![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Mar 2005
Location: Hawaii (now in Oklahoma)
Posts: 111
OS: windows 2000
|
Hello. Sorry to have to be back again.
The first thing I noticed is that when I went to Add/Remove programs to remove SunJava, it wouldnt load. I let it sit there for about 20 minutes and nothing would load. I couldnt click on anything, had to restart the computer just to make it go away. So I went ahead and uninstalled it through CCleaner. Now the Windows Update icon has been sitting in my system tray for the past two days at 0%. I tried going to the update page, but it keeps freezing and i have to use Task Manager to shut the page down. Than yesterday when i was trying to run CCleaner my computer kept shutting off, and when my husband was trying to print something it shut off. My computer has been moving way slower than usually also. I ran spybot, and adaware and both found nothing. Heres the pandascan log... Incident Status Location Adware:adware/isearch Not disinfected Windows Registry Adware:adware/beginto Not disinfected Windows Registry Potentially unwanted tool:Application/Processor Not disinfected C:\WINNT\SYSTEM32\Process.exe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINNT\NirCmd.exe Heres the dss.exe txt...the only one that came up was the main.txt, no extra.txt. Deckard's System Scanner v20070905.67 Run by ruben on 2007-10-15 03:33:37 Computer is in Normal Mode. -------------------------------------------------------------------------------- Total Physical Memory: 128 MiB (256 MiB recommended). -- HijackThis (run as ruben.exe) ----------------------------------------------- Unable to find log (file not found); running clone. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of HijackThis v1.99.1 Scan saved at 2007-10-15 03:33:44 Platform: Windows 2000 Service Pack 4 (5.00.2195) MSIE: Internet Explorer (6.00.2800.1106) Running processes: C:\WINNT\system32\SMSS.EXE C:\WINNT\system32\WINLOGON.EXE C:\WINNT\system32\SERVICES.EXE C:\WINNT\system32\LSASS.EXE C:\WINNT\system32\svchost.exe C:\WINNT\system32\ZoneLabs\vsmon.exe C:\WINNT\system32\spoolsv.exe C:\Program Files\Grisoft\AVG7\avgamsvr.exe C:\Program Files\Grisoft\AVG7\avgupsvc.exe C:\Program Files\Grisoft\AVG7\avgemc.exe C:\WINNT\explorer.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\mstask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\system32\wbem\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\Program Files\Browser MOUSE\mouse32a.exe C:\Program Files\Grisoft\AVG7\avgcc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINNT\system32\wuauclt.exe C:\WINNT\system32\svchost.exe C:\Documents and Settings\ruben\Desktop\dss.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.com/search?q=%s R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie R1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\GoogleToolbar2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\GoogleToolbar2.dll O4 - HKEY_LOCAL_MACHINE\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKEY_LOCAL_MACHINE\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe O4 - HKEY_LOCAL_MACHINE\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKEY_LOCAL_MACHINE\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O16 - DPF: Hearts by pogo () - http://game1.pogo.com/v/8.1.1.13/app...arts-en_US.cab O16 - DPF: Thousand Island Solitaire by pogo () - http://game1.pogo.com/v/8.1.1.18/app...brae-en_US.cab O16 - DPF: World Class Solitaire by pogo () - http://game1.pogo.com/v/8.1.1.1/appl...lass-en_US.cab O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...tent/opuc3.cab O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get.../ultrashim.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {D27CDB6E-AE6D-0000-0000-000000000000} () - http://download.macromedia.com/pub/s...sh/swflash.cab O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\Program Files\Grisoft\AVG7\avgemc.exe -- Files created between 2007-09-15 and 2007-10-15 ----------------------------- 2007-10-14 14:04:40 0 d-------- C:\FOUND.001 2007-10-02 19:35:42 0 d-------- C:\FOUND.000 2007-09-23 07:57:06 0 d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier -- Find3M Report --------------------------------------------------------------- 2007-09-23 07:59:48 4212 ---h----- C:\WINNT\system32\zllictbl.dat 2007-09-11 09:31:22 16384 --a------ C:\WINNT\system32\Perflib_Perfdata_378.dat -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [06/19/03 11:05a C:\WINNT\system32\mobsync.exe] "FLMOFFICE4DMOUSE"="C:\Program Files\Browser MOUSE\mouse32a.exe" [03/22/05 06:59p] "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [09/14/07 08:51a] "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [09/06/07 04:14p] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [07/23/07 08:57p] [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce] "^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop C:\Documents and Settings\ruben\Start Menu\Programs\Startup\ SpywareGuard.lnk - C:\Program Files\SpywareGuard\sgmain.exe [8/29/2003 7:05:35 PM] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [9/23/2005 10:05:26 PM] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys] @="Driver" -- End of Deckard's System Scanner: finished at 2007-10-15 03:35:41 ------------ Last edited by sailorvenus; 10-15-2007 at 03:00 AM. |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#4 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,024
OS: WinXP and Vista
|
Re: computer shuts self off....
Hello sailorvenus,
This does not appear to be a malware issue. I would suggest the following: Click Start>Run and type in sfc /scannow (there is a space between sfc and /) and let it scan for missing/corrupt files. This command will immediately initiate the Windows File Protection service to scan all protected files and verify their integrity, replacing any files with which it finds a problem. If it finds any problems, it will prompt you for the Windows 2000 Install disc so have it handy. If any issues are found, or remain, please begin a thread in the Windows 2000 section of this forum. |
|
|
|
|
#6 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 27,024
OS: WinXP and Vista
|
Re: computer shuts self off....
Could be. Judging by your previous threads, this system has had issues for quite some time. All I can suggest then is to talk to the folks in Windows 2000 and see if they can help you out with these OS issues.
|
|
|
| Thread Tools | |
|
|