madboy33 Posted December 5, 2003 Report Share Posted December 5, 2003 hi all i am having big problems hereI had a virus and just got rid of itwhen trying to close down i get this (picture below) Link to comment Share on other sites More sharing options...
madboy33 Posted December 5, 2003 Author Report Share Posted December 5, 2003 second problem, in start up i have found a couple of progs that should not be there and outlook express trys to start at startup, however, i have it password protected so it cantchrist knows whats gone on herepicture for start up is belowheeeeelp Link to comment Share on other sites More sharing options...
Guest Grim Reaper Posted December 5, 2003 Report Share Posted December 5, 2003 http://www.windowsforum.org/support/forum/...artup+inspector - have a look at this thread, download the prog and it will tell you which items you can delete from your startup, there looks to be a couple of dodgy ones there...... Link to comment Share on other sites More sharing options...
bvw Posted December 5, 2003 Report Share Posted December 5, 2003 Belt.exe is a trojan I think madboy. Link to comment Share on other sites More sharing options...
Guest ellas Posted December 5, 2003 Report Share Posted December 5, 2003 it is a trojan madboy,try this http://www.simplysup.com/tremover/details.html Link to comment Share on other sites More sharing options...
Boris Posted December 5, 2003 Report Share Posted December 5, 2003 Belt is definitely a Trojan.Download this new aSquared anti-trojan Scanner and give it a blast through your HD?http://www.windowsforum.org/support/forum/...t=0entry54976What yhrmsbkz.exe and vvfvsn and uwhqvagl.exe are I've no idea yet - but they're definitely dubious !Perhaps aSquared will recognise them ? Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 thanks guysi have just re-installed pc-cillin 2002 as 2003 had loads of hiccupsdownloading the trojan detecter thingy and will come back to you Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 No malware files found folkswhat next? Link to comment Share on other sites More sharing options...
bvw Posted December 6, 2003 Report Share Posted December 6, 2003 http://security2.norton.com/sscv6/default....id=ie&venid=symTry both tests madboy.Must go to bed now :) Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 Tried that bvw all came back OKnow when i start IE i get a verisign thingy asking if i want free porn and a box comes up asking me if i want to download the dialer etc etcthis is really starting to wind me upI am nowadays running XP pro, looks like ever since loading, it lets in viruses as have had the MSblaster virus, one tonight and now sygate firewall is having a conflict and i am now having to use the PC-Cillin firewallplease help all or i am going to get rid of XP pro and re-install XP homeheeeeeeeeeeeeeeelpp.s below is one of the popups that came whilst i was typing this Link to comment Share on other sites More sharing options...
Tankus Posted December 6, 2003 Report Share Posted December 6, 2003 Don't know much about this stuff mad-boy , but I had a nasty case of "back-door fraggle" (a trojan , like sub7 that allows other users access to my comp while I'm on line ) It was a bugger to get rid of as it kept reloading,after being deleted... I ended up doing a system restore from start .....I cant exactly remember what , but when running the trojan deleter for it , system restore had do be turned of , as it was rebooting from there..?Don't quite understand exactly what happened, but it seemed to have got rid of it ... Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 Tankusthanks for the replyi have turned system restore off, thats the 1st thing i did as i knew that could be a problem when uninstalling programmes and reinstalling themi just am getting reather frustrated herei am off to download another firewall now, looks like it has to be Zonealarm Link to comment Share on other sites More sharing options...
Tankus Posted December 6, 2003 Report Share Posted December 6, 2003 Try this http://www.newdotnet.com/#removeAlso somebody got it out on this forumhttp://www.computing.net/security/wwwboard/forum/7431.htmland here http://forums.techguy.org/t180655/s372ff40...90e1207a16.htmlboth cleared it Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 thanks matewill work my way through that lotnight night Link to comment Share on other sites More sharing options...
Tankus Posted December 6, 2003 Report Share Posted December 6, 2003 This is also over on the pit....: re: belt .exeGetting rid of it is related to turning the system restore off then runing the trojan scan ......Hope you get rid of it Mads.... I should hit the sack too....... gotta get up for work in just over 4 hours ...too much blasted coffee again , but I just cannot leave it alone..... Link to comment Share on other sites More sharing options...
-pops- Posted December 6, 2003 Report Share Posted December 6, 2003 At the risk of being infinitely boring and it will not be of help now anyway but don't you have a backup??????PCA members may well remember that I was always going on about backing up (when I was allowed in there) and I still take the same view.My way of backing up is to have a grandfather/father/son method in which I do a full system backup (using DI7) each week and retain them for three weeks. After that, the oldest backup is replaced by a new one. This way I always have at least two weeks worth of backup to use if the need arises. In addition to this I keep daily files and settings secure via Windows backup.I'm sorry you're having these problems, of course, but, a lot of heartache could have been prevented by quite simple means. Link to comment Share on other sites More sharing options...
mark2 Posted December 6, 2003 Report Share Posted December 6, 2003 Madboy,From Pacman's Startups BeltBelt.exeAbetterinternet adware related Go to http://tomcoyote.org/hjt/ , and download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".When the scan is finished, the "Scan" button will change into a "Save Log" button.Press that, save the log somewhere, and please show us its contents.Most of what it lists will be harmless or even required, so do NOT fix anything yet.Once we've looked at it we can sort it . Link to comment Share on other sites More sharing options...
andsome Posted December 6, 2003 Report Share Posted December 6, 2003 hi all i am having big problems hereI had a virus and just got rid of itwhen trying to close down i get this (picture below)I had exactly this window a few days ago. I ran Norton Windows Doctor, and it found errors and corrected them. Since then NO PROBLEM Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 Go to http://tomcoyote.org/hjt/ , and download 'Hijack This!'. Unzip, doubleclick HijackThis.exe, and hit "Scan".When the scan is finished, the "Scan" button will change into a "Save Log" button.Press that, save the log somewhere, and please show us its contents.Most of what it lists will be harmless or even required, so do NOT fix anything yet.Once we've looked at it we can sort it .page canot be displayed mark2 Link to comment Share on other sites More sharing options...
bvw Posted December 6, 2003 Report Share Posted December 6, 2003 http://mjc1.com/mirror/hjt/ Link to comment Share on other sites More sharing options...
Guest nellie2 Posted December 6, 2003 Report Share Posted December 6, 2003 try here madboyhttp://mjc1.com/mirror/hjt/edit: oops... bvw got in there before me!!! :) Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 nopeboth say when clicking on "Hijack this"THIS PAGE CAN NOT BE DISPLAYED Link to comment Share on other sites More sharing options...
Guest nellie2 Posted December 6, 2003 Report Share Posted December 6, 2003 this link works but make sure you read the instructions on the other pagehttp://www.spywareinfo.com/~merijn/files/hijackthis.zip Link to comment Share on other sites More sharing options...
madboy33 Posted December 6, 2003 Author Report Share Posted December 6, 2003 ok folks, found itLogfile of HijackThis v1.97.7Scan saved at 10:05:46, on 06/12/2003Platform: Windows XP SP1 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Logitech\iTouch\iTouch.exeC:\WINDOWS\System32\sstray.exeC:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exeC:\Program Files\Iomega\AutoDisk\ADUserMon.exeC:\Program Files\Iomega\DriveIcons\ImgIcon.exeC:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exeC:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exeC:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exeC:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exeC:\Program Files\Logitech\MouseWare\system\em_exec.exeC:\PROGRA~1\Iomega\System32\AppServices.exeC:\WINDOWS\System32\nvsvc32.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Trend Micro\PC-cillin 2002\Tmntsrv.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\Program Files\Iomega\AutoDisk\ADService.exeC:\Program Files\Trend Micro\PC-cillin 2002\PCCPFW.exeC:\Documents and Settings\Tony Dos Santos\My Documents\hijackthis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.blueyonder.co.uk/blueyonder/index.jspR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O1 - Hosts: 211.162.108.123 www.123buyviagra.comO1 - Hosts: 211.162.108.123 www.1-2-3-buy-viagra.comO1 - Hosts: 211.162.108.123 www.2-buy-cheap-viagra.comO1 - Hosts: 211.162.108.123 www.2-buy-viagra-cheap-online.comO1 - Hosts: 211.162.108.123 www.a1b2c3.comO1 - Hosts: 211.162.108.123 www.agingwithsuccess.comO1 - Hosts: 211.162.108.123 www.all-viagra.comO1 - Hosts: 211.162.108.123 www.amazingpills.netO1 - Hosts: 211.162.108.123 www.americanpharmacy.comO1 - Hosts: 211.162.108.123 www.a-zonlinedrugs.comO1 - Hosts: 211.162.108.123 www.bluecommunity.netO1 - Hosts: 211.162.108.123 www.buycheappills.netO1 - Hosts: 211.162.108.123 www.buy-cheap-rx.comO1 - Hosts: 211.162.108.123 www.buy-generic-viagra.comO1 - Hosts: 211.162.108.123 www.buy-generic-viagra-sildenafil-citrate.comO1 - Hosts: 211.162.108.123 www.buy-low-cost-viagra.comO1 - Hosts: 211.162.108.123 www.buy-order-viagra.comO1 - Hosts: 211.162.108.123 www.buy--viagra.comO1 - Hosts: 211.162.108.123 www.buy-viagra-4less.comO1 - Hosts: 211.162.108.123 www.buyviagra-direct.comO1 - Hosts: 211.162.108.123 www.buy-viagra-free-prescriptions.comO1 - Hosts: 211.162.108.123 www.buy-viagra-here.comO1 - Hosts: 211.162.108.123 www.buy-viagra-internet.netO1 - Hosts: 211.162.108.123 www.buy-viagra-now.netO1 - Hosts: 211.162.108.123 www.buy-viagra-now.tripod.comO1 - Hosts: 211.162.108.123 www.buy-viagra-online-cheap.netO1 - Hosts: 211.162.108.123 www.buyviagraonlineforless.comO1 - Hosts: 211.162.108.123 www.buy-viagra-online-sales.comO1 - Hosts: 211.162.108.123 www.buy-viagra-usa-prescription.comO1 - Hosts: 211.162.108.123 www.buy-viagra-viagara-online.comO1 - Hosts: 211.162.108.123 www.buyviagra-viagra.comO1 - Hosts: 211.162.108.123 www.canadaexpressrx.comO1 - Hosts: 211.162.108.123 www.cheap-viagra-4u.comO1 - Hosts: 211.162.108.123 www.cheap-viagra-pharmacy.comO1 - Hosts: 211.162.108.123 www.click-viagra.comO1 - Hosts: 211.162.108.123 www.cyberpillsnetwork.comO1 - Hosts: 211.162.108.123 www.discount-viagra-cheap.comO1 - Hosts: 211.162.108.123 www.doctorviagra.netO1 - Hosts: 211.162.108.123 www.drugstore.comO1 - Hosts: 211.162.108.123 www.ed-pharmacy.comO1 - Hosts: 211.162.108.123 www.ed-pills.comO1 - Hosts: 211.162.108.123 www.e-order-viagra.comO1 - Hosts: 211.162.108.123 www.epillz.comO1 - Hosts: 211.162.108.123 www.find-viagra.comO1 - Hosts: 211.162.108.123 www.free-viagra-sample.comO1 - Hosts: 211.162.108.123 www.genericviagra.infoO1 - Hosts: 211.162.108.123 www.generic-viagra.wsO1 - Hosts: 211.162.108.123 www.genuine-pfizer-viagra.comO1 - Hosts: 211.162.108.123 www.global-viagra.comO1 - Hosts: 211.162.108.123 www.horizondrugs.comO1 - Hosts: 211.162.108.123 www.howtogetviagra.comO1 - Hosts: 211.162.108.123 www.lmtc.netO1 - Hosts: 211.162.108.123 www.lowpricepills.comO1 - Hosts: 211.162.108.123 www.mailorderviagra.netO1 - Hosts: 211.162.108.123 www.menscripts.comO1 - Hosts: 211.162.108.123 www.mixpills.comO1 - Hosts: 211.162.108.123 www.moodmaniac.comO1 - Hosts: 211.162.108.123 www.myclinics.comO1 - Hosts: 211.162.108.123 www.myviagrasupplier.comO1 - Hosts: 211.162.108.123 www.overnightprescription.comO1 - Hosts: 211.162.108.123 www.pharmaviagra.comO1 - Hosts: 211.162.108.123 www.pillcraze.comO1 - Hosts: 211.162.108.123 www.pilldealfinder.comO1 - Hosts: 211.162.108.123 www.pillrange.comO1 - Hosts: 211.162.108.123 www.pilltip.comO1 - Hosts: 211.162.108.123 www.pillwatch.comO1 - Hosts: 211.162.108.123 www.planetarymed.comO1 - Hosts: 211.162.108.123 www.platinum-rx.comO1 - Hosts: 211.162.108.123 www.romance-tips.comO1 - Hosts: 211.162.108.123 www.shoprxonline.comO1 - Hosts: 211.162.108.123 www.starpills.comO1 - Hosts: 211.162.108.123 www.top-10-viagra-pharmacies-online.comO1 - Hosts: 211.162.108.123 www.top-pharmacy-guide.comO1 - Hosts: 211.162.108.123 www.usapills.netO1 - Hosts: 211.162.108.123 www.viagrabuyonline.netO1 - Hosts: 211.162.108.123 www.viagra-online--now.comO1 - Hosts: 211.162.108.123 www.viagraonlinepharmacy.comO1 - Hosts: 211.162.108.123 www.viagraprice.netO1 - Hosts: 211.162.108.123 www.viagra-price-guide.comO1 - Hosts: 211.162.108.123 www.viagraprices.netO1 - Hosts: 211.162.108.123 www.viagra-qs.comO1 - Hosts: 211.162.108.123 www.viagrastories.comO1 - Hosts: 211.162.108.123 www.v-viagra.comO1 - Hosts: 211.162.108.123 www.1000med.comO1 - Hosts: 211.162.108.123 www.123pill.comO1 - Hosts: 211.162.108.123 www.123prescriptionpills.comO1 - Hosts: 211.162.108.123 www.1soma.comO1 - Hosts: 211.162.108.123 www.24-7online-pharmacy.comO1 - Hosts: 211.162.108.123 www.247-pharmacy.comO1 - Hosts: 211.162.108.123 www.24hourpill.comO1 - Hosts: 211.162.108.123 www.abcweightloss.netO1 - Hosts: 211.162.108.123 www.alfadrugs.comO1 - Hosts: 211.162.108.123 www.alfaus.comO1 - Hosts: 211.162.108.123 www.ashevillelist.comO1 - Hosts: 211.162.108.123 www.bestprescription.comO1 - Hosts: 211.162.108.123 www.buy.affordable-prescriptions.comO1 - Hosts: 211.162.108.123 www.buyambienonline.comO1 - Hosts: 211.162.108.123 www.buy-carisoprodol.comO1 - Hosts: 211.162.108.123 www.buy-drugs-without-prescription.comO1 - Hosts: 211.162.108.123 www.buy-flexeril-00.bizO1 - Hosts: 211.162.108.123 www.buy-flexeril-i-a.bizO2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dllO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {8C0DE7AF-38CF-ED1F-7EDD-81BB42DC45EE} - C:\WINDOWS\system32\culakkma.dllO2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocxO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.ExeO4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exeO4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /rO4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exeO4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exeO4 - HKLM\..\Run: [iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exeO4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTARTO4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\pccguide.exe"O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\PCCClient.exe"O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2002\Pop3trap.exe"O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exeO4 - HKLM\..\Run: [belt] C:\WINDOWS\Belt.exeO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXEO4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXEO8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTMO8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTMO9 - Extra button: ieSpell (HKLM)O9 - Extra 'Tools' menuitem: ieSpell (HKLM)O9 - Extra 'Tools' menuitem: ieSpell Options (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Messenger (HKLM)O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CABO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...director/sw.cabO16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CABO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cabO16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/d2c89f6...all/xscan53.cabO16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7937.7888194444O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab Link to comment Share on other sites More sharing options...
Guest nellie2 Posted December 6, 2003 Report Share Posted December 6, 2003 Mark2 will have a look at that for you when he pops back in.... but it would probably be easier for him if you just pasted it into the text box rather than attaching a file. Link to comment Share on other sites More sharing options...
Recommended Posts