|
|
|||||||||
|
|||||||||
| |||||||||
|
|
|
| |||||||||
![]() |
|
|
«
Previous Thread
|
Next Thread
»
|
Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
Be the architects of evolution and help create the mobile internet future. It’s your move---enter to win here! |
|
#1
|
|||
|
|||
|
Please help!!! + hijackthis log
I have been having major problems the last few days. First, my registry editor was disabled because I 'did not have supervisor access' when I am the only user on this computer. Next, my norton is basically permanently disabled. It won't start up (as it used to) on boot and it won't auto-protect. When I click enable nothing happens. I have run the full norton scan as well as TrendMicro and it is still happening.
After running TrendMicro (housecall) today again, I can access my registry but Norton is still disabled. EDIT: I forgot to also mention that my Internet Explorer gets errors going to many major websites. For example, I can't get to gmail.com - Also Mozilla will not load any websites at all. Also, when I go to OPTIONS -> INTERNET SECURITY in Norton Internet Security, I get the message "Access Denied. Only the supervisor can view/change the options." Here's my HiJackThis log, thanks. Logfile of HijackThis v1.97.7 Scan saved at 3:12:25 PM, on 10/4/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Norton Internet Security\NISUM.EXE C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\RUNDLL32.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Winamp\winampa.exe C:\Program Files\2Wire\2PortalMon.exe C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\System32\nortonswap.exe C:\Program Files\Norton Internet Security\ccPxySvc.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\AIM\aim.exe C:\WINDOWS\System32\nvsvc32.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\MoTo\Local Settings\Temporary Internet Files\Content.IE5\YHQN2LCT\HijackThis[1].exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs O4 - HKLM\..\Run: [reg.reg] qserv.exe O4 - HKLM\..\Run: [Norton Swap Cleaner] nortonswap.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe O4 - HKLM\..\RunServices: [reg.reg] qserv.exe O4 - HKLM\..\RunServices: [Norton Swap Cleaner] nortonswap.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe O4 - HKCU\..\Run: [DesktopX] "C:\Program Files\Stardock\Object Desktop\DesktopX\DesktopX.exe" O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKCU\..\Run: [reg.reg] qserv.exe O4 - HKLM\..\RunOnce: [reg.reg] qserv.exe O4 - HKCU\..\RunOnce: [reg.reg] qserv.exe O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button: Yahoo! Login (HKLM) O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM) O9 - Extra button: Research (HKLM) O9 - Extra button: AIM (HKLM) O9 - Extra button: Related (HKLM) O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Messenger (HKLM) O16 - DPF: {0000000A-9980-0010-8000-00AA00389B71} - http://download.microsoft.com/download/8/B/E/8BE028EC-F134-4AA0-84AB-64F76D6B9842/wmsp9dmo.cab O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://download.yahoo.com/dl/installs/yab_af.cab O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {F2A84794-EE6D-447B-8C21-3BA1DC77C5B4} (SDKInstall Class) - http://activex.microsoft.com/activex/controls/sdkupdate/sdkinst.cab |
|
#2
|
|||
|
|||
|
Update
UPDATE: I just ran Kaspersky and it found somewhere around 10,000 viruses or scripts, the majority of which were in the Norton directory. I am still not able to access Norton Internet Security or enable auto-protect. =(
|
|
#3
|
|||
|
|||
|
Another Update
Another Update: I restarted my computer and upon loading a website, I saw a K at the bottom of Internet Explorer (the Kaspersky logo), a second later it became black and static-y and then IE closed. This happened repeatedly until I uninstalled Kaspersky.
|
|
#4
|
|||
|
|||
|
bump ;x
|
|
#5
|
|||
|
|||
|
I reinstalled Mozilla and now I get this error: (at least it's an error)
"The connection was refused when attempting to contact www.google.com" -happens with every website and i can't seem to get on secure websites with Internet Explorer (like checking my email) |
|
#6
|
|||
|
|||
|
Hi defx,
Let's do an onlne virus scan from these two these sites: Panda Active Scan www.pandasoftware.com/activescan/activescan Bitdefender http://www.bitdefender.com/scan/licence.php Please copy and paste the report logs into your next post. Then... Let's do some more cleaning up: Download Ad-Aware SE Personal Edition from: http://www.lavasoft.de/support/download/ Run Adaware, click the "Check for Updates now" link. Install the latest reference file Perform a "Full system scan" with Adaware. Remove all checked items. Then... Download, install and UPDATE Spybot Search and Destroy 1.3. Scan and fix all items checked in RED. http://www.safer-networking.org/en/download/index.html Reboot. Please update HijackThis, you are using an outdated version: Open HijackThis, click Config > Misc Tools > Check for Update online Or download a copy of version 1.98.2 at: http://www.majorgeeks.com/download3155.html Post a fresh log with this new version. Tom
__________________
HijackThis Ad-aware Spybot Search & Destroy SpywareBlaster SpywareGuard Housecall Online A/V Scan Please read the stickys at the top of the forum before posting! |
|
#7
|
|||
|
|||
|
Error
Well, first off, I get an error when trying to do the Panda ActiveScan and it won't let me open the page to do the actual scanning. I'm thinking this is the same problem as when I try to check my email and it won't load the page. It says at the bottom "Done...but with errors on the page."
|
|
#8
|
|||
|
|||
|
Did you do any of the other items suggested?
Tom |
![]() |
| Viewing: Dev Shed Forums > System Administration > Antivirus Protection > Please help!!! + hijackthis log |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
|
|