|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
Survey |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
IP: 213.112.*.*
Guest
|
Posted: Thu Dec 04, 2003 6:07 pm Post subject: Hello i got some virus |
|
|
Hello i got some virus these days theres o much spyware,trojans,viruses etc i had all those cool web,scpack viruses etc but now i got a virus that makes it imposible to change my settings in grapics resolution...i only have 16 colors and 640x480 when i change the settings nothin happens i know its one off those viruses had explorer,...often get alexa regestery and cool-web trojans...and java trojans....anybody have clue what this virus is that prevents me to change to more than 16 colors and 640x480?
i use spykiller,adaware,antivir personal edition...sometimes when u run thoose programs it detects viruses and hijaks and sometime it dont these viruses seem to hide sometimes..anybody had same preobs in control panes diplay settings?
|
|
| Back to top |
|
 |
TonyKlein
Site Moderator Microsoft MVP
 Joined: Oct 15, 2002 Posts: 13113 Location: Netherlands
|
Posted: Thu Dec 04, 2003 6:28 pm Post subject: |
|
|
I'm not sure a virus could be responsible for "blocking" changes to your display settings.
Let's start by giving us a closer look at your configuration:
Go to http://tomcoyote.org/hjt/ , and download 'Hijack This!'.
Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.
Most of what it lists will be harmless or even required, so do NOT fix anything yet.
Someone here will be happy to help you analyze the results. _________________ Tony CLSID List
|
|
| Back to top |
|
 |
IP: 213.112.*.*
Guest
|
Posted: Thu Dec 04, 2003 7:07 pm Post subject: |
|
|
Logfile of HijackThis v1.97.7
Scan saved at 19:53:32, on 2003-12-04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACRORD32.EXE
C:\PROGRAM FILES\SPYKILLER\SPYKILLER.EXE
C:\WINDOWS\DESKTOP\TEMP\HIJAK\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.metacrawler.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O4 - HKCU\..\RunServices: [SpyKiller] C:\Program Files\SpyKiller\spykiller.exe /startup
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/plugins/en_US/DjVuControl_en_US.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
thx for any help...
|
|
| Back to top |
|
 |
TonyKlein
Site Moderator Microsoft MVP
 Joined: Oct 15, 2002 Posts: 13113 Location: Netherlands
|
Posted: Thu Dec 04, 2003 7:30 pm Post subject: |
|
|
Well, it's a pretty clean log. Just have Hiijack This fix these:
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
You may want to reinstall or update your video driver. _________________ Tony CLSID List
|
|
| Back to top |
|
 |
IP: 213.112.*.*
Guest
|
Posted: Thu Dec 04, 2003 8:31 pm Post subject: |
|
|
thx i cleaned thoose but when i run spykiller now it found 2 spys and adaware but cant delet they want gss...the adreses are not complete to see line if not buy program....also not only 16 colors unchangable but when i delet things it slows up for 30 seconds its def some kind of virus had similare before....
Spy:
EmployeeWa...? HKEY_CURRENT_USER\software\microsoft\Windows\...?
Company name: User friendly program...
Registry
Adaware:
BDE C:\WINDOWS\SYSTEM\Catroot\{127D0A1D-4EF2-11D...?
Company name: Brilliant Digital
Drives
this all info got it dont show all cause wana make u but their prog...
but i think i got some virus that constatly resetts my display colors ive reinstale both win 98 and video drv...
|
|
| Back to top |
|
 |
IP: 213.112.*.*
Guest
|
Posted: Thu Dec 04, 2003 8:33 pm Post subject: |
|
|
also searched for Catroot and found 2 cataloges that i deleted..
|
|
| Back to top |
|
 |
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|