1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.


Discussion in 'Virus & Other Malware Removal' started by aric49, Apr 26, 2004.

Thread Status:
Not open for further replies.
  1. aric49

    aric49 Thread Starter

    Apr 25, 2004
    I think i have a virus, but I`m not sure. AIM will not let me send IMs, this happens on all versions of it. everytime i try to send a IM my pc makes a stupid beeping noise that ususally sounds when ever a error message comes up.

    Does anyone know a patch or most perferably a freeware virus scanner that will rid me of this once and for all?
  2. Infidel_Kastro


    Nov 21, 2003
    Hi Aric. first, go to www.sherrylynn.us/privacypolicy and click on hjt.exe. Save it to its own permanent folder and open it up. Click on "scan" and scan only. After it creates a log, the "scan" button will say "save". Save it as a notepad file and cut and poaste the file into this thread and post it so we can look at it.
    For anti-virus, the one that I use and like is available at www.grissoft.com. Its free. Go to www. grisoft.com and on the left hand side click on "Free version AVG" or something like that. ON the next page, scroll down and download and follow the prompts. Once you have installed, click on "Virus database" and update it. Its easy. (y)
  3. aric49

    aric49 Thread Starter

    Apr 25, 2004
    Well I dled Highjackthis and it needed some .dll file to run, so that did not work. Then i went to the other site you listed, and it took me to some weird search engin site called http://netster.com are you sure you got your links right?
  4. sleekluxury


    Oct 5, 2003
  5. sleekluxury


    Oct 5, 2003
  6. sleekluxury


    Oct 5, 2003
    Do you have a firewall, if so is it set to let aim send messages back and forth?
  7. aric49

    aric49 Thread Starter

    Apr 25, 2004
    No, i do not have a firewall, i didn`t think i needed one with dialup
  8. Flrman1


    Jul 26, 2002
  9. aric49

    aric49 Thread Starter

    Apr 25, 2004
    well, I still could not get hijack this running, but i really don`t think it was spy ware or adware, because i have ad-aware and scan my pc all the time. Anyway the virus scanning prog, i ran it and it picked up 3 viruses, i put them in the vault, (I guess that means that it deleted it) and i downloaded AIM and it worked!! i could send IMS again!!!!!!!!!!!! THANKYOU SOOOO MUCH!
  10. aric49

    aric49 Thread Starter

    Apr 25, 2004
    About the firewall, where can i get a free one thats a good quality one? I`m a bit paranoid about viruses now....
  11. FinestRanger


    Oct 13, 2003
    Read this thread. There are free firewalls listed. If you're new to firewalls, I'd suggest ZoneAlarm. Also, I'd recommend downloading SpyBot and SpywareBlaster. Both can be found in the thread and I think it'll be good reading for you and your "paranoia" :) Hope this helps.
  12. Flrman1


    Jul 26, 2002
    Did you try this?

    Just because you have Adaware doesn't mean that you are not infected with some type malware. We really need to see a hijack This log.
  13. aric49

    aric49 Thread Starter

    Apr 25, 2004
    ya, the message you posted is the message i got.... I`ll be sure to run it as soon as possible, if you want to talk to me in person, my aim name is aric131
  14. aric49

    aric49 Thread Starter

    Apr 25, 2004
    * HijackThis v1.97 *
    Written by Merijn - [email protected]

    See below version history for short info on hijack sections.

    * Version history *
    * Lots of bugfixes and small enhancements! Among others:
    * Fix for Japanese IE toolbars
    * Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
    * O19 (user stylesheet) now only checks for known bad filenames
    * Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
    * Added several files to the LSP whitelist
    * Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
    * All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
    * Added a new regval to check for from Whazit hijack (Start Page_bak).
    * Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
    * New in logfile: Running processes at time of scan.
    * Checkmarks for running StartupList with /full and /complete in HijackThis UI.
    * New O19 method to check for Datanotary hijack of user stylesheet.
    * Google.com IP added to whitelist for Hosts file check.
    * Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
    * Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
    * Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
    * Fixed a bug where DPF could not be deleted.
    * Fixed a stupid bug in enumeration of autostarting shortcuts.
    * Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
    * Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
    * Added support for backing up F0 and F1 items (d'oh!).
    * Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
    * Fixed a bug in LSP routine for Win95.
    * Made taborder nicer.
    * Fixed a bug in backup/restore of IE plugins.
    * Added UltimateSearch hijack in O17 method (I think).
    * Fixed a bug with detecting/removing BHO's disabled by BHODemon.
    * Also fixed a bug in StartupList (now version 1.52.1).
    * Fixed two stupid bugs in backup restore function.
    * Added DiamondCS file to LSP files safelist.
    * Added a few more items to the protocol safelist.
    * Log is now opened immediately after saving.
    * Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
    * Updated integrated StartupList to v1.52.
    * In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
    * Rudimentary proxy support for the Check for Updates function.
    * Added rd.yahoo.com to the Nonstandard But Safe Domains list.
    * Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
    * Added listing of programs/links in Startup folders (O4).
    * Fixed 'Check for Update' not detecting new versions.
    * Added check for Lop.com 'Domain' hijack (O17).
    * Bugfix in URLSearchHook (R3) fix.
    * Improved O1 (Hosts file) check.
    * Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
    * Added AutoConfigURL and proxyserver checks (R1).
    * IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
    * Added check for extra protocols (O18).
    * Added 'ignore non-standard but safe domains' option.
    * Improved Winsock LSP hijackers detection.
    * Integrated StartupList updated to v1.4.
    * Fixed a few bugs.
    * Adds detecting of free.aol.com in Trusted Zone.
    * Adds checking of URLSearchHooks key, which should have only one value.
    * Adds listing/deleting of Download Program Files.
    * Integrated StartupList into the new 'Misc Tools' section of the Config screen!
    * Improves detecting of O6.
    * Some internal changes/improvements.
    * Adds backup function! Yay!
    * Added check for default URL prefix
    * Added check for changing of IERESET.INF
    * Added check for changing of Netscape/Mozilla homepage and default search engine.
    * Fixes Runtime Error when Hosts file is empty.
    * Added enumerating of MSIE plugins
    * Added check for extra options in 'Advanced' tab of 'Internet Options'.
    * Adds 'Uninstall & Exit' and 'Check for update online' functions.
    * Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
    * Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
    * A few bugfixes/enhancements
    * Adds detecting of extra MSIE context menu items
    * Added detecting of extra 'Tools' menu items and extra buttons
    * Added 'Confirm deleting/ignoring items' checkbox
    * Adds 'Ignorelist' and 'Info' functions
    * Supports BHO's, some default URL changes
    * Original release

    A good thing to do after version updates is clear your Ignore list and re-add them, as the format of detected items sometimes changes.

    The different sections of hijacking possibilities have been separated into these groups:
    R - Registry, StartPage/SearchPage changes
    R0 - Changed registry value
    R1 - Created registry value
    R2 - Created registry key
    R3 - Created extra registry value where only one should be
    F - IniFiles, autoloading entries
    F0 - Changed inifile value
    F1 - Created inifile value
    N - Netscape/Mozilla StartPage/SearchPage changes
    N1 - Change in prefs.js of Netscape 4.x
    N2 - Change in prefs.js of Netscape 6
    N3 - Change in prefs.js of Netscape 7
    N4 - Change in prefs.js of Mozilla
    O - Other, several sections which represent:
    O1 - Hijack of auto.search.msn.com with Hosts file
    O2 - Enumeration of existing MSIE BHO's
    O3 - Enumeration of existing MSIE toolbars
    O4 - Enumeration of suspicious autoloading Registry entries
    O5 - Blocking of loading Internet Options in Control Panel
    O6 - Disabling of 'Internet Options' Main tab with Policies
    O7 - Disabling of Regedit with Policies
    O8 - Extra MSIE context menu items
    O9 - Extra 'Tools' menuitems and buttons
    O10 - Breaking of Internet access by New.Net or WebHancer
    O11 - Extra options in MSIE 'Advanced' settings tab
    O12 - MSIE plugins for file extensions or MIME types
    O13 - Hijack of default URL prefixes
    O14 - Changing of IERESET.INF
    O15 - Trusted Zone Autoadd
    O16 - Download Program Files item
    O17 - Domain hijack
    O18 - Enumeration of existing protocols
    O19 - User stylesheet hijack

    You can get more detailed information about an item by selecting it from the list of found items or highlighting the relevant line above, and clicking 'Info on selected item'.
  15. aric49

    aric49 Thread Starter

    Apr 25, 2004
    atleast i think thats it..........
  16. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/224093

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice