to all
had a internet connection problem which a member solved for me , thus i awarded him the points...but my computer was moving super slow afterwards and i was still getting advice from that submission , but as in other cases once the question was solved the advice quit coming....so here is a resubmission with copies of our last commentsComment from armydog
Date: 05/13/2004 08:30PM PDT
Your Comment
LucF
sorry i took so long to respond to my progress.
i have good and bad news...yes your solution did get me reconnected, and i appreciate the excellent advise the points are fortcoming LucF.
my problem is that i'm moving so slow i couldn't even come to this website and congradulate you.....i ended up reconnecting my inteva to post this.
may i ask for more of your helpful advice?
Comment from LucF
Date: 05/14/2004 01:33AM PDT
Comment
Yes, you can :) but, I'll be away for a week (holliday to France) so I won't be able to respond then so maybe SheharyaarSaahil can help you during that time.
First take a look at the tools listed here:
http://www.experts-exchange.com/Q_20975384.htmlI suggest you to check with Adaware, Spybot and CWShredder. If that doesn't help, use Hijackthis, it'll create a logfile which you can post at this site for us to look at.
Good luck,
LucF
Comment from armydog
Date: 05/14/2004 07:17AM PDT
Your Comment
LucF
sorry..it seems i can't stop running out of problems.
do you think my best bet would be to put hijack this on a floppy then hook-up my IBM and run the program then put the results back on a floppy so i can reconnect my inteva and post the results here?
i ask because right now my IBM takes forever to get anywhere
Comment from armydog
Date: 05/14/2004 08:29AM PDT
Your Comment
to all
went ahead and copied the log file from my IBM...here it isLogfile of HijackThis v1.97.7
Scan saved at 11:18:22 AM, on 5/14/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32
.DLL
C:\WINDOWS\SYSTEM\MSGSRV32
.EXE
C:\WINDOWS\SYSTEM\MPREXE.E
XE
C:\WINDOWS\SYSTEM\mmtask.t
sk
C:\WINDOWS\SYSTEM\MSTASK.E
XE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV
9.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.
EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32
.EXE
C:\PROGRAM FILES\YAHOO!\MESSENGER\YPA
GER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.E
XE
A:\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\In
ternet Explorer,SearchURL =
http://sharempeg.com/find/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://hddubb.t.rack.cc/hp.php (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.white-pages.ws/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://www.white-pages.ws/results.php?show=R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Search,CustomizeS
earch =
http://findloss.com/srchasst.htmlR1 - HKLM\Software\Microsoft\In
ternet Explorer,SearchURL =
http://www.the-huns-yellow-pages.com/sp.htmlR0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://hddubb.t.rack.cc/hp.php (obfuscated)
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.comR1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.comR0 - HKLM\Software\Microsoft\In
ternet Explorer\Search,SearchAssi
stant =
http://hddubb.t.rack.cc/sp.php (obfuscated)
R1 - HKCU\Software\Microsoft\In
ternet Explorer\SearchURL,(Defaul
t) =
http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr/*http://www.yahoo.comR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = ;127.0.0.1
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,HomeOldSP =
http://hddubb.t.rack.cc/hp.php (obfuscated)
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R1 - HKLM\Software\Microsoft\In
ternet Explorer\Search,(Default) =
http://findloss.com/srchasst.htmlR3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3
DBE0391097
2} - (no file)
R3 - URLSearchHook: XTSearchHook Class - {6E6DD93E-1FC3-4F43-8AFB-1
B7B90C9D3E
B} - C:\PROGRAM FILES\SQWIRE\S.DLL (file missing)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7
695ECA0567
0} - C:\PROGRAM FILES\YAHOO!\COMPANION\INS
TALLS\CPN\
YCOMP5_3_1
2_0.DLL
O2 - BHO: (no name) - {60E78CAC-E9A7-4302-B9EE-8
582EDE22FB
F} - (no file)
O3 - Toolbar: Band Class - {BDF6CE3D-F5C5-4462-9814-3
C8EAC330CA
8} - C:\WINDOWS\ADROAR.DLL (file missing)
O3 - Toolbar: Funk Vga Idol - {4AF452F4-3E49-AEB8-4FD5-3
3B41149E7A
A} - C:\PROGRAM FILES\STARTLOVE\EQ SLOW.DLL (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\SYSTEM\MSDXM.OC
X
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\PROGRAM FILES\YAHOO!\COMPANION\INS
TALLS\CPN\
YCOMP5_3_1
2_0.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [SENTRY] C:\WINDOWS\SENTRY.exe
O4 - HKLM\..\Run: [sys] regedit -s sys.reg
O4 - HKLM\..\Run: [WINSTART001.EXE] C:\WINDOWS\System\WINSTART
001.EXE -b
O4 - HKLM\..\Run: [SQConfigChecker] C:\Program Files\Sqwire\cc.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\a
vgcc32.exe
/STARTUP
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPw
rScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] C:\WINDOWS\SYSTEM\mstask.e
xe
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\A
vgserv9.ex
e
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypa
ger.exe -quiet
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates
\System\Te
mp\ebatesw
ebsavings_
script0.ht
m
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch
.htm
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict
.htm
O9 - Extra button: xxx (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D
3488ABDDC6
B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-4
4455354000
0} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {A1DC3241-B122-195F-B21A-0
0000000000
0} -
http://pluginaccess.com/cd/Browser_Plugin.cabO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exeO16 - DPF: {459729AC-727D-4D97-B18A-7
2EE224EFEC
0} -
http://defender.veloz.com/pub/download/scandl_lycos.cabO16 - DPF: {E7DBFB6C-113A-47CF-B278-F
5C6AF4DE1B
D} -
http://download.abacast.com/download/files/abasetup.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
E41684E07B
B} -
http://imgfarm.com/images/nocache/funwebproducts/CursorManiaInitialSetup1.0.0.6.cabO16 - DPF: {00000EF1-0786-4633-87C6-1
AA7A44296D
A} -
http://www.netpaloffers.net/NetpalOffers/DMO1/emCraft1.cabO16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/potc_x.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: Yahoo! Literati -
http://download.games.yahoo.com/games/clients/y/tt2_x.cabO16 - DPF: {62969CF2-0F7A-433B-A221-F
D8818C06C2
F} (Blockwerx Control) -
http://mirror.worldwinner.com/games/v42/blockwerx/blockwerx.cabO16 - DPF: {30528230-99F7-4BB4-88D8-F
A1D4F56A2A
B} (YInstStarter Class) -
http://download.yahoo.com/dl/installs/yinst0401.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-6
0DB54C1000
0} (YahooYMailTo Class) -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dllO19 - User stylesheet: c:\windows\system.css