0

I was browsing in hopes of trying to fix this problem and happened on this site. I am using Win XP, sorry I don't know what service pack.

I have lots of new weird stuff on my computer. I have gathered from my few short minutes on this site that I should post a Hijack this log, but I don't know what that is. If that would help, could someone advise me on how to obtain it and post a log.

The aforementioned weird stuff comes up on my windows task manager when I hit ctrl+alt+delete, I have also found weird stuff(sorry, I am not too technical with the termage) by going to Run and typing msconfig. It's not really doing anything other than deleting my google tool bar and opening up strange search windows, but it still gives me a not so good feeling. The programs are: kdzpvpfw.exe, zvokiqis.exe, and winfavorites.exe. I just updated my adaware in hopes of getting rid on comwiz.exe(I think I did). But I can't figure out how to get rid of this other stuff. I am going to guess that there is other stuff on this computer that I just haven't noticed yet.

Nothing comes up when I google the programs that is easy to understand.

Can someone please help me?

6
Contributors
26
Replies
27
Views
13 Years
Discussion Span
Last Post by RoseC87Kat
0

I was browsing in hopes of trying to fix this problem and happened on this site. I am using Win XP, sorry I don't know what service pack.

I have lots of new weird stuff on my computer. I have gathered from my few short minutes on this site that I should post a Hijack this log, but I don't know what that is. If that would help, could someone advise me on how to obtain it and post a log.

The best single page I have found: HijackThis Quick Start Page. It includes a download link and the most basic instructions.

According to the evidence in your post, you have both hijackers and viruses. Grisoft AVG is one of the best anti-virus programs, and free for personal use.

You should use Spybot Search & Destroy and/or Ad-Aware spyware/adware tools, as well. You can find links to both on my Malware Information page, along with more detailed information. I know it's a lot of information, but as long as you continue to use Internet Explorer and Outlook instead of Mozilla you are forced to become an expert on malware of every type.

0

Please Download hijackthis from

http://www.merijn.org/files/hijackthis.zip

Unzip, doubleclick HijackThis.exe, and hit "Scan".

After the scan has finished the "scan" button will turn into a "save log" button

save the log file and paste it here

Do not delete anything yet, as most things hijackthis finds are harmless and needed.

steam

0

I can't post my hijackthis log, I have tried about ten times and it keeps telling me the page is down. Any suggestions?

0

Nope, I am not trying to attach a file. I have tried in both Netsacape and IE. IE gives me a Page can't not be displayed error, Netscape tells me the document is empty. The text shows up here, so I don't know what the deal is.


I just tried again, No go.

0

Logfile of HijackThis v1.96.1
Scan saved at 8:23:37 AM, on 1/9/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.eastlink.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.eastlink.ca
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {5B27C20D-FFB6-4054-BA78-DE4A059BC75A} (Microsoft Office Template Downloader) - http://office.microsoft.com/ca/TemplateGallery/msotd.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37992.612349537
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab

0

ok the above is mine ,i just ran hijack and the scan button turns into a copy button ,hit it and when asked to save hit sAVE when note pad opens copy the text from there and past it here .

0

I originally did that and it didn't work. I'm sorry. I am not trying to be difficult. The file is saved in a .txt on my desktop. I have tried to copy and paste it from there several times, just doesn't work. What am I supposed to do?

0

I originally did that and it didn't work. I'm sorry. I am not trying to be difficult. The file is saved in a .txt on my desktop. I have tried to copy and paste it from there several times, just doesn't work. What am I supposed to do?

1. Double-click on the .TXT file. It will open in NotePad or WordPad.

2. Single-click on the File menu, then move down the list on the drop-down menu to the menu-item Select All. Alternatively, press the keyboard shortcut [Ctrl]+[A] (Ctrl-All). This will highlight all the text in the file.

3. Once again, single-click on the File menu, then move down the list on the drop-down menu, this time to the menu-item Copy. Alternatively, press the keyboard shortcut [Ctrl]+[C] (Ctrl-Copy). This copies the text to the Clipboard.

4. In your browser, open the Post Reply window in the forum. Make sure that the cursor is blinking there.

5. Go to the browser's File menu, then move down the list on the drop-down menu to the menu-item Paste. Alternatively, press the keyboard shortcut [Ctrl]+[V].

6. Voila!

0

It's just plain not doing it. No matter what I try, I swear the text shows up in this box. I am starting to get worried.

0

Hi

Try this :-

Go to Tools/internet options/security/custom level......

Scroll down to.....

"Drag and Drop or Copy and paste files"

Make sure it is not disabled

steam

0

It wasn't disabled. So, I don't think that was the problem. I am really getting worried about this. I should be able to do something as simple as copying and pasting.

0

Hi Rose

I have a feeling this this will turn out to be something simple.

So let's try something simple first....

Go to start/run and type in notepad...click ok

This will open a new notepad

Now type in "this is a test"

Highlight the text you have written....right click ...copy

Move down the page a couple of lines...right click...paste

Did it work ?

This will tell us whether information is being retained by the clipboard.

steam

0

Yes, it works. As I said the text pastes fine to here(the lil' message box) but it just won't send. Come to think of it, I have had this problem before on certain message boards. Of course, the page would load on those boards, but when I went and looked at my post my c and p text was not there. Odd thing is, we sell on eBay and C&P terms and such and that shows up. I just don't get it. It's too weird. And it's across every browser I use. I would like to figure out what the heck is going on. My copy and paste function works elsewhere just not on message boards.

My original problem has been taken care of(I think, I hope) through a combination of googling, several different Ad/Spa/Mal ware removers, hope and just blind faith; My hijack log, MSConfig and Task bar seem to be empty. I was getting a message that one of that one of the viri was detected behind my system restore partition thingie, but I think I got that one. I hope.

I think I will hang out on the boards here and lurk. This place is facinating.

Steamwiz, if you have any other suggestions about my c&p problem. I will gladly try them.

0

Hi Rose

No more suggestions at the moment......but I'll post back to this thread if I find out anything.

If you still want your log checking (for peace of mind)
You could upload it as an attachment to your next post.

steam

0

Logfile of HijackThis v1.97.7
Scan saved at 5:08:41 PM, on 1/10/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\S3tray2.exe
C:\HP\KBD\KBD.EXE
C:\windows\system\hpsysdrv.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Documents and Settings\Kathryn\Local Settings\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamewinners.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qus7.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus7.hpwis.com/
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Kathryn\Application Data\Mozilla\Profiles\default\iabum06u.slt\prefs.js)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WCOLOREAL] "C:\Program Files\COMPAQ\Coloreal\coloreal.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [MoneyStartUp10.0] "c:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [BlockTracker] c:\hp\bin\BlockTracker.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.imdb.com
O15 - Trusted Zone: http://www.ninagordon.com
O15 - Trusted Zone: http://www.tvguide.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.24.142/code/PWActiveXImgCtl.CAB
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{339CD31E-CAA4-4F02-93B4-61280F80C7FC}: NameServer = 152.163.241.134

0

Well, it worked that time. Other than it just being today and I haven't tried it since last night when I was pretty sure the machine was cleaned off...............I also just changed the .log to .txt.

If you could analyze the above I would appreciate it. Are there any viri/malware that would affect such a basic function such as c&p'ing?

0

Your log's clean now

You can fix these ....just to tidy up

Close all browser windows - run hijackthis and tick to fix :-

R3 - Default URLSearchHook is missing

O2 - BHO: (no name) - {71ED4FBA-4024-4bbe-91DC-9704C93F453E} - (no file)

If you could analyze the above I would appreciate it. Are there any viri/malware that would affect such a basic function such as c&p'ing?

Oh yes.....I wouldn't be surprised at malware causing anything.

steam

0

"Hunh? What? What porn?"

Just a sarcastic crack. Porn sites are known to be among the worst for scumware -- no surprise, right? They often make extra money if they can deliver a "payload" to each visitor, often a percentage based on the number of hits to the hijacking sites. Even an accidental hit on a porn site can cause problems, which is why preventive measures like the Spybot Search & Destroy Immunize function are so useful.

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.