Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #31  
Old April 22nd, 2004, 04:42 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi teacher4u!

How's thing's going? Catching any big ones lately? Thanks for following up on this post!

Hi MOSTB,

Please post your log in a new thread. Things get way too crazy with more than one person's log in one thread. Thanks!

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #32  
Old April 22nd, 2004, 04:56 PM
teacher4u teacher4u is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: Alhambra CA
Posts: 165 teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 8 h 3 m 23 sec
Reputation Power: 7
Send a message via AIM to teacher4u Send a message via Yahoo to teacher4u
Tom,Can I send you a Photo?

Tom,Where could I send you a photo of myself(fat) on my kayak in California with the halibut I caught last Wednesday? teacher4u !

Reply With Quote
  #33  
Old April 22nd, 2004, 08:59 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Thanks! I really prefer to stay anonymous as possible. Maybe you can IM an attachment to me through your User Control Panel here.

Reply With Quote
  #34  
Old April 22nd, 2004, 11:11 PM
teacher4u teacher4u is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: Alhambra CA
Posts: 165 teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 8 h 3 m 23 sec
Reputation Power: 7
Send a message via AIM to teacher4u Send a message via Yahoo to teacher4u
I understand Tom.

Tom,Anonymity is a good thing! I understand. I'll try,but I haven't had much success doing that! If I don't succeed just drop me an email when you're coming to California(unless yuo're already here!) and we'll go catch some! Teacher4u

Reply With Quote
  #35  
Old April 23rd, 2004, 12:13 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Thanks, I could use a vacation!

Reply With Quote
  #36  
Old April 23rd, 2004, 06:55 PM
teacher4u teacher4u is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: Alhambra CA
Posts: 165 teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 8 h 3 m 23 sec
Reputation Power: 7
Send a message via AIM to teacher4u Send a message via Yahoo to teacher4u
images?

Can you tell me how to send an image using the ucp if the image isn't web-based? No URL! It's in my pc! Thank you!

Reply With Quote
  #37  
Old May 31st, 2004, 10:04 AM
Kickster Kickster is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 1 Kickster User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
res://mshp.dll/index.html#37049

I'm new here so i'm just learning this site, My homepage keeps going to this res://mshp.dll/index.html#37049 I ran cwshredder & highjackthis, It removes the R1 & R0 that I want to remove but it keeps coming back after I restart the computer, Can anyone help ? Thanks

Reply With Quote
  #38  
Old May 31st, 2004, 07:22 PM
teacher4u teacher4u is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: Alhambra CA
Posts: 165 teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 8 h 3 m 23 sec
Reputation Power: 7
Send a message via AIM to teacher4u Send a message via Yahoo to teacher4u
Exclamation Kickster's post

Dear Devshed.the post above isn't mine.You need to get kickster to start his own thread. I can't be in the middle of this! Thank you,teacher4u

Reply With Quote
  #39  
Old June 2nd, 2004, 08:44 AM
001jaycee 001jaycee is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: May 2004
Posts: 2 001jaycee User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
I just got rid of this thing, there is a dos utility called dllfix.exe that will find the hidden dll which is causing the problem then you have to manually remove the
file (in Dos)

Good luck

Reply With Quote
  #40  
Old June 16th, 2004, 04:38 PM
imnotcrazyyet imnotcrazyyet is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 1 imnotcrazyyet User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Hi and thanks in advance. I had the same problem on an XP box. Used Adaware and Hijack This! and CWShredder. The problem is still there. I have two questions...

1) When using CWShredder, is the following filename random: C:\WINDOWS\MLUninst.exe Should CWShredder delete it?

2) Here is the Hijack This log. Can someone please tell me what to delete?
Logfile of HijackThis v1.97.7
Scan saved at 1:21:16 PM, on 6/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
c:\jetsuite\jsdaemon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\iebd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\sysfo32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\jetsuite\JETSTAT.EXE
c:\jetsuite\JSFMAN.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\bbyon\Local Settings\Temp\Temporary Directory 1 for hijackthis1977.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = URL
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\stale.dll/sp.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://stale.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\stale.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://stale.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\stale.dll/sp.html#96676
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = URL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {CC99040E-760C-7B3F-DB14-4EE4EB7AA49E} - C:\WINDOWS\mfcyk32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [sysfo32.exe] C:\WINDOWS\sysfo32.exe
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: DllCmd32.lnk = C:\jetsuite\DLLCMD32.EXE
O4 - Global Startup: HP LaserJet 3100 Status.lnk = C:\jetsuite\JETSTAT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: IBM Java Console (HKLM)
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - URL

Again, thanks a lot!

Reply With Quote
  #41  
Old June 16th, 2004, 05:19 PM
teacher4u teacher4u is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2004
Location: Alhambra CA
Posts: 165 teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level)teacher4u User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 8 h 3 m 23 sec
Reputation Power: 7
Send a message via AIM to teacher4u Send a message via Yahoo to teacher4u
What to do!

Here's what to do. Go to www.devshed.com. You're on it now. you'll need to sign up. It's
free. Go to their forum. You should post a new post on the windows section
of their forum. Give it a title that states your problem ,and the text in
your post elaborates about it. They'll respond,step by step and you follow
and fix the problem! Good Luck! Jerry

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Browser start page hijacked by /index.html#37049 !Help!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support |