CommonNames problem

Reply

Join Date: Jan 2004
Posts: 25
Reputation: scyth02 is an unknown quantity at this point 
Solved Threads: 0
scyth02 scyth02 is offline Offline
Light Poster

CommonNames problem

 
0
  #1
Jan 6th, 2004
OS is Windows 2000
The problem is that my IE has been very slow and even crashing the comp
I've been using SpyBot for a while, but it can't delete some stuff in a file called CommonNames. I know nothing about the file, but I'm guessing it's the source of the problem. Is this a known problem? Should I just delete the file myself?
Reply With Quote Quick reply to this message  
Join Date: Nov 2003
Posts: 66
Reputation: peterska2 is an unknown quantity at this point 
Solved Threads: 0
peterska2's Avatar
peterska2 peterska2 is offline Offline
Junior Poster

Re: CommonNames problem

 
0
  #2
Jan 6th, 2004
Have you updated your spybot recently?

If not update it and try again.

If that doesn't work then can you post a bit more info about the file such as the extension (.doc, .txt, .php, etc) and the size as well as where abouts in your system it is.

Have you also cleared out cookies and temporary internet files recently?

If not then this would also be a good idea. The temp internet files quickly mount up and make a big impact on your speed.
Reply With Quote Quick reply to this message  
Join Date: Jan 2004
Posts: 25
Reputation: scyth02 is an unknown quantity at this point 
Solved Threads: 0
scyth02 scyth02 is offline Offline
Light Poster

Re: CommonNames problem

 
0
  #3
Jan 6th, 2004
This showed up after a recent SpyBot update. I've cleared all the temps and cookies while on selective start up. Inside CommonNames is a second file called AddressBar. In that are 8 DAT files, cnbabe.dll, and two applications, comwiz and winnet.
Reply With Quote Quick reply to this message  
Join Date: Oct 2003
Posts: 73
Reputation: steamwiz is an unknown quantity at this point 
Solved Threads: 1
steamwiz's Avatar
steamwiz steamwiz is offline Offline
Junior Poster in Training

Re: CommonNames problem

 
0
  #4
Jan 7th, 2004
Hi scyth02

Do this and we'll get rid of it :-

Download hijackthis from

http://www.merijn.org/files/hijackthis.zip

Unzip, doubleclick HijackThis.exe, and hit "Scan".

After the scan has finished the "scan" button will turn into a "save log" button

save the log file and paste it here

Do not delete anything yet, as most things hijackthis finds are harmless and needed.

steam
Reply With Quote Quick reply to this message  
Join Date: Jan 2004
Posts: 25
Reputation: scyth02 is an unknown quantity at this point 
Solved Threads: 0
scyth02 scyth02 is offline Offline
Light Poster

Re: CommonNames problem

 
0
  #5
Jan 7th, 2004
OK, but the file created by HijackThis can't be attached to the post and has no text for Copy/Paste. What should I do with it?
Reply With Quote Quick reply to this message  
Join Date: Oct 2003
Posts: 73
Reputation: steamwiz is an unknown quantity at this point 
Solved Threads: 1
steamwiz's Avatar
steamwiz steamwiz is offline Offline
Junior Poster in Training

Re: CommonNames problem

 
0
  #6
Jan 7th, 2004
RE : HJT log file...

After the scan has finished the "scan" button will turn into a "save log" button

Click the "save log" button.....this will open the log in notepad....save it to the desktop.

Go to the file and open it....

Click .....edit....select all.....edit again ...copy

Open a new post here...right click...paste.
Reply With Quote Quick reply to this message  
Join Date: Jan 2004
Posts: 25
Reputation: scyth02 is an unknown quantity at this point 
Solved Threads: 0
scyth02 scyth02 is offline Offline
Light Poster

Re: CommonNames problem

 
0
  #7
Jan 7th, 2004
OK, for whatever reason my PC tried to open it with IE, so I just went into Notepad and opened it from there. Here it is:
Logfile of HijackThis v1.97.7
Scan saved at 1:47:31 PM, on 1/7/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0600)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SYSTEM32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\ADAPTEC\DIRECTCD\DIRECTCD.EXE
C:\PROGRAM FILES\MICROSOFT HARDWARE\MOUSE\POINT32.EXE
C:\PROGRAM FILES\VERIZON ONLINE\WINPOET\WINPPPOVERETHERNET.EXE
C:\PROGRAM FILES\OFFICE KEYBOARD UTILITY\1.2\OFFICEKB.EXE
C:\PROGRAM FILES\OFFICE KEYBOARD UTILITY\1.2\MMKEYB.EXE
C:\WINDOWS\SYSTEM\HPZTSB07.EXE
C:\PROGRAM FILES\OFFICE KEYBOARD UTILITY\1.2\TRAYMON.EXE
C:\WINDOWS\WGHZVWHJ.EXE
C:\PROGRAM FILES\OFFICE KEYBOARD UTILITY\1.2\OSD.EXE
C:\WINDOWS\SYSTEM\VFBTIAWM.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\COMMONNAME\ADDRESSBAR\WINNET.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WORKS SHARED\WKCALREM.EXE
C:\PROGRAM FILES\COMMONNAME\ADDRESSBAR\COMWIZ.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\PROFILES\BENJI\MY DOCUMENTS\HIJACKTHIS\HIJACKTHIS.EXE
C:\PROGRAM FILES\COMMON FILES\GMT\GMT.EXE
C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wizards.com/default.asp?x=mtgcom/welcome
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir..._PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir...5.5&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer customized for Verizon Online
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {BB0DE97B-9FF6-ECEF-A54C-867FA63C9C05} - C:\windows\system\otyxkabb.dll
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\Verizon Online\WinPoET\winpppoverethernet.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe C:\PROGRA~1\AIM95\DeadAIM.ocm,ExportedCheckODLs
O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Program Files\Office keyboard utility\1.2\OFFICEKB.exe
O4 - HKLM\..\Run: [System32] System32.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [xvjkwgvs] C:\WINDOWS\wghzvwhj.exe
O4 - HKLM\..\Run: [CFJ] C:\WINDOWS\CFJ.exe
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\SYSTEM\vfbtiawm.exe
O4 - HKLM\..\Run: [BEHK] C:\WINDOWS\BEHK.exe
O4 - HKLM\..\Run: [JZAQHXO] C:\WINDOWS\JZAQHXO.exe
O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe
O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKLM\..\RunServices: [System32] System32.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - User Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - User Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: AIM (HKLM)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.142/code/PWActiveXImgCtl.CAB
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex...trol_v1-32.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab
O16 - DPF: {39DD1CC2-6D79-92FD-3EE3-F235B5C8FB2F} (DownloadUL Class) - http://public.searchbarcash.com/cab/035/xribqjzj.cab
Reply With Quote Quick reply to this message  
Join Date: Oct 2003
Posts: 73
Reputation: steamwiz is an unknown quantity at this point 
Solved Threads: 1
steamwiz's Avatar
steamwiz steamwiz is offline Offline
Junior Poster in Training

Re: CommonNames problem

 
0
  #8
Jan 8th, 2004
You have several problems.....

Close all browser windows - run hijackthis and tick to fix :-

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wizards.com/default.asp?x=mtgcom/welcome <<<<<<<<<<fix this if you didn't put it there.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about_:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about_:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about_:blank

O2 - BHO: (no name) - {BB0DE97B-9FF6-ECEF-A54C-867FA63C9C05} - C:\windows\system\otyxkabb.dll

O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL

O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL

O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime

O4 - HKLM\..\Run: [xvjkwgvs] C:\WINDOWS\wghzvwhj.exe

O4 - HKLM\..\Run: [nvid] C:\WINDOWS\SYSTEM\vfbtiawm.exe

O4 - HKLM\..\Run: [BEHK] C:\WINDOWS\BEHK.exe

O4 - HKLM\..\Run: [JZAQHXO] C:\WINDOWS\JZAQHXO.exe

O4 - HKLM\..\Run: [winnet] C:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe

O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"

O4 - HKLM\..\RunServices: [System32] System32.exe

O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe

O4 - User Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - User Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe

O16 - DPF: {39DD1CC2-6D79-92FD-3EE3-F235B5C8FB2F} (DownloadUL Class) - http://public.searchbarcash.com/cab/035/xribqjzj.cab

Reboot Then find and delete :-

C:\WINDOWS\wghzvwhj.exe - file
C:\WINDOWS\SYSTEM\vfbtiawm.exe - file
C:\WINDOWS\BEHK.exe - file
C:\WINDOWS\JZAQHXO.exe - fil
C:\Program Files\CommonName - folder
C:\WINDOWS\SYSTEM\SYSTEM32.EXE - file
C:\Program Files\Common Files\CMEII\ - folder
C:\Program Files\Common Files\GMT\ - folder

steam
Reply With Quote Quick reply to this message  
Join Date: Jan 2004
Posts: 25
Reputation: scyth02 is an unknown quantity at this point 
Solved Threads: 0
scyth02 scyth02 is offline Offline
Light Poster

Re: CommonNames problem

 
0
  #9
Jan 8th, 2004
Thanks for all your help! One last Q. Is the file SYSTEM32 in the WINDOWS file any concern?
Reply With Quote Quick reply to this message  
Join Date: Oct 2003
Posts: 73
Reputation: steamwiz is an unknown quantity at this point 
Solved Threads: 1
steamwiz's Avatar
steamwiz steamwiz is offline Offline
Junior Poster in Training

Re: CommonNames problem

 
0
  #10
Jan 8th, 2004
You're welcome

If you mean the.....

C:\WINDOWS\SYSTEM32 .... Folder

Yes that is a legitimate folder....leave it alone.

steam
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Other Threads in the Web Browsers Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC