Fires of Heaven Guild Message Board  

Go Back   Fires of Heaven Guild Message Board > General forums > Development
User Name
Password
Or, use your gamerDNA username: (more...)
ForumSpy Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 05-29-2008, 10:55 AM   #1 (permalink)
Camerous
Registered User
 
Camerous's Avatar
 
Join Date: Nov 2003
Location: Overthere next to that place
Posts: 2,223
-34 Internets
Virus scanner/ spyware detector

I didn't see a thread about this so figured I would ask. I have got the Mona Lisa virus and no matter what online scanners I dl, such as Ad-Aware, Spydoctor, One Care, and Norton, nothing seems to fix my damn comp. What is a good scanner/fixer program I can go buy? I do not like Norton's that much because it's always popping shit up wanting me to buy/apply to their service. I want a stand alone program I can get for around 100 bucks. Any suggestions?
__________________
Camerous' Magelo
Camerous is offline   Reply With Quote
Old 05-29-2008, 11:52 AM   #2 (permalink)
royo
Registered User
 
Join Date: Aug 2007
Posts: 9
Format your stuff and start off from scratch. I'm using Symantec Endpoint Protection and haven't had any problems so far; try getting a trial for it or something, it includes pretty much everything and has great pro-active protection.
royo is offline   Reply With Quote
Old 05-29-2008, 12:19 PM   #3 (permalink)
tikkus
Banned
 
Join Date: Nov 2003
Posts: 1,219
-3 Internets
Its very difficult to rid your computer of any virus after you've already been infected for a long while. I found the best results by starting clean and setting AVG or something to scan once a week.
tikkus is offline   Reply With Quote
Old 05-30-2008, 01:50 AM   #4 (permalink)
Baradak
Registered User
 
Join Date: Jul 2002
Posts: 215
-4 Internets
Super Antispyware - SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!. Download the home version. Install. Update. Complete scan. Win. That'll cover spyware.

Kaspersky Antivirus. Find/DL a trial. Install. Update. Complete scan. Win.

Purchase: Kaspersky Internet Security. Install without firewall. (I fucking hate software firewalls.)

I would add HijackThis, but you can fuck shit up if you don't know what you're doing. Run it, have it save a log file, copy/paste and send me the log in a PM and I can tell you what to nuke.
__________________
FFXI: Spheric (Taru ??/??) - Fenrir
Baradak (57 GAL BRD/WHM) - Hades (lost for now)
WoW: Baradak 61 Warrior - Stormrage
Everquest: Baradak 71 Warrior - Prexus (Terris Thule)
Baradak is online now   Reply With Quote
Old 05-30-2008, 05:09 AM   #5 (permalink)
Camerous
Registered User
 
Camerous's Avatar
 
Join Date: Nov 2003
Location: Overthere next to that place
Posts: 2,223
-34 Internets
Quote:
Originally Posted by Baradak View Post
Super Antispyware - SUPERAntiSpyware.com - AntiAdware, AntiSpyware, AntiMalware!. Download the home version. Install. Update. Complete scan. Win. That'll cover spyware.

Kaspersky Antivirus. Find/DL a trial. Install. Update. Complete scan. Win.

Purchase: Kaspersky Internet Security. Install without firewall. (I fucking hate software firewalls.)

I would add HijackThis, but you can fuck shit up if you don't know what you're doing. Run it, have it save a log file, copy/paste and send me the log in a PM and I can tell you what to nuke.
I went to send you a pm with the log but figured I would do it here so if someone else had the same problems they could also see which ones to zap. Might as well help as many folks as we can with my problem.

Spoiler Alert, click show to read:
Logfile of HijackThis v1.99.1
Scan saved at 7:01:13 AM, on 5/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo!
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: banneradsgalore browser optimizer - {0b765f12-ba89-5509-a30e-13c643d126f3} - C:\WINDOWS\system32\{869da71b-263c-0932-5a68-bc92bd0bb950}.dll
O2 - BHO: (no name) - {15235775-21D1-4E3B-A8B9-8F1DB929648F} - (no file)
O2 - BHO: (no name) - {445789A8-3174-4C34-A148-DC216CE26601} - (no file)
O2 - BHO: (no name) - {5359A9FE-FFCC-4BB3-9C23-22D21D2E228E} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {6DE606AA-34D4-4DB7-BB66-E9DF58745D10} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7FB38D36-F4EF-4B16-B70F-B751145317FA} - (no file)
O2 - BHO: BeSideit IE Helper - {83C35173-E029-42f1-9692-0341EE379A0D} - C:\Program Files\QdrDrive\QdrDrive16.dll
O2 - BHO: (no name) - {86D0CC30-5A31-46D9-96C7-F893485EB595} - (no file)
O2 - BHO: (no name) - {8827B1C8-C470-4681-AD95-0AB79480BE9E} - (no file)
O2 - BHO: (no name) - {8A290466-39BD-419B-93DB-0E9599506654} - C:\WINDOWS\System32\tuvVLCSJ.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: (no name) - {BACCCAD1-8195-4FBF-9CD3-C6AE855EAB12} - (no file)
O2 - BHO: (no name) - {BDADB734-3AC6-4913-833C-0CA58C07E9C5} - C:\WINDOWS\system32\yayyaARi.dll (file missing)
O2 - BHO: (no name) - {D71E234B-334C-4B0F-B8E4-DF5662FDDD38} - (no file)
O2 - BHO: (no name) - {E188EE2D-C2BD-48D2-8458-4B1FB05B6FBE} - C:\WINDOWS\system32\hgGWNEXO.dll (file missing)
O2 - BHO: (no name) - {EF3C3774-3A20-4B72-A331-DA08405AE822} - (no file)
O2 - BHO: (no name) - {fa5794a6-d55f-4e2a-8ec2-a867208e3d05} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [{f686a2b9-4685-c0f0-71e2-4d6e80452361}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{869da71b-263c-0932-5a68-bc92bd0bb950}.dll" DllStart
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: winlogin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102799199500
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/Visi.../TLIEFlash.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - Winlogon Notify: tuvVLCSJ - tuvVLCSJ.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe


Thanks for your help.
__________________
Camerous' Magelo
Camerous is offline   Reply With Quote
Old 05-30-2008, 06:47 AM   #6 (permalink)
Goofy
AzN PrYdE
 
Goofy's Avatar
 
Join Date: Nov 2003
Location: Singapore
Posts: 1,009
-1 Internets
Send a message via ICQ to Goofy Send a message via MSN to Goofy
anyone knows if symantec antivirus is good?

Been using it for many years and its been quite good.
__________________
got milk?
Goofy is offline   Reply With Quote
Old 06-01-2008, 08:16 PM   #7 (permalink)
Angerz
Rock and Roll Gangster
 
Join Date: Aug 2003
Posts: 1,860
-2 Internets
Go here HijackThis Logfileauswertung

Paste in your log, and then remove the ones with an X next to them.

Quote:
Originally Posted by Camerous View Post
I went to send you a pm with the log but figured I would do it here so if someone else had the same problems they could also see which ones to zap. Might as well help as many folks as we can with my problem.

Spoiler Alert, click show to read:
Logfile of HijackThis v1.99.1
Scan saved at 7:01:13 AM, on 5/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Yahoo!
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = Yahoo! SearchBar Home Page
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo!
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Yahoo!
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo!
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: banneradsgalore browser optimizer - {0b765f12-ba89-5509-a30e-13c643d126f3} - C:\WINDOWS\system32\{869da71b-263c-0932-5a68-bc92bd0bb950}.dll
O2 - BHO: (no name) - {15235775-21D1-4E3B-A8B9-8F1DB929648F} - (no file)
O2 - BHO: (no name) - {445789A8-3174-4C34-A148-DC216CE26601} - (no file)
O2 - BHO: (no name) - {5359A9FE-FFCC-4BB3-9C23-22D21D2E228E} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {6DE606AA-34D4-4DB7-BB66-E9DF58745D10} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7FB38D36-F4EF-4B16-B70F-B751145317FA} - (no file)
O2 - BHO: BeSideit IE Helper - {83C35173-E029-42f1-9692-0341EE379A0D} - C:\Program Files\QdrDrive\QdrDrive16.dll
O2 - BHO: (no name) - {86D0CC30-5A31-46D9-96C7-F893485EB595} - (no file)
O2 - BHO: (no name) - {8827B1C8-C470-4681-AD95-0AB79480BE9E} - (no file)
O2 - BHO: (no name) - {8A290466-39BD-419B-93DB-0E9599506654} - C:\WINDOWS\System32\tuvVLCSJ.dll (file missing)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\3.8.0\ViewBarBHO.dll
O2 - BHO: (no name) - {BACCCAD1-8195-4FBF-9CD3-C6AE855EAB12} - (no file)
O2 - BHO: (no name) - {BDADB734-3AC6-4913-833C-0CA58C07E9C5} - C:\WINDOWS\system32\yayyaARi.dll (file missing)
O2 - BHO: (no name) - {D71E234B-334C-4B0F-B8E4-DF5662FDDD38} - (no file)
O2 - BHO: (no name) - {E188EE2D-C2BD-48D2-8458-4B1FB05B6FBE} - C:\WINDOWS\system32\hgGWNEXO.dll (file missing)
O2 - BHO: (no name) - {EF3C3774-3A20-4B72-A331-DA08405AE822} - (no file)
O2 - BHO: (no name) - {fa5794a6-d55f-4e2a-8ec2-a867208e3d05} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Common Files\Viewpoint\Toolbar Runtime\3.8.0\IEViewBar.dll
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [{f686a2b9-4685-c0f0-71e2-4d6e80452361}] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\{869da71b-263c-0932-5a68-bc92bd0bb950}.dll" DllStart
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: winlogin.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/mini...ansporter.cab?
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_44.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102799199500
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.dell.com/Media/Visi.../TLIEFlash.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DL L
O20 - Winlogon Notify: tuvVLCSJ - tuvVLCSJ.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe


Thanks for your help.
Angerz is offline   Reply With Quote
Old 06-03-2008, 05:53 AM   #8 (permalink)
Salshun
+Internets can now be exchanged for free original thought potions!
 
Join Date: May 2003
Location: Las Vegas, NV
Posts: 1,583
Send a message via AIM to Salshun
I agree with a lot of the posts in here, adding to them, here's my recommendation to clean up your box:

1. Format, and I mean REALLY format. If your BIOS supports low level formatting, do that. Note: This can take a stupid amount of time
2. Install your OS, fully update the OS and all drivers from manufacturing companies website itself.
3. I personally love Norton 360 Premium, it's a little bloated, but in one suite you get anti-virus, anti-spyware, internet security, PC performance tools (disk scanner, defragmenter) and various other apps used to try to keep your computer from bogging down, and for the most part, they work.
4. I would recommend Firefox, and configure the security settings by hand, trust me, it will make a difference.
5. From that point on, and this is the biggest, most crucial step, more important than your protection software: Before you download anything, or install a thing, check the source. Know the website you're getting shit from, have all media checked when inserted, try to stick to original, legit installation media, etc. No virus every "appeared" on any computer. It got there somehow. Someone did something to allow it. I would say if you avoid any zip file with the words "serialz" or "crackz" in it, and never go to astalavista.box.sk, 99% chance you'll be fine.
Salshun is offline   Reply With Quote
Old 06-06-2008, 08:36 AM   #9 (permalink)
Sabolin
Registered User
 
Join Date: May 2003
Posts: 313
+9 Internets
Not a fan of Norton or Symantec... they are at the bottom of the pile from my experiences with them. The McAffee Suite is better and then AVG Suite is better than McAffee.

I personally don't use any of them, and instead use AVG free and have it scan once a day at 1pm while I'm at the office, and sunbelt-kerio personal firewall just for being able to monitor active connections/ports and such. If I need to go one step further, then I google "housecall antivirus" and run their free online scanner, but I don't think I've ever had to on my own computer. I also run Firefox 100% of the time.

I built my computer a year and a half ago, download stuff from public/private torrent sites and astalavista constantly, and never had any problems with viruses or spyware.
Sabolin is offline   Reply With Quote
Old 06-06-2008, 03:12 PM   #10 (permalink)
Baradak
Registered User
 
Join Date: Jul 2002
Posts: 215
-4 Internets
Quote:
Originally Posted by Sabolin View Post
Not a fan of Norton or Symantec... they are at the bottom of the pile from my experiences with them. The McAffee Suite is better and then AVG Suite is better than McAffee.

I personally don't use any of them, and instead use AVG free and have it scan once a day at 1pm while I'm at the office, and sunbelt-kerio personal firewall just for being able to monitor active connections/ports and such. If I need to go one step further, then I google "housecall antivirus" and run their free online scanner, but I don't think I've ever had to on my own computer. I also run Firefox 100% of the time.

I built my computer a year and a half ago, download stuff from public/private torrent sites and astalavista constantly, and never had any problems with viruses or spyware.
Norton's 2008 and upcoming 2009 product lines are better than McAfee, AVG, Trend Micro, no contest. The 2009 product line in some testing has installed on machines in under 3 minutes. They've done a lot of work after many years of ignoring feedback.

Personally, I don't run any active protection of any kind. XP firewall is on I guess. I'll do a SuperAS and Kaspersky online scan once every few months, neither ever come up with anything. SAS actually had a false positive on a FFXI DAT file one time, but thats it. But most people aren't as careful/intelligent about their browsing/downloading habits.
__________________
FFXI: Spheric (Taru ??/??) - Fenrir
Baradak (57 GAL BRD/WHM) - Hades (lost for now)
WoW: Baradak 61 Warrior - Stormrage
Everquest: Baradak 71 Warrior - Prexus (Terris Thule)
Baradak is online now   Reply With Quote
Old 06-10-2008, 11:03 AM   #11 (permalink)
Araxen
Pride Never Die
 
Araxen's Avatar
 
Join Date: Mar 2002
Location: Near Chicago, IL
Posts: 2,504
Send a message via ICQ to Araxen Send a message via AIM to Araxen
This is what I use: Newegg.com - ESET NOD32 Antivirus Home Edition V3.0 - Security / Utilities Software
__________________
Currently Playing: WoW: Nuklear, Araxen - Thrall
PSN: Araxen
Araxen is offline   Reply With Quote
Old 06-13-2008, 05:36 AM   #12 (permalink)
slitz
euro scum
 
slitz's Avatar
 
Join Date: Aug 2002
Location: Sweden
Posts: 819
-9 Internets
Once Firefox is installed, download this also: NoScript - JavaScript/Java/Flash blocker for a safer Firefox experience! - what is it? - InformAction
slitz is offline   Reply With Quote
Old 06-15-2008, 01:17 AM   #13 (permalink)
Bladefury
Registered User
 
Bladefury's Avatar
 
Join Date: May 2002
Posts: 377
+0 Internets
best free anti-virus imo: free.grisoft.com

New AVG 8.0 has real time protection and anti-spyware built into it, for free.
__________________
What?
Bladefury is offline   Reply With Quote
Old 09-13-2008, 10:52 AM   #14 (permalink)
Lyrical
Registered User
 
Lyrical's Avatar
 
Join Date: Mar 2005
Posts: 2,873
So I am sort of having the same problem. I downloaded a CyberDefender trial. I decided to not purchase it. The problem is that now it is dumping malware onto my comp. I did some research on CyberDefender, and from what I have been reading, it basically puts tough to remove malware on your comp on purpose, and you can't remove it unless you pay them to be "protected." I am not going to trust someone with my credit card if that is how they do business.

I have tried Ad Aware 2007, Norton Antivirus, AVG 8.0, Spybot SD (which does detect the malware, but won't remove it), Spy Sweeper and HijackThis. Both Spybot and HijackThis are detecting CyberDefender as malware, but won't delete the files. Uninstalling the program won't work either.

What should I do when even HijackThis won't remove the CyberDefender files? Are there any virus/malware scanners that detect and remove CyberDefender files?

I can at least surf the net and open folders on my comp now (I couldn't earlier), but I don't want to keep any CyberDefender files on the comp. Thanks for the help in advance.
__________________
Quote:
Originally Posted by rinthea View Post
I dont know where this declines going to end. This is crazy stuff. Worse than I've ever seen. I remember 2002, with the markets tanking, everyone was panicing... going haywire... someone was saying how its terrible and it doesnt look like stopping. One trader said something like 'wtf do you want? bruce willis on a meteorite? This is what market bottoms are made off', he pretty much bought the low. His nickname was digits for a while, coz his account was growing by them monthly.
Lyrical is offline   Reply With Quote
Old 09-14-2008, 04:52 PM   #15 (permalink)
Baradak
Registered User
 
Join Date: Jul 2002
Posts: 215
-4 Internets
Quote:
Originally Posted by Lyrical View Post
So I am sort of having the same problem. I downloaded a CyberDefender trial. I decided to not purchase it. The problem is that now it is dumping malware onto my comp. I did some research on CyberDefender, and from what I have been reading, it basically puts tough to remove malware on your comp on purpose, and you can't remove it unless you pay them to be "protected." I am not going to trust someone with my credit card if that is how they do business.

I have tried Ad Aware 2007, Norton Antivirus, AVG 8.0, Spybot SD (which does detect the malware, but won't remove it), Spy Sweeper and HijackThis. Both Spybot and HijackThis are detecting CyberDefender as malware, but won't delete the files. Uninstalling the program won't work either.

What should I do when even HijackThis won't remove the CyberDefender files? Are there any virus/malware scanners that detect and remove CyberDefender files?

I can at least surf the net and open folders on my comp now (I couldn't earlier), but I don't want to keep any CyberDefender files on the comp. Thanks for the help in advance.
Install SuperAntiSpyware, update fully. Download ComboFix. Reboot into safemode. (Hit F8 as your computer is starting up, continue doing so even if it starts beeping while you hit the F8 key.)

Full scan with SAS. Reboot back into safemode again. Run Combofix. Run HJT, remove bad entries (can search if you are unsure).

Open up my computer. Browse to C:\windows\system32. Sort the "Date Modified" category so it lists from newest to oldest, IE 9-14-08 at the top. Ignore the folders, scroll down the beginning of the files. If you see randomly named DLLs, INIs, VBS, DAT, etc, above the MRT.EXE (Microsoft malicious software removal tool, obtained from windows updates) most likely they're deleteable. Lookup any and all if you are unsure.

Purchase Pick 1: Norton IS09 (much much improved. 08 was good, 09 is even better), KasperskyIS09, Spysweeper with Antivirus. Install, update, full scan. Make sure you uninstall adaware, spybot, old norton, crap avg 8.0 before installing your new software.

Look up shit before you install it to avoid this in the future. Protection software like the ones I recommended can help prevent infection, but not 100%. User installed shit is even harder to prevent from occuring.

Even better steps for protection: Setup two accounts: 1 with admin privs, 1 as a limited user. ONLY install software under the admin. Do not browse the net whatsoever. Get everything setup while under the admin account, then use the limited account for browsing, etc. MUCH MUCH harder to infect a limited account.
__________________
FFXI: Spheric (Taru ??/??) - Fenrir
Baradak (57 GAL BRD/WHM) - Hades (lost for now)
WoW: Baradak 61 Warrior - Stormrage
Everquest: Baradak 71 Warrior - Prexus (Terris Thule)
Baradak is online now   Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
uberguilds network



All times are GMT -7. The time now is 01:24 AM.


Powered by vBulletin® Version 3.6.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.0.0 RC6