caperjack 875 I hate 20 Questions Team Colleague

Only one I could think of at the time.:)
OK ,is you computer set in the bios to boot to the cd drive first or the floppy .

caperjack 875 I hate 20 Questions Team Colleague

poat a new log ,and i'll have a look later today to see whats left

caperjack 875 I hate 20 Questions Team Colleague

Were do you live I'll come over and fix your broken floppy !:)

caperjack 875 I hate 20 Questions Team Colleague

so just type in BUMP !:)

caperjack 875 I hate 20 Questions Team Colleague
caperjack 875 I hate 20 Questions Team Colleague

This is one i use to search .exe's to see if they are good or bad.
STARTUP

This site is use to check hijackthis logs ,to know that the files is bad depends a alot of factors ,mostly what foder its in or if it is spelt the same but has caps or not or one letter different .not all files show up

caperjack 875 I hate 20 Questions Team Colleague

I did some looking around on the website that you (caperjack) posted on another link. I looked at all of the processes that were running when I pressed ALT+CTL+DEL and it said that svchost.exe, services.exe, lsass.exe, csrss.exe, spoolsv.exe, winlogon.exe, smss.exe, winreg.exe, and explorer.exe were all created from various viruses. That really surprised me b/c my computer seems to be running better than it used to, and if all of those processes were gone, there would be almost nothing left on the menu. Should I do something about these or just leave them there? If anyone knows the answer, please let me know. Thanks a bunch.

-Jeff-

You have to be careful and rely on you anti viruse program for virus as the virus will add files that are just like actuall windows files ,it just puts them in a different folder that the orignal !!

caperjack 875 I hate 20 Questions Team Colleague

actually this file[O4 - HKLM\..\Run: [Windows Update Agent] winupdate.exe] could be the results of a virus ,there is an good ,winupdate.exe file but it would be in the c:\windows\system , folder ,do a search for the file and let me know how many you find and where they are located .

caperjack 875 I hate 20 Questions Team Colleague

Sorry, but one more thing, I ran ad-aware 6.0 personal and it found 212 items (I not very good w/ computers, so I have no idea what this means.) Are these files that I should delete? I didn't do anything w/ them b/c it seemed like a whole lot of files to delete. Please let me know what I should do w/ them (if anything).

Thanks again!

-Jeff-

Thats what ad-aware is for removing spyware file ,safe to remove everything it finds .

caperjack 875 I hate 20 Questions Team Colleague
caperjack 875 I hate 20 Questions Team Colleague

I'm over 50,And the eyes aren't what they use to be ,You font makes it hard for me to See !!:)
Anyway have you run Spybot and Ad-aware to remove any unwanted spyware/adware from you computer .check my signature for Ad-aware and download and update it and run it and post back and tell ,if that helps .

caperjack 875 I hate 20 Questions Team Colleague

only thing is this ,but if this [206.141.192.60 ]is your IP address then it ok ,if you know its not you IP Address then fix it .
O17 - HKLM\System\CCS\Services\Tcpip\..\{304C4BF2-A542-4371-9FA1-8AC82751B787}: NameServer = 206.141.192.60 206.141.193.55

caperjack 875 I hate 20 Questions Team Colleague

This is one i use to search .exe's to see if they are good or bad.
STARTUP

caperjack 875 I hate 20 Questions Team Colleague
caperjack 875 I hate 20 Questions Team Colleague

What i would do is ,run you AV and Quarentene the affected files .The photo you post shows the sub7ledgenes in a folder on c:\ delete the folder .

caperjack 875 I hate 20 Questions Team Colleague

The hijackthis log would have shown the virus if it were in Run that was why I got you to use hijackthis and post the log in the other thread.

caperjack 875 I hate 20 Questions Team Colleague

Glad i could help !

caperjack 875 I hate 20 Questions Team Colleague

no not at all i never do anything at 12:54 im sleeping then.

didn't mean you were up doing it I said do you jou have anything set to auto run ,The file was created after you went to bed ,so I assummed you leave the computer turned on .

caperjack 875 I hate 20 Questions Team Colleague

what do you mean by clean log?

Sorry .I meant that the log is clean of any problems .I got you to do all this hopeing to see something related to the trojan but there was nothing ,so I got you to fix the other problems that the log showed ,You trojan seems to be new as i can't find anything about the Mosucker.W ,othe Mosucker but not the .W !
I think you should delete that sub7ledgents file and folder .

caperjack 875 I hate 20 Questions Team Colleague

Clean log .

caperjack 875 I hate 20 Questions Team Colleague

get hijack out of the temp folder and put it in its own folder on your harddrive first .like c:\HJ\Hijackthis.exe

then run it and fix this make sure all Windows explore and browser windows are closed

R3 - URLSearchHook: (no name) - {D6DFF6D8-B94B-4720-B730-1C38C7065C3B} - (no file)


O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://216.65.38.226/crack.CAB
-DynamicDesktopMedia Contro


reboot and post new log

caperjack 875 I hate 20 Questions Team Colleague

You still have hijackthis in a temp folder please put it in its own folder something like C:\HJ\Hijackthis.exe ,so that it can create a backup when you use it thanks .

Make sure all browser windows are closed
and run hijack and fix the following


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about_:blank

R3 - Default URLSearchHook is missing


O4 - HKCU\..\Run: [sws.exe] c:\program files\HaldexLtd\boob3\3141917.exe -remove

This one is optional but reccomended to fix resource hog and no need to be running all the time .

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

[X] O16 - DPF: {41F31718-2B9D-4F76-85E2-DD11BBA99F8D} - http://install.spywarelabs.com/Dist...r2501031120.EXE

[X] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/295d8c1e261c4d...ip/RdxIE601.cab

[X] O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab


Reboot computer into safe mode [hitting f8 on bootup]and delete the following folder

c:\program files\HaldexLtd--- delete folder

Reboot and post new log

caperjack 875 I hate 20 Questions Team Colleague

Sorry I'm running XP Pro and don't get that dialog box.

caperjack 875 I hate 20 Questions Team Colleague

First please get Spybot S&D to clear out most of the spyware.In my signature .


Fix everything SpybotSD labels in red.

Then after reboot:
Download 'Hijack This!'. the file is below!!
Unzip to a permanent folder,NOT A TEMP FOLDER , doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, load it in Notepad, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.
then post the log here

caperjack 875 I hate 20 Questions Team Colleague

First UDP= http://www.webopedia.com/TERM/U/User_Datagram_Protocol.html

Then Packets= http://www.webopedia.com/TERM/p/packet.html

now put the 2 together and you got the answer .:)

caperjack 875 I hate 20 Questions Team Colleague

in the meantime you might want to try, AIDA32 to find out the actual name of you motherboard .

caperjack 875 I hate 20 Questions Team Colleague

thanks for moving it here .Looks great just fix a few more minor ones .

Make sure all browser windows are closed and run hijack again and have it fix these .

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about_:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about_:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about_:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about_:blank

I figured CWShredder would fix it but it is recommended to run SpyBot and Ad-Aware first .

See How I got Infected In the first place Also in my Signature .

Good Luck

caperjack 875 I hate 20 Questions Team Colleague

I dont know what but it looks like something making a backup or something .are you running any auto scans at that hour or windows updates .ect.ect.ect .
The files in the folder are from your C:\windows \system32 folder .

caperjack 875 I hate 20 Questions Team Colleague

If you want a program to run at startup,put its .EXE in the startup folder .
Open windows explorer ,and copy the progrms .exe to the startup folder .

the startup folder is in C:\Documents and Settings\YOUR USER NAME\Start Menu\Programs\Startup. just place a copy of the programs .EXE here ,
Like if it were notpad.exe you wanted to start you would go to c:\windows ,and drag and drop a copy of notepat.exe to .
C:\Documents and Settings\YOUR USER NAME\Start Menu\Programs\Startup that its ..
Or if the program is in ,START/All Programs just drag and drop its icon to the startup folder there .

J☼E commented: thanks for the help +5
caperjack 875 I hate 20 Questions Team Colleague

I mean nothing comes on the fan is running but its like it died

I know what you mean .it's possible to short out the mother board when changing ram ,both with static and DC electricity ,did you unplug the computer when you changed it did you ground yourself to the case ,were you careful with the ram when handling it .
Did you put the ram back in the same slots .are you adding compatable Ram ,did you ,did you, did you !! lots of Questions ,got any answeres.

caperjack 875 I hate 20 Questions Team Colleague

Nothing is ever enough, Anymore ,The bad guys find there way around everything

caperjack 875 I hate 20 Questions Team Colleague

first time I've heard the turm dropped out when refering to IE .so is Dropped out the same as Goes Away !.
Run ad-aware and Spybot ,download and update them and scan your computer .get them in my signature .have spybot fix any thing in red!! use both because one finds stuff the other doesent ! post back .

caperjack 875 I hate 20 Questions Team Colleague

lol, But I still know it is beeping at that kills my soul! lol Thanks for the tip though.

Matt

so does it bootup into windows or just keep beeping.

You bios is AI bios and it has this function ,maybe it needs to be enabled first .

ASUS POST Reporter~
A voice warning design during POST notifies users of any system errors, which means no more complicated LED messages

caperjack 875 I hate 20 Questions Team Colleague

KraKpipe ,first start you own topic ,it gets to mixed up trying to help multiple people in the one thread , do that ,then run cwshredder and post new log in new topic ,get CWSHREDDER from my signature ,un zip it and run it ,hit Fix And not scan .
and run it then post back a new log

caperjack 875 I hate 20 Questions Team Colleague

Help Me!!! Please!!!

right click the file /properties ,what info is there like when it as created and such!

caperjack 875 I hate 20 Questions Team Colleague

I have a HP pavillion 512 @ my work I installed new ram yesterday now it wont do anything. I even took out the new and put the old back in, but it will not start. I can hear the fan running it beeps once then the amber light comes on the monitor like its gone in sleep mode. What did I do wrong and how can it be fixed.

Make sure you didn't loosen and cables like to the harddrive ,motherboard ,video card pullit out and reseet it maybe ,make sure monitor cables connected goot good .

caperjack 875 I hate 20 Questions Team Colleague

hmm...did you go to Add Hardware, in the control panel? That could help you out. If it still is messed up, and your computer isnt working, try doing system restore, while your old memory is installed. Select a date when it was working fine. Then try re-installing the memory, step by step. hope i helped

the computer won't boot !!!

caperjack 875 I hate 20 Questions Team Colleague

disable you AntiViris program [if you use one ]and see what happens when try the things that make it freeze for 1-2 seconds .

caperjack 875 I hate 20 Questions Team Colleague
caperjack 875 I hate 20 Questions Team Colleague

I've been trying to run the hijackthis program but the link does not work and keeps coming up as the page cannot be displayed.

I'm not sure what's going on.

hijackthis click and download .

caperjack 875 I hate 20 Questions Team Colleague

thx :-D , now is there anything i should check off in the settings link?

If you mean settings for AIM ,sorry I don't use it .

caperjack 875 I hate 20 Questions Team Colleague

one word can fix your problem. STOP ZILLA its one of the best pop up blockers ive ever seen. I never get any pop ups. It has a free trial, then u have to purchase it, but its well worth it in the long run. If you have no patience clicking the (X) button 400 times just to clear the pop ups. Also, you can try going to tools and internet options, then privacy and move the cookies blocker to a higher level.

the above computer has a trojan that needs fixing ,Stop Zilla will not fix it ,may have prevented it !.
Google toolbak stops almost all popups and its Free!!

caperjack 875 I hate 20 Questions Team Colleague

Go to control panell ,network connections ,and right click the icon and then properties ,then advanced and check it to enable .


http://www.liutilities.com/products/wintaskspro/processlibrary/firedaemon/

caperjack 875 I hate 20 Questions Team Colleague

I've been trying to run the hijackthis program but the link does not work and keeps coming up as the page cannot be displayed.

I'm not sure what's going on.

Yeah ,the site where it located at is down .You all ready posted a log what did you do with the program .?????

Did you run the peper trojan remover yet !

caperjack 875 I hate 20 Questions Team Colleague

not sure what its for but it came with ICQ,the internet chat program

caperjack 875 I hate 20 Questions Team Colleague

make sure all windows explore and IE explorer windows are close and have hijack fix these .

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about_:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about_:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about_:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about_:blank

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about_:blank

[X] O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/f...etup1.0.0.6.cab
-FunWebProducts
[X] O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1878c4dcf31ce3...ip/RdxIE601.cab
-Netster
[X] O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
-Coulomb Dialer Variant .

Reboot computer and check if dialer is gone and then post a new log

caperjack 875 I hate 20 Questions Team Colleague

clean log

caperjack 875 I hate 20 Questions Team Colleague

Clean log .Except for this one if you know its your IP don't fix it but fix it if its not you IP.

O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.0.1

Also you should run Spybot and or Ad-aware weekly.Download and update before scanning ,Fix everything SpybotSD labels in red!
Also spywareblaster is a neat program to block Adware from being install .Update it and slect to block all.
Links to them in my signature.

caperjack 875 I hate 20 Questions Team Colleague

post you hijackthis log ,i'll have a look

caperjack 875 I hate 20 Questions Team Colleague

Follow the Advice above ,the download site for hijackthis is down ,get it here .and don't fix anything until after you post a log and someone reads it ;


http://www.lurkhere.com/%7Enicefiles/

http://www.lurkhere.com/%7Enicefiles/hijackthis1977.zip