Folder Options Missing...

Thread Solved

Join Date: Nov 2006
Posts: 1
Reputation: mureed is an unknown quantity at this point 
Solved Threads: 0
mureed mureed is offline Offline
Newbie Poster

Folder Options Missing...

 
0
  #1
Nov 19th, 2006
Hi,

I know there is thread to this topic but I couldnt find it..
My Folder Options is no longer there under tools..
I even when to safe mode and checked to delete this [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
but there is no folderoptionsvalue called thing there...

heres the very recent i got from HijackThis....Please reply soon..Thank You...

Logfile of HijackThis v1.99.1
Scan saved at 6:54:48 PM, on 11/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\System32\svchost.exe
M:\Azureus\Azureus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Desktop Calendar XP] C:\Program Files\Desktop Calendar XP\Desktop Calendar XP.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Tok-Cirrhatus-1266] "C:\Documents and Settings\user\Local Settings\Application Data\smss.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00000000-0000-0000-0000-100005000004} - http://code.trasferimento.biz/l/23dd...5e9521b_35.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1159970476453
O17 - HKLM\System\CCS\Services\Tcpip\..\{7625B67E-115C-4FC1-A12A-1137BF9DBB6F}: NameServer = 202.188.0.133 202.188.1.5
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: Antiwpa - C:\WINDOWS\SYSTEM32\antiwpa.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
Reply With Quote Quick reply to this message  
Join Date: Apr 2009
Posts: 2
Reputation: jp2code is an unknown quantity at this point 
Solved Threads: 0
jp2code's Avatar
jp2code jp2code is offline Offline
Newbie Poster

Re: Folder Options Missing...

 
0
  #2
Sep 8th, 2009
I got this same exact virus, the only one I've had in over 10 years, only after visiting Daniweb's site. Coincidence?
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,017
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer

Re: Folder Options Missing...

 
0
  #3
Sep 8th, 2009
Originally Posted by jp2code View Post
I got this same exact virus, the only one I've had in over 10 years, only after visiting Daniweb's site. Coincidence?
What "virus" might that be? It would probably be a good idea to bring that to the attention of site administration......

BTW - Are you using a cracked/pirated copy of Windows like the original poster?

Cheers
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,126
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 770
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: Folder Options Missing...

 
0
  #4
Sep 8th, 2009
Originally Posted by jp2code View Post
I got this same exact virus, the only one I've had in over 10 years, only after visiting Daniweb's site. Coincidence?
Maybe its a spam virus?
Reply With Quote Quick reply to this message  
Join Date: Apr 2009
Posts: 2
Reputation: jp2code is an unknown quantity at this point 
Solved Threads: 0
jp2code's Avatar
jp2code jp2code is offline Offline
Newbie Poster

Re: Folder Options Missing...

 
0
  #5
Sep 8th, 2009
Originally Posted by PhilliePhan View Post
What "virus" might that be? It would probably be a good idea to bring that to the attention of site administration......

BTW - Are you using a cracked/pirated copy of Windows like the original poster?

Cheers
PP
No, this is on my work PC. Company managed Windows licenses and Trend Micro antivirus.

Trend caught it and displayed the message, at which time I had our IT guy come record it. By the time he got here (he is 2 cubicals over), the virus had removed all access Admin tools (Control Panel, Regedit, Process Explorer, Safe Mode, etc.) and it replicated to over 20,000 different variations before Trend crashed, then it removed Trend's ability to run, installed some third party firewall/antivirus utility, and posted a big screenshot on the desktop saying the PC was infected.

I'd love to give more info about the virus, but the IT guy took my hard drive away for cleaning.

Here's how I got the virus:
1) I received my a monthly email from Daniweb about their featured poster, who talked about the virus forum being her favorite.
2) I'd never seen a virus forum, so I came went to Daniweb's virus forum, a popup in IE8 tried to install some 3rd party control (which I ignored, as always), and
3) Bam! Trend started showing the errors.

I would bring it to the daniweb admin's attention, but I don't know what to tell them to look for.
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,017
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer

Re: Folder Options Missing...

 
0
  #6
Sep 8th, 2009
Originally Posted by jp2code View Post
No, this is on my work PC. Company managed Windows licenses and Trend Micro antivirus.
I would bring it to the daniweb admin's attention, but I don't know what to tell them to look for.
That is indeed odd - I and many others hit this site and forum a lot and no problems....

However, I am not going to dismiss your post because I have seen many legitimate sites get hacked, resulting in code insertions and the like. Plus, I have seen a lot of infected advertising from 3rd parties on legit sites as well.

I am sorry you got infected - too bad we couldn't see any info to try to pinpoint the problem.

PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Join Date: Aug 2007
Posts: 1,729
Reputation: Suspishio is an unknown quantity at this point 
Solved Threads: 137
Sponsor
Suspishio's Avatar
Suspishio Suspishio is offline Offline
Simples!

Re: Folder Options Missing...

 
0
  #7
Sep 8th, 2009
This is the trojan:

winjgf32.dll
Suspishio
My advice is at your risk
Qosmio G50-10H; T9400 2.53GHz Core 2 Duo; 4GB RAM; Vista HP (32)
nForce 680i LT; Q6600 Quad Core 2.4GHz; 8GB RAM; XP Pro (64)
Dell XPS M1710; T7200 2GHz Core 2 Duo; 2GB RAM; XP Pro (32)
Reply With Quote Quick reply to this message  
Join Date: Dec 2006
Posts: 1,017
Reputation: PhilliePhan will become famous soon enough PhilliePhan will become famous soon enough 
Solved Threads: 49
Moderator
PhilliePhan's Avatar
PhilliePhan PhilliePhan is offline Offline
Central Scrutinizer

Re: Folder Options Missing...

 
0
  #8
Sep 8th, 2009
Originally Posted by Suspishio View Post
This is the trojan:
winjgf32.dll
The original post is from almost 3 years ago.

Plus, a ton of different malware could cause these symptoms.
That looks like old Vundo - definitely not something that would cause the issues that jp2code described.....

Cheers
PP
In some sort of crude sense, which no vulgarity, no humor, no overstatement can quite extinguish, the physicists have known sin; and this is a knowledge which they cannot lose.
~ J. Robert Oppenheimer

ASAP
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 4986 | Replies: 7
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC