Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Please take a look.  (Read 39648 times)

0 Members and 2 Guests are viewing this topic.

Ivy

  • Guest
Re: Please take a look.
« Reply #30 on: September 25, 2007, 08:19:18 PM »
Here is the fresh HJT  log.

Logfile of HijackThis v1.99.1
Scan saved at 7:45:49 AM, on 9/26/2007
Platform: Windows XP SP2, v.2096 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2096)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\system32\ctfmon.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sify Broadband\BBClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sify Broadband\BBImpSec.exe
C:\Documents and Settings\All Users\Documents\New Folder\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://in.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://in.search.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [SifyBB] C:\Program Files\Sify Broadband\BBImpSec.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{6543E2C5-829D-414B-B44F-96201B0C51B6}: NameServer = 202.144.13.50,202.144.66.6
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

Thankyou Fed for so much help, and no i dont have windows update in start menu , but i have windows updates enabled , its in the control panel ,in security settings.
Thankyou again.

Fed

  • Moderator


  • Sage
  • Thanked: 35
    • Experience: Experienced
    • OS: Windows XP
    Re: Please take a look.
    « Reply #31 on: September 26, 2007, 02:05:27 PM »
    Your Internet Explorer has an 'odd' version number have you ever had IE7 on that machine? It may be mis-reporting the number.

    I see you haven't used the Spybot S&D realtime protection, any reason?

    Ivy

    • Guest
    Re: Please take a look.
    « Reply #32 on: September 26, 2007, 07:15:37 PM »
     I dont know where to get Spybot S&D realtime protection from. I dont know about the number of IE ,could you please help me with this Fed, thankyou so much for so so much help already.
    Thankyou.

    The Saviour

    • Guest
    Re: Please take a look.
    « Reply #33 on: September 26, 2007, 07:35:35 PM »
    You can get SpyBot Search and Destroy from here, Ivy:

    Spybot Search and Destroy

    To find out what version of IE you have...from IE's toolbar menu click Help/About Internet Explorer and copy the version number down.

    -Steve

    Fed

    • Moderator


    • Sage
    • Thanked: 35
      • Experience: Experienced
      • OS: Windows XP
      Re: Please take a look.
      « Reply #34 on: September 26, 2007, 07:40:57 PM »
      If you already have Spybot S&D then just open it up then change the 'Mode' at he top of the screen to 'Advanced', if you don't have Spybot S&D then get it from here.
      Spybot S&D
      Then we can go on from there.

      I don't know about your IE6 Version number either, perhaps someone with IE7 can help with the Version Number.
      I don't think it's anything to worry about at this stage.

      You can check it in IE>Help>About Internet Explorer.

      Edit: When I hit post and saw that you had posted Saviour I thought, "I'm not wasting my additional typing so I posted anyway. LOL!"

      Ivy

      • Guest
      Re: Please take a look.
      « Reply #35 on: September 26, 2007, 07:46:21 PM »
      Thankyou ,
      Here is the IE version number:
      Version-6.0.2900.2096
      Cipher strength:128bit
      Update version:;SP2;
      Now im gonna try the Spybot real time protection.
      Thankyou again.

      Ivy

      • Guest
      Re: Please take a look.
      « Reply #36 on: September 26, 2007, 07:54:51 PM »
      It has  the options to downdolad it from a number of locations , do i select just one location at random?

      These are the options given.
      Download Spybot-S&D [link] 
      Here comes a list of available download locations for Spybot-S&D. Select one in this list to download Spybot-S&D from that page.

      Safer-Networking thanks all of our mirrors for their contribution!
       
       BN FileForum 
       Freeware-Archiv 
       PlanetMirror
       Download from our server
      Safer-Networking Ltd. 
       Download from our server
      Safer-Networking Ltd. 
       
       
      Further Mirrors   
       InternetSecurity.cc 
       Spybot-Download.net 
       XTeq 
       SecurityWonks 
       Download.com 
       ZoNE-X
       

      patio

      • Moderator


      • Genius
      • Maud' Dib
      • Thanked: 1769
        • Yes
      • Experience: Beginner
      • OS: Windows 7
      Re: Please take a look.
      « Reply #37 on: September 26, 2007, 08:05:39 PM »
      Any choice should be fine.
      This is common for popular DLoads as the huge amount of traffic can bog things down.
      A mirror is simply another server who has volunteered to host the file for DLoad.
      " Anyone who goes to a psychiatrist should have his head examined. "

      Ivy

      • Guest
      Re: Please take a look.
      « Reply #38 on: September 26, 2007, 08:31:19 PM »
      Thankyou ,
      I downloaded the file but at 21% it says download complete, and when i try to run it, my comp displays the message that the setup  files  are corrupted please obtain new copy of the program.


      (Same thing happening on youtube , downloads only half of the video)

      Fed

      • Moderator


      • Sage
      • Thanked: 35
        • Experience: Experienced
        • OS: Windows XP
        Re: Please take a look.
        « Reply #39 on: September 26, 2007, 08:37:56 PM »

        Ivy

        • Guest
        Re: Please take a look.
        « Reply #40 on: September 26, 2007, 08:43:40 PM »
        Again the same message.
        setup  files  are corrupted please obtain new copy of the program.
        Im gonna cry. why is my computer so horribly against anything i wanna do!!!!!!!!

        Fed

        • Moderator


        • Sage
        • Thanked: 35
          • Experience: Experienced
          • OS: Windows XP
          Re: Please take a look.
          « Reply #41 on: September 26, 2007, 08:50:23 PM »
          Clear your Temporary Internet Files, they can do some 'odd' things to downloads, don't ask me why. :)
          IE>Tools>Internet Options>Delete Cookies, Delete Files, Clear History.

          Ivy

          • Guest
          Re: Please take a look.
          « Reply #42 on: September 26, 2007, 08:56:49 PM »
          I have set the settings of IE on default, and till now it is downloading , hope it survives till 100%, I have cleared all cookies, files, history, actually i ran ccleaner ;D.
          Im waiting,it seems to be working right now.

          patio

          • Moderator


          • Genius
          • Maud' Dib
          • Thanked: 1769
            • Yes
          • Experience: Beginner
          • OS: Windows 7
          Re: Please take a look.
          « Reply #43 on: September 26, 2007, 09:27:54 PM »
          What type of connection are we talking about ? ?
          " Anyone who goes to a psychiatrist should have his head examined. "

          Ivy

          • Guest
          Re: Please take a look.
          « Reply #44 on: September 26, 2007, 09:35:38 PM »
          OH NO!
          I tried again ,at 82% it again stopped, and then again i tried downloading it and at 46% it again stopped.
          pleeeeeeeeeeeease help me.
          Could it be that comodo is doing somthing?
          What type of connection are we talking about ? ?
          Im sorry , im unable to understand this.