Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old April 9th, 2005, 01:36 AM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 35 inxs454 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 29 m 59 sec
Reputation Power: 4
Windows Closes using Java

I keep getting viruses in Java so I downloaded Java 2 , That didnt work so I attempted to delete it causing more problems. Yet i still have viruses I'm unable to get into Yahoo games Yet I can get in to the chat site I can't even log into java.com it closes all my windows down heres my thread if anyone can help i'd be grateful.

\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - unable to open file - not scanned.
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT - unable to open file - not scanned.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT - unable to open file - not scanned.
C:\Documents and Settings\LocalService\ntuser.dat - unable to open file - not scanned.
C:\Documents and Settings\LocalService\ntuser.dat.LOG - unable to open file - not scanned.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - unable to open file - not scanned.
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - unable to open file - not scanned.
C:\Documents and Settings\NetworkService\NTUSER.DAT - unable to open file - not scanned.
C:\Documents and Settings\NetworkService\ntuser.dat.LOG - unable to open file - not scanned.
C:\hiberfil.sys - unable to open file - not C:\I386\ASCENT.JP_ - scan incomplete.
C:\I386\ASMS\1\DEFAULT\DEFAULT.CA_ - scan incomplete.
C:\I386\ASMS\10\MSFT\WINDOWS\GDIPLUS\GDIPLUS.CA_ - scan incomplete.
C:\I386\ASMS\10\MSFT\WINDOWS\GDIPLUS\GDIPLUS.DL_ - scan incomplete.
C:\I386\ASMS\10\POLICY\MSFT\WINDOWS\GDIPLUS\GDIPLUS.CA_ - scan incomplete.
C:\I386\ASMS\2\DEFAULT\DEFAULT.CA_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\DXMRTP\DXMRTP.CA_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\DXMRTP\DXMRTP.DL_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\RTCDLL\RTCDLL.CA_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\RTCDLL\RTCDLL.DL_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\RTCRES\RTCRES.CA_ - scan incomplete.
C:\I386\ASMS\52\MSFT\WINDOWS\NET\RTCRES\RTCRES.DL_ - scan incomplete.
C:\I386\ASMS\52\POLICY\MSFT\WINDOWS\NETWORKING\DXMRTP\DXMRTP.CA_ - scan incomplete.
C:\I386\ASMS\52\POLICY\MSFT\WINDOWS\NETWORKING\RTCDLL\RTCDLL.CA_ - scan incomplete.
C:\I386\ASMS\60\MSFT\WINDOWS\COMMON\CONTROLS\COMCTL32.DL_ - scan incomplete.
C:\I386\ASMS\60\MSFT\WINDOWS\COMMON\CONTROLS\CONTROLS.CA_ - scan incomplete.
C:\I386\ASMS\60\POLICY\60\COMCTL\COMCTL.CA_ - scan incomplete.
C:\I386\ASMS\70\MSFT\WINDOWS\MSWINCRT\MSVCIRT.DL_ - scan incomplete.
C:\I386\ASMS\70\MSFT\WINDOWS\MSWINCRT\MSVCRT.DL_ - scan incomplete.
C:\I386\ASMS\70\MSFT\WINDOWS\MSWINCRT\MSWINCRT.CA_ - scan incomplete.
C:\I386\ASMS\70\POLICY\MSFT\MSWINCRT\MSWINCRT.CA_ - scan incomplete.
C:\I386\ASTRO.BM_ - scan incomplete.
C:\I386\ASWRULE.GI_ - scan incomplete.
C:\I386\ATABOOT.SY_ - scan incomplete.
C:\I386\ATIINTAA.IN_ - scan incomplete.
C:\I386\ATOMIC.WM_ - scan incomplete.
C:\I386\ATT.HT_ - scan incomplete.
C:\I386\AUTHSERV.MI_ - scan incomplete.
C:\I386\AUTUMN.JP_ - scan incomplete.
C:\I386\AZUL.JP_ - scan incomplete.
C:\I386\BALLOON.XS_ - scan incomplete.
C:\I386\BAR.XS_ - scan incomplete.
C:\I386\BCKG.DL_ - scan incomplete.
C:\I386\BCKGRES.DL_ - scan incomplete.
C:\I386\BCKGZM.EX_ - scan incomplete.
C:\I386\BEACH.BM_ - scan incomplete.
C:\I386\BEETHOV9.WM_ - scan incomplete.
C:\I386\BIG5.NL_ - scan incomplete.
C:\I386\BIGFOOT.BM_ - scan incomplete.
C:\I386\BINLSVC.DL_ - scan incomplete.
C:\I386\BLANK.HT_ - scan incomplete.
C:\I386\BLANKBKG.GI_ - scan incomplete.
C:\I386\BLISS.JP_ - scan incomplete.
C:\I386\BLUEBARH.GI_ - scan incomplete.
C:\I386\BLUEBARV.GI_ - scan incomplete.
C:\I386\BLUEHILL.JP_ - scan incomplete.
C:\I386\BLUESKY.WM_ - scan incomplete.
C:\I386\BLUE_SS.DL_ - scan incomplete.
C:\I386\BLULAC16.BM_ - scan incomplete.
C:\I386\BOOTCONP.CH_ - scan incomplete.
C:\I386\BOPOMOFO.NL_ - scan incomplete.
C:\I386\BRMSI02F.IC_ - scan incomplete.
C:\I386\BRMSI03.IC_ - scan incomplete.
C:\I386\BRMSI03F.IC_ - scan incomplete.
C:\I386\BROWA.TT_ - scan incomplete.
C:\I386\BROWAB.TT_ - scan incomplete.
C:\I386\BROWAI.TT_ - scan incomplete.
C:\I386\BROWAU.TT_ - scan incomplete.
C:\I386\BROWAUB.TT_ - scan incomplete.
C:\I386\BROWAUI.TT_ - scan incomplete.
C:\I386\BROWAUZ.TT_ - scan incomplete.
C:\I386\BROWAZ.TT_ - scan incomplete.
C:\I386\BRPINFO.DL_ - scan incomplete.

C:\I386\YAHOO.BM_ - scan incomplete.
C:\I386\ZAPOTEC.BM_ - scan incomplete.
C:\I386\ZCLIENTM.EX_ - scan incomplete.
C:\I386\ZCOREM.DL_ - scan incomplete.
C:\I386\ZEEVERM.DL_ - scan incomplete.
C:\I386\ZNETM.DL_ - scan incomplete.
C:\I386\ZONECLIM.DL_ - scan incomplete.
C:\I386\ZONELIBM.DL_ - scan incomplete.
C:\I386\_DEFAULT.PI_ - scan incomplete.
C:\pagefile.sys - unable to open file - not scanned.
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VIRUSLOG.TXT - unable to open file - not scanned.
C:\Program Files\EarthLink Setup\Windows\Config\eln98se.cab - scan incomplete.
C:\Program Files\Java\j2re1.4.1_02\lib\jaws.jar - scan incomplete.
C:\Program Files\Java\j2re1.4.1_02\lib\jsse.jar - scan incomplete.
C:\Program Files\Java\j2re1.4.1_02\lib\rt.jar - scan incomplete.
C:\Program Files\Java\j2re1.4.2_05\javaws\javaws.jar - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\agent.cab - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\agentcfg.cab - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\agentdui.cab - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\agentsub.cab - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\agentupd.cab - scan incomplete.
C:\Program Files\McAfee AntiSpyware 1.00 Install\MSC\shared\mghtml.cab - scan incomplete.
C:\Program Files\Prevx Home\dat\ads.cab - scan incomplete.
C:\Program Files\Yahoo!\Messenger\ypager.log - unable to open file - not scanned.
C:\WINDOWS\Debug\PASSWD.LOG - unable to open file - not scanned.
C:\WINDOWS\Driver Cache\I386\DRIVER.CAB - scan incomplete.
C:\WINDOWS\Driver Cache\I386\SP2.CAB - scan incomplete.
C:\WINDOWS\Internet Logs\D78V1T51.ldb - unable to open file - not scanned.
C:\WINDOWS\Internet Logs\IAMDB.RDB - unable to open file - not scanned.
C:\WINDOWS\Internet Logs\tvDebug.log - unable to open file - not scanned.
C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHDT_P3.CAB - scan incomplete.
C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\instance_Personal_32_1033.cab - scan incomplete.
C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_1.cab - scan incomplete.
C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_11.cab - scan incomplete.
C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_2.cab - scan incomplete.
C:\WINDOWS\PCHEALTH\HELPCTR\PackageStore\package_3.cab - scan incomplete.
C
Finished scanning: 2:24:15 AM, 4/9/2005
Number of files scanned: 101392.
Number of files that could not be scanned: 62
Number of archives containing infected files: 1
Number of infections: 4
Number of infected files not cleaned/deleted/renamed: 4
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-77a4f8fa.zip>BlackBox.class (Java.ByteVerify!exploit trojan)
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-77a4f8fa.zip>VB.class (Java.ByteVerify!exploit trojan)
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-77a4f8fa.zip>Dummy.class (Java.ByteVerify!exploit trojan)
C:\Documents and Settings\Drew\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-77a4f8fa.zip>Beyond.class (Java.Shinwow.AM trojan)

Reply With Quote
  #2  
Old April 9th, 2005, 08:37 AM
megumi amatuka megumi amatuka is offline
Contributing User
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jun 2004
Posts: 4,869 megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level)megumi amatuka User rank is Major (30000 - 40000 Reputation Level) 
Time spent in forums: 2 Months 6 Days 21 h 24 m 42 sec
Reputation Power: 333
(^^;?( I think you'd better do clean installation straightforward.)

Hijack log is only accepted in Antivirus Forum. But this would be helpless.

Reply With Quote
  #3  
Old April 9th, 2005, 12:30 PM
aitken325i's Avatar
aitken325i aitken325i is offline
At a NO MA'AM meeting . . . .
Dev Shed God 18th Plane (13500 - 13999 posts)
 
Join Date: Mar 2004
Location: nr Edinburgh, Scotland
Posts: 13,544 aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)aitken325i User rank is General 15th Grade (Above 100000 Reputation Level)  Folding Points: 10110 Folding Title: Novice Folder
Time spent in forums: 5 Months 2 Weeks 1 Day 8 h 1 m 22 sec
Reputation Power: 1953
I agree with Megumi that this would be better in the AntiVirus forum. What AntiVirus software are you using ?
__________________
The No Ma'am commandments:

1.) It is O.K. to call hooters 'knockers' and sometimes snack trays
2.) It is wrong to be French
3.) It is O.K. to put all bad people in a giant meat grinder
4.) Lawyers, see rule 3
5.) It is O.K. to drive a gas guzzler if it helps you get babes
6.) Everyone should car pool but me
7.) Bring back the word 'stewardesses'
8.) Synchronized swimming is not a sport
9.) Mud wrestling is a sport

Reply With Quote
  #4  
Old April 9th, 2005, 02:00 PM
edwinbrains's Avatar
edwinbrains edwinbrains is offline
Retired Moderator
Dev Shed God 4th Plane (6500 - 6999 posts)
 
Join Date: Jan 2004
Location: London, UK
Posts: 6,670 edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)edwinbrains User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced FolderFolding Points: 85411 Folding Title: Advanced Folder
Time spent in forums: 1 Week 6 Days 23 h 39 m 19 sec
Reputation Power: 92
Thread moved from Windows Help to Antivirus Protection.
__________________
- Edwin -

The General Rules Thread | The General FAQ Thread

Reply With Quote
  #5  
Old April 10th, 2005, 03:45 AM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 35 inxs454 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 29 m 59 sec
Reputation Power: 4
Quote:
Originally Posted by aitken325i
I agree with Megumi that this would be better in the AntiVirus forum. What AntiVirus software are you using ?


Im using EZ Anti virus which can't delete the problem I've downloaded spy bot /ad ware/pestpatrol and dash bug free programs none seem to be able to dominish the trojan .I thought I could do it manually by cleaning Java cashe .but when I go in to the control panel it wouldnt allow me to open the java plug in ,so im really lost

Reply With Quote
  #6  
Old April 12th, 2005, 03:01 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi inxs454,

Let's start out with a HijackThis log.

Please download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix.

Run the program, click the button at the top "Do a system scan and save a logfile". Save the log to a convenient place such as C:\HJT Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed!

http://www.majorgeeks.com/download3155.html

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #7  
Old April 12th, 2005, 10:11 PM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 35 inxs454 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 29 m 59 sec
Reputation Power: 4
I might have to do half at a time ,too many charaters ugh
Logfile of HijackThis v1.99.1
Scan saved at 11:10:24 PM, on 4/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\Program Files\Spyware Doctor\spydoctor.exe
C:\Program Files\RamBooster\Rambooster.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Documents and Settings\Drew\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr6/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hackerwatch.org/library/app/feedback/?Md5=22FD4E58D69969A9165721C797D54931&hwid=A518CB957173873B
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.240.37.28:80
F3 - REG:win.ini: load=??? ?
F3 - REG:win.ini: run=??? ?
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\system32\smiehlp.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\CA\ETRUST~1\ETRUST~2\ca.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [eTrust PestPatrol Active Protection] none
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster\Rambooster.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program Files\SECRETMAKER\secretmaker.exe

Reply With Quote
  #8  
Old April 12th, 2005, 10:12 PM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 35 inxs454 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 29 m 59 sec
Reputation Power: 4
Continuation of Hijack log

O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .UVR: %programfiles%\Internet Explorer\Plugins\NPUPano.dll
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://64.154.241.33/activex/AxisCamControl.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1442/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://www.webcamnow.com/broadcast/ActiveXWebCam.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {A8739816-022C-11D6-A85D-00C04F9AEAFB} (Web Camera Server Control) - http://146.145.49.244/wg_webeye.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BB95299D-B65B-47E0-8DDB-697A66298C3A} (UniVoiceX Control) - http://webcamnow.com/fs5/voice/voice.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/insaniquarium/popcaploader_v6.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4419/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Reply With Quote
  #9  
Old April 16th, 2005, 01:28 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
First I would like you you to empty your Java cache:

Close all browsers go to Start > Settings > Control panel > Java Plugin > General > Delete files

Next, click the Update Tab > Update now

The current version is at 1.5.0

Then...

I would like you to perform an onlne virus scan at Trend Micro Housecall

http://housecall.trendmicro.com/

Select all of your drives listed for scanning. Please check "Auto clean" before scanning.

Please copy and paste the report logs from the scan into your next post. If you can't capture the information, please write down what was found and if anything was or was not deleted. Please include this information in your next post.

Please post a fresh HijackThis log.

Tom

Reply With Quote
  #10  
Old April 18th, 2005, 01:45 AM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2005
Posts: 35 inxs454 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 7 h 29 m 59 sec
Reputation Power: 4
Quote:
Originally Posted by Tom Myboy
First I would like you you to empty your Java cache:

Close all browsers go to Start > Settings > Control panel > Java Plugin > General > Delete files

Next, click the Update Tab > Update now

The current version is at 1.5.0

Then...

I would like you to perform an onlne virus scan at Trend Micro Housecall

http://housecall.trendmicro.com/

Select all of your drives listed for scanning. Please check "Auto clean" before scanning.

Please copy and paste the report logs from the scan into your next post. If you can't capture the information, please write down what was found and if anything was or was not deleted. Please include this information in your next post.

Please post a fresh HijackThis log.

Tom


Hi thanks for responding. I've tried to get into Java I have Win XP I have the icon now it wont open theres no plug in . I did the scan theres no problems according to that .I think I might have deleted something in the registry trying to fix it , Now i get a lot of errors when I restart my computer . i think i might have to reformat Im not sure if theres any other solution and I dont know too much about XP more about 98 . Man things seem to run a little better on 98 lol

Reply With Quote
  #11  
Old April 18th, 2005, 09:25 AM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Quote:
Man things seem to run a little better on 98 lol

There was a time I thought that too, XP is much more stable and secure though. 98's support will end in about a year, you will probably want to hang on to XP:

Quote:
Windows 98 and Windows 98 Second Edition support was scheduled to end on January 16, 2004. The continual evaluation of the Support Lifecycle policy revealed, however, that customers in the smaller and the emerging markets needed additional time to upgrade their product. Therefore, Microsoft will continue to support Windows 98, Windows 98 Second Edition, and Windows Me through June 30, 2006.


http://support.microsoft.com/default.aspx?pr=LifeAn1

The log you posted on April 12 didn't look too bad. The java can be uninstalled and reinstalled.

Post a fresh HijackThis log and we'll see what's up.

Tom

Reply With Quote
  #12  
Old April 18th, 2005, 09:52 PM
inxs454 inxs454 is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)