Jump to content


Been awhile-How am I looking Boss?


  • You cannot reply to this topic
15 replies to this topic

#1 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 15 September 2006 - 08:35 PM

Logfile of HijackThis v1.99.1
Scan saved at 3:34:39 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NetVeda\Safety.Net\ipcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAV.EXE
C:\Program Files\NetVeda\Safety.Net\ipcTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [SafetyNet] "C:\Program Files\NetVeda\Safety.Net\ipcTray.exe"
O4 - HKLM\..\Run: [SafetyNet_Notifier] "C:\Program Files\NetVeda\Safety.Net\ipcLn.exe"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1141265351607
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.c...tacceptlang.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AE27AD2-9CE7-486E-867B-E29FF3E603E2}: NameServer = 142.161.130.155 142.161.2.155
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NetVeda Safety.Net (ipcSvc) - NetVeda LLC - C:\Program Files\NetVeda\Safety.Net\ipcsvc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

#2 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 15 September 2006 - 09:00 PM

Log looks good. Hows netveda treating you?

You might want to check your Etrust AV. I don't see isafe.exe, cavtray.exe or vetmsg.exe in your log. Thats its auto update feature, tray icon and real time scanning. If you have it turned off thats of course ok but I just thought I'd point it out. :D

You can remove this:
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\WINDOWS\system32\shdocvw.dll
(old outpost entry. button for IE)

#3 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 02:11 AM

Thanks rridgely. How do i get these to work/show? I dont remember disabling them.


isafe.exe, cavtray.exe or vetmsg.exe

and i deleted that outpost one. and netveda has been treating better than any other firewall so far-so until/unless it gives me a problem, its staying.

Thanks!

#4 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 02:13 AM

Well etrust doesn't even seem to be running at all. Just open it up from the start menu and make sure everything is enabled.

Once you open it up look in your task manager and see if everything comes back.

#5 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 02:52 AM

this is my task manager screen shot. i just shut down and then reenabled the etrust. dont see those .exe.

should i uninstall and reinstall or something?

#6 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 02:58 AM

Thats really strange. I don't see etrust in your system system tray though.
Make sure netveda isn't blocking any of those processes first. Look in etrust at the bottom where it says "active protections status" and click details and see if everything is checked off. Its not running though...

Try all of that and if nothing works I would just do a reinstall. Didn't you just try a registry cleaner or somthing that caused problems(I think it was you that mentioned it)? I wonder if thats what did this. Did you get any kind of warning about not have an antivirus from windows security panel?

#7 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 03:08 AM

they are all checked except for the email scanning status. otherwise they are fine. also, no windows warning about not having an antivirus. i will uninstall, reinstall and repost. thanks. :)

#8 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 03:30 AM

ok, this is weird. i cant update the antivirus, firewall is turned off, and now my windows security balloon is on. this after deleting the old antivirus, and reinstalling this one. and the antivirus says im not connected to the internet-which i obviously am. hmmmmmm.

this is what it says when i try to update:

#9 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 03:42 AM

Try rebooting.

#10 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 03:49 AM

did it twice. now reinstall wont even let me do on demand scanner. hmmmm. and windows balloon says "try turning on antivirus" 55 billion dollars and gates couldnt come up with better? :)

#11 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 03:55 AM

View PostLordoftheweb, on Sep 15 2006, 11:49 PM, said:

did it twice. now reinstall wont even let me do on demand scanner. hmmmm. and windows balloon says "try turning on antivirus" 55 billion dollars and gates couldnt come up with better? :)
LOL, I wonder whats wrong with it. Your sure your not blocking it with your firewall?
Thats about the only thing I can think of.(are those processes I listed loading now?)

You might have to uninstall it again delete the program folder and run an issues clean with ccleaner. Have you noticed any problems with any other programs not working lately?

#12 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 03:58 AM

nope everything else is working. and after the first uninstall, i ran ccleaner issues scan and deleted everything. never had this prob before. hmmmm.

etrust is gone now, gonna try another and see if it works. will check back later.

#13 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 04:00 AM

Very strange. I'm really not sure.
For other ones to try you could go for avg, avast, or antivir. Bit defender has a good free version but its only the scanner and updates(no real time). It sucks etrust just quit working. <_<

Edit:
I guess its a good thing I noticed though. You were without virus protection and didn't know it! :o

#14 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 04:16 AM

Ok i added a copy of my new hijackthis log and my new tasks. i reinstalled (for a third time) after running tuneup2006, and then it reinstalled properly! seems ok. let me know! here goes:

Logfile of HijackThis v1.99.1
Scan saved at 11:11:21 PM, on 9/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\NetVeda\Safety.Net\ipcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\Program Files\NetVeda\Safety.Net\ipcTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [SafetyNet] "C:\Program Files\NetVeda\Safety.Net\ipcTray.exe"
O4 - HKLM\..\Run: [SafetyNet_Notifier] "C:\Program Files\NetVeda\Safety.Net\ipcLn.exe"
O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\LaunchPd.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1141265351607
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.c...tacceptlang.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1AE27AD2-9CE7-486E-867B-E29FF3E603E2}: NameServer = 142.161.130.155 142.161.2.155
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: NetVeda Safety.Net (ipcSvc) - NetVeda LLC - C:\Program Files\NetVeda\Safety.Net\ipcsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Internet Security Suite\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)

anything else to clean or speed things up?

thanks for the info! i cant believe i was surfing with my pants off! at least i dont go to porn or crack sites, so im sure im ok. but will run all the tests just to be sure. thanks again!

hmmmm. wont let me add the attachment. thats strange. lets try again.



hmmm. still wont. anyhoo, the three processes you mentioned are there now! good times!

#15 OFFLINE   rridgely

    I hate computers

  • Moderators
  • 8,858 posts
  • Gender:Male

Posted 16 September 2006 - 04:27 AM

Ah that looks better. :)

You can remove this and then stop the process in the task manager:O4 - HKLM\..\Run: [CaISSDT] "C:\Program Files\CA\eTrust Internet Security Suite\caissdt.exe"

caissdt.exe(end in task manager). Its that dumb security center they added like all the other suites.

Not sure what you were trying to attatch to the forum but for some reason it will only work if you put it in a zip file.(not sure why but not a big deal.)

You should be good to go for now. :)

#16 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 16 September 2006 - 03:53 PM

i was using faststone image capture, saving the file and then uploading it-like i always have, but this time it wouldnt let me. hmmm. thanks again!