• Home
  • Reviews
  • Articles
  • News
  • Tools
  • GamingHeaven
  • Forums
  • Network
 

Go Back   DriverHeaven.net > Forums > Software / Tools > Windows XP / 2000 / NT / 9x Forum

Notices

Reply
 
LinkBack Thread Tools
Old Jul 11, 2006, 01:11 AM   #1
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

Virus won't go away

I have had some virus problems on my computer now and most are gone. I still keep getting some popups about stuff like WinAntivirusPro. I have done full system scans using Avast, Spybot, Ad-Aware, and Ewido in both regular mode and safe mode. I am still getting problems though, plz help.
rian222 is offline   Reply With Quote
Old Jul 11, 2006, 11:22 AM   #2
DriverHeaven Granddaddy
 
Dyre Straits's Avatar
 
Join Date: May 2002
Location: Georgia, USA
Posts: 12,115
Dyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to all

You may want to do an online free scan to see exactly what virus/es may still be present.

Popups don't necessarily mean you have a virus. It could just be adware.
Dyre Straits is offline   Reply With Quote
Old Jul 11, 2006, 02:00 PM   #3
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

but spybot, ad-aware, and ewido keep dectecting the same things everytime i run them, even though i delete the viruses. How do i run an online scan? Oh, and by virus, i mean adware spyware etc.
rian222 is offline   Reply With Quote
Old Jul 12, 2006, 01:15 AM   #4
DriverHeaven Granddaddy
 
Dyre Straits's Avatar
 
Join Date: May 2002
Location: Georgia, USA
Posts: 12,115
Dyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to all

Quote:
Originally Posted by rian222
but spybot, ad-aware, and ewido keep dectecting the same things everytime i run them, even though i delete the viruses. How do i run an online scan? Oh, and by virus, i mean adware spyware etc.
Well, then, you don't mean 'virus'. You mean adware, spyware, etc. There's quite a difference between them.

As for detecting the same thing, it's likely due to one of your frequent WEBsites putting it back each time you visit that site.

Download Crap Cleaner [Google for CCleaner] and then run the Cleaner and then the Issues apps. It does an excellent job of cleaning out junk that others leave behind.
Dyre Straits is offline   Reply With Quote
Old Jul 12, 2006, 09:50 AM   #5
DriverHeaven Extreme Member
 
Join Date: May 2002
Location: Boston, USA
Posts: 3,528
dipstick is on a distinguished road
System Specs

Have you tried CWShredder?
http://www.intermute.com/spysubtract..._download.html

Also you can do an online scan at http://www.kaspersky.com/virusscanner

Edit- Didnt see your other post hehe. Maybe its time for a windows reinstall

Last edited by dipstick; Jul 12, 2006 at 10:23 AM.
dipstick is offline   Reply With Quote
Old Jul 12, 2006, 11:34 AM   #6
DriverHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,122
The_Neon_Cowboy is on a distinguished road
System Specs

Stage one:

make sure you have loaded the lastest spyware blaster, spybot and adaware,
as well as thier program updates.

1) download hijack this
you'll need this.

2) Turn off system restore!!! in you contol panel under system

3) got start, run, type sfc /purgenow
this will cear out file back up by system file protection wich can b used against you
a windows will replace those files if they are deleted or alterd, with the cached version

Stage 2:

Disconnect the internet

Stage3:

2) unpack and run the program
3) choose do a scan and make a log
4) post the log created and let us have a look see or if you think you can figure out
what souldn't be loading by all means check them and do the fix. Of couse you'll be
to be back online to post and recive our responces. in wich just discconect from the
internet before fixing.

5) After you've removed those entries, scan with spybot, and adaware remove all threats
6) reboot, rerun the spybot, and adaware scans and remove anything they detect...
7) open you windows hosts file in a txt editor like notepad. The file can be found
in "C:\WINDOWS\system32\drivers\etc the file name is "hosts" (it has no extension)
inside this file it should only read


# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost


If there is anything else there delete it and save the file.

8) right click te IE icon on you destop, then click proerties, click th advanced tab ,
then click restore defaults, then go to the secuity tab and make sure it desn't say
"custom" if so just click the defaults butteon after clicking each zone one at a time.
then click apply...

10) reboot, see if you popups are gone, if so re-enable system restore, go in and
create a restore point,

Start Menu\Programs\Accessories\System Tools\System Restore

then goto

Start Menu\Programs\Accessories\System Tools\Disk Cleanup
click more options

under system restore click "clean up"



THat should be it...... connect the internet and cross your fingers
The_Neon_Cowboy is offline   Reply With Quote
Old Jul 12, 2006, 01:33 PM   #7
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

Okay, i am about to do what u guys said. But i have a quick question. Which ones of the resident protections are overkill. I have avast resident, ad-watch resident, spybot resident and teatimer, ewido resident, and i am about to get spyware blaster. Thats a lot of resident protection. Is there any I can safely disable so I dont have so much running at once?
rian222 is offline   Reply With Quote
Old Jul 12, 2006, 01:36 PM   #8
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

heres the log:

Logfile of HijackThis v1.99.1
Scan saved at 11:35:23 AM, on 7/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Compaq_Owner\Desktop\hijackthis\HijackThi s.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://americasarmy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {09A2B6CE-83ED-11D2-9844-00104B2CD3A4} (DemoShield DemoX Class) - http://www.hornflush.com/web/demox.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1151535501906
O16 - DPF: {7B41B7AC-3496-4C13-A70F-DE6B60A6A8A8} (MGAME manager Class) - http://www.legendofares.com/download...nagerv1001.cab
O16 - DPF: {A352D8E5-25DE-4B83-872F-98842905DE04} (NlsComm Component Class) - http://login.hanbiton.com/cab/NLSnSSO.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O20 - AppInit_DLLs: nslookup.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
rian222 is offline   Reply With Quote
Old Jul 12, 2006, 01:42 PM   #9
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

Here is the logfile after I installed Spyware Blaster if its nessacary:

Logfile of HijackThis v1.99.1
Scan saved at 11:41:31 AM, on 7/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Compaq_Owner\Desktop\hijackthis\HijackThi s.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://americasarmy.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...rm1=seconduser
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {09A2B6CE-83ED-11D2-9844-00104B2CD3A4} (DemoShield DemoX Class) - http://www.hornflush.com/web/demox.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1151535501906
O16 - DPF: {7B41B7AC-3496-4C13-A70F-DE6B60A6A8A8} (MGAME manager Class) - http://www.legendofares.com/download...nagerv1001.cab
O16 - DPF: {A352D8E5-25DE-4B83-872F-98842905DE04} (NlsComm Component Class) - http://login.hanbiton.com/cab/NLSnSSO.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O20 - AppInit_DLLs: nslookup.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_ 3dsmax8server.exe
rian222 is offline   Reply With Quote
Old Jul 12, 2006, 01:46 PM   #10
DriverHeaven Granddaddy
 
Dyre Straits's Avatar
 
Join Date: May 2002
Location: Georgia, USA
Posts: 12,115
Dyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to all

Quote:
Originally Posted by rian222
Okay, i am about to do what u guys said. But i have a quick question. Which ones of the resident protections are overkill. I have avast resident, ad-watch resident, spybot resident and teatimer, ewido resident, and i am about to get spyware blaster. Thats a lot of resident protection. Is there any I can safely disable so I dont have so much running at once?
I have the new Microsoft Spyware app installed, Ad-Aware PE, Spybot Search & Destroy.

Then, I do have my physical router w/ its firewall, and a software firewall (not using Windows Firewall).

And, only ONE Virus Program. I don't have but one active at a time. Although, I do have the free AVG to run manually when I choose.
Dyre Straits is offline   Reply With Quote
Old Jul 12, 2006, 01:50 PM   #11
DriverHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,122
The_Neon_Cowboy is on a distinguished road
System Specs

ARG! I don't see anything that jumps out and bites me, do a CTL+ ALT+ DEL
make sure show processes from all users is checked, post a screen shot of
that screen. If it's still showing crap there has to be something running...
The_Neon_Cowboy is offline   Reply With Quote
Old Jul 12, 2006, 01:56 PM   #12
DriverHeaven Senior Member
 
Join Date: Jul 2003
Location: Calgary, Alberta, Canada
Posts: 596
technonerd is on a distinguished road

I suggest you try going to http://www.bleepingcomputer.com/ for help.

Go to the forum on security section and you'll see Hijack, copy your hijack files and somebody will help ya.

This forum would be the the best place for spyware, virus and some other problem.

Good luck.
technonerd is offline   Reply With Quote
Old Jul 12, 2006, 02:07 PM   #13
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

Here is the screenshot of my processes:


rian222 is offline   Reply With Quote
Old Jul 12, 2006, 02:07 PM   #14
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

dangit, why does it always shrink!?!?!
rian222 is offline   Reply With Quote
Old Jul 12, 2006, 02:14 PM   #15
DriverHeaven Granddaddy
 
Dyre Straits's Avatar
 
Join Date: May 2002
Location: Georgia, USA
Posts: 12,115
Dyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to all

Quote:
Originally Posted by rian222
dangit, why does it always shrink!?!?!
Are you clicking the option to automatically resize it? If so, don't.

NOTE: Will be gone for a while....maybe the rest of the day.
Dyre Straits is offline   Reply With Quote
Old Jul 12, 2006, 02:16 PM   #16
DriverHeaven Lover
 
Join Date: May 2006
Posts: 168
rian222 is on a distinguished road

rian222 is offline   Reply With Quote
Old Jul 12, 2006, 02:18 PM   #17
Member
 
Join Date: Mar 2003
Posts: 5,984
PangingJr has a spectacular aura aboutPangingJr has a spectacular aura aboutPangingJr has a spectacular aura about

saw you have the Winantiviruspro advertisements pop up,
this might help, check it out... http://www.geekstogo.com/forum/index...howtopic=88126

"still keep getting some popups about stuff like WinAntivirusPro"

anyway, besides that, what else have happened on your system that you think they are strange things and computer viruses causing them?

Last edited by PangingJr; Jul 12, 2006 at 02:41 PM.
PangingJr is offline   Reply With Quote
 

 
Powered by: vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Artwork by Allan 'Zardon' Campbell, vBulletin implementation by Craig '5320' Humphreys based on original artwork by Ratchet.

All times are GMT -5. The time now is 08:00 AM. Copyright ©2008 HeavenMedia.net