Home | Community | Message Board

Cannabis Seeds Zamnesia
This site includes paid links. Please support our sponsors.


Welcome to the Shroomery Message Board! You are experiencing a small sample of what the site has to offer. Please login or register to post messages and view our exclusive members-only content. You'll gain access to additional forums, file attachments, board customizations, encrypted private messages, and much more!

Myyco.com Shop: Golden Teacher Liquid Culture For Sale

Jump to first unread post Pages: 1
Need your help
    #9915555 -

Ok, so I have some kind of program that keeps opening Internet explorer in the back ground. I need to figure out how to disable it altogether. I have run spybot several times in safe mode, and it says the shit was removed, but it is still happening. I am using Fire fox, but it keeps opeing Iexplorer.. Any help would be great
thanks


--------------------


Nam-myoho-renge-kyo

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9915572 -

u need norton 360, its great shit.


--------------------
Spirit is the Life, Mind is the Builder, and the Physical is the Result

Extras: Filter Print Post Top
Re: Need your help [Re: DoYouMusHrOOM]
    #9915581 -

oh, i like the rat humping the water pipe, musta been some good shit for him to miss it like that.


--------------------
Spirit is the Life, Mind is the Builder, and the Physical is the Result

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9915631 -

Hi-
It definitely sounds like adware/ spyware, Each time you run Spybot does it keep finding it? You can also try Ad-Aware, that might be able to find something out too. I have class now but I'll check back later.

Extras: Filter Print Post Top
Re: Need your help [Re: DoYouMusHrOOM]
    #9915636 -

> u need norton 360, its great shit.

Symantec products (such as norton) used to be decent, but they have gone way downhill the last few years.  I would not recommend any norton product.


--------------------
Just another spore in the wind.

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9918626 -

try malwarebytes, its a great free program...and gets a lot of stuff that spybot doesn't.

peace

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9927676 -

If spybot reports the same spyware each time, I'd google it as there is probably an installer hidden in the system files that duplicates itself with random names and such and hooks into the system.

If you're a bit computer savvy, download HijackThis and see what else is starting up with your system on boot.  Just don't mess with it if you don't know what you're doing, easy to screw up the registry.

Also, Norton is fail.  :thumbdown:
A good few AV's are: Kapersky, AVG 7.5, Nod32.  :thumbup:


--------------------
~Happy sailing~

Extras: Filter Print Post Top
Re: Need your help [Re: RuNE]
    #9929062 -

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll
O3 - Toolbar: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1202660629-436374069-839522115-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User '?')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
O18 - Filter hijack: text/html - {81505e9a-8359-4309-821b-4b440084af2c} - C:\WINDOWS\system32\mst120.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)


--------------------


Nam-myoho-renge-kyo

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9929184 -

flip3084 said:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll
O3 - Toolbar: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-21-1202660629-436374069-839522115-1003\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User '?')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} -
O18 - Filter hijack: text/html - {81505e9a-8359-4309-821b-4b440084af2c} - C:\WINDOWS\system32\mst120.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)



first, i would go to start --> run then type in msconfig and press enter.  Go to the startup tab and disable these from startup:

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe

They are all unnecessary, and will start up on demand anyways, so no need to be running with boot.

I would also remove this

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [url=http://us.rd.yahoo.com/customize/ycomp_adbe/defaults/sb/]http://us.rd.yahoo.com

that is yahoo search bar, i hate toolbars, but if you like it, no harm in it, best to just uninstall from add/remove programs.

R3 - URLSearchHook: Mininova-Vuze Toolbar - {d51d388b-f5dc-471a-a1ce-5e2d671091c0} - C:\Program Files\Mininova-Vuze\tbMini.dll

is another toolbar, don't know if you use it or not, if not, its safe to remove, its still being reviewed if it has malicious code or not, but again, i hate toolbars, so this is personal choice.

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

this is quicktime updater, you can remove it here, just delete it through hijackThis, its useless, and runs whenever you use quicktime anyways...more apple crap.


O4 - HKUS\S-1-5-18\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User '?')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [system tool] C:\WINDOWS\sysguard.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [svcho] C:\WINDOWS\svcho.exe (User 'Default user')

These are some pretty nasty virus/malware downloaders...not the easiest to get rid of, but possible...What you need to do is download malwarebytes, schedule a boot up scan, reboot, let it scan, then delete everything it asks you to.  Also install avast antivirus, and do a full scan with it as well, these two should clean up all remnants of this...i recently had to clean it off of a friends computer...it can be a bitch, and block certain spyware scanners from updating...good luck

O18 - Filter hijack: text/html - {81505e9a-8359-4309-821b-4b440084af2c} - C:\WINDOWS\system32\mst120.dll

this is also a piece of spyware, and should be deleted, if you can remove it through hijack this, then do so, but if you scan with malwarebytes, it will probably take care of it.  it is disguising itself as a legit dll, but its part of netmeeting, which its location shoudl be C:\Program Files\netmeeting, not in your system32 folder.  Again, do malwarebytes first, and avast, then run hijack this again, if its still there, then delete through hijack this.

That should be good.  Oh, if your going to install avast, be sure to remove McAfee, its not as horrible as norton, but still not that great.  Avast is free and better.

peace

Extras: Filter Print Post Top
Re: Need your help [Re: supra]
    #9938403 -

ok, so, I am now using the other computer. I ran avast upon startup, an apparently put a couple of vital files in the chest.. It asked me if I wanted to delete the infected file, or put it in the chest, and I put them In the chest. Now I cannot start windows. It starts to open profile with an empty desktop, an then automaticly logs off.... What should I do?? I am so tired of windows, I think once I work this out, i am using linux....


--------------------


Nam-myoho-renge-kyo

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9941247 -

flip3084 said:
ok, so, I am now using the other computer. I ran avast upon startup, an apparently put a couple of vital files in the chest.. It asked me if I wanted to delete the infected file, or put it in the chest, and I put them In the chest. Now I cannot start windows. It starts to open profile with an empty desktop, an then automaticly logs off.... What should I do?? I am so tired of windows, I think once I work this out, i am using linux....



don't know man...sorry.  I actually do use linux, only know how to read those logs because I used to go use it at peoples houses when i ran my own computer consulting service in college...im sure someone will come along to help you out.

I would think your best bet would be to get a jump drive with a distro of linux that has the ntfs-3g driver on it, so you can read your partitions, boot to that jumpdrive, put the windows CD in, download the files that you had put in the chest, and restore them to their original locations, delete the infected ones, reboot computer and remove jump drive, may work, may not, but thats what i would go for.

If your serious about linux, i would recommend

Archlinux (good distro to learn on, very fast and very minimal, will make you actually LEARN linux though)
sabayon linux (what im using now, i still think arch is my favorite, but can't go wrong with either..i actually use emerge instead of equo as my package manager usually still, more used to it)
Gentoo linux (only if you want to get really serious...sabayon IS gentoo, just prebuilt and has a bunch of binary packages...really, all the time you spend optimizing with gentoo anyways is wasted with todays computers, i guess its good for something REAL old, but no need really...)

And if you want the 'windows' of linux, go for ubuntu, i don't really like it personally, since its uber bloated with all kinds of everything, and loaded down, but fact is, it just works easily right out of the box most the time...if you don't feel like messing with anything or really learning linux, this is probably your best choice, or pclinuxos...

peace

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9944224 -

Can you start up in safe mode?  If so, create a new user, reboot normal, and login to the new user.  If that works, then the old user profile is corrupt.  I hate windows.


--------------------
Just another spore in the wind.

Extras: Filter Print Post Top
Re: Need your help [Re: Seuss]
    #9944430 -

Yeah, I tried safe mode with networking and command prompt. It will not log into windows. It is okay I suppose, nothing to important on the computer, and I have a linux OS on the way.. Good bye windows.


--------------------


Nam-myoho-renge-kyo

Extras: Filter Print Post Top
Re: Need your help [Re: flip3084]
    #9944445 -

One other thing to try (or two)... boot from optical and go into the recovery console.  There, run a chkdsk /r and see if that fixes it.  I tend to run it two or three times, until it no longer reports errors.  Other would be to run sfc from safemode.


--------------------
Just another spore in the wind.

Extras: Filter Print Post Top
Jump to top Pages: 1

Myyco.com Shop: Golden Teacher Liquid Culture For Sale


Similar ThreadsPosterViewsRepliesLast post
* Hijack this flip3084 565 3 01/15/09 05:51 PM
by supra
* Statistics time: Programming Languages and Programmers
( 1 2 all )
delta9 4,685 26 05/16/07 12:17 PM
by SymmetryGroup8
* Limewire Sucks - Need better program
( 1 2 all )
Robo 4,722 22 08/04/07 07:20 AM
by automan
* Program design help SeussA 1,569 8 05/04/07 09:11 AM
by phi1618
* Shroomery programming/math/etc. self-study peer(s)? If you want to mentor, that's fine too.
( 1 2 all )
seek 3,024 22 06/03/14 09:41 PM
by Satira
* What can i program for you?
( 1 2 all )
vaporbrains 3,205 22 05/03/03 04:33 AM
by dumlovesyou
* 64-bit OS'es and Program Compatablity blink 2,384 19 01/07/06 12:26 AM
by Vampire999
* need a free virus protection program rugergirl79 512 6 10/14/08 05:44 PM
by supra

Extra information
You cannot start new topics / You cannot reply to topics
HTML is disabled / BBCode is enabled
Moderator: trendal, automan, Northerner
696 topic views. 0 members, 39 guests and 0 web crawlers are browsing this forum.
[ Show Images Only | Sort by Score | Print Topic ]
Search this thread:

Copyright 1997-2026 Mind Media. Some rights reserved.

Generated in 0.031 seconds spending 0.006 seconds on 14 queries.