little slow, still fast

Status
Not open for further replies.

jp198780

New Member
here's a HJT log 4 my GX240, i scanned with Panda also and it found some junk, can someone help me get rid of it? thanks :) :

Logfile of HijackThis v1.99.1
Scan saved at 4:06:49 AM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\1152392111\ee\AOLSoftware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\MCROSO~1\netdde.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Documents and Settings\Ryan\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - URLSearchHook: (no name) - {EBC707DB-B712-EA9A-3C83-E67B43872ACC} - C:\WINDOWS\system32\lmced.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {EBC707DB-B712-EA9A-3C83-E67B43872ACC} - C:\WINDOWS\system32\lmced.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152392111\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Dcar] "C:\WINDOWS\MCROSO~1\netdde.exe" -vt mt
O4 - HKCU\..\Run: [Avnm] C:\Documents and Settings\Ryan\My Documents\?ymbols\d?dplay.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22-1.dll' missing
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123260774044
O17 - HKLM\System\CCS\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O17 - HKLM\System\CS1\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O17 - HKLM\System\CS2\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22-1.dll' missing

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca...C_2.1.2.76.cab

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

remove all those and you should be good
 
way2evil said:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22-1.dll' missing

O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yaho...st20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/ca...C_2.1.2.76.cab

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

remove all those and you should be good
Ummm, I don't think so, you've missed quite a few entries, and he could lose his internet access. I'll get to this later.
 
dont want that ;), is this computer very infected? it's still real fast.

alright, hope you dont forget about this thread lol, dont want 2 stay infected.
 
ok, now i have a virus, AVG just told me, here's another HJT:

Logfile of HijackThis v1.99.1
Scan saved at 3:11:38 AM, on 7/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\AOL\1152392111\ee\AOLSoftware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\MCROSO~1\netdde.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Documents and Settings\Ryan\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R3 - URLSearchHook: (no name) - {EBC707DB-B712-EA9A-3C83-E67B43872ACC} - C:\WINDOWS\system32\lmced.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {EBC707DB-B712-EA9A-3C83-E67B43872ACC} - C:\WINDOWS\system32\lmced.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152392111\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Dcar] "C:\WINDOWS\MCROSO~1\netdde.exe" -vt mt
O4 - HKCU\..\Run: [Avnm] C:\Documents and Settings\Ryan\My Documents\?ymbols\d?dplay.exe
O4 - HKCU\..\Run: [PCShield] regsvr32 /s "C:\WINDOWS\system32\sfg.dll"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet7_22-1.dll' missing
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.2.76.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123260774044
O17 - HKLM\System\CCS\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O17 - HKLM\System\CS1\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O17 - HKLM\System\CS2\Services\Tcpip\..\{12348426-535B-44BA-A0D4-3B9BEC9CD23F}: NameServer = 192.168.3.30,192.168.1.46
O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
 
Yes, you still have infections.Let's start here and do some cleaning.

Download, install, update and run 'CWShredder' http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe

Next, download,install,and update 'Ewido' http://www.ewido.net/en/download/ then set it up this way http://rstones12.geekstogo.com/ewidosetup.htm You will need this later in safe mode

Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ You will need it later in safe mode

Next follow these directions to reboot into Safemode http://service1.symantec.com/SUPPOR...001052409420406?OpenDocument&src=sec_doc_nam/

Run Ewido and let it delete all that it finds.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Reboot and then download,install,update and run 'Superantispyware' free edition http://www.superantispyware.com/download.html

Then proceed here and run this free online scan from 'Kaspersky' http://kaspersky.com/kos/english/kavwebscan.html
Click Accept
When the updates are finished downloading, click Next, Scan Settings
Under Scan using the following antivirus database:, select extended
Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK
Click My Computer and wait for the scan to finish
Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here along with a new 'HijackThis' log.

Hopefully 'Buzz' will finish this as a specialty cleaning tool will probably be needed also.Good luck.
 
not 2 be mean or anything, but i dont think you know what your talking about :), i got Ewido already, and i would use Panda ActiveSCan over Kaspersky.
 
Did you run 'Ewido' in safemode?.As for 'Panda', not only does 'Kaspersky' have better detection rates, 'Panda' sends 'spam emails' out to anyone who has used their online scan.

not 2 be mean or anything, but i dont think you know what your talking about , i got Ewido already, and i would use Panda ActiveSCan over Kaspersky.

I quess i will take into account your age for that immature and inaccurate response.Let's see here.I use KAV 6.0 with Kerio 4.2.2 Firewall, WinPatrol and System Safety Monitor HIPS programs and am not infected and haven't been in a long time.

You on the other hand are infected, have toolbars installed which are a magnet for malware and use 'AVG' which is the worst antivirus of the freebies.So if you don't want help, then fine.If you do, then cut the lip and start the cleaning process.
 
well, this wasnt my computer, if it was, it would never been infected. i dont want your help, i'll what 4 Buzz.
 
well, this wasnt my computer, if it was, it would never been infected.

That's Funny!.This is what you said.


here's a HJT log 4 my GX240, i scanned with Panda also and it found some junk, can someone help me get rid of it? thanks

Dell Optiplex GX240 1.5GHZ, P4, Windows XP, 20GB HD 5400RPM, 256MB, 32MB Nvidia Riva.
Dell Optiplex GX110 1GHz P3, Windows XP Pro SP2, 384 MB RAM, 20GB HD 5400RPM
Dell Latitude C600 851MHz P3, Windows XP Pro SP2, 256MB RAM, 10GB HD 4200RPM
Dell Inspirion 5000 700MHz P3, Windows 2000 SP4, 384MB RAM, 20GB HD 4200RPM
Gateway Solo 3300 500MHz P3, Windows ME, 128MB RAM, 6.4GB HD
Compaq Presario 5155 350MHz K6-2, Windows 2000 SP4, 384MB RAM, 5.12GB HD 5400RPM.

Hmmmmm!.Someone's not telling the truth!

i dont want your help, i'll what 4 Buzz.

Suit yourself!
 
here's a HJT log 4 my GX240, i scanned with Panda also and it found some junk, can someone help me get rid of it? thanks

Dell Optiplex GX240 1.5GHZ, P4, Windows XP, 20GB HD 5400RPM, 256MB, 32MB Nvidia Riva.
Dell Optiplex GX110 1GHz P3, Windows XP Pro SP2, 384 MB RAM, 20GB HD 5400RPM
Dell Latitude C600 851MHz P3, Windows XP Pro SP2, 256MB RAM, 10GB HD 4200RPM
Dell Inspirion 5000 700MHz P3, Windows 2000 SP4, 384MB RAM, 20GB HD 4200RPM
Gateway Solo 3300 500MHz P3, Windows ME, 128MB RAM, 6.4GB HD
Compaq Presario 5155 350MHz K6-2, Windows 2000 SP4, 384MB RAM, 5.12GB HD

well, this wasnt my computer, if it was, it would never been infected.

Do i need to explain any further?.
 
yes, please do, im seripusly about 2 report you, your really getting on my nerves, i need 2 get rid of these nasties, and your trying 2 start an arguement.
 
How 'Buzz' manages to deal with some of the attitudes here is beyond me.I will offer no more help to you and can't believe i have to explain this but here it goes.

You said in your very first post of this thread-

here's a HJT log 4 my GX240, i scanned with Panda also and it found some junk, can someone help me get rid of it? thanks

You said 'My GX240'.

You have these listed in every one of your posts which includes 'GX240'.

Dell Optiplex GX240 1.5GHZ, P4, Windows XP, 20GB HD 5400RPM, 256MB, 32MB Nvidia Riva.
Dell Optiplex GX110 1GHz P3, Windows XP Pro SP2, 384 MB RAM, 20GB HD 5400RPM
Dell Latitude C600 851MHz P3, Windows XP Pro SP2, 256MB RAM, 10GB HD 4200RPM
Dell Inspirion 5000 700MHz P3, Windows 2000 SP4, 384MB RAM, 20GB HD 4200RPM
Gateway Solo 3300 500MHz P3, Windows ME, 128MB RAM, 6.4GB HD
Compaq Presario 5155 350MHz K6-2, Windows 2000 SP4, 384MB RAM, 5.12GB HD

So now your saying that it isn't your computer after referring to it as yours from the beginning.

well, this wasnt my computer, if it was, it would never been infected.

So what do we believe?.Huh! End of discussion and hopefully with that attitude of yours, no-one else offers you the help you need.
 
im reporting you, im tired of this, this was my friends brothers computer, i just got it a couple weeks ago, now there you go.
 
jp198780 said:
im reporting you, im tired of this, this was my friends brothers computer, i just got it a couple weeks ago, now there you go.
Jp it sounds like he knows what he is talking about and you just won't take the help. First you said it was yours then you said it wasn't and now you said it was yours again. Don't post a thread in a section where everyone can post and type and help you when you want help. You asked for help and then someone gives it to you and you tell them they don't know what they are talking about. You need to grow up.
 
holyjunk125

Thank you for the levelheaded and mature response.While i'm not in the league of 'Buzz' as far as malware cleaning goes, i know enough to help out in alot of situations and if a specialty cleaning tool is needed, i've saved 'Buzz' some time by doing some of the leg work for him.Cheers!.
 
I agree with edifier and holyjunk125.


jp198780, you have just returned to this forum after a few days off and this is what happens???

As the old saying goes: do not bite the hand that feeds you. edifier seemed to want to help you with your computer problems and you were incredibly rude and kept changing your story. I was shocked when I got the email where you reported the post... why? Because you did not like the answers he gave you?


Actually, I AM going to close this thread... not because of edifier, but because of YOU.
 
Status
Not open for further replies.
Back
Top