Sitcoms Online - Main Page / Message Boards - Main Page / News Blog / Photo Galleries / DVD Reviews / Buy TV Shows on DVD and Blu-ray

View Today's Active Threads (No Chit Chat/Chit Chat Only) / View New Posts (No Chit Chat/Chit Chat Only) / Mark All Boards Read / Chit Chat Board

Chit Chat - Main Board / Games / Movies / Music / Sports / Video Games / Chit Chat - Classic / View Latest Threads in All Chit Chat Boards


Sitcoms Online Message Boards - Forums  

Go Back   Sitcoms Online Message Boards - Forums > Chit Chat > Chit Chat - Classic

Notices

SitcomsOnline.com News Blog Headlines Facebook X/Twitter Bluesky Threads Instagram YouTube RSS

SitcomsOnline Digest: Joe Dirt Animated Series in the Works at Fox; First Look at The Varnell Hill Show
Disney's Big City Greens Brings Out the Guest Stars; The New SuperKitty Premieres Today
The Varnell Hill Show Coming to Paramount+ on September 1; Hallmark's 3rd Installment of Holiday Touchdown
Colin from Accounts Final Season Premieres September 10; The X-Files: I Want to Believe Gets Director's Cut on Disney+ & Hulu
Amazon MGM Studios Orders Improvised Sitcom; The CW Renews Game Shows for Season 3
CBS Announces Comics Unleashed with Byron Allen 20th Anniversary Special; Hulu to Debut Exclusive Bob's Burgers Holiday Short
Sitcom Stars on Talk Shows; This Week in Sitcoms (Week of August 3, 2026)


New on DVD and Blu-ray

Abbott Elementary - The Complete Fourth Season (DVD) The Office - The Complete Series - Superfan Extended Episodes (Blu-ray) The Bill Dana Show - The Complete Series (DVD) I Love Lucy - The Complete Series - 75th Anniversary Edition (Blu-ray) Perfect Strangers - The Complete Series (Blu-ray)

01/20/26 - The Woody Woodpecker and Friends Golden Age Collection (Blu-ray)
01/27/26 - The New Fred and Barney Show - The Complete Series (Blu-ray)
02/11/26 - Tom and Jerry - The Complete CinemaScope Collection (Blu-ray)
03/24/26 - Looney Tunes Collector's Vault - Volume 2 (Blu-ray)
04/11/26 - Abbott Elementary - The Complete Fourth Season (DVD)
04/21/26 - Famous Studios Champion Collection (Blu-ray) (DVD)
05/19/26 - I Love Lucy - The Complete Series - 75th Anniversary Edition (DVD)
05/19/26 - Looney Tunes Cartoons - The Complete Series (Blu-ray) (DVD)
06/16/26 - Difficult People - The Complete Series (Blu-ray)
06/30/26 - Dastardly and Muttley in Their Flying Machines - The Complete Series (Blu-ray)
07/14/26 - The Office - The Complete Series - Superfan Extended Episodes (Blu-ray)
07/28/26 - The Bill Dana Show - The Complete Series (DVD)
07/28/26 - I Love Lucy - The Complete Series - 75th Anniversary Edition (Blu-ray)
07/28/26 - The Paper - Season One (Blu-ray) (DVD)
08/25/26 - Perfect Strangers - The Complete Series (Blu-ray)
09/08/26 - Looney Tunes Collector's Vault - Volume 3 (Blu-ray)
09/22/26 - Bridget Loves Bernie - The Complete Series (Blu-ray)

More Recent and Upcoming TV DVD and Blu-ray Releases / TV Shows on DVD, Blu-ray and Prime Video / DVD Reviews Archive


Search Sitcoms Online:



Donate

Please make a donation if you can help with Sitcoms Online's web hosting costs. Thanks for your support!

We receive a small commission on all DVDs, Blu-rays, CDs, Books, and any other items ordered through our Amazon.com links as an associate. Thanks for using our links for your online shopping!

Reply
 
Thread Tools Search this Thread
Old 11-11-2005, 04:56 PM   #1
PZelda
Two Valeries! <3
Forum Addict
 
PZelda's Avatar
 
Join Date: Jul 15, 2002
Location: I'm STILL missing NYC. :(
Posts: 78,236
Angry Computer heeeeeeelp

Ohhhhh, Rob...

Even I don't know how to get rid of this annoying virus/trojan on my dad's computer -- that's where I am at right now, actually... My dad's place. The last time I was here for more than five minutes was two months ago and even so, I didn't get much of a chance to check it out then.

This computer has this virus (and trojans also) but I can't get rid of them. I don't know my dad's username and password to update the definitions (McAfee ), so I have to wing it on my own. I can run the virus scanner, but it really doesn't remove anything. So the obvious thing to do would be...AHA...run the antispyware progs AND HijackThis. I have no probs running the antispyware progs...BUT if I go, download HT and unzip it...McAfee pops up and says it detected a virus and that it deleted HT to prevent further spread. SOOOOOOOO.....I can't run HT to check it out myself and post a log here.

Here is a screencap. Toolbar on the desktop is part of the problem, and the 9905 (9/9/05) logfile is a log I saved from Adaware that day. Toolbar points to C:\Program Files\WhenUSearch\whse.exe.

If I go to Start > Settings > Control Panel > Add or Remove Programs, there is a listing for My Way Search Assistant with NO WAY to remove it. No "remove" button. Nothing. (I am going to murder one of my stepsisters... )

There are so many problems, I don't know where to start. This computer is only NINE MONTHS OLD, for crying out loud.
__________________
Cheers behind the couch!

Last edited by PZelda; 10-06-2006 at 07:30 PM.
PZelda is offline   Reply With Quote
Old 11-11-2005, 05:16 PM   #2
MsOrange
Bringin' Sexy Back
Forum Veteran
 
Join Date: Dec 27, 2004
Posts: 6,133
Default

i take it there is no way to get the passwords from your dad? is there an option in McAfee to disable it long enough to download HT?
MsOrange is offline   Reply With Quote
Old 11-11-2005, 05:24 PM   #3
PZelda
Two Valeries! <3
Forum Addict
 
PZelda's Avatar
 
Join Date: Jul 15, 2002
Location: I'm STILL missing NYC. :(
Posts: 78,236
Default

Quote:
Originally Posted by MsOrange
i take it there is no way to get the passwords from your dad? is there an option in McAfee to disable it long enough to download HT?
Nope. My dad and stepmom are on a hunting trip until Sunday at the latest so it's just me here.

I didn't think about the disabling thing...I tried it and I finally got HT to run.

Logfile of HijackThis v1.99.1
Scan saved at 3:23:13 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Allison\My Documents\Unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
PZelda is offline   Reply With Quote
Old 11-11-2005, 05:25 PM   #4
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,225
Default

it wouldn't matter if you had the password for McAfee or not; the virus has corrupted your Virusscan program - you are going to have to manually remove the virus in safemode

you can probably get more info by running HijackThis in safemode, but you will have to open the Task Manager and disable any related processes

check out this page for more info:

http://sarc.com/avcenter/venc/data/p...searchbar.html
robyrob is offline   Reply With Quote
Old 11-11-2005, 05:26 PM   #5
MsOrange
Bringin' Sexy Back
Forum Veteran
 
Join Date: Dec 27, 2004
Posts: 6,133
Default

yay! i actually helped someone!

i'm not goign to give advice on the log, i'm still learning that myself, so i'm going to let rob teach us both on that one...
MsOrange is offline   Reply With Quote
Old 11-11-2005, 05:30 PM   #6
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,225
Default

ok - from your log the things to follow up on are:

npjpi150_04.dll

netsvc.exe

mcgdmgr.cab

everything else is "normal"
robyrob is offline   Reply With Quote
Old 11-11-2005, 05:32 PM   #7
MsOrange
Bringin' Sexy Back
Forum Veteran
 
Join Date: Dec 27, 2004
Posts: 6,133
Default

Rob, are you able to pick up on stuff in a log just because you've been doing it for a while? I mean, i looked at all that and couldn't tell what aws "normal" and what wasn't... share your vast wisdom, oh great one.
MsOrange is offline   Reply With Quote
Old 11-11-2005, 05:40 PM   #8
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,225
Default

Quote:
Originally Posted by MsOrange
Rob, are you able to pick up on stuff in a log just because you've been doing it for a while? I mean, i looked at all that and couldn't tell what aws "normal" and what wasn't... share your vast wisdom, oh great one.
a good portion of it is experience, combined with some plain old common sense; I look at each entry and what it "claims" to be by where it is - say for example if it is a file in the Windows or System directory, is it actually a Windows file, or if it is in a folder for a popular or common program if I recognize it. Some of that just takes time to recognize what the common files you will see for the more popular programs, after that it is a matter of actually googling the ones that look the most suspicious...
robyrob is offline   Reply With Quote
Old 11-11-2005, 05:41 PM   #9
PZelda
Two Valeries! <3
Forum Addict
 
PZelda's Avatar
 
Join Date: Jul 15, 2002
Location: I'm STILL missing NYC. :(
Posts: 78,236
Default

Thanks -- let me go run HT in safe mode...Should take me about 5 min to come back with a new log.
PZelda is offline   Reply With Quote
Old 11-11-2005, 05:46 PM   #10
PZelda
Two Valeries! <3
Forum Addict
 
PZelda's Avatar
 
Join Date: Jul 15, 2002
Location: I'm STILL missing NYC. :(
Posts: 78,236
Default

New log after running in safe mode:

Logfile of HijackThis v1.99.1
Scan saved at 3:44:05 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...23/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
PZelda is offline   Reply With Quote
Old 11-11-2005, 05:56 PM   #11
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,225
Default

Quote:
Originally Posted by robyrob
ok - from your log the things to follow up on are:

npjpi150_04.dll

netsvc.exe

mcgdmgr.cab

everything else is "normal"
"fix" these items with HijackThis, then search for and and delete any occurences of npjpi150_04.dll and mcgdmgr.cab

run your antispyware programs in safemode, run ccleaner, clear out your system restore (turn it off, and turn it back on after everything is OK) reset your Internet Zone settings to medium-high and make sure that NOTHING has been added to the "trusted zone"
robyrob is offline   Reply With Quote
Old 11-11-2005, 06:39 PM   #12
PZelda
Two Valeries! <3
Forum Addict
 
PZelda's Avatar
 
Join Date: Jul 15, 2002
Location: I'm STILL missing NYC. :(
Posts: 78,236
Default

Okay, I did all the above, EXCEPT for the Internet Zone settings. I need a refresher course...Where do I go to do this? I remembered how to at one time, but forgot now.

I am STILL having trouble with that virus and got an error upon running HT that the same virus I spoke of in my first post had been detected in HT, so HT got deleted. Had to shut down everything McAfee-related to run it. I see netsvc.exe is still in there. I removed that in Safe Mode.

Anyway, here's my HT log:

Logfile of HijackThis v1.99.1
Scan saved at 4:36:24 PM, on 11/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Allison\My Documents\Unzipped\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_0_0.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...0/mcinsctl.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

Oh, and the MyWay thing... Had to search for instances of that in Safe Mode and delete as well. I noticed that the directory it was in pointed to Spybot Restore...Hmm.

Anyway, I have to get on scooting home...So I won't be able to do anymore stuff on this computer tonight.

Last edited by PZelda; 11-11-2005 at 06:55 PM.
PZelda is offline   Reply With Quote
Old 11-11-2005, 09:39 PM   #13
robyrob
certified wackball#3
Moderator
Forum Icon
 
robyrob's Avatar
 
Join Date: Aug 03, 2003
Location: hiding under the third booth at Arnold's
Posts: 58,225
Default

Quote:
Oh, and the MyWay thing... Had to search for instances of that in Safe Mode and delete as well. I noticed that the directory it was in pointed to Spybot Restore...Hmm.
- thats normal - if Spybot previously tried to remove it, it would've move the files ino its "backup" folder, you can clean that folder out, or disable the setting to undo changes....
(go to "Mode" on the toolbar, select "Advanced", in the left pane click on "settings" and under "Main settings", uncheck "Create backups of fixed spyware problems for easy recovery")

Quote:
Okay, I did all the above, EXCEPT for the Internet Zone settings. I need a refresher course...Where do I go to do this? I remembered how to at one time, but forgot now.
to change your Internet Zone settings - open the Internet Properties applet in the Control Panel (you can do it from within IE, but if IE is infected you're better off NOT opening it), click on the "Security" tab, select "Internet" and click on "Default Level" to reset or "Custom Level..." to set it to something else (I usually set it to "Medium High" and tweak the individual settings a bit)
- next click on the "Trusted Sites" icon and click on "Default Level", then click on "Sites..." and delete EVERYTHING in there that you didn't put in there yourself... which is probably nothing
- if you add an Ad-Blocking hosts file (like the one in my sig) it will add the addresses of a very large number of the bad sites to your "Restricted sites" zone - preventing them from having ANY access to that PC

Quote:
I am STILL having trouble with that virus and got an error upon running HT that the same virus I spoke of in my first post had been detected in HT, so HT got deleted. Had to shut down everything McAfee-related to run it. I see netsvc.exe is still in there. I removed that in Safe Mode.
you probably need to disable McAfee and do an online scan (housecall.antivirus.com or Panda activescan to try figure out WHAT exactly is in there

you could also to try a scan with ewido security suite - its a free trial version of an excellent program
robyrob is offline   Reply With Quote
Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 07:20 PM.


Although the administrators and moderators of the Sitcoms Online Message Boards will attempt to keep all objectionable messages off this forum, it is impossible for us to review all messages. All messages express the views of the author, and neither the owners of the Sitcoms Online Message Boards, nor vBulletin Solutions Inc. (developers of vBulletin) will be held responsible for the content of any message. The owners of the Sitcoms Online Message Boards reserve the right to remove, edit, move or close any thread for any reason.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.