to your desktop:http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exePlease double-click OTMoveIt.exe to run it.Copy the file paths below to the clipboard by highlighting ALL of them ... Read more 9 more replies Answer Match 84.42% Somehow my husband has downloaded something on my laptop that I cannot get rid of. On Webroot it comes up as Trojan-Downloader-Ruin and the info underneath it says JHKU\S-1-5-21-3453069361-4141592110-2220185813-1000\software\microsoft\windows\currentversion\_r\. Any help that anyone could give in getting rid of this would be very much appreciated A:Trojan-Downloader-Ruin cannot get rid of even with Webroot Spy Sweeper HELP!!!!!!!!!! Please go HERE and carry out the instructions that are posted.Thankyou.. 1 more replies Answer Match 83.58% Hi, can anyone help.My computer was infected with a trojan-downloader-ruin virus which was picked up by Webroot Spy Sweeper and repaired.Ever since the computer has been running slowly.Starting the computer up takes ages ,internet explorer takes ages to open and so do web pages.Can anyone help ,have run the computer in safe mode and run the clean up 4.0 program but this didnt help. Can anyone help many thanx. Marmid............ Read more A:computer slow after trojan-downloader-ruin virus 11 more replies Answer Match 82.74% Thank you for your help!! I have gotten the trojan-downloader-ruin virus and I need some help removing it. I searched the forum and it appears that someone that has knowledge needs to read the hijackthis log to determine how to remove the virus. Thank you for your help!! I have gotten the trojan-downloader-ruin virus and I need some help removing it. I searched the forum and it appears that someone that has knowledge needs to read the hijackthis log to determine how to remove the virus. Read more A:Help removing trojan-downloader-ruin - hijackthis log file posted Thanks I did what you said but the trendmicro did not find the trojan. I have given up and I called someone to come out and take care of the computer. I really appreciate your advice. Thanks again 2 more replies Answer Match 79.38% Recently my Explorer has been acting up, not all pictures loading, click on a page and it won't load but then hit refresh and it works, plus my Java won't work either. The porgram NoAdware has found a keylogger called Second Sight and the program won't delete it, any tips? Could someone please take a look at my log and help me out. Thanks in advance. Read more A:Explorer acting funny... 16 more replies Answer Match 78.54% Internet Explorer has been acting funny. When I enter text, it is delayed. My HiJackThis log is attached, A:Internet Explorer Acting Funny HiThere's no malware showing in your log ...Just this entry :-O4 - HKCU\..\Run: [?????????] ??????????????eDid you obscure it before posting it, or is that exactly how it normaly shows in hijackthis ?If it is, then I want you to remove it ... Disconnect from the internet Close ALL browser windows (including this one) - run hijackthis and tick to fix (check the box next to) the list below.........when all are ticked (checked) click the Fix Checked button at the bottom. :-O4 - HKCU\..\Run: [?????????] ??????????????eWhat you are describing sounds like a lack of resources or possibly a memory leak ...You have a lot of programs running at startup to begin with, so if you run too many more programs you will eventualy run out of resources, does this only happen when you have a lot of programs running ?Please Download CCleaner from :-http://www.filehippo.com/download_ccleaner/ (click the download tab)During the installation be sure to UN-check the box for "Ccleaner Yahoo Toolbar" unless you want it.doubleclick the ccsetup.exe file and install the program...After installing, go to Start > programs > CCleaner > Options > Advanced > UNCHECK "Only delete files in Windows Temp folder older than 48 hours" Make sure the "windows" tab is selectedUnder "internet explorer" tick...Temporary internet filesCookies* > see Note belowHistoryRecently typed URL's (leave this unticked if you DON'T want to clear the drop do... Read more 3 more replies Answer Match 78.54% I need to open a new window three different times, and if i need to click links or anything, it freezes a lot. tried windows updates, but there's nothing there that needs to be updated. help!~Dani(Moderator edit: moved thread to more appropriate forum. jgweed) A:Internet Explorer Acting Funny Make sure you are Spyware & Malware clean.See if this will solve the problem.See this article:Taking out the trashSee this article:The Parasite FightShow all Files & Foldershttp://www.bleepingcomputer.com/forums/ind...showtutorial=62Try these free tools.Trendmicro (free virus scan only)http://housecall.trendmicro.com/These cleaning programs may produce better results if run in Safe Mode.Ewido (free Trojan Scan)http://www.ewido.net/en/download/Adware SE (update after installing)http://www.lavasoftusa.com/software/adaware/Spybot S&D (update after installing)http://www.download.com/Spybot-Search-Dest...4-10122137.htmlAfter doing this and the problems are not better feel free to post a HJT log.Be sure to read the How to submit a HJT Log and submit it to the appropriate forum. HJT Forum links provided below.How to submit a Hijackthis Loghttp://www.bleepingcomputer.com/forums/How...s_Log-t956.htmlHJT Forumhttp://www.bleepingcomputer.com/forums/Hij...alysis-f22.html 2 more replies Answer Match 78.54% Ok, I posted a question a few months how I had to click the back button 3 times instead of one time in order for my browser to go back just one page, and that is still happening. Now on every website, the advertisments, not the popups, but the advertisments that appear on the page itself, say "Page Cannot be displayed" where the ads are suppose to be, on everyone, I have a feeling these two things are connected. One thing is, if I reinstall IE will I still have my built in IE popup blocker that came with IE when I purchased this PC? The PC is only like 4 months old and i actually enjoy the popup blocker thats built right in with IE. Thanks for any help! A:Internet Explorer Acting Funny... excuse me, I need your guide...ance.

Besides running slower, I've noticed on my cable modem, the activity light stays on, solid, constantly. It used to randomly blink. Also, I've noticed a network connection icon pops up in my task bar, sometimes stating connection inactive. No network here. ?? Freezes up a lot suddenly too...needs restart. I've run CWShredder, Spy-bot S&D, Norton AV and here is the HJT log. Any help, greatly appreciated. A problem with this webpage has caused internet explorer to close and reopen the tab" here is the hjt log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at PM 07:24:48, on 2011/3/8 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\PROGRA~1\AVG\AVG10\avgchsvx.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdnserv.exe C:\WINDOWS\system32\lxdncoms.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe C... Read more A:Internet explorer acting funny Hello, and welcome to TSF! Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below. Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. If you have Windows XP, the search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that 'Search system folders', 'Search hidden files and folders', and 'Search subfolders' are checked. For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep). =============== The version of Internet Explorer your currently using is out of date, and should be upgraded to the newest version as soon as possible. =============== Download, unzip to your desktop CWShredder and run it, then: 1. Click "Check For Update" (If an update isn't available, skip to s... Read more 19 more replies Answer Match 77.7% IF THE HJT LOG LOOKS FINE... PLZ POST THAT.. Explorer.exe has restarted itself two times today... and the computers ive seen that happen to always have viruese and what not.. could someone look at my HJT log and see if anything is wrong with it? i dont think so myself, but eh.. IF THE HJT LOG LOOKS FINE... PLZ POST THAT.. Explorer.exe has restarted itself two times today... and the computers ive seen that happen to always have viruese and what not.. could someone look at my HJT log and see if anything is wrong with it? i dont think so myself, but eh.. Under "Configuration and Preferences", click the Preferences button. Click the Scanning Control tab. Under Scanner Options make sure the following are checked (leave all others unchecked): Close browsers before scanning. Scan for tracking cookies. Terminate memory threats before quarantining. Click the "Close" button to leave the control center screen. Back on the main screen, under "Scan for Harmful Software" click Scan your computer. On the left, make sure you check C:\Fixed Drive. On the right, under "Complete Scan&quo... Read more 1 more replies Answer Match 72.66% Hello My PC is a AMD 1.2 with 1 gig ram and a 80 gig western digital harddrive running Windows XP SP2 Pro. My old hard drive died the other day so I implemented my sneacky plan of switching to my back up hardrive. However all dod not go as planned since the move of all the programs seems to have failed, sigh, SO I fix that by dumping all the programs and starting a new. However by yesterday it appeared that I have something on the computer I am running Lava and Avg and Lava said that I had a Worm. This morning I spent the last four hours trying to run lava and avg but no dice. I then came on here and read the sticky and have downloaded a bunch of stuff, hijack and spywareblocker (i think). I will enter the HIjack log in next post> Cheers Z A:Solved: PC acting funny not ha ha Logfile of HijackThis v1.99.1 Scan saved at 11:14:30 AM, on 10/30/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sygate\SPF\smc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE E:\PROGRA~1\avg\avgcc.exe E:\PROGRA~1\avg\avgamsvr.exe E:\PROGRA~1\avg\avgupsvc.exe E:\PROGRA~1\avg\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe F:\DOWNLOADS\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [AVG7_CC] E:\PROGRA~1\avg\avgcc.exe /STARTUP O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - Winlogon Notify: WgaLogon - C:\WINDOW... (NOTE: Lolifox is basically another version of firefox) Logfile of HijackThis v1.99.1 Scan saved at 11:22:43 AM, on 7/31/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe C:\PROGRA~1\Grisoft\AVG7\avgemc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\ALCXMNTR.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\iTunes\iTunesHelper.exe C:\PROGRA~1\Grisoft\AVG7\avgcc.exe C:\Program Files\AIM\aim.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Compaq_Owner\Desktop\Programs\utorrent.exe C:\Prog... Read more A:Solved: Computer acting funny (HJT log) 7 more replies Answer Match 71.82% I get popups, my start page gets changed, I get weird .dll's in my System32 folder, I run CWShredder and it always removes CWS.Bootconf, then I run it again and it removes it again. I remove the bad things from the HJT log, and they come back. I haev been running PestPatrol, XoftSpy, and NoAdware, as well as having scanned my computer several times for viruses with AVG. On top of all of that, the recycle bin appears full, but when I open it there is nothing in it, and when I right click it to empty it it says "Are you sure you want to delete these 27 files" and I click yes and it makes the noise that it empties it, but the icon still says its full and when i do it again it still says there are 27 files in it. Also, for some reason but Temporary Internet Files folder has changes from Local Settings\Temporary Internet Files to Local Settings\Temp\Temporary Internet Files. So the other day my sister was using my computer and when i got it back it was just running really slow. and at the time it would not let me access the task manager because it said that i was not the administrator... so i ran avg and it found a few things here and there, but its still acting really slow, so i was hoping that you guys could help.... Thanks A:Solved: T-SQL statement acting funny Problem was due to the ascii " is not the same as '' Thanks 1 more replies Answer Match 71.82% Just fixed my laptop after about a year and a half of it being broken. Now after i got all the new updates and stuff its acting wierd. When I first turn it on, I cant goto any online mail sites or search engines, also a handfull of other sites wont work. After a while, the bar at the bottom, with the start button, goes away and then the sites work, but I keep getting all kinds of popups. I tried to run adaware, but it didnt find anything. Any help would be appreciated. I attached a hijackthis log. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 4:01:46 PM, on 7/13/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVir... Or doesn't need to be Thanks Logfile of HijackThis v1.99.1 Scan saved at 8:56:43 PM, on 7/5/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\NavNT\defwatch.exe C:\Program Files\NavNT\rtvscan.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\MsgSys.EXE C:\WINDOWS\Explorer.EXE C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\NavNT\vptray.exe C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Nikon\PictureProject\NkbMonitor.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe C:\Program Files\Picaboo\Picaboo\PicabooMain.exe C:\WINDOWS\webshots.scr C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe C:\WINDOWS\System32\HPZipm12.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\outlook express\msimn.exe C:\Documents and Settin... Read more A:Solved: Computer acting funny... 6 more replies Answer Match 70.98% Please help me I had or have a problem with a trojan or virus. It installed extra toolbars and other nasty stuff the other day. I managed to run Ad-Aware SE in safe-mode and cleaned allot of the stuff, Norton found nothing, Spybot SD freezes up, none of my registry cleaners will run (freeze up, even in safe mode), used a few online scanners and came up clean. I found one registry key that acts funny and will freeze up regedit just by high lighting it (have to use task manager to end process): HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count Computer also freezes every now and then for about 30 seconds and then is fine (started with the above problem). I just spent a while updating my computer to service pack 3 and getting other critical updates (I have to do it manually and haven't bothered for some time). Now, when I start up firefox and do a google search, I noticed that there's something called Wikisearch (which I don't really get) is on but I can turn it off with the Greasemonkey app. However, now when there's a list of things from the search result, where before I would click on the titles of the search results and it would take me to the page, now I click on something and the url says "find-www.net/?q=*whatever I'm searching*" and it just reroutes me to some random pages. I have to copy and paste the url under the title of my search results to get where I need to go. It does the same for when Wikisearch is off or on. Can anyone explain? Thanks! Steve A:Solved: Mozilla google search acting funny after updates... You've most likely got some form of malware. Post a Hijack this log and lets see what it is. 2 more replies Answer Match 69.72% We are working in network and have our contact folder logged on the server. There are 5 PC linked to the server. All the contacts are present as we can locate them using a manual search but when we try to search for a specific contact the reply is always “No Items Found”. I have tried to do a normal search as well as advanced search to no avail. This function was working fine until recently even though no new software or hardware has been installed. I have checked the configuration on the folder and permission is given at an owner level to all users, and the problem exists with all users. I am not sure how public folders work in this capacity. 3 more replies Answer Match 69.3% Hi, I've been having this annoying problem ever since installing the latest IE 7 update recently. When I open IE, the location of the links toolbar appears as per the initial defualt settings (whereas I always prefer to have the links toolbar just below the menu bar). However despite changing this, when I close IE and then reopen it, the links toolbar again appears at it's default location Can someone help. Thanks. More replies Answer Match 68.46% Hi there, I need a bit of help if you can. 1st post, so apologies for any breaches of protocol . I found unspyPC on my laptop yesterday, it's some sort of spyware toolbar that masquerades as anti spyware software. I followed some instructions found here to erradicate it. Not sure how I got it, had been offline for a month, so maybe my security profiles were out of date. Hi! I have a Dell Optiplex GX 280 running Windows XP Professional SP3. For some reason, I cant run defrag at all, and Windows Security Center is acting strange as well. My windows security shield keeps popping up for a split millisecond, then disappears. It keeps making a popping noise when it does this, kinda like a popup blocker. It never used to do this. I had downloaded some anti-virus software from a torrent site, and ever since, my computer is not running like it should. I got rid of the suspicious software, but I think the computer is infected with a keylogger, or other malicious software. I have downloaded Combofix, and will wait to run it until I have someone to help me. Thanks in advance for any help! - Chuck The problem is that it will seemingly recognize and read audio CD's without a hitch, but when it comes to data CD's most of the time the CD will spin a bit in the drive and then either it will not be recoginzed as being even in the drive( complete with red/orange flashing light) or it will act as if recognizes the CD but a look at the My computer-> Cd drive icon/exploring the drive shows the data cd as a audio one with a single track!. I am at a loss as to what to do. I am currently running Windows ME ( I know, I know) on a 800 Mhz machine with a good 30 gig of HD space and 128 MB of Ram. Any advice you can give me would be greatly appreceiated(sp). -Sincerely A:CD-RW acting funny... Is this the only CD drive in the system or do you have reader also if you do then dose that one read correctly. I’m asking because it sounds like you associated data CD's to audio. 1 more replies Answer Match 62.58% hi, recently my pc has started running very slow ,freezing up and at times also making a high pitch sound like something is running a 100 mph in the backgraound thus stopping what ever web site im on. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:42:10 AM, on 9/11/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThi... More replies Answer Match 62.58% for some reason, whenever i open my Internet Explorer, the page is "trunkated". what i mean is, even when i maximize the window, it's not formatted so that everything on the page is shown at once, from a width view. therefore, i have to use the arrows on the bottom in order to see the whole page. if anyone can help, i'd really appreciate it. thanks! W A:IE acting funny Howdy, is it just in IE ....are the other programs size OK? Have you tried changing your screen resolution Right click an empty place on the Desktop and choose properties then Settings 2 more replies Answer Match 62.58% Ok so i have vista not sure what service pack, anyways i have comcast internet service and when i am online it works great for a few minutes then i cant connect to the internet or anything else and i have to reboot my computer everytime. This is getting annoying as i cant get any work done. I have run my avg antivirus but it comes up clean, i have cleared my history and cache and still the same thing. Not sure what to do. Thank you for any heap. Leigha A:Please help acting funny Hi - Go into Device Manager and un-install ALL Network devices. START | devmgmt.msc | expand Network tree branch | right-click on each device and select un-install. Re-boot. Vista will re-install the drivers.  5 more replies Answer Match 62.58% Hello, My PC has been going through a few different issues recently. It all started about 3 weeks ago, when it started slowing down really bad (using 100% system memory according to Task Manager). I noticed that the installation of Zone Alarm Suite that I was using was using a lot more memory than the other programs. After running a virus scan and both Spy Bot and Adaware scans with no major issues, I tried uninstalling and re-installing Zone Alarm with no success. So I completely uninstalled ZA and installed Bit Defender 9. This seemed to stop the lag issues. However, soon after I found that I kept getting "exploit.html.codebase.exe" warnings in BD. Soon after getting these my wireless logitech trackball functionality has deteriorated (ie: initial left click isn't acknowledged, cannot drag cursor across multiple characters and some other issues). The battery level seems fine, so does connection with the hub. BTW, I think that I have successfully cleaned my PC of all "exploit.html.codebase.exe" infected files.??? Here is my HJT file: Logfile of HijackThis v1.99.1 Scan saved at 2:03:55 PM, on 8/6/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS... Read more A:PC Just acting funny??? Also would it be beneficial to upgrade the CPU to a Pentium Extreme 3.2GHz for like 40USD$? Is there a program I can use? Ive used CPUID and SIW and the bios and memtest and got all different speed ratings. (sighs) sorry for the long post I just want to understand why the computer is sluggish with these specs. Thanks for any help

A:XPS 600 acting very funny

9 more replies

Hello everyone. I just reinstalled windows because my computer was acting slow and sluggish, thinking it would fix the problem, but the problem persists.

It takes forever for it to load up windows, and it actually sits on the "Loading Windows Xp Pro" Screen for 51 seconds before finally flickering to a black screen for a few seconds, then finally shows my accounts to log on to.

Once windows is loaded my mouse is very jerky and the sound you hear when windows first loads up begins to sound very choppy as well.

I also have an "Unknown" Device in device manager but I don't know what device it's talking about! I have all of my drivers installed and they are all up to date and all my hardware appears to be working fine.

-Eric

More replies

Not sure where to really ask this question. Everytime I put in a cd (blank or already with data) before I can even exlplore the cd a window pops up announcing that my printer is being configured. Meassage say to please wait while configuring.

Eventually a pop up box labeleld HP All-In-One series with 4 steps appears (checking system, prepare to install, install, configure) . Once it finishes I can do what I want with the cd. One time I hit ctl alt del and stopped the process. got a message that ice 2.5 was stopped from exectuing.

What is this and how can I fix it!

A:CD R/ Acting Funny

That could date back to a failed or interupted or installer probelm if an HP all in one driver and software disc was ever placed into that dirve and run. Or it could be something else. I'd want to know if its possible an HP all in one was ever installed first.

You could check the autorun properties of the drive and either restore the defaults or check each CD type to see if the action is set to what you intended.

1 more replies

excuse me, I need your guide...ance.

Besides running slower, I've noticed on my cable modem, the activity light stays on, solid, constantly. It used to randomly blink. Also, I've noticed a network connection icon pops up in my task bar, sometimes stating connection inactive. No network here. ?? Freezes up a lot suddenly too...needs restart. I've run CWShredder, Spy-bot S&D, Norton AV and here is the HJT log. Any help, greatly appreciated.

Logfile of HijackThis v1.98.2
Scan saved at 9:46:29 PM, on 11/1/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
Hello Lord Shamar and welcome to TSF,

Please print these instructions out for use in Safe Mode.

Before we begin, let's move HiJackThis to it's own folder; like c:\HJT. When we're done 'cleaning' off your system, we're going to 'flush' the temporary folders which, with HiJackThis in it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later.
Click My Computer, then C:\
Right click in the right-hand panel.
In the menu that opens, click New>Folder.
Rename it"HJT".

Double-click VundoFix.exe to extract the files

*This will create a VundoFix folder on your desktop.
Computers acting real funny. I logged in to facebook to see it in Thai and my browser seemed a lot slower so I did a drive restore/reset. Still feels kind of slow... DDS (Ver_10-03-17.01) - NTFSx86 Run by Junker at 1:32:54.35 on 04/14/2010 WedInternet Explorer: 7.0.6000.16982AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}SP: Norton Internet Security *enabled* (Updated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\nvvsvc.exeC:\Windows\system32\svchost.exe -k rpcssC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\system32\SLsvc.exeC:\Windows\system32\nvvsvc.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k NetworkServicec:\Program Files\Common Files\Symante... Read more

A:Computer acting funny

4 more replies

My computer has been running strange as well. I have read over several posts and see mention of Hi Jack This Log, can you please direct me on how to do this so that I may post my information as well.

My computer keeps giving me a message when I try to shut it down that says ieexplorer.exe is still in process, the end task or cancel button do not do anything. My computer is also "breathing heavy" as we like to call it. Running very loudly and not normal. I do have Spyware and have recently ran it and fixed problems. I have Windows ME.

A:Computer acting funny

So the other day my sister was using my computer and when i got it back it was just running really slow. and at the time it would not let me access the task manager because it said that i was not the administrator... so i ran avg and it found a few things here and there, but its still acting really slow, so i was hoping that you guys could help.... here is my hjt log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:32:53 PM, on 3/18/2009
Scan saved at 7:16:52 AM, on 4/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Incident Status Location

More replies

My Daughter's computer had been acting funny, and being really slow. Any advice?
Hi, She is or has used Kazaa and we highly recommend that it be uninstalled- perhaps the reason why you did not get any replies.
If you keep Kazaa installed she will always have problems, some will be a lot worse than now. The latest info is about half the files you download from Kazaa networks will be viruses or other junk....
You can uninstall Kazaa from now till next week, but remnants of bad built-in components will stay on the system. It actually looks like it may have already been uninstalled, but there is an entry for it in her logfile....There is a tool that makes the uninstall easier called kazaabegone> location posted below.

Logfile of HijackThis v1.99.1
Scan saved at 3:52:26 PM, on 4/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
13 more replies

Using a cordless optical Logitech mouse. Pointer is "jumping" from point to point. (also runs slow)

Any help would be appreciated..........

Hello, and welcome to the HijackThis Help Forum.

Apologies for any delay in replying, but we have been rather busy lately.

Since it has been a few days since you first posted, please post a fresh HijackThis Log if you still need assistance.

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
Logfile of HijackThis v1.99.1
Scan saved at 10:02:38 PM, on 10/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
The presence of "VchsYQop" indicates you have the Peper trojan.

Spybot should be able to get rid of it (at least it says it can).

Download Spybot, immediately update it and run it. Then post a new Hijack This! log back here.

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
GroupPolicyUsers\S-1-5-21-4202764842-948285082-223560448-1000\User: Group Policy restriction detected <======= ATTENTION

End

6 more replies

A:Windows acting funny

lets see a log with everything enabled as well to compaere before we start

also
Right Click the Zip Folder and Select "Extract All"
Extract it somewhere you will remember like the Desktop
Dont do anything with it yet!

Reboot into Safe Mode
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Doubleclick WinPFind.exe
Click " Configure Scan Options"
Select " Run Add ONs" and then select ALL the options in the box below it, Press Apply
Now Click "Start Scan"
It will scan the entire System, so please be patient!
Once the Scan is Complete
Reboot back to Normal Mode!
Go to the WinPFind folder
Locate WinPFind.txt
Place those results in the next post!. It will be too big to post so you will need to attach it to your reply

1 more replies

So as of the last few days my google search links are getting redirected, my cursor turning to white over any text space, general slowness,and worst of all, starcraft 2 is playing slowly...can anyone help??
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:41 AM, on 3/28/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Steam\Steam.exe
C:\Sun\SDK\jdk\bin\javaw.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page... Read more

A:Pc acting funny - hijack this log

2 more replies

Recently, my computer has been acting funny: freezing at times when I'm online, or working with my Windows Movie Maker, and the screen flashes once, and it's a slow manner with the toolbar and windows becoming blue. It doesn't happen all the time, or most, but it does happen at times. What could be going on?

Just in case: it is a Deskjet F4480, and I got New Years Day 2010.

Thank you.

A:Computer Acting Funny

When the window turns blue is there writing on it and what does it say. How do you get out of the blue windows? The deskjet F4480 is a printer not a computer isn't it?

9 more replies