1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

[Window with title "??ompt" opening while on-line]

Discussion in 'Malware and Virus Removal Archive' started by tonylouwanna, 2006/11/20.

  1. 2006/11/20
    tonylouwanna

    tonylouwanna Inactive Thread Starter

    Joined:
    2006/11/20
    Messages:
    20
    Likes Received:
    0
    hello. i am new here and my cousin told me about this site for help with windows, computers, etc. thought id give you a try at solving this perplexing problem ive been having.
    1st things 1st, im not a novice computer user. almost everyone i know calls me for help when things go crazy with thier computers. havent found unsolvable problem yet.
    now i have run into a very wierd dilemna. at random times while im on line a box will open on my desktop with the word " ??ompt " at its top left corner. below in the main box theres a message asking me for a password and user name. obviously this is a replacement of the word prompt. once this shows up, my browser freezes. i try to shut or cancel this thing but it comes back repeatedly, only can kill it by shutting down browser with task manager then restarting. it seems like a sort of browser hijacker but am not sure. have run hijack this, ad-aware, bho, etc. but none find anything.
    any clues?
    by the way, i use Orca browser, and also use Acoo browser, Avant, yet this doesnt happen with them.
    any help would be greatly appreciated.

    windows xp w/sp2, avg antivirus, zone alarm on cable
     
  2. 2006/11/20
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Hello and welcome to WindowsBBS Forums.

    Seeing as you have already run Ad-Aware and HJT, would you please post the log from HJT so we can review it for discrepancies. Also please be sure it is installed as instructed below.

    And to be clear, this prompt window only comes up on the Orca browser and not any other?

    Please follow these instructions, exactly, for proper HJT installation. Please place HJT into ITS OWN PERMANANT FOLDER. Installation on the desk top is not a proper install..

    You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. (C:\HJT\HijackThis.exe)Move HijackThis.exe into this folder. When you run HijackThis.exe from C:\HJT folder and have it "Fixed checked" it will create a backup file of modifications to use if restore is necessary which is easily accessible.

    Btw, I'll move this thread over to the proper forum.
     

  3. to hide this advert.

  4. 2006/11/21
    tonylouwanna

    tonylouwanna Inactive Thread Starter

    Joined:
    2006/11/20
    Messages:
    20
    Likes Received:
    0
    ??ompt again

    hi. just ran HijackThis again to get you the log. oh, and so far this hasnt happened with any other browser i have...but Orca is the one i use most.
    by the way, i have another for you to chew on. while using Avant browser awhile back i would right-click to open a feature on a page in a new page, then the browser would freeze (sounds familiar) and about ten seconds later a page in Avant would pop up as if it was a google search with the word (and this is exactly how it was spelled) ... -embedding. just that one word. below it would be a list of supposed web pages as if search results. strange because i wasnt doing a search, just trying to open a new page. ive been on several sites for help with that one and no luck so far. so ill post that too. see what you make of it. that was the reason i went from Avant to Orca. wierd tho how theyre both developed by the same people. hmmm.

    oh, just read the posting rules. seems i cant insert or whatever an attachment. only members with a subscription can i guess. anyhow, i dont know what else to do. hijack this doesnt pull up anything suspicious.
    thanks for the speedy response.
     
  5. 2006/11/21
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Please follow Posting Rules (#3 - Meaningful Subject) when posting.

    I have adjusted your subject.
     
    Arie,
    #4
  6. 2006/11/21
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    You need to Copy/Paste the HJT info in a post.
     
    Arie,
    #5
  7. 2006/11/21
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    It appears that the problems you're experiencing are browser specific, and not likely related to malware. But we can't 100% sure until you post a log for us.
     
  8. 2006/11/21
    tonylouwanna

    tonylouwanna Inactive Thread Starter

    Joined:
    2006/11/20
    Messages:
    20
    Likes Received:
    0
    ok. heres the HJT log.

    Logfile of HijackThis v1.99.1
    Scan saved at 12:53:10 AM, on 11/21/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Unable to get Internet Explorer version!

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Universal Shield 4.0\US30Service.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Orca Browser\orca.exe
    C:\Program Files\Acoo Browser\AcooBrowser.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {B31B29D9-5B4C-41F3-AF9E-89322200E5FD} - C:\WINDOWS\system32\iewiz.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Open In New Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: Keylan - {579E308C-CFB8-44B6-9A91-242A8DF8A12D} - C:\WINDOWS\system32\usblock.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
    O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
    O23 - Service: US30Service - Unknown owner - C:\Program Files\Universal Shield 4.0\US30Service.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    hope this helps someone come up with a solution.

    while im here heres a copy/pste of the -embedding thing that comes up on Avant browser.



    -Embedding - Google SearchSign in

    Web Images Groups News Froogle Maps more »

    Advanced Search
    Preferences





    Web Results 1 - 20 of about 25,270,000,000 for -Embedding [definition].
    (0.05 seconds)

    Arts & Letters Daily - ideas, criticism, debateNews and reviews from the
    world of letters. Includes current issue and archives. Published by the...
    aldaily.com/ - 156k - Cached - Similar pages

    The Chronicle of Higher EducationThe Chronicle of Higher Education is the
    number one news and job-information source for college and university
    faculty members, administrators, ...
    chronicle.com/ - 38k - Cached - Similar pages

    OSU Open Source LabThe Open Source Lab is located in the Kerr
    Administration Building on the beautiful OSU campus in Corvallis, Oregon.
    osuosl.org/ - 32k - Cached - Similar pages

    TWiki - Enterprise Collaboration Platform & WikiTWiki is a wiki and an
    enterprise collaboration platform & Wiki. It looks and feels like a normal
    Intranet. Every web page has a Edit link, ...
    twiki.org/ - 33k - Cached - Similar pages

    Plone: A user-friendly and powerful open source Content Management
    ...Content Management Framework (CMF) that runs on top of Zope. Can be
    used as an intranet server, a...
    plone.org/ - 48k - Cached - Similar pages

    Transportation Research Board -- HomepageEncouraging Research and
    Innovation in Transportation since 1920.
    trb.org/ - 33k - Cached - Similar pages

    The Flash BlogtheFlashBlog.com is a Flash resource devoted to providing
    insight and tutorials about all kinds of topics relating to Flash
    development.
    theflashblog.com/ - 20k - Cached - Similar pages

    PHP-NukeThe Future of the Web. ... Welcome to PHP-Nuke. the future of the
    web... Main Menu. · Home · PIXEL ADS · Advertising · AvantGo · Club ·
    Commercial License ...
    phpnuke.org/ - 59k - Cached - Similar pages

    SourceForge.net: Welcome to SourceForge.netResources for open-source
    developers and a directory of in-development open-source software.
    sourceforge.net/ - 27k - Cached - Similar pages

    Welcome to TextDrive "“ Reliable, high performance web hosting you
    ...TextDrive is a hosting company run by and for people who love
    publishing on the web. From shared hosting to fully managed dedicated
    servers, Ruby on Rails, ...
    textdrive.com/ - 14k - Cached - Similar pages

    ThinkGeek :: Stuff for Smart MassesSelling geek t-shirts, mugs, ties, high
    caffeine products, and many other gifts for programmers, linux hackers,
    and open source geeks.
    thinkgeek.com/ - 30k - Cached - Similar pages

    photo slideshow Guide | stock photography | photo printingGuide to photo
    slideshow | photo slideshow news, stock photography photos, photo printing
    articles & blogs.
    photoslideshow.info/ - 36k - Cached - Similar pages

    The Web Standards ProjectThe Web Standards Project is a grassroots
    coalition fighting for standards which ensure simple, affordable access to
    web technologies for all.
    webstandards.org/ - 19k - Cached - Similar pages

    Free Counter and Advanced Web Site Statistics - SiteTracker.comDetailed
    Web site traffic analysis packages from free to professional paid services
    offering over...
    sitetracker.com/ - 23k - Cached - Similar pages

    OSDir.com :: Open Source, Linux News & SoftwareDirectory of open-source
    and just working programs.
    osdir.com/ - 47k - Cached - Similar pages

    University of California, San DiegoHome Page of the University of
    California, San Diego.
    ucsd.edu/ - 33k - Cached - Similar pages

    andreasviklund.comThe online home of Andreas Viklund from Jokkmokk,
    Sweden, and his work: mp3 music, free website templates, photos, art, blog
    and much more.
    andreasviklund.com/ - 23k - Cached - Similar pages

    Thomson Careers - One Company, Many OpportunitiesCareer development tools
    and job opportunities for a leading global e-information company in the
    financia...
    thomsoncareers.com/ - 55k - Cached - Similar pages

    Search Engine Watch: Tips About Internet Search Engines & Search ...Search
    Engine Watch is the authoritative guide to searching at Internet search
    engines and search engine registration and ranking issues.
    searchenginewatch.com/ - 52k - Cached - Similar pages

    SF Gate: News and Information for the San Francisco Bay AreaSFGate: The
    Bay Area's Home Page -- online home of the San Francisco Chronicle, and
    much more.
    sfgate.com/ - 82k - Cached - Similar pages

    Try your search again on Google Book Search


    Result Page:

    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    Next


    Free! Get the Google Toolbar. Download Now - About Toolbar






    Search within results | Language Tools | Search Tips | Dissatisfied? Help
    us improve






    Google Home - Advertising Programs - Business Solutions - About Google

    ©2006 Google

    this has been confounding me for weeks. you have to picture this laid out on a browser with the search and results aligned accordingly.
    anyway thanks again for offering your help.
     
  9. 2006/11/21
    tonylouwanna

    tonylouwanna Inactive Thread Starter

    Joined:
    2006/11/20
    Messages:
    20
    Likes Received:
    0
    "??ompt" again ! ! !

    im back already. i just restarted the Orca browser and i got that prompt-looking box again. i wish i could post what this box looked like.

    at the top left is the word ??ompt, then in the box itself it says:
    Enter username and password for "at xxx.wingchuntong.com

    then there are two boxes for username and pass, then a checkable box that says: Use Passwod Manager to remember this password.
    and then OK and Cancel buttons at bottom.
    im afraid to type in this wingchuntong on a search cause who knows where this could take me.
    anyway, Orca browser is now frozen with this box in front of it. i cant click to close it or anything. very frustrating to say the least.
    thanks again.
     
    Last edited by a moderator: 2006/11/21
  10. 2006/11/21
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Ok, sounds like your browser is hijacked, does IE also open to this page?

    Btw, I went there and I guess it's just some private site that prompts you for user name and a password. The reason you get the '??ompt' is likley because your OS will not translate the Chinese properly.

    Lest fix a few things.

    Run Hijackthis and look over the following entries I have listed, check the boxes next to them and press the "Fix Checked" button with HijackThis. When you are doing this, make sure you have No IE windows, or other browsers open, including this one. Reboot if I have specified below, and post a fresh HijackThis log.

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    O2 - BHO: (no name) - {B31B29D9-5B4C-41F3-AF9E-89322200E5FD} - C:\WINDOWS\system32\iewiz.dll


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present<<<<<<USER SET? IF SO, IGNORE FIX


    O21 - SSODL: Keylan - {579E308C-CFB8-44B6-9A91-242A8DF8A12D} - C:\WINDOWS\system32\usblock.dll


    Reboot, into safe mode, this way:
    Turn on the computer
    Immediately begin tapping the <F8> key.
    Use the arrow keys to highlight Safe Mode and press the <Enter> key.

    Also, enable the 'Show Hidden Folders' option, like this:
    Click Start.
    Open My Computer.
    Select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.
    Click OK.

    And search for, then delete, if found, (some may not be present after previous steps) the following files/folders:
    C:\WINDOWS\system32\iewiz.dll<<<--this file
    C:\WINDOWS\system32\usblock.dll<<<--this file

    To exit Safe Mode, click the Start button, click Turn Off Computer, click Restart.

    Post a new HJT log back into this thread please.
     
  11. 2006/11/22
    tonylouwanna

    tonylouwanna Inactive Thread Starter

    Joined:
    2006/11/20
    Messages:
    20
    Likes Received:
    0
    hi again. just a note in response to last persons comment. he asked if internet explorer also opened to that page. first, i believe he was under the impression that my browser was hijacked and only one page came up. not so. the Orca browser like Avant has option to save last opened pagesof last browsing session. i was opening my last opened pages (ebay, this site, amazon, qconlineauction) and thats when this thing came up as a small box in front of my browser. all pages stopped loading and the browser froze.
    i dont use IE. notorious for attracting pop ups, adware, other nasties.
    anyway, i ran hijack this again and here now is the new log:

    Logfile of HijackThis v1.99.1
    Scan saved at 5:51:23 PM, on 11/21/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Unable to get Internet Explorer version!

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Universal Shield 4.0\US30Service.exe
    C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe "
    O4 - HKLM\..\Run: [zSPGuard] c:\program files\pjw\spguard\spguard.exe /s
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O8 - Extra context menu item: Open In New Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
    O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
    O23 - Service: US30Service - Unknown owner - C:\Program Files\Universal Shield 4.0\US30Service.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

    incidentally, the dll's that TeMerc told me to eliminate are now gone and hijackthis took care of the rest. so far no return of this complexing buttinsky.
    thanks TeMerc and everyone else. love this site!!!!!
     
  12. 2006/11/22
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    The log appears clear and we're glad you no longer have the problem.

    Incidentally, IE does what you tell it. Adjusting a few settings here and there and there's no problem with it. What 'attracts' the malware is that IE is the most used browser on the planet, so whats the point of targeting something where your 'return' is likely to be miniscule.

    The more FF gains in popularity, the more holes will be found, you can count on it.


    We have 3 more things to do, mostly maintenance and then our recommendations:

    Empty the TIF (Temporary Internet Files)
    Delete all the files in (and any subfolders of) the C:\Windows\Temp folder
    The app below will help with temp files.
    Index.dat Suite

    Also, delete all your cookies, and empty your recycle bin. But remember, by deleting your cookies, you will have to re-enter any passwords and log-in info for any sites you are usually required to do so with.

    This would also be a good time to set a new system restore point for your machine.
    Set New System Restore Point. Do not do this unless there are no other user accounts to be diagnosed.

    Also, as you are an XP user, if there are any other accounts on this machine, they too, must be cleaned with AdAware, Spybot S&D, then HJT. Not all infections are global, nor are all the HJT fixes global. You can post each user account here into this thread, but please, do only one at a time to avoid confusion.

    Here is a link which describes how security apps work with WIN XP machines.
    XP User Accts Security Apps Operation

    To further prevent the installation of ad/mal/spyware, DL the apps below, which are just as good the fight against ad/mal/spyware as AdAware & Spybot S&D:

    SpywareBlaster
    With SpywareBlaster v3.5.1 , just DL, install and check for updates, enable Internet Explorer protection, and your done! I don't recommend using IE restricted sites protection as it's not a very large database. Use IE-SPYADs below.

    To avoid known malware infested sites from loading in IE install IESPY ADS.
    And MVPS Hosts File will accomplish a similar tactic and provide another layer of protection.

    And to prevent unknown applications from being inserted to start up on your machine install WinPatrol v10.0.5.

    Another thing I would suggest, is to install SiteAdvisor. It gives sites a few different 'ratings' and while not fool proof, a good additional layer of information about many sites.

    Links for tutorials for all the apps I mentioned can be found on my site as well.

    Confused about which apps are good or not? Read about Rogue/Approved Anti Security apps

    And just because you have security apps installed, they are useless unless updated regularly. Keep track of updates for ALL your security needs here:
    Calendar of Updates

    Subscribe to update alerts for all the above security apps here.

    You can also see my own ongoing security testing with all the above apps proving how securely you can safe with them installed.
    TeMerc Test Box Forum

    Happy surfing!!
    Tom :D
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.