![]() |
| |||||||
| |
![]() |
| | Thread Tools |
|
#16
| ||||
| ||||
| Yes. This happens with Casino Royal movie. We played King Kong and it does not happen. Sony flash player starts with the CR movie which Does Not happen with the King Kong movie. Plus there are 4 users. So far it Only occurs with one user. The rest seem to be ok. ![]() |
| |
|
#17
| ||||
| ||||
| I will do HiJack This right now. Thank you. |
|
#18
| ||||
| ||||
| Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:06:49 PM, on 11/4/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe C:\PROGRA~1\TRENDM~1\INTERN~3\PccGuide.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.investors.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\pkext.dll O3 - Toolbar: AbsoluteShield - {EE9DD090-902D-4623-9360-FB7D8666202B} - C:\Program Files\SysShield Tools\Internet Eraser\AbsoluteBar.dll O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: HPAiODevice(hp officejet d series) - 2.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02...s/MSNPUpld.cab O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase4009.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1112912480746 O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1143419328031 O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} - http://secure2.comned.com/signuptemp...ogin-devel.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6...ws-i586-jc.cab O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (PlotWon Control) - http://www.investors.com/member/ocx/plotwon.ocx O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocx O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\PcCtlCom.exe O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~3\Tmntsrv.exe O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\TmPfw.exe O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~3\tmproxy.exe O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe -- End of file - 7141 bytes |
|
#19
| ||||
| ||||
| Is this the way I was suppose to send HiJackThis? |
|
#20
| ||||
| ||||
| You need to pick one antivirus and uninstall the other. Since you have the PcCillin suite I would get ri of the BitDefender. Two antivirus causes instability and conflicts. Open HijackThis and select "Do a system scan only" Place a check mark next to this entry O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} - http://secure2.comned.com/signuptemp...ogin-devel.cab Close all windows except for HijackThis and click "Fix checked" Run this program. It is a trial version but has full functions during the trial period. Have it remove anything found. TrojanHunter Let me know if anything was found. Also let me know how things are now. |
|
#21
| ||||
| ||||
| OK! Thanks once again. I will run the program mentioned. I realize that only One Anti-Virus should run and that is the way I have it set. BitDefender is turned Off and is used only as a scanner without any real-time protection on whatsoever. This is also true for MultiVirus scanner which is also installed but is only used to scan. Your help is greatly needed and I really cannot thank you enough. I will run the Trojan scan and get back ASAP. |
|
#22
| ||||
| ||||
| Quarantined file C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax This is what TH found. I am uninstalling K-Lite. Too bad since this was a way for a no cost program to watch DVD's. Thank you |
|
#23
| ||||
| ||||
| Found trojan file: C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax (Generic.TrojanDownloader.A) Quarantined file C:\Program Files\K-Lite Codec Pack\filters\CoreAVCDecoder.ax This is all of the report Trojan Hunter found. |
|
#24
| ||||
| ||||
| After uninstalling K-Lite you can reinstall a fresh version from Here It is possible it had become infected. |
|
#25
| ||||
| ||||
| Not only did I uninstall K-Lite but I had to system restore several times to find the right spot for the bug to be gone. I did download from FileHippo the first time and most of the time all programs from FileHippo are clean. Still scratching my head trying to figure out how this happend since this was the first time to use it. Plus I uninstalled WMP 11 and all Codecs I could find. It is just not worth it to have this thing popping up just to watch a movie. Thanks for the help. ![]() |
|
#26
| ||||
| ||||
| OK, just a few more things, Delete: Combofix Go to C:\qoovox <---Delete this whole folder Uninstall TrojanHunter <---unless you want to keep it until the trial is over Toggle System Restore to remove infected restore points. System Restore 1: Right click on the My Computer icon on your desktop and select properties. 2: Click on the system restore tab. 3: Check the box that says "Turn off system restore on all drives". Click OK. 4: Click Yes when you are prompted to restart the computer 5: To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box. Suggested reading Keeping Yourself Safe On The Web Let me know if there is anything else that comes up. Last edited by evilfantasy : 05-11-2007 at 10:23 PM. |
|
#27
| ||||
| ||||
| Your help has helped greatly. I have followed the above steps. Plus I have done yet another thorough cleaning. Now I would like to check again to see if that infected site appears again. This is basically the steps that I use when trying to view the Casino Royal DVD movie. At present I have no software that I am aware of to play DVD's. That does not matter since the bug shows up with WMP. I insert or auto play the DVD. Next the Sony Flash player appears. I press play movie with Sony 's player. Then WMP starts. Then it sits there idle until I press play on WMP. Once play is clicked then a connection is made to the web. In the Now Playing section the word “trailer” appears and then the unwanted nasty commercial begins to play. Is it safe to check this without getting “bit” again? I am really timid to attempt to play a movie. I'd like to reinstall WMP 11 also. Is that something else I should tip toe with? ![]() Last edited by silver : 06-11-2007 at 03:22 AM. |
|
#28
| ||||
| ||||
| It sounds like the movie has an extra bit of footage on it that you are forced to watch. You could try to install another free player and see if it happens with that one also. If it does then I would have to say it is something installed on the CD. WMP can be difficult at times. I use winamp http://www.winamp.com/ and it plays most everything I need it to. |
|
#29
| ||||
| ||||
| Thank you, thank you, and thank you. I'll try those steps also. It's too bad I could find anyone here on this side of the world to be as helpful or as knowledgeable. God bless ya! Last edited by silver : 06-11-2007 at 03:29 AM. Reason: grammer |
![]() |
| Thread Tools | |
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Google Webmaster Central - Site Verification (Freewebs site) | jsh4 | Web Design & Programming | 5 | 22-01-2008 11:01 AM |
| Unwanted Tab on IE7 | dfr200764 | Web Browsers & FTP Clients | 3 | 10-12-2007 04:51 PM |
| Unwanted Folders | Jayu | Windows Operating Systems | 1 | 17-08-2007 10:17 PM |
| PC Porn | alex | CPUs, Motherboards & RAM | 2 | 24-06-2007 10:00 PM |
| how do i get internet explorer to stop unwanted pages... | sharon c | Web Browsers & FTP Clients | 2 | 20-03-2007 05:15 PM |
| Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc. |