Win 2000 OS Problems

Discussion in 'Software' started by jinxlinx, Apr 13, 2004.

  1. jinxlinx

    jinxlinx Private E-2

    I mistakingly d/l a v. of spyware. It has been doing nothing but eating up my computer. I have access to my internet for about 10 mins. then my browser no longer comes up. My screen background will not show up. If anybody can help I sure would appreciate it.
     
  2. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    Ok Jinxlinx
    Welcome to Majorgeeks, first things first go here and read the information provided ;)
    http://www.majorgeeks.com/vb/showthread.php?t=25834
    then download the scanning tools listed, before running the scans make sure you use the check for updates buttons
    After using the scanners select and delete all items found, they will make back-ups which can be used if on the very rare occasion this causes a problem with a program you have installed

    If you decide to use Hijack This to have a look at whats running in your system etc, please read the information listed here
    http://www.majorgeeks.com/vb/showthread.php?t=26149

    I would also reccomend an online Virus--Trojan scan at one of the links here
    http://www.trojanscan.com/
    http://housecall.trendmicro.com/
    http://www.pandasoftware.com/activescan/

    Do all these things and report back, any questions just ask
    Also when you report back please list some system specs, and some details on what Anti-Virus and Firewall software you are using, plus anything else you may think is relevant
     
  3. jinxlinx

    jinxlinx Private E-2

    working on a win 2000 pro machine
    have had ad-aware for a month using daily.
    also have Norton AV

    I can't stay logged on long enough to use the online virus scans that you specified. I get about 2/3 the way through them and my web connection is no more.

    If you want more info just ask.

    Thanks
     
  4. General_Lee_Stoned

    General_Lee_Stoned BuZZed Lightyear

    Did you try Spybot and run a scan with it

    Is your Norton fully updated, if so can you run a full system scan

    Did you try running Hijack This and look for some bogus entries
     
  5. goldfish

    goldfish Lt. Sushi.DC

    Good links GLS :)
    You could try The Cleaner :
    http://www.majorgeeks.com/download.php?det=1666

    You could try that for trojan detection, if your connection is fast enough to get it before youre signed off again.

    Hijack This is a tiny program, so you should be able to get that no problem.

    BTW, what do you mean "a v. of spyware" ?
     
  6. LeVanay

    LeVanay Private E-2

  7. jinxlinx

    jinxlinx Private E-2

    I d/l Spybot I already had Ad Aware I ran them both and to no evail, I still lose my connection with the server after 10 min +/-.
     
  8. jinxlinx

    jinxlinx Private E-2

    Ok I have run ad aware, spybot and Hijack This

    I deleted all of the files that appeared for Adaware and spybot but I am not sure on the files listed from Hijack This so if you all could scan the list and let me know what needs to go I would appreciate it.
     
  9. jinxlinx

    jinxlinx Private E-2

    Trying to send the list again...

    Logfile of HijackThis v1.97.7

    Scan saved at 10:50:22 AM, on 4/16/2004

    Platform: Windows 2000 SP2 (WinNT 5.00.2195)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINNT\System32\smss.exe

    C:\WINNT\system32\winlogon.exe

    C:\WINNT\system32\services.exe

    C:\WINNT\system32\lsass.exe

    C:\WINNT\system32\svchost.exe

    C:\WINNT\system32\spoolsv.exe

    C:\Program Files\Intel\ASF Agent\ASFAgent.exe

    C:\WINNT\System32\svchost.exe

    C:\Program Files\Dell\OpenManage\Client\Iap.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\WINNT\system32\regsvc.exe

    C:\WINNT\system32\MSTask.exe

    C:\WINNT\System32\mspmspsv.exe

    C:\WINNT\Explorer.EXE

    C:\Program Files\Microsoft Hardware\Mouse\point32.exe

    C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe

    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe

    C:\PROGRA~1\NORTON~1\navapw32.exe

    C:\WINNT\loadqm.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\WINNT\System32\internat.exe

    C:\Program Files\MSN Messenger\MsnMsgr.Exe

    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    C:\Program Files\WinZip\WZQKPICK.EXE

    C:\My Downloads\Misc. Downloads\HijackThis.exe





    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://government.dellnet.com/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://government.dellnet.com/

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: (no name) - {8A321C7D-9CED-45A8-870D-DAE843A45FD0} - C:\Program Files\Trustix\Trustix Personal Firewall\PopUpKiller.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon

    O4 - HKLM\..\Run: [POINTER] point32.exe

    O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r

    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\System32\spool\drivers\w32x86\3\hpztsb03.exe

    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe

    O4 - HKLM\..\Run: [LoadQM] loadqm.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKCU\..\Run: [Internat.exe] internat.exe

    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    O4 - Global Startup: AutoCAD LT Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

    O10 - Unknown file in Winsock LSP: c:\program files\trustix\trustix personal firewall\netdog.dll

    O10 - Unknown file in Winsock LSP: c:\program files\trustix\trustix personal firewall\netdog.dll

    O10 - Unknown file in Winsock LSP: c:\program files\trustix\trustix personal firewall\netdog.dll

    O10 - Unknown file in Winsock LSP: c:\program files\trustix\trustix personal firewall\netdog.dll

    O10 - Unknown file in Winsock LSP: c:\program files\trustix\trustix personal firewall\netdog.dll

    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab

    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/156e899fa5b5f40d5016/netzip/RdxIE601.cab

    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab

    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD LT 2002\AcDcToday.ocx

    O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD LT 2002\InstBanr.ocx

    O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD LT 2002\InstFred.ocx

    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD LT 2002\AcPreview.ocx

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab



     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds