Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2005-01-27, 06:51 PM   #1
th3g4me
Trying is the first step towards failure
 
th3g4me's Avatar
 
Join Date: Feb 2004
Posts: 121
have you tried system restore?
th3g4me is offline   Reply With Quote
Old 2005-01-27, 07:04 PM   #2
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by th3g4me
have you tried system restore?
no not yet on this moment i am on my other puter, the infected puter will run spybot, but shut down adaware and all, i cant get on the net anymore with that one.
stuveltje is offline   Reply With Quote
Old 2005-01-27, 07:14 PM   #3
Linkster
NO! Im not a female - but being a dragon, I do eat them.
 
Linkster's Avatar
 
Join Date: Mar 2003
Location: Sex Delta
Posts: 5,084
Send a message via ICQ to Linkster
can you run hijackthis on the infected computer? If so could you post the log from running it and maybe we can get rid of whatevers causing it
__________________
Pussy Chompers
Porn Links
NSCash
Linkster is offline   Reply With Quote
Old 2005-01-27, 07:42 PM   #4
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by Linkster
can you run hijackthis on the infected computer? If so could you post the log from running it and maybe we can get rid of whatevers causing it
i cant get online anymore with the other puter i still can do hyjack this. spybot can do also find nothing but as soon i run adware or my virus scanner it restarts, i just run a fix tool for beagle.ay that oneisnt in my puter. i am gonna try to write the hyjack thing and type it on my other puter.so i can post it on the board
stuveltje is offline   Reply With Quote
Old 2005-01-27, 07:48 PM   #5
tiny
Hello, is this President Clinton? Good! I figured if anyone knew where to get some tang it would be you
 
Join Date: Aug 2003
Location: maine
Posts: 447
Back up all your stuff for work and format it you'll be better off.Do you have a external storage device.You might unknowly infect other folks.Atleast thats what i would do whatever you have is deep in the system anything thats important save to backup and wipe that puppy clean
tiny is offline   Reply With Quote
Old 2005-01-27, 07:49 PM   #6
ngb1959
Oh no, I'm sweating like Roger Ebert
 
ngb1959's Avatar
 
Join Date: Jun 2004
Location: In A Box, A Big Old Box
Posts: 501
I just had a bunch of computer problems similar to yours.

I had to uninstall that stupid spybot thing. It was messing up my computer. I also took off the alexa toolbar that messed it up and the google desktop thingy.

Had to reinstall adaware. Then it worked normal again.
ngb1959 is offline   Reply With Quote
Old 2005-01-27, 07:55 PM   #7
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by ngb1959
I just had a bunch of computer problems similar to yours.

I had to uninstall that stupid spybot thing. It was messing up my computer. I also took off the alexa toolbar that messed it up and the google desktop thingy.

Had to reinstall adaware. Then it worked normal again.
mmmmmmmm i can try that, on this moment i am dead tired, i have been from 5 this morning on the net and its now almost 2 midnight, i have to give up for now.........goddamnnnn fucking shit puters, and that fucking thing is just 5 months old, thanks for your help all, i wil try some suggestions tomorrow morning .....if it not works i wil beg for more help again.........
stuveltje is offline   Reply With Quote
Old 2005-01-28, 05:54 AM   #8
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by Linkster
can you run hijackthis on the infected computer? If so could you post the log from running it and maybe we can get rid of whatevers causing it
oke:
Logfile of HijackThis v1.99.0
Scan saved at 11:53:15, on 28-1-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\VTTimer.exe
C:\Program Files\VIAudioi\SBADeck\ADeck.exe
C:\PROGRA~1\QUICKH~1\MailSvr.exe
C:\PROGRA~1\QUICKH~1\UPSCHD.EXE
C:\PROGRA~1\QUICKH~1\QHM32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\PROGRA~1\QUICKH~1\QHONLINE.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\QUICKH~1\QHWSCSVC.EXE
C:\PROGRA~1\QUICKH~1\QHONSVC.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\hopeloos\Bureaublad\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Quick Heal e-mail Protection] C:\PROGRA~1\QUICKH~1\MailSvr.exe
O4 - HKLM\..\Run: [QH Live Update Scheduler] C:\PROGRA~1\QUICKH~1\UPSCHD.EXE /Check
O4 - HKLM\..\Run: [QH Office 2K Check] C:\PROGRA~1\QUICKH~1\O2KCHECK.EXE /CHECK
O4 - HKLM\..\Run: [Quick Heal On-Line Protection] C:\PROGRA~1\QUICKH~1\CATEYE.EXE
O4 - HKLM\..\Run: [Quick Heal Messenger] C:\PROGRA~1\QUICKH~1\QHM32.EXE
O4 - HKLM\..\Run: [Quick Heal Startup Scan] C:\PROGRA~1\QUICKH~1\QHSTRT32.EXE /LOADRUN
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\Program Files\ICQ\NDetect.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Quick Heal Startup Scan] C:\PROGRA~1\QUICKH~1\QHSTRT32.EXE /check
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...38&clcid=0x409
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1096750544656
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...23/mcfscan.cab
O23 - Service: Quick Heal Helper Service WSC - Unknown - C:\PROGRA~1\QUICKH~1\QHWSCSVC.EXE
O23 - Service: Quick Heal Online Protection - Unknown - C:\PROGRA~1\QUICKH~1\QHONSVC.EXE
stuveltje is offline   Reply With Quote
Old 2005-01-28, 07:35 AM   #9
Linkster
NO! Im not a female - but being a dragon, I do eat them.
 
Linkster's Avatar
 
Join Date: Mar 2003
Location: Sex Delta
Posts: 5,084
Send a message via ICQ to Linkster
Stuveltje - that log file looks clean except that I would shut off some of the virus programs as they may conflict with each other. I would also shut down Windows messenger unless you need it.
It looks like you have raid set up for your drives?
I noticed youre also loading Windows Media activeX on startup - unless youre doing a lot of D/L of movies and music constantly, it might be better to run that when you really need it.
I would then run the update to SP2 for Windows XP which will get a pretty fresh copy of all of the windows drivers - and if ya want the extra protection, the IE SP2 update as well - Ive been running it for some time and it seems to be running a little cleaner - has a builtin popup blocker.

I would also D/L and install the Webroot Spy Sweeper and let it run once to make sure that nothing is in your hosts file and some other little hidden places
__________________
Pussy Chompers
Porn Links
NSCash
Linkster is offline   Reply With Quote
Old 2005-01-28, 07:49 AM   #10
stuveltje
Live and learn. And take very careful notes!
 
stuveltje's Avatar
 
Join Date: Apr 2003
Location: Sunny Holland
Posts: 6,157
Send a message via ICQ to stuveltje
Quote:
Originally Posted by Linkster
Stuveltje - that log file looks clean except that I would shut off some of the virus programs as they may conflict with each other. I would also shut down Windows messenger unless you need it.
It looks like you have raid set up for your drives?
I noticed youre also loading Windows Media activeX on startup - unless youre doing a lot of D/L of movies and music constantly, it might be better to run that when you really need it.
I would then run the update to SP2 for Windows XP which will get a pretty fresh copy of all of the windows drivers - and if ya want the extra protection, the IE SP2 update as well - Ive been running it for some time and it seems to be running a little cleaner - has a builtin popup blocker.

I would also D/L and install the Webroot Spy Sweeper and let it run once to make sure that nothing is in your hosts file and some other little hidden places
oh ah well i dont even know what that stuff what is running all do, lol, i am gonna try to shut most of...wish me luck
stuveltje is offline   Reply With Quote
Old 2005-01-28, 08:44 AM   #11
Linkster
NO! Im not a female - but being a dragon, I do eat them.
 
Linkster's Avatar
 
Join Date: Mar 2003
Location: Sex Delta
Posts: 5,084
Send a message via ICQ to Linkster
One other thing you could do - run the task manager (ctrl-alt-del) and do a screen copy of it and post it
__________________
Pussy Chompers
Porn Links
NSCash
Linkster is offline   Reply With Quote
Old 2005-01-28, 06:50 PM   #12
GenXer
Are you sure this is the Sci-Fi Convention? It's full of nerds!
 
GenXer's Avatar
 
Join Date: Dec 2004
Location: The U.S.A
Posts: 267
I use this to clean up my computer, it seems to do a great job.

It's freeware and I've used it for a while now, always cleans up some stuff that some of my other programs can't.

The download site is here in case you are interested.

http://www.xblock.com/download-freeware.shtml
__________________
Top Adult Writing Services
icq 375-089-597
GenXer is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 09:10 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc