Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
 
Old 10-21-2007, 08:27 PM   #1 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default sisters computer is going off the wall

messages in the bottom right hand corner of screen every few seconds.
random IE pop ups...yet IE is never used.

Logfile of HijackThis v1.99.1
Scan saved at 7:22:26 PM, on 10/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Video Add-on\icthis.exe
C:\Program Files\Video Add-on\isfmntr.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\eHome\Wireless G EH102\wirelesscm.exe
C:\Program Files\Video Add-on\isfmm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Video Add-on\icmntr.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Amy\Desktop\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {CFE15135-C591-4000-A55E-A50E5F9F82BC} - C:\Program Files\Video Add-on\isfmdl.dll
O3 - Toolbar: IE Custom Tools - {23ED2206-856D-461A-BBCF-1C2466AC5AE3} - C:\Program Files\Video Add-on\ictmdl.dll
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\RunOnce: [AAW] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe" "+b1"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6880] command /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"
O4 - HKLM\..\RunOnce: [SpybotDeletingC435] cmd /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [SpybotDeletingB932] command /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"
O4 - HKCU\..\RunOnce: [SpybotDeletingD529] cmd /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"
O4 - Global Startup: Wireless Connection Manager.lnk = ?
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Static_11 is offline  
Old 10-22-2007, 11:13 AM   #2 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,207

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: sisters computer is going off the wall

remove these entries

C:\Program Files\Video Add-on\icthis.exe

C:\Program Files\Video Add-on\isfmntr.exe

C:\Program Files\Video Add-on\isfmm.exe

Uninstall Java and remove this C:\Program Files\Java\jre1.6.0_01\bin\jucheck.exe

C:\Program Files\Video Add-on\icmntr.exe

O2 - BHO: (no name) - {CFE15135-C591-4000-A55E-A50E5F9F82BC} - C:\Program Files\Video Add-on\isfmdl.dll

O3 - Toolbar: IE Custom Tools - {23ED2206-856D-461A-BBCF-1C2466AC5AE3} - C:\Program Files\Video Add-on\ictmdl.dll

O4 - HKLM\..\RunOnce: [SpybotDeletingA6880] command /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"

O4 - HKLM\..\RunOnce: [SpybotDeletingC435] cmd /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"

O4 - HKCU\..\RunOnce: [SpybotDeletingB932] command /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"

O4 - HKCU\..\RunOnce: [SpybotDeletingD529] cmd /c del "C:\WINDOWS\system32\nczupfw.dll_tobedeleted_o ld"

if these cant be remove in normal mode, reboot into safemode and delete, then post a new log
__________________
Osiris is online now  
Old 10-22-2007, 08:21 PM   #3 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: sisters computer is going off the wall

Logfile of HijackThis v1.99.1
Scan saved at 7:20:25 PM, on 10/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\eHome\Wireless G EH102\wirelesscm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Amy\Desktop\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {CFE15135-C591-4000-A55E-A50E5F9F82BC} - C:\Program Files\Video Add-on\isfmdl.dll (file missing)
O3 - Toolbar: IE Custom Tools - {23ED2206-856D-461A-BBCF-1C2466AC5AE3} - C:\Program Files\Video Add-on\ictmdl.dll (file missing)
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Wireless Connection Manager.lnk = ?
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
Static_11 is offline  
Old 10-22-2007, 08:29 PM   #4 (permalink)
SirCyber's Avatar
 
Ultra Techie

Join Date: Sep 2007

Location: Oregon USA

Posts: 745

SirCyber is on a distinguished road

Send a message via Yahoo to SirCyber
Default Re: sisters computer is going off the wall

the original post sounded like an issue I've had before... got system clean and it's all better lol
__________________


SirCyber is offline  
Old 10-22-2007, 09:00 PM   #5 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,207

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: sisters computer is going off the wall

Looks much better....

remove these entries

O2 - BHO: (no name) - {CFE15135-C591-4000-A55E-A50E5F9F82BC} - C:\Program Files\Video Add-on\isfmdl.dll (file missing)

O3 - Toolbar: IE Custom Tools - {23ED2206-856D-461A-BBCF-1C2466AC5AE3} - C:\Program Files\Video Add-on\ictmdl.dll (file missing)

Now you can reinstall Java

Is her pc better or are you still getting popups?
__________________
Osiris is online now  
Old 10-22-2007, 10:36 PM   #6 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: sisters computer is going off the wall

yeah so far it's a lot better.

could this be from her playing all kinds of disney games and other free kids game sites?

thats about all that computer is used for.
Static_11 is offline  
Old 10-23-2007, 01:07 PM   #7 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,207

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: sisters computer is going off the wall

Looks like she tried to watch a video that needed a codec to play and she downloaded it.
__________________
Osiris is online now  
Old 10-23-2007, 10:38 PM   #8 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: sisters computer is going off the wall

no offense to my sister but she's to dumb to know how. haha.
Static_11 is offline  
Old 10-23-2007, 10:56 PM   #9 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,207

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: sisters computer is going off the wall

Well you are good to go till next time
__________________
Osiris is online now  
Old 10-23-2007, 11:34 PM   #10 (permalink)
Static_11's Avatar
 
Monster Techie

Join Date: Apr 2005

Posts: 1,944

Static_11 is on a distinguished road

Send a message via AIM to Static_11 Send a message via Yahoo to Static_11
Default Re: sisters computer is going off the wall

thanks a lot.
Static_11 is offline  
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
A switch, and a router....Aren't they the same? ReikokuKo Networking Tips, Tricks & FAQ 10 04-10-2009 06:24 PM
POST Troubleshooting Guide SYL\X/3K Hardware Troubleshooting 7 03-07-2009 11:24 AM
Along came a hub, a switch, and a router....Aren't they the same? ReikokuKo Articles 16 06-23-2008 08:24 AM
Serious computer problem. HeeRoMaKi Hardware Troubleshooting 71 07-28-2007 11:42 PM
Wall socket computer ComatoseClown Off Topic Discussion 2 06-24-2007 06:04 AM