Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

browser highjack [CLOSED]


  • This topic is locked This topic is locked

#31
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
ok ?? I got a .bmp to work on the desktop but nothing else works? :)
I had to use the browse button and go into the folder to see the .bmp files and then selected one it set the desktop but still no preview as shown

















Capture bmp work on desktop but still can't see them as seen unless browsing

Attached Thumbnails

  • Capture_bmp_work_on_desktop_but_still_can__t_see_them_as_seen_unless_browsing.JPG

Edited by _The_Nothing_, 08 September 2008 - 11:41 AM.

  • 0

Advertisements


#32
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Thanks I didn't find those posts so I will see what they did and why and then see if I can jiggle it some
  • 0

#33
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
I think it's getting worse !

do these have anything to do with it ?

Attached Thumbnails

  • Capture3.JPG
  • Capture2.JPG
  • Capture_clicking_on_this_one_shows_.bmp_on_desktop.JPG
  • Capture_clicking_on_this_one_shows_.bmp_on_desktop.JPG
  • switched_from_icons_back_to_thumbnails.JPG

  • 0

#34
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Did you start experiencing these problems before or after using VLite ?
  • 0

#35
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
you know I just saw that Tuesday, should I use it and try to repair vista with it

Slipstream

Edited by _The_Nothing_, 10 September 2008 - 11:55 AM.

  • 0

#36
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
I went on kaspersky to use their online scanner and I got this result, does that mean I still have something on here ?

Attached Thumbnails

  • what_is_this3.JPG
  • what_is_this2.JPG
  • what_is_this.JPG
  • what_is_this4.JPG

  • 0

#37
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
Java Plug-in 1.6.0_07
Using JRE version 1.6.0_07 Java HotSpot™ Client VM
User home directory = C:\Users\Me and my angels 2


----------------------------------------------------
c: clear console window
f: finalize objects on finalization queue
g: garbage collect
h: display this help message
l: dump classloader list
m: print memory usage
o: trigger logging
p: reload proxy configuration
q: hide console
r: reload policy configuration
s: dump system and deployment properties
t: dump thread list
v: dump thread stack
x: clear classloader cache
0-5: set trace level to <n>
----------------------------------------------------

java.io.IOException: Invalid keystore format
at sun.security.provider.JavaKeyStore.engineLoad(Unknown Source)
at sun.security.provider.JavaKeyStore$JKS.engineLoad(Unknown Source)
at java.security.KeyStore.load(Unknown Source)
at com.sun.deploy.security.DeploySigningCertStore$1.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at com.sun.deploy.security.DeploySigningCertStore.loadCertStore(Unknown Source)
at com.sun.deploy.security.DeploySigningCertStore.load(Unknown Source)
at com.sun.deploy.security.DeploySigningCertStore.load(Unknown Source)
at com.sun.deploy.security.ImmutableCertStore.load(Unknown Source)
at com.sun.deploy.security.TrustDecider.isAllPermissionGranted(Unknown Source)
at com.sun.deploy.security.TrustDecider.isAllPermissionGranted(Unknown Source)
at sun.plugin.security.PluginClassLoader.getPermissions(Unknown Source)
at java.security.SecureClassLoader.getProtectionDomain(Unknown Source)
at java.security.SecureClassLoader.defineClass(Unknown Source)
at java.net.URLClassLoader.defineClass(Unknown Source)
at java.net.URLClassLoader.access$000(Unknown Source)
at java.net.URLClassLoader$1.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at java.net.URLClassLoader.findClass(Unknown Source)
at sun.applet.AppletClassLoader.findClass(Unknown Source)
at java.lang.ClassLoader.loadClass(Unknown Source)
at sun.applet.AppletClassLoader.loadClass(Unknown Source)
at java.lang.ClassLoader.loadClass(Unknown Source)
at sun.applet.AppletClassLoader.loadCode(Unknown Source)
at sun.applet.AppletPanel.createApplet(Unknown Source)
at sun.plugin.AppletViewer.createApplet(Unknown Source)
at sun.applet.AppletPanel.runLoader(Unknown Source)
at sun.applet.AppletPanel.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
=> MainApplet.MainApplet <=
=> MainApplet.init <=
=> MainApplet.start <=
java.lang.ExceptionInInitializerError
at com.kaspersky.kosp.MainApplet.start(MainApplet.java:91)
at sun.applet.AppletPanel.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
Caused by: java.security.AccessControlException: access denied (java.util.PropertyPermission user.name read)
at java.security.AccessControlContext.checkPermission(Unknown Source)
at java.security.AccessController.checkPermission(Unknown Source)
at java.lang.SecurityManager.checkPermission(Unknown Source)
at java.lang.SecurityManager.checkPropertyAccess(Unknown Source)
at java.lang.System.getProperty(Unknown Source)
at com.kaspersky.kosp.common.Common.<clinit>(Common.java:18)
... 3 more
  • 0

#38
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I think that Vista on your system is in a bit of a mess. Java now no longer works. So I would seriously consider backing up all your data and reformating. Slipstream programmes are good if you know what you are doing, if not it can ruin the install
  • 0

#39
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
ok I found a program called Autoruns
it says I have files missing
O.K. here it goes

[url="http://www.google.com/search?q=adxapie.sys&rls=com.microsoft:*:IE-Address&ie=UTF-8&oe=UTF-8&sourceid=ie7&rlz=1I7GGLJ""]http://www.google.com/search?q=adxapie.sys...z=1I7GGLJ"[/url][/url]

[url="http://www.google.co...e7&rlz=1I7GGLJ"
[url="http://"http://www.google.co...z=1I7GGLJ"[/url"]


[url="http://www.google.co...e7&rlz=1I7GGLJ"
[url="http://"http://www.google.co...z=1I7GGLJ"[/url"]
[url="http://www.google.co...e7&rlz=1I7GGLJ"
[url="http://"http://www.google.co...z=1I7GGLJ"[/url"]


[url="http://www.google.co...e7&rlz=1I7GGLJ"
[url="http://"http://www.google.co...z=1I7GGLJ"[/url"]
[url="http://www.google.co...e7&rlz=1I7GGLJ"
  • 0

#40
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
sptd.sys
oleaut32.dll
Appinit_Dlls Worm ?
  • 0

Advertisements


#41
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Have you tried the Vista repair function as opposed to sfc scannow there is a tutorial on how to do it Here that may replace the missing files

But the big question is what deleted those files in the first place. Did you run any scans or use any tools prior to coming here, if so which ?
  • 0

#42
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Jacee found this and I pinched it from her thread try it and see what happens http://software.tech...px?docid=344540
  • 0

#43
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
here are some of the logs
I've never used kazaa don't know where it came from
I tried that program you found things have sure have gotten quicker but the pic's still don't work right


a-squared Free - Version 3.5
Last update: 9/12/2008 12:53:31 PM

Scan settings:

Objects: Memory, Traces, Cookies, C:\, D:\
Scan archives: On
Heuristics: On
ADS Scan: On

Scan start: 9/12/2008 12:54:21 PM

Key: HKEY_USERS\S-1-5-21-239065566-3441178637-797170251-1000\software\kazaa detected: Trace.Registry.KaZaA
Value: HKEY_USERS\S-1-5-21-239065566-3441178637-797170251-1000\Software\RegClean\RegClean\RegClean --> scanonstartup detected: Trace.Registry.RegClean
c:\users\me and my angels 2\appdata\roaming\microsoft\windows\start menu\programs\games detected: Trace.Directory.Fiber Twig 2

Scanned

Files: 11179
Traces: 354484
Cookies: 6
Processes: 81

Found

Files: 0
Traces: 3
Cookies: 0
Processes: 0
Registry keys: 0

Scan end: 9/12/2008 1:05:37 PM
Scan time: 0:11:16


avast! Virus cleaner free

9/3/2008, 2:20:01 PM
Memory scanning started...
No virus body found in memory.
Memory scanning finished (204.1s).
----------


__________________________________________________
ewido anti-spyware online scanner
http://www.ewido.net
__________________________________________________


Name: Adware.CometCursor
Path: HKU\S-1-5-21-239065566-3441178637-797170251-1000\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\205\Shell\{B3690E58-E961-423B-B687-386EBFD83239}\\MaxPos1280x720(1).x
Risk: Medium


DrWeb2

List-C.bat;C:\327882R2FWJFW;Probably BATCH.Virus;;
psexec.cfexe;C:\327882R2FWJFW;Program.PsExec.171;;
psexec.cfexe;C:\ComboFix(0);Program.PsExec.171;;
ACSSETUP.EXE\data008;C:\Documents and Settings\Me and my angels 2\DoctorWeb\Quarantine\ACSSETUP.EXE;Probably BACKDOOR.Trojan;;
ACSSETUP.EXE;C:\Documents and Settings\Me and my angels 2\DoctorWeb\Quarantine;Archive contains infected objects;Moved.;
Beertender2.exe;C:\Documents and Settings\Me and my angels 2\Downloads\Games\Games Folder\Beertender2;Probably DLOADER.Trojan;Moved.;
Beertender2.exe;C:\Users\Me and my angels 2\Downloads\Games\Games Folder\Beertender2;Probably DLOADER.Trojan;Invalid path to file ;

Files scanning started...
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log... file could not be scanned!
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log... file could not be scanned!
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb... file could not be scanned!
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb... file could not be scanned!
C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{885d26af-7884-11dd-882b-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{885d26c5-7884-11dd-882b-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{aeddab62-7460-11dd-9af8-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{aeddae4f-7460-11dd-9af8-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{aeddb153-7460-11dd-9af8-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{aeddb58e-7460-11dd-9af8-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{c0bd201d-79dd-11dd-8dc4-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{c0bd2027-79dd-11dd-8dc4-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{c0bd2031-79dd-11dd-8dc4-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\System Volume Information\{c0bd2043-79dd-11dd-8dc4-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
C:\Users\Me and my angels 2\ntuser.dat.LOG1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbc2e.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbdam... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbdao... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbeam... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbeao... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbu2d.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbvm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\dbvmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\fii.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\fiih.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\hpt2i.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\rpm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\rpm1m.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\rpm1mh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\rpmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-black-enchashm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-black-enchashmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-black-urlm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-black-urlmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-malware-domainm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-malware-domainmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-white-domainm.cf1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Google\Google Desktop\84d901b53bb0\safeweb\goog-white-domainmh.ht1... file could not be scanned!
C:\Users\Me and my angels 2\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1... file could not be scanned!
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1... file could not be scanned!
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat... file could not be scanned!
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat... file could not be scanned!
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1... file could not be scanned!
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0... file could not be scanned!
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0... file could not be scanned!
C:\Windows\System32\catroot2\edb.log... file could not be scanned!
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb... file could not be scanned!
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb... file could not be scanned!
C:\Windows\System32\config\COMPONENTS.LOG1... file could not be scanned!
C:\Windows\System32\config\DEFAULT.LOG1... file could not be scanned!
C:\Windows\System32\config\SAM.LOG1... file could not be scanned!
C:\Windows\System32\config\SECURITY.LOG1... file could not be scanned!
C:\Windows\System32\config\SOFTWARE.LOG1... file could not be scanned!
C:\Windows\System32\config\SOFTWARE.LOG2... file could not be scanned!
C:\Windows\System32\config\SYSTEM.LOG1... file could not be scanned!
C:\Windows\System32\config\RegBack\COMPONENTS... file could not be scanned!
C:\Windows\System32\config\RegBack\DEFAULT... file could not be scanned!
C:\Windows\System32\config\RegBack\SAM... file could not be scanned!
C:\Windows\System32\config\RegBack\SECURITY... file could not be scanned!
C:\Windows\System32\config\RegBack\SOFTWARE... file could not be scanned!
C:\Windows\System32\config\RegBack\SYSTEM... file could not be scanned!
C:\Windows\System32\drivers\sptd.sys... file could not be scanned!
C:\Windows\Temp\TMP0000005CC2F4A9908BFEAE89... file could not be scanned!
C:\Windows\Temp\TMP0000009074D5A322670431A8... file could not be scanned!
D:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
D:\System Volume Information\{c0bd2044-79dd-11dd-8dc4-001636bc1244}{3808876b-c176-4e48-b7ae-04046e6cc752}... file could not be scanned!
No virus body found.
Files scanning finished (215163 files, 0 infected, 3943.0s).
Drives scanned: C: D:
----------


aswBoot

09/04/2008 00:43
Scan of all local drives

File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI-expert_15bots.exe is infected by Win32:Trojan-gen {Other}, Repair: Error 42060 {The file was not repaired.}, Deleted
File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI-expert_31bots.exe is infected by Win32:Trojan-gen {Other}, Repair: Error 42060 {The file was not repaired.}, Deleted
File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI-expert_47bots.exe is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI_15bots.exe is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI_31bots.exe is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI_47bots.exe is infected by Win32:Trojan-gen {Other}, Deleted
Number of searched folders: 25872
Number of tested files: 215965
Number of infected files: 6
  • 0

#44
_The_Nothing_

_The_Nothing_

    Member

  • Topic Starter
  • Member
  • PipPip
  • 72 posts
Trace.Registry.Kazaa google search results

Trace.Registry.RegClean google results nothing found

Trace.Directory.Fiber Twig 2 google search results
  • 0

#45
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Trace directory means that it was an registry entry that may be the remnants of malware

These were because they have the characteristics of malware

C:\Program Files\EA GAMES\Battlefield 2\mods\ultimate\AI_47bots.exe


Bottom line is that I do not believe you have any malware on the system but a lot of the system files/registry are corrupted

I will continue searching for a resolution
  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP