please god someone help fix my pc!

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
MY computer is totally fucked. i need SOME ADVICE ASAP. SERIOUS PROBLEMS HERE. sorry about caps but it relly can't be helped.

problem i'm havin.

computer had a mind of its own. have to click on web page every 10 seconds to be able to type or scroll. while on ebay pages jump around by themself. something i looked at 5 minutes ago will just appear. i have no control over where i go on ebay. computer freezes quite often. text size switches to largest instead of medium on its own. i will be typing and all of a sudden it goes caps on its own. new popups every day. for some odd reason i am asked if i am ready to disconnect every 45 seconds. it is very annoying. the list is never ending annoyances.

i have been using that lava soft ad ware removal and spybot every day. every day i find about 160 devices.

why do they keep coming back?

what are my options?

it's at the point where i wont log in any website like ebay or paypal.

should i format my hard drive?

if so, where can i get my recovery discs? i never got any witht his computer. i have a gateway.

well, i'm off to destroy some more viruses. hopefully i will be able to get back on to see if anyone has some ideas.

god, i am so pissed at my computer.

thanks everyone!!
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
Neomodus said:
:buttrock: Formatt your HDD...and after install a good and well configured "firewall" ...

do you think it would be possible for me to get the recovery discs from gateway even though i am not the original owner of the computer?

also what exactely does a firewall do?

where can i get a good firewall?
 

Neomodus

n00b
Joined
Feb 14, 2004
Posts
24
perhaps ...with the PC's serial you'll manage to get your recovery discs with a little fees...

FOr the "Firewall" ...try a "google" search ...and you will understand (basically it will protect your PC ..against virus..and Hacker job ...)
 

Chicago Cheeseburgler Crew

BANNED , Banned , Here's why
10 Year Member
Joined
Jun 11, 2002
Posts
24,280
Download ad-aware or spybot. If your getting frequent pop-ups and shit it sound like you have some hijaking spyware in your machine, some nasty little shits that an anti-virus program wouldn't catch. Download these programs and see what you find, you can even immunize your computer (with spybot I think) to prevent these things happening in the future. Be careful with spybot though and make sure you read about what your deleting, sometimes it wants to delete important components of programs like outlook express. Ad-aware should be fine though.
 

Chicago Cheeseburgler Crew

BANNED , Banned , Here's why
10 Year Member
Joined
Jun 11, 2002
Posts
24,280
Woop sorry, I didn't notice you were using spybot the first time I read through your post!

You probably have done so already, but if you haven't, you need to update the reference files of your spyware removal programs. New spyware is created every day so if you don't have your anti-spyware programs updated chances are they're not catching all of the bugs.
 

SSS

neo retired
Joined
Sep 27, 2002
Posts
10,771
I would just back up any files you want to keep on a cd and then reformat the drive.
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
thanks for all the help. hopefully i will get it figured out. i seem to be working ok today since i use that lava soft again. but i guess tomorrow a whole nother day.
 

galfordo

Analinguist of the Year
15 Year Member
Joined
Mar 14, 2003
Posts
18,418
Back up as best you can then format that sucker. It's usually the only way to completely decontaminate your system.
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
i'm just gonna get the recovery discs from gateway and reformat.

how would i go about saving other things i have, like roms and turbo lister. is this possible? i don't have a cd burner so i'm guessing i'm screwed.
 

eclypse

Banned
Joined
Mar 26, 2004
Posts
964
greedostick said:
i'm just gonna get the recovery discs from gateway and reformat.

how would i go about saving other things i have, like roms and turbo lister. is this possible? i don't have a cd burner so i'm guessing i'm screwed.

Welp for that problem your best bet is to go out and buy a copy of Partition magic 7 or 8.. whatever the latest is. With this software you'll beable to add a partition to your hard drive that you can use to back up your important stuff. I think it runs around 50-70 bucks but is the best software i ever bought! I use it all the time when i want to repartition and reformat my 2 120GB hard drives.. And it does it in less then 5 mins.

So most likely you have just a C drive that takes up all your hard drive space.. All you have to do is slap that partition magic software in the drive and boot up with the disk inserted in your cdrom drive and follow the menues to add a partition of whatever size you want for your back up space and it will take the available free space from your exisiting drive and use that for the new partition.

Then after your done backing up your important stuff, use the same software to reformat your C drive.. That way all your stuff on the backup partition wont be harmed and safe.

If you just go out and buy up a copy of windows XP you can install the computer again with that without having to get the reinstall disks.. Windows xp sould have all the drivers needed to reinstall all the hardware on your computer.

WHat i said above would be your best solution and cheapest. Though you could also just buy an external USB hard drive and use that for backup as well as long as your computer has USB ports, firewire would be even better. The cost of that, would be way more though.

Good luck!

P.S. Yes run your add aware software after installing software to keep you safe and i 2 suggest using atleast the free version of Zone Alarm for a software based firewire in the future. If you have a cable modem or other broadband connect, then you better buy a harware firewall solution like a router to keep your computer invisable to the outside world.
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
eclypse said:
Welp for that problem your best bet is to go out and buy a copy of Partition magic 7 or 8.. whatever the latest is. With this software you'll beable to add a partition to your hard drive that you can use to back up your important stuff. I think it runs around 50-70 bucks but is the best software i ever bought! I use it all the time when i want to repartition and reformat my 2 120GB hard drives.. And it does it in less then 5 mins.

So most likely you have just a C drive that takes up all your hard drive space.. All you have to do is slap that partition magic software in the drive and boot up with the disk inserted in your cdrom drive and follow the menues to add a partition of whatever size you want for your back up space and it will take the available free space from your exisiting drive and use that for the new partition.

Then after your done backing up your important stuff, use the same software to reformat your C drive.. That way all your stuff on the backup partition wont be harmed and safe.

If you just go out and buy up a copy of windows XP you can install the computer again with that without having to get the reinstall disks.. Windows xp sould have all the drivers needed to reinstall all the hardware on your computer.

WHat i said above would be your best solution and cheapest. Though you could also just buy an external USB hard drive and use that for backup as well as long as your computer has USB ports, firewire would be even better. The cost of that, would be way more though.

Good luck!

P.S. Yes run your add aware software after installing software to keep you safe and i 2 suggest using atleast the free version of Zone Alarm for a software based firewire in the future. If you have a cable modem or other broadband connect, then you better buy a harware firewall solution like a router to keep your computer invisable to the outside world.

thats a damn good idea. i think i will do that. thanks alot!
 

Sundance

Sho's Rival
Joined
Feb 3, 2004
Posts
1,447
You might also contact your ISP and have your IP changed. Last year when i was doin a lotta Downloading i found that even after i logged off Kazaa my IP was being bombarded by peoples PCs checkn for Downloads that i had made available while DL'n myself. I got viruses hours after i had shut off Kazaa even though i was no longer connected to it. Granted i'm on a Broadband connection and thus have a Static IP so that won't apply to Dial-up.
 

Poison Sama

The Hentai Christ
20 Year Member
Joined
Jun 29, 2002
Posts
6,631
Sundance said:
Granted i'm on a Broadband connection and thus have a Static IP so that won't apply to Dial-up.

Interesting...

I'm using DSL and my IP Address is dynamic. Well, its supposed to be anyway...
 

J.Boswell

n00b
Joined
May 24, 2004
Posts
19
ahh the wonders of broadband.

what was the movie "hackers" ?
where they connected to the internet through payphones.
you need a good firewall, you should contact ibm and see if you can get one of theres. this norton or mcaffee shit is a joke.

but the best thing to do is get a 260 gb hd and reinstall windows.

those recovery disk are nothing but a pain in the rear. should always build a pc from the ground up. never ever buy a "non upgradeable" pc.

good luck on your quest.
 

Nallchan

Quiz Detective
Joined
Feb 23, 2004
Posts
88
:multi_co: Alright, Listen up... if you want your comp fixed.. this is what you gota do... i have NO doubt this WILL fix your computer.. :multi_co:

my Personal Opinion as a computer tech..

everyone that saying format your Hard drive is Over reacting... yes its a "Fix all" but its also just going to happen again if you dont take the Right steps... not to mention you will lose all of your data...

heres what i suggest.... yes it will take alittle bit.. but its going to fix your problem...

:multi_co: First .. Go Download.. The Stinger tool - from the link below.. its free and is a first step in the right direction...

- http://vil.nai.com/vil/stinger/

:multi_co: Second - Go download AVG - One of the BEST Virus scanners out there.. AND its free ..
http://www.grisoft.com/us/us_dwnl_free.php

:multi_co: Third - Download - Hijack This - This is a VERY good program for telling you EXACTLY whats running on your computer..

http://download.com.com/3000-8022-10227352.html?tag=lst-0-4

( After you get Hijack this .. run it then do "ALT + Print Screen" .... Open Paint ... then hit paste.... Save the resulting Image and either Post it or Email me it .. )


:multi_co: - Forth - goto Microsoft Update - Get ALL the Critical Updates.. downloaded and Installed... ( yes this is important )


:multi_co: Fifth - goto START - RUN - and type MSCONFIG ... goto the Start up tab... and then take more pictures ( ALT + PRINT SCREEN ) how ever many times you need to get ALL the settings on the screen ... Again PM / Post or Email the results to me...


:multi_co: Next ..... Download the Norton AntiVirus Trial Version .. update it and Run it...
http://download.com.com/3000-2239-10223639.html?tag=lst-0-4

Furthermore, Grab a Copy of Zone Alarm - Free ware.. you can get it in many places... DO NOT INSTALL OR SET IT UP .. until everything else is done.. As this can acctually hinder the virus removal process..

Next... JUST to make sure .. Run a ScanDisk ( with Surface scan ) to check for File Currption / Errors.... i do not think it is this.. but you cant be to careful... ive seen weirder things happen....

You might also want to run Disk Defragment when everything is starting to run alittle Cleaner... it wont FIX your problem.. but what it will do is make all the files in order.. and lower your hard drives Seek time... aka get the files and folders open faster....

Every Virus that comes up.. Write down its NAME and its File location...

Once you have done all of this you are WELL on your way to having control of your computer back... but you must get back to me with the information above if you want the other virus that AVG / Norton and Stinger didnt get...

ALSO, There are a few more steps to get your computer Running Faster As well...

AFTER your computer is tottally Virus free.. and up and running...we're gonna walk you thru a Back-up of all your important files... Just alittle FYI... Everyone should do a Entire Back up once every 2 - 3 months... if your files are Extremly important do an Incremental back up every week... CD-R 's are next to free now a days.. and if you feel your data is worth it.. then the time is worth it..

Let me know when you have gotten this far....

If you do what i listed above your computer WILL be virus free very soon...

From what you have told me ... ( i am only basing my Coarse of action upon what you have told me as i cant exactly look at your computer first hand ) This is a Common Problem.. it is Most likely the Result of a Back Door Virus in which a user can take Remote control of your computer... or other types of Virus ( Back door being the most likely )... I seriously doubt this has anything to do with Hardware .. unless theres some High pitch Noise coming from your hardrive your not telling me about ...

FYI, i do this process at LEAST 3 times a week for others locally who cant keep their fingers out of the Virus bin... and usally charge $69 an hour ...

Questions or comments ? Feel free to email me or PM ...
 
Last edited:

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
Nallchan said:
:multi_co: Alright, Listen up... if you want your comp fixed.. this is what you gota do... i have NO doubt this WILL fix your computer.. :multi_co:

my Personal Opinion as a computer tech..

everyone that saying format your Hard drive is Over reacting... yes its a "Fix all" but its also just going to happen again if you dont take the Right steps... not to mention you will lose all of your data...

heres what i suggest.... yes it will take alittle bit.. but its going to fix your problem...

:multi_co: First .. Go Download.. The Stinger tool - from the link below.. its free and is a first step in the right direction...

- http://vil.nai.com/vil/stinger/

:multi_co: Second - Go download AVG - One of the BEST Virus scanners out there.. AND its free ..
http://www.grisoft.com/us/us_dwnl_free.php

:multi_co: Third - Download - Hijack This - This is a VERY good program for telling you EXACTLY whats running on your computer..

http://download.com.com/3000-8022-10227352.html?tag=lst-0-4

( After you get Hijack this .. run it then do "ALT + Print Screen" .... Open Paint ... then hit paste.... Save the resulting Image and either Post it or Email me it .. )


:multi_co: - Forth - goto Microsoft Update - Get ALL the Critical Updates.. downloaded and Installed... ( yes this is important )


:multi_co: Fifth - goto START - RUN - and type MSCONFIG ... goto the Start up tab... and then take more pictures ( ALT + PRINT SCREEN ) how ever many times you need to get ALL the settings on the screen ... Again PM / Post or Email the results to me...


:multi_co: Next ..... Download the Norton AntiVirus Trial Version .. update it and Run it...
http://download.com.com/3000-2239-10223639.html?tag=lst-0-4

Furthermore, Grab a Copy of Zone Alarm - Free ware.. you can get it in many places... DO NOT INSTALL OR SET IT UP .. until everything else is done.. As this can acctually hinder the virus removal process..

Next... JUST to make sure .. Run a ScanDisk ( with Surface scan ) to check for File Currption / Errors.... i do not think it is this.. but you cant be to careful... ive seen weirder things happen....

You might also want to run Disk Defragment when everything is starting to run alittle Cleaner... it wont FIX your problem.. but what it will do is make all the files in order.. and lower your hard drives Seek time... aka get the files and folders open faster....

Every Virus that comes up.. Write down its NAME and its File location...

Once you have done all of this you are WELL on your way to having control of your computer back... but you must get back to me with the information above if you want the other virus that AVG / Norton and Stinger didnt get...

ALSO, There are a few more steps to get your computer Running Faster As well...

AFTER your computer is tottally Virus free.. and up and running...we're gonna walk you thru a Back-up of all your important files... Just alittle FYI... Everyone should do a Entire Back up once every 2 - 3 months... if your files are Extremly important do an Incremental back up every week... CD-R 's are next to free now a days.. and if you feel your data is worth it.. then the time is worth it..

Let me know when you have gotten this far....

If you do what i listed above your computer WILL be virus free very soon...

From what you have told me ... ( i am only basing my Coarse of action upon what you have told me as i cant exactly look at your computer first hand ) This is a Common Problem.. it is Most likely the Result of a Back Door Virus in which a user can take Remote control of your computer... or other types of Virus ( Back door being the most likely )... I seriously doubt this has anything to do with Hardware .. unless theres some High pitch Noise coming from your hardrive your not telling me about ...

FYI, i do this process at LEAST 3 times a week for others locally who cant keep their fingers out of the Virus bin... and usally charge $69 an hour ...

Questions or comments ? Feel free to email me or PM ...

i am going to try and do all this this weekend.

hopefully this thread will help other people with the same problems as me.

thanks for all the great help everyone ;)
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
here's my results.

thanks for the help!

Logfile of HijackThis v1.97.7
Scan saved at 6:16:23 PM, on 6/2/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\VCBIND~1\LicenseCash.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\NetZero\exec.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\mgkrkd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\SYSTEM32\CS4P028.EXE
C:\WINDOWS\SYSTEM32\CS4P028.EXE
C:\Documents and Settings\Jeremy Forrest\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hkcu
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=145872
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default-homepage-network.com/start.cgi?new-hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hklm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.netzero.net/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R3 - URLSearchHook: (no name) - _{37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - (no file)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: IE Agent - {00000000-0000-0000-0000-000000000221} - C:\PROGRA~1\Lycos\IEagent\CSIE.DLL
O2 - BHO: (no name) - {00000762-3965-4A1A-98CE-3D4BF457D4C8} - C:\Program Files\Lycos\Sidesearch\sidesearch1400.dll
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {4BCF322B-9621-4e90-9678-F1424EB7584E} - C:\WINDOWS\udpmod.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem218.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ConMgr.exe] "C:\Program Files\EarthLink 5.0\ConMgr.exe"
O4 - HKLM\..\Run: [APIMon] C:\WINDOWS\System32\apimonx.exe
O4 - HKLM\..\Run: [LOCKS GRID] C:\PROGRA~1\VCBIND~1\LicenseCash.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [mityfqbslndi] C:\WINDOWS\System32\mgkrkd.exe
O4 - HKLM\..\Run: [ClrSchLoader] C:\PROGRA~1\Lycos\IEagent\Loader.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\NZSearch\hcm.exe" -w
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Sidesearch (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{95083966-8A34-44DA-AF63-206531
 

Nallchan

Quiz Detective
Joined
Feb 23, 2004
Posts
88
Ok .. i do see a few problems..

First thing... do you use Netzero or Earthlink for your ISP ? ( internet Service provider )

Second... From a first glance.. the following Entry's are questionable... ( these are NOT all virus's... but they are NON-CRITCAL system files and i recommend they all go )
---------------------------------------------------------------------------------------

C:\PROGRA~1\VCBIND~1\LicenseCash.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SYSTEM32\CS4P028.EXE
C:\WINDOWS\SYSTEM32\CS4P028.EXE
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\System32\mgkrkd.exe
C:\WINDOWS\System32\mshta.exe
C:\WINDOWS\system32\ntvdm.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
---i REALLY dont like the way that Smartbotpro .. looks / sounds.. im not 100 % sure.. but that sounds like part of your problem right there... so Get rid of anything related to that..


--- Understand why i chose these Files.... ---
since i dont know EXACTLY what programs you do you on a daily basis .. im just going to Suggest what i think you should take off to speed up and reduce the chance of hacker problems... you DO NOT have to take all of these registry keys out.. BUT... the ones i listed above ARE NOT CRITICAL system files ...

On a side note: Usally ( not in all cases ) the files with Random letters that end with .exe ... ( example "mgkrkd.exe ) are virus's .. as a general rule of thumb...


if in the Event one of your programs stops working... reinstall the program ... or re-enter the registry key ( Highjack this has a backup feature for all deleted registry keys ) ... it is inevitable... that you will find one or two registry keys that are oddly named EXE's that are part of Valid / safe programs...dont worry about it.. just reinstall anything that stops working like your yahoo messager..

got it ?

Also.. i CANT say this enough... Toolbars .. that you see people give out ARE THE DEVIL... not only do they acctually slow your browsing speed.. but 98 % of All toolbars have Spyware in them.... that track your online movement and activites and report them for Reasearch purposes to their presepective owners...

think about it... WHY would a company spend the time and money to give out a free toolbar if it doesnt have SOME kind of advantage for them.. and market reseach is BILLION's of dollars a year.

Aka.. if you can Live without the tool bar ( net zero and Yahoo ).... its in your best interest not to have it...

im assuming you Ran AVG / Norton and Spybot search and destroy as well correct ?

Remember to Update Windows ...

Also... still waiting for the MSconfig screen shots / List ...

your not done.. but your definatly on your way to a safer computer...
 

Nightmare Tony

*Account control passed, on to Tony's family.Ex Ro
Joined
Sep 19, 2001
Posts
1,029
In addition, I personally recommend NOT using internet explorer. Go for Mozilla instead. Better security features, faster and more of a joy to use. Also, if you use outlook express, now is a GREAT time to stop.
 

Neo Fan

King's Dry Cleaner
Joined
Nov 23, 2000
Posts
396
Also, if you are running windows xp, you can turn your system back to any date within the past two to three months. Any settings will be restored to that date, an anything installed since that date will be un-installed. The feature is called system restore, I can't remember right now where to find the tool, but if you look around you'll come across it.
 

greedostick

Kyukyogenryu Black Belt
20 Year Member
Joined
Aug 11, 2003
Posts
4,939
yes, i am using netzero at the moment. for some reason that alt print will not work. so i am going to type parts of them all.

all of them end in HKLML\SOFTWARE\MICROSOFT\WINDOWS\CURRENT VERSION

and they end in

exe
system
VCBIN
earth
cpl
com
iprops.c..
STA
ISTs
netZ

i hope this helps out some. i am guessing if it does not end in
netz
system

to delete it. if you need more info let me know. i keep running virus scans everyday but new toolbars keep appearing.

thanks for all the help!
 

eclypse

Banned
Joined
Mar 26, 2004
Posts
964
Should of just done what i said and this prob would of been all over with long ago.

People should reformat and reinstall windows once a year anyhow so dont think reinstalling windows is the end of the world.
 
Top