Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

iSearch. Desktop Search WONT LEAVE! [resolved]


  • This topic is locked This topic is locked

#31
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,well we are making progress,I will need to see a copy of your Hosts File,to Do this,Open HijackThis and Click Config>>Misc Tools>>Open Hosts File Manager>>Open in Notepad>>Copy&Paste the Results in the Next Post!!

I hate to ask you but I am going to have to see what all is running around in there!!

Please Download F-Secure Blacklight:
http://www.f-secure....light/try.shtml
Please download this to the same folder HijackThis is in!!

Once at the page,Click "I Accept"

Then Click Download,which sits right under "Graphical user interface version:"

Once Downloaded,Double Click blbeta.exe to Start it,then Click "I accept the agreement" and click "Next"

Now Click "Expert Mode" and then"Scan" and let it do its thing,if it finds anything,it will automatically tell you and go to Step 2 to begin the cleaning process,if not post back and let me know ASAP!!

If all went well,look back in the folder that blbeta.exe resides in,there you should see "fsbl.log"

If Blacklight identified anything,it will be in that log,I will need to see those Results!

Once all is complete,post both logs back here!!

Edited by Cretemonster, 02 May 2005 - 04:15 PM.

  • 0

Advertisements


#32
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Hey...

Alright... heres the host thing... I recently ran something called Hoster or whatever which i think restored the default in this. So there isnt much there:

# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a "#" symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
#
127.0.0.1 localhost


And F-Secure DID NOT find anything to clean. Is that good?

Thanks for your continued help :tazz:

~Lance
  • 0

#33
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Yeah,thats a definite good sign,what ticks me off,is I have no Idea,as of yet,what is keeping the MSN Functions from not working!!

If you type in msn.com into any browser,the page will not load??

Is this just Internet Explorer or other browsers?

MSN Messanger,Not Windows Messanger,Correct?

Let me see what I can dig up,I know there are 2 bugs flying around that are directed towards MSN Messanger specifically!

We just have to figure out what the bug did or Undid!!!

Gimmie some time,I will figure it out!!!
  • 0

#34
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
You are correct... i tried firefox with the same results...

It's all MSN services..... msn.com, MSN messenger, hotmail...
They just wont load.


This is just a hunch.... but Coachwife asked me to make this file and merge it with my registry.... and things went all screwy after i did that...

I believe thats the case anyways....
  • 0

#35
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
OK,Thats what I needed to know!!!

I have like 4 hours to get some sleep before work comes!!!

I will take this post with me so I can study it and maybe something will click!!!

Bear with me,I am running short on time!

Have you tried the Windows Update Site yet??

If not give it a try and tell me what happens!!

Edited by Cretemonster, 02 May 2005 - 07:21 PM.

  • 0

#36
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Windows Update wouldnt work b4..... and just gave me lots of errors, so i disabled it....

I just tried to turn it on again... and it would not connect to the website.

There are other websites that i cannon access as well as i have discovered..

I also cannot connect to:

www.fastweb.com
  • 0

#37
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
WOW!!!

I dont know what happened..... but for some reason..... everything seems to be working... I am able to get on MSN..... the websites work..... and now my updates seem to be working!


This is soooo random!

Thank you very much for your help, both Cretemonster and Coachwife6....

God willing.... if I am able to spare... Expect a paypal donation for each of you.


Peace!
  • 0

#38
coachwife6

coachwife6

    SuperStar

  • Retired Staff
  • 11,413 posts
Isn't CM a genius? I'm sure he will ask you for a new HJThis log. ;) Please post it. :tazz:
  • 0

#39
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Now thats Bizarre!!!!!

There is a folder that is associated with MSN Messanger,its called:

My Recieved Files and is located in C:\Documents and Settings

Please look in that folder and see if there isnt a bunch of garbage in it!!!

Anything you dont need from that folder can go!!!

If you will,please post a fresh HijackThis log!!!

As for the PayPal Comment,if you feel compelled to make a donation,please make it to Geeks to Go!! (CoachWife)

I too was once infected and some kind person helped me get disinfected,much the same way you have done!!

That being said,being a gentleman with a conscience,I say save the money,go out this weekend and have a throw down!!!

But,thats just me!!!!! :tazz:

Lets have a look at a HijackThis log and we will get some Security programs installed!!!

Edited by Cretemonster, 05 May 2005 - 05:13 AM.

  • 0

#40
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
So in other words... you are encouraging me to blow my hard-earned paycheck on a party? I like your style! :tazz:

A throw-down as you put it, WILL be occuring this weekend. Thanks a ton!


Peace,
~Lance

P.S I'm not at home at the moment, but i will post a HJT Log when I get home.
  • 0

Advertisements


#41
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Logfile of HijackThis v1.99.1
Scan saved at 11:05:33 PM, on 5/6/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe
C:\Program Files\Creative\SBLive 24-Bit External\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Creative\MediaSource\RemoteControl\OSDMenu.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\AntiSpyware\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBLive 24-Bit External\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [SbUsb AudCtrl] RunDll32 sbusbdll.dll,RCMonitor
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [RemoteCenter] C:\Program Files\Creative\MediaSource\RemoteControl\RCMan.EXE
O4 - HKCU\..\Run: [Utopia Angel] "C:\Utopia\Angel\Angel.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://jcs.chat.dcn....v45/yacscom.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1109120593156
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A3D8F130-0418-46DA-8890-3204CE440DC1}: NameServer = 165.154.140.8 165.154.140.9
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

Looking good??
  • 0

#42
Wizard

Wizard

    Retired Staff

  • Retired Staff
  • 5,661 posts
Absolutley!!!!!!!!!!!!!!!

A Throw Down should have occured by this time!!!!

How is the PC Acting???


Everything looks Peachy in the Log!!!
  • 0

#43
takemeaway2004

takemeaway2004

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
So far so good...

I just rolled out of bed.... last night was a late one :tazz:

Thanks a million ;)


~Lance

This topic has been closed. If you need it reopened for any reason, please contact a staff member.

Edited by coachwife6, 09 May 2005 - 05:25 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP