Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't Connect to MY Network....this is excrutiating.........


  • Please log in to reply
25 replies to this topic

#1 .ZER0.

.ZER0.

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 19 January 2005 - 06:35 PM

OK, Today I come home from college and turn on my monitor (i leave my comp on, i know its not healthy, but im allways downloading something big).

and i launch Firefox and i cant get onto any website, yet I'm downloading at full speed....normally it would all work.

so i think...hmm maybe a glitch, so i pause the DL, and restart my comp. nope. this time, i cant launch my bittorrent client which i use to download......now that is freaky. how that could happen i dont know. and firefox gives me the same "page cannot be found".

the network connection is constantly saying "low or no connectivity" (and I'm using a full wired network/router). the error given when i try to "repair" the connection, is "could not renew IP address".

ive checked all the cables etc, but i fear it cannot be anything like that, or else this comp im typing on right now wouldnt be working perfectly like it is. it has to be in my COMP. which means theres some software blocking my connection or something. like malware or hijackers or something....i really dont know....


---

another little problem i have is a diabolical search bar in MS internet explorer (which i dont primarily use, but i still want to kill it) that wont die, which tries to change its reg. setting every 2 mins.

i think there could be another problem, but i cant think of it now.

oh, i cant remove Panda antivirus from my add/remove Prgrms list. ive deleted everything to do with panda off my comp manually , but the add/remove thing just flashes when i click "remove".

I hope someone can help, i would REALLY appreciate it, as i more or less NEED my connection on that comp.

thanks !!
ZER0
I really shouldnt only come here when I need help should I..... :P

BC AdBot (Login to Remove)

 


#2 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 20 January 2005 - 12:51 PM

bump.
I really shouldnt only come here when I need help should I..... :P

#3 efizzer

efizzer

  • Members
  • 360 posts
  • OFFLINE
  •  
  • Local time:01:44 PM

Posted 20 January 2005 - 01:02 PM

Which taskbar is it? I'd try Hijack This and upload the log file and see if others can assist with the removal of bleep. That helped me when i had a BIG issue with crappy toolbars because you know there's something else in there. I've had those low connectivity issues problems with my wireless at home. I usually just unplug the router, count to 10, then plug it in. :thumbsup:
Posted Image

We're going to make the merry-go-round go faster, so everyone needs to hang on tighter-just to keep from being thrown to the wolves.

#4 phawgg

phawgg

    Learning Daily


  • Members
  • 4,543 posts
  • OFFLINE
  •  
  • Location:Washington State, USA
  • Local time:09:44 AM

Posted 20 January 2005 - 01:52 PM

I think efizzer is right , .ZERO. and you should post a HJT log.
Please read Here and once it's posted, expect it to take days not hours to effect repairs.
BTW, leaving your computer on is perfectly acceptable behavior. It might even extend the life of the components, some say.

Welcome to bleepingcomputers.com both of you. :thumbsup:
patiently patrolling, plenty of persisant pests n' problems ...

#5 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 26 January 2005 - 06:16 PM

Logfile of HijackThis v1.98.1
Scan saved at 23:01:09, on 26/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\DOCUME~1\ZER0\LOCALS~1\Temp\2005120212550_mcinfo.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Diskeeper\DkService.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\NFSU 2\speed2.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\ZER0\Desktop\Appz\Web-Net-Security\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.vxselckeonwkfwrtj.com/uW4Bqku3K...hLQiXhNWEG.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [itch comp load time] C:\Documents and Settings\All Users\Application Data\PLANTOOLITCHCOMP\Fork blue.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ZER0\LOCALS~1\Temp\2005120212550_mcinfo.exe /insfin
O4 - HKCU\..\Run: [Pureamok] C:\DOCUME~1\ZER0\APPLIC~1\PLATFO~1\Mode Iso.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Broken Internet access because of LSP provider 'c:\program files\panda titanium antivirus 2005\pavlsp.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll



theres my HJT logfile. i hope thats not revealing too much :thumbsup:

anyway, do what you can do guys. thanks.
I really shouldnt only come here when I need help should I..... :P

#6 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 26 January 2005 - 06:19 PM

oh SH*T !!!!

excuse my bad language.....

i just realised...its because of that bastard program panda antivirus. looks like I'm gonna need that DLL file. there were 3 that wouldnt delete.... but theres only a report for one of them,........

ok, whats the quickest way of getting that DLL file?? there are a few bittorrent files i need to pick up before all the seeders dissapear....well if they havnt gone already that is......

edit:

wow, just actully browsed the logfile, and it explains EVERY problem I'm having.

I really think this app was handed to me by jah :thumbsup:

Edited by .ZER0., 26 January 2005 - 06:23 PM.

I really shouldnt only come here when I need help should I..... :P

#7 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 27 January 2005 - 05:40 PM

so...


could someone give me a hand here??

i dont want to just tick everything and end up with a fooked up computer......

thanks guys...
I really shouldnt only come here when I need help should I..... :P

#8 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:44 PM

Posted 27 January 2005 - 10:24 PM

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.vxselckeonwkfwrtj.com/uW4Bqku3K...hLQiXhNWEG.html
R3 - Default URLSearchHook is missing
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [BearShare] "C:\Program Files\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [itch comp load time] C:\Documents and Settings\All Users\Application Data\PLANTOOLITCHCOMP\Fork blue.exe
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ZER0\LOCALS~1\Temp\2005120212550_mcinfo.exe /insfin
O4 - HKCU\..\Run: [Pureamok] C:\DOCUME~1\ZER0\APPLIC~1\PLATFO~1\Mode Iso.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)


Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)


C:\Documents and Settings\All Users\Application Data\PLANTOOLITCHCOMP\
C:\Documents and Settings\\ZER0\LOCAL SETTINGS\Temp\2005120212550_mcinfo.exe
C:\Documents and Settings\ZER0\Application Data\PLATFO~1\


Reboot your computer to go back to normal mode and post a new log.


Do you have the panda cd available as we will need to reinstall it? I can fix your internet connectivity but panda wont work well

#9 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 28 January 2005 - 11:07 AM

^^ ok, I'll do that stuff, but the thing is..

i dont want to connect through panda. i want to connect the way i did without panda.

me being the idiot that i am, I've gone and messed around with LSPfix, and i took one of the "protocol handlers" off the list. theres just the panda antivirus one in the remove section now, and the tcpip asnd the other thing in the keep section.

I'll do that stuff up there though. thanks.
I really shouldnt only come here when I need help should I..... :P

#10 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 28 January 2005 - 12:57 PM

i did all those things and saved another log.

the log i did this time is with a newer version of hijackthis. also, when i started up after deleting the stuff in safemode, some reg keys wanted to be changed, and i disallowed them using spybot..

should I have allowed them ? they seem to be back in this new HJT log......
I really shouldnt only come here when I need help should I..... :P

#11 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 28 January 2005 - 01:08 PM

well heres the new logfile with those fixes done, and with the v1.99 HJT rather than the v1.98 that i did earlier. every time i reboot my computer, the 3 reg keys asked to be changed, whether i allow or disallow them. its the mcinfo, the search bar, and that other 04 thing off the last logfile.

Logfile of HijackThis v1.99.0
Scan saved at 18:05:21, on 28/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Diskeeper\DkService.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\ZER0\Desktop\HijackThis.exe

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper\DkIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O10 - Broken Internet access because of LSP provider 'c:\program files\panda titanium antivirus 2005\pavlsp.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Diskeeper\DkService.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Panda Function Service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\PavFnSvr.exe (file missing)
O23 - Service: Panda Pavkre - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\Pavkre.exe (file missing)
O23 - Service: Panda PavProt - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\PavProt.exe (file missing)
O23 - Service: Panda anti-virus service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\pavsrv51.exe (file missing)
O23 - Service: Panda IManager Service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\psimsvc.exe (file missing)
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Edited by .ZER0., 28 January 2005 - 01:23 PM.

I really shouldnt only come here when I need help should I..... :P

#12 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:44 PM

Posted 28 January 2005 - 07:10 PM

I need you to let those changes occur so I can see them in the log. Reboot allow the changes and then post a new log

#13 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 29 January 2005 - 10:11 AM

I need you to let those changes occur so I can see them in the log. Reboot allow the changes and then post a new log

ok.
I really shouldnt only come here when I need help should I..... :P

#14 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,593 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:01:44 PM

Posted 29 January 2005 - 11:47 AM

Lets see a log after the changes have been allowed

#15 .ZER0.

.ZER0.
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:12:44 PM

Posted 29 January 2005 - 01:46 PM

Well here's the log...
This LSP thing is severely annoying me.
Isnt there any way to change the LSP protocol handler back to its original form ?? the one on this computer is called rsvpsp.dll, it seems to be the official windows one....

isnt there any way to change it back ??

Logfile of HijackThis v1.99.0
Scan saved at 18:42:46, on 29/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Diskeeper\DkService.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Spybot\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Documents and Settings\ZER0\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.cqiuceggnmjpzl.com/uW4Bqku3KTUx...hLQiXhNWEG.html
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\ACE Mega CoDecS Pack\SystemS\RealMedia\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [msci] C:\DOCUME~1\ZER0\LOCALS~1\Temp\2005120212550_mcinfo.exe /insfin
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [Pureamok] C:\DOCUME~1\ZER0\APPLIC~1\PLATFO~1\Mode Iso.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O10 - Broken Internet access because of LSP provider 'c:\program files\panda titanium antivirus 2005\pavlsp.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Diskeeper\DkService.exe
O23 - Service: Macromedia Licensing Service - Unknown - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Panda Function Service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\PavFnSvr.exe (file missing)
O23 - Service: Panda Pavkre - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\Pavkre.exe (file missing)
O23 - Service: Panda PavProt - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\PavProt.exe (file missing)
O23 - Service: Panda anti-virus service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\pavsrv51.exe (file missing)
O23 - Service: Panda IManager Service - Unknown - C:\Program Files\Panda Titanium Antivirus 2005\psimsvc.exe (file missing)
O23 - Service: SoundMAX Agent Service - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StyleXPService - Unknown - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I really shouldnt only come here when I need help should I..... :P




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users