CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

i have tried.

 
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
supes113

Cadet
Cadet


Joined: Aug 09, 2004
Posts: 5
Location: USA

PostPosted: Tue Aug 10, 2004 3:53 pm    Post subject: i have tried.
Reply with quote

my computer has something running in the background that will not allow norton, task manager, or even hijackthis to run, i try and open them and it immedietly closes them. do you know of an adware or virus that would cause programs to be closed while eating up my memory?

Back to top
View users profile Send private message Send email
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Tue Aug 10, 2004 4:34 pm    Post subject:
Reply with quote

hello
reboot to safe mode run norton from there. see if it finds any viruses.
next run hijack this from there and put its log file in a note pad save it reboot follow the drirctons here for where to install hijack this etc.
In order to help you we need a HiJackThis log.

You will be posting the HiJackThis log in the HiJackThis forum: CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html

Read the HJT forum posting rules: CastleCops Link/postt8864.html

Download HiJackThis from : CastleCops Link/downloads-cat-14.html

Create a folder and unzip the HiJackThis download to the folder. Do not unzip the HiJackThis download to your Desktop or the Temp folder - it won't work.

Doubleclick "HijackThis.exe". First, update HiJackThis by pressing the "Config" button, then press "Misc Tools", followed by "Check for update online". If you downloaded an updated HJT, click "Yes" at the "Open the file?" prompt. If you did not update, press the "Back" button .

Press "Scan".When the scan is finished, use "Save Log" button and save the log as a text file. Its best to save your text file in the same folder as where you put HiJackThis.

DO NOT FIX ANYTHING YOURSELF UNTIL INSTRUCTED TO DO SO ONLY BY A CCSP EXPERT. MOST OF THE HJT LOG ENTRIES ARE NEEDED TO RUN YOUR COMPUTER. REMOVING THE NEEDED ENTRIES CAN CAUSE SERIOUS DAMAGE TO YOUR COMPUTER.

Post your log in the HiJackThis forum : CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html. Click "NewTopic" and simply copy/paste the HJT log into the textbox. Include the information requested in the HJT forum posting rules: CastleCops Link/postt8864.html

Make sure your HJT log is posted only in the HiJackThis forum: CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html.


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
supes113

Cadet
Cadet


Joined: Aug 09, 2004
Posts: 5
Location: USA

PostPosted: Tue Aug 10, 2004 8:18 pm    Post subject:
Reply with quote

well, i have tried running hijackthis in safe, no go. still blocked it. task manager and norton are a go though. i will continue to try. thanks.

Back to top
View users profile Send private message Send email
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Tue Aug 10, 2004 8:39 pm    Post subject:
Reply with quote

you might try d/ling a2 trojin scaner.
d/l a2 free
http://download.emsisoft.com/a2freesetup.exe
and update it run it.
if it won,t runn in normale mode try safe mode.


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
supes113

Cadet
Cadet


Joined: Aug 09, 2004
Posts: 5
Location: USA

PostPosted: Wed Aug 11, 2004 5:03 am    Post subject:
Reply with quote

Logfile of HijackThis v1.98.2
Scan saved at 12:53:49 AM, on 8/11/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\winlogon.exe
C:\WINDOWS\system32\dllcache\win32\csrss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
C:\WINDOWS\System32\RUNDLL32.exe
C:\Program Files\a2 free\a2start.exe
C:\WINDOWS\System32\chfffxem.exe
C:\Program Files\a2 free\a2scan.exe
C:\Documents and Settings\supes\Desktop\hijackthis\jo.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Microsoft Update] wserv32.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPOR~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [Windows Media Player] chfffxem.exe
O4 - HKLM\..\RunServices: [Microsoft Update] wserv32.exe
O4 - HKLM\..\RunServices: [Windows Media Player] chfffxem.exe
O4 - HKCU\..\Run: [SFP] C:\Program Files\Common Files\Verizon Online\SFP\vzSFPWin.EXE /s
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Windows Media Player] chfffxem.exe
O4 - HKCU\..\RunServices: [Windows Media Player] chfffxem.exe
O4 - Startup: Ubisoft register.lnk = C:\Program Files\Ubisoft\Register\schedule.exe
O4 - Global Startup: Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\SupportCenter\bin\matcli.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O10 - Broken Internet access because of LSP provider 'xfire_lsp_7626.dll' missing
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://register3.valueactive.com/420/webolr/OCX/FlashAX.cab






i had to rename the hijackthis file. then it worked, just thought i would get creative. anyway, here ya go. i tried the a2 program to no avail.

Back to top
View users profile Send private message Send email
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Wed Aug 11, 2004 5:17 am    Post subject:
Reply with quote

Make sure your HJT log is posted only in the HiJackThis forum: CastleCops Link/f67-Trend_Micro_HijackThis_Logs.html.


this as stated above allso is where it needs to be posted!!!!!!


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> General Computer Problems All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can report post to moderators in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer