Jump to content

Problems, big problems


Recommended Posts

Belt is definitely a Trojan.

Download this new aSquared anti-trojan Scanner and give it a blast through your HD?

http://www.windowsforum.org/support/forum/...t=0entry54976

What yhrmsbkz.exe and vvfvsn and uwhqvagl.exe are I've no idea yet - but they're definitely dubious !

Perhaps aSquared will recognise them ?

Link to comment
Share on other sites

Tried that bvw

all came back OK

now when i start IE i get a verisign thingy asking if i want free porn and a box comes up asking me if i want to download the dialer etc etc

this is really starting to wind me up

I am nowadays running XP pro, looks like ever since loading, it lets in viruses as have had the MSblaster virus, one tonight and now sygate firewall is having a conflict and i am now having to use the PC-Cillin firewall

please help all or i am going to get rid of XP pro and re-install XP home

heeeeeeeeeeeeeeelpp.s below is one of the popups that came whilst i was typing this

post-30-1070673170.jpg

Link to comment
Share on other sites

Don't know much about this stuff mad-boy , but I had a nasty case of "back-door fraggle" (a trojan , like sub7 that allows other users access to my comp while I'm on line ) It was a bugger to get rid of as it kept reloading,after being deleted... I ended up doing a system restore from start .....

I cant exactly remember what , but when running the trojan deleter for it , system restore had do be turned of , as it was rebooting from there..?

Don't quite understand exactly what happened, but it seemed to have got rid of it ...

Link to comment
Share on other sites

Tankus

thanks for the reply

i have turned system restore off, thats the 1st thing i did as i knew that could be a problem when uninstalling programmes and reinstalling them

i just am getting reather frustrated here

i am off to download another firewall now, looks like it has to be Zonealarm

Link to comment
Share on other sites

This is also over on the pit....: re: belt .exe

Getting rid of it is related to turning the system restore off then runing the trojan scan ......

Hope you get rid of it Mads....

I should hit the sack too....... gotta get up for work in just over 4 hours ...too much blasted coffee again , but I just cannot leave it alone.....

Link to comment
Share on other sites

At the risk of being infinitely boring and it will not be of help now anyway but don't you have a backup??????

PCA members may well remember that I was always going on about backing up (when I was allowed in there) and I still take the same view.

My way of backing up is to have a grandfather/father/son method in which I do a full system backup (using DI7) each week and retain them for three weeks. After that, the oldest backup is replaced by a new one. This way I always have at least two weeks worth of backup to use if the need arises. In addition to this I keep daily files and settings secure via Windows backup.

I'm sorry you're having these problems, of course, but, a lot of heartache could have been prevented by quite simple means.

Link to comment
Share on other sites

Madboy,From Pacman's Startups

Belt

Belt.exe

Abetterinternet adware related

Go to http://tomcoyote.org/hjt/ , and download 'Hijack This!'.

Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.

Press that, save the log somewhere, and please show us its contents.

Most of what it lists will be harmless or even required, so do NOT fix anything yet.

Once we've looked at it we can sort it .

Link to comment
Share on other sites

hi all i am having big problems here

I had a virus and just got rid of it

when trying to close down i get this (picture below)

I had exactly this window a few days ago. I ran Norton Windows Doctor, and it found errors and corrected them. Since then NO PROBLEM

Link to comment
Share on other sites

Go to http://tomcoyote.org/hjt/ , and download 'Hijack This!'.

Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.

Press that, save the log somewhere, and please show us its contents.

Most of what it lists will be harmless or even required, so do NOT fix anything yet.

Once we've looked at it we can sort it .

page canot be displayed mark2

Link to comment
Share on other sites

ok folks, found it

Logfile of HijackThis v1.97.7

Scan saved at 10:05:46, on 06/12/2003

Platform: Windows XP SP1 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Logitech\iTouch\iTouch.exe

C:\WINDOWS\System32\sstray.exe

C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

C:\Program Files\Iomega\AutoDisk\ADUserMon.exe

C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe

C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe

C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe

C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe

C:\Program Files\Logitech\MouseWare\system\em_exec.exe

C:\PROGRA~1\Iomega\System32\AppServices.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exe

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

C:\Program Files\Iomega\AutoDisk\ADService.exe

C:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exe

C:\Documents and Settings\Tony Dos Santos\My Documents\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/blueyonder/index.jsp

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

O1 - Hosts: 211.162.108.123 www.123buyviagra.com

O1 - Hosts: 211.162.108.123 www.1-2-3-buy-viagra.com

O1 - Hosts: 211.162.108.123 www.2-buy-cheap-viagra.com

O1 - Hosts: 211.162.108.123 www.2-buy-viagra-cheap-online.com

O1 - Hosts: 211.162.108.123 www.a1b2c3.com

O1 - Hosts: 211.162.108.123 www.agingwithsuccess.com

O1 - Hosts: 211.162.108.123 www.all-viagra.com

O1 - Hosts: 211.162.108.123 www.amazingpills.net

O1 - Hosts: 211.162.108.123 www.americanpharmacy.com

O1 - Hosts: 211.162.108.123 www.a-zonlinedrugs.com

O1 - Hosts: 211.162.108.123 www.bluecommunity.net

O1 - Hosts: 211.162.108.123 www.buycheappills.net

O1 - Hosts: 211.162.108.123 www.buy-cheap-rx.com

O1 - Hosts: 211.162.108.123 www.buy-generic-viagra.com

O1 - Hosts: 211.162.108.123 www.buy-generic-viagra-sildenafil-citrate.com

O1 - Hosts: 211.162.108.123 www.buy-low-cost-viagra.com

O1 - Hosts: 211.162.108.123 www.buy-order-viagra.com

O1 - Hosts: 211.162.108.123 www.buy--viagra.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-4less.com

O1 - Hosts: 211.162.108.123 www.buyviagra-direct.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-free-prescriptions.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-here.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-internet.net

O1 - Hosts: 211.162.108.123 www.buy-viagra-now.net

O1 - Hosts: 211.162.108.123 www.buy-viagra-now.tripod.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-online-cheap.net

O1 - Hosts: 211.162.108.123 www.buyviagraonlineforless.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-online-sales.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-usa-prescription.com

O1 - Hosts: 211.162.108.123 www.buy-viagra-viagara-online.com

O1 - Hosts: 211.162.108.123 www.buyviagra-viagra.com

O1 - Hosts: 211.162.108.123 www.canadaexpressrx.com

O1 - Hosts: 211.162.108.123 www.cheap-viagra-4u.com

O1 - Hosts: 211.162.108.123 www.cheap-viagra-pharmacy.com

O1 - Hosts: 211.162.108.123 www.click-viagra.com

O1 - Hosts: 211.162.108.123 www.cyberpillsnetwork.com

O1 - Hosts: 211.162.108.123 www.discount-viagra-cheap.com

O1 - Hosts: 211.162.108.123 www.doctorviagra.net

O1 - Hosts: 211.162.108.123 www.drugstore.com

O1 - Hosts: 211.162.108.123 www.ed-pharmacy.com

O1 - Hosts: 211.162.108.123 www.ed-pills.com

O1 - Hosts: 211.162.108.123 www.e-order-viagra.com

O1 - Hosts: 211.162.108.123 www.epillz.com

O1 - Hosts: 211.162.108.123 www.find-viagra.com

O1 - Hosts: 211.162.108.123 www.free-viagra-sample.com

O1 - Hosts: 211.162.108.123 www.genericviagra.info

O1 - Hosts: 211.162.108.123 www.generic-viagra.ws

O1 - Hosts: 211.162.108.123 www.genuine-pfizer-viagra.com

O1 - Hosts: 211.162.108.123 www.global-viagra.com

O1 - Hosts: 211.162.108.123 www.horizondrugs.com

O1 - Hosts: 211.162.108.123 www.howtogetviagra.com

O1 - Hosts: 211.162.108.123 www.lmtc.net

O1 - Hosts: 211.162.108.123 www.lowpricepills.com

O1 - Hosts: 211.162.108.123 www.mailorderviagra.net

O1 - Hosts: 211.162.108.123 www.menscripts.com

O1 - Hosts: 211.162.108.123 www.mixpills.com

O1 - Hosts: 211.162.108.123 www.moodmaniac.com

O1 - Hosts: 211.162.108.123 www.myclinics.com

O1 - Hosts: 211.162.108.123 www.myviagrasupplier.com

O1 - Hosts: 211.162.108.123 www.overnightprescription.com

O1 - Hosts: 211.162.108.123 www.pharmaviagra.com

O1 - Hosts: 211.162.108.123 www.pillcraze.com

O1 - Hosts: 211.162.108.123 www.pilldealfinder.com

O1 - Hosts: 211.162.108.123 www.pillrange.com

O1 - Hosts: 211.162.108.123 www.pilltip.com

O1 - Hosts: 211.162.108.123 www.pillwatch.com

O1 - Hosts: 211.162.108.123 www.planetarymed.com

O1 - Hosts: 211.162.108.123 www.platinum-rx.com

O1 - Hosts: 211.162.108.123 www.romance-tips.com

O1 - Hosts: 211.162.108.123 www.shoprxonline.com

O1 - Hosts: 211.162.108.123 www.starpills.com

O1 - Hosts: 211.162.108.123 www.top-10-viagra-pharmacies-online.com

O1 - Hosts: 211.162.108.123 www.top-pharmacy-guide.com

O1 - Hosts: 211.162.108.123 www.usapills.net

O1 - Hosts: 211.162.108.123 www.viagrabuyonline.net

O1 - Hosts: 211.162.108.123 www.viagra-online--now.com

O1 - Hosts: 211.162.108.123 www.viagraonlinepharmacy.com

O1 - Hosts: 211.162.108.123 www.viagraprice.net

O1 - Hosts: 211.162.108.123 www.viagra-price-guide.com

O1 - Hosts: 211.162.108.123 www.viagraprices.net

O1 - Hosts: 211.162.108.123 www.viagra-qs.com

O1 - Hosts: 211.162.108.123 www.viagrastories.com

O1 - Hosts: 211.162.108.123 www.v-viagra.com

O1 - Hosts: 211.162.108.123 www.1000med.com

O1 - Hosts: 211.162.108.123 www.123pill.com

O1 - Hosts: 211.162.108.123 www.123prescriptionpills.com

O1 - Hosts: 211.162.108.123 www.1soma.com

O1 - Hosts: 211.162.108.123 www.24-7online-pharmacy.com

O1 - Hosts: 211.162.108.123 www.247-pharmacy.com

O1 - Hosts: 211.162.108.123 www.24hourpill.com

O1 - Hosts: 211.162.108.123 www.abcweightloss.net

O1 - Hosts: 211.162.108.123 www.alfadrugs.com

O1 - Hosts: 211.162.108.123 www.alfaus.com

O1 - Hosts: 211.162.108.123 www.ashevillelist.com

O1 - Hosts: 211.162.108.123 www.bestprescription.com

O1 - Hosts: 211.162.108.123 www.buy.affordable-prescriptions.com

O1 - Hosts: 211.162.108.123 www.buyambienonline.com

O1 - Hosts: 211.162.108.123 www.buy-carisoprodol.com

O1 - Hosts: 211.162.108.123 www.buy-drugs-without-prescription.com

O1 - Hosts: 211.162.108.123 www.buy-flexeril-00.biz

O1 - Hosts: 211.162.108.123 www.buy-flexeril-i-a.biz

O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {8C0DE7AF-38CF-ED1F-7EDD-81BB42DC45EE} - C:\WINDOWS\system32\culakkma.dll

O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe

O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe

O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe

O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe

O4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe

O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART

O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"

O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"

O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe

O4 - HKLM\..\Run: [belt] C:\WINDOWS\Belt.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE

O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM

O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM

O9 - Extra button: ieSpell (HKLM)

O9 - Extra 'Tools' menuitem: ieSpell (HKLM)

O9 - Extra 'Tools' menuitem: ieSpell Options (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Messenger (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cab

O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab

O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d2c89f6...all/xscan53.cab

O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7937.7888194444

O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

Link to comment
Share on other sites

Guest nellie2

Mark2 will have a look at that for you when he pops back in.... but it would probably be easier for him if you just pasted it into the text box rather than attaching a file.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy