HardwareLogic

Go Back   HardwareLogic > General Discussions > General Computing
Home Forums Rules All AlbumsBlogs Subscriptions Register Mark Forums Read

General Computing Need help with recommendations? Want to discuss general technology issues? This is the place.

Reply
 
LinkBack Thread Tools
Old June 26th, 2007   #1
SB4L!! Oh..and um..C4L...
 
duckingzebra's Avatar
 
Join Date: Nov 2006
Location: Las Vegas, Nevada
Posts: 230
Default ok i got a question

i got to icons on my desktop that my brother got there. he said he downloaded them. one is a "key generator" for some game he plays and the other i have no clue. I try to delete them and it says "cannot delete, it is being used by anoher program." i tried to look in windows task manager for any program that might be running that looked like it had the same names, but couldnt find any. how can i delete them?



Intel Celeron CPU 2.8GHz
MS-6714 Mainboard
Intel 845G Chipset
Intel Integrated 82845G Graphics
40GB UltraDMA Hard Drive
Sony DVD/CD RW
Steady-state 200 watts PSU
duckingzebra is offline   Reply With Quote
Old June 26th, 2007   #2
Yes - the Doctor is back.
 
Dr. V's Avatar
 
Join Date: Nov 2006
Location: Toronto, Ontario, Canada
Posts: 1,698
Default Re: ok i got a question

The first thing you should always do is boot up in SAFE MODE and then try deleting them.

Try that then repost.

Good luck man!



Dr. V is online now   Reply With Quote
Old June 27th, 2007   #3
We take both criticism and positive comments very positively
 
Capper's Avatar
 
Join Date: Dec 2005
Location: Las Vegas, NV
Posts: 5,854
Blog Entries: 6
Default Re: ok i got a question

download "Hijack This" and "CCleaner", and report back



INTEL E8400 // Gigabyte EP45 Extreme // 4GB DDR3-1600 // Palit HD 4870 // Antec 1200 // Seagate 750GB HDD // Zalman CNPS9700 // BFG ES 800W PSU
Capper is online now   Reply With Quote
Old June 27th, 2007   #4
Beer Drinking Association
 
Banditman's Avatar
 
Join Date: Feb 2007
Location: Longview, Texas
Posts: 200
Default Re: ok i got a question

Another solution to your problem is an app called Wholockme. It is not as advanced as Hijackthis but it will let you select files that are in use to be deleted automaticly upon reboot.

|MG| Free Download - WhoLockMe 1.04 Beta



Athlon 64 4000+ 2.4 ghz 2 ghz HT
2 x 1GB PC3200 RAM
LG Lightscribe DVD/CD write 18x/48x read 16x/48x
Windows XP Pro SP 2 & Windows 2000 pro sp4
BFG Geforce 7800 GS OC 256mb running dual displays
Zalman CNPS9500 CPU Cooler
K8 Triton GA-K8U-939 Mobo w/ULI M1689 Chipset
Xion 600W PSU w/dual 12v rails

Banditman is offline   Reply With Quote
Old July 3rd, 2007   #5
SB4L!! Oh..and um..C4L...
 
duckingzebra's Avatar
 
Join Date: Nov 2006
Location: Las Vegas, Nevada
Posts: 230
Default Re: ok i got a question

ok so i tried booting in safe mode, didnt work so now ill try those programs, is there a link on the site to them, i guess i can just google them.

ok i ran HijackThis and since im stupid it told me to show my log to knowledgeable folks so here...

Logfile of HijackThis v1.99.1
Scan saved at 2:10:56 AM, on 7/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Glass2k\Glass2k.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\program files\steam\steam.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = MySpace
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = Play Games, Free Online Games at AddictingGames
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SDWin32 Class - {31822611-3879-4A74-A9AA-416B6AB0F09A} - C:\WINDOWS\System32\dpylg.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll
O4 - HKLM\..\Run: [Glass2k] C:\Program Files\Glass2k\Glass2k.exe
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\ServicePackFiles\i386\msconfig.exe /auto
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxdm006DWUS
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {019330B9-6CF3-42F9-81AF-3712198EBB1A} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (HKCU)
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1172524800968
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/instal...sinstaller.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: Microsoft DirectXb - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Ocbeck32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\system32\ImapiRox.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sprint PCS v3 Utility Service - Sprint Spectrum, L.L.C - C:\Program Files\Sprint\Sprint PCS Connection Manager\CMSPCSUtilSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Ok and i tried to install WhoLockMe and a Ms Dos screen showed up for like half a second and nothing happened...so ya.

Ok and i also installed CCleaner and it got rid of a little more than 2 gigs of crap but didnt fix my original problem.



Intel Celeron CPU 2.8GHz
MS-6714 Mainboard
Intel 845G Chipset
Intel Integrated 82845G Graphics
40GB UltraDMA Hard Drive
Sony DVD/CD RW
Steady-state 200 watts PSU

Last edited by duckingzebra; July 3rd, 2007 at 01:46.
duckingzebra is offline   Reply With Quote
Old July 3rd, 2007   #6
ako the pinoy
 
halutzparilla's Avatar
 
Join Date: Jul 2006
Location: by the beach
Posts: 1,698
Default Re: ok i got a question

CCleaner should help you get rid of those... run cleaner then run for issues it will help you delete those things including the registry they inputed. then check with the ccleaner at tools options in uninstall everything that is installed, you should only have your basic necessity there... any other unknown program google it first if you need it... if not uninstall it...



Abit IP35-E
C2D E6750 G0 @ 2.66ghz [TR Ultra120EX]
EVAG 8800GTS [TR HR03]
Corsair [2gbDual@800]
820GB HDD[120/200/500]
Antec TP 550W
Silverstone Temjin 09
Saitek Eclipse1 & Razer DeathAdder
Windows Vista Ultimate 32bit
halutzparilla is offline   Reply With Quote
Old July 3rd, 2007   #7
Meow means woof in cat.
 
Panda Man's Avatar
 
Join Date: Oct 2006
Location: Elba, AL
Posts: 1,910
Default Re: ok i got a question

Beat your brother for using illegal serials, then try restarting explorer. Go to the task manager, close explorer.exe, go to File>New Task and type "explorer." See if that helps, if not, grab unlocker and use that.

UNLOCKER 1.8.5 BY CEDRICK 'NITCH' COLLOMB

I use unlocker all the time.



Intel Core 2 Duo E6420 Conroe @ 2.80GHz
Cooler Master GeminII - Thanks Rich and HL!
GIGABYTE GA-965P-DS3 (rev. 1.3)
EVGA GeForce 8800GTS 320MB @ 726/962
CORSAIR XMS2 4GB (4 x 1GB) DDR2-800
OCZ GameXStream 600W PSU
Maxtor 300GB 7200RPM SATA150 16MB cache HDD
Seagate 500GB 7200ROM SATA300 16mb cache HDD
Sony NEC Optiarc 18X DVD±R DVD
Creative Sound Blaster X-Fi XtremeMusic 7.1
ZyXel m-202 802.11g adapter
Antec Nine Hundred
Creative 5.1 speakers
Viewsonic Optiquest q20wb 20" LCD
Panda Man is offline   Reply With Quote
Old July 3rd, 2007   #8
Yes - the Doctor is back.
 
Dr. V's Avatar
 
Join Date: Nov 2006
Location: Toronto, Ontario, Canada
Posts: 1,698
Default Re: ok i got a question

Yea definitely beat the brother, and that unlocker isn't bad either - you should be up and running soon enough!



Dr. V is online now   Reply With Quote
Old July 3rd, 2007   #9
Colonel Calamity
 
screwballl's Avatar
 
Join Date: Oct 2006
Location: Sandy South
Posts: 6,279
Blog Entries: 6
Default Re: ok i got a question

you have a Trojan:

O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -

I would suggest getting rid of eTrust anti-virus and getting Avira ( AntiVir PersonalEdition Classic - More than Security ) and also getting a-squared to help with the trojan.

Once these are installed then go to safe mode and run full system scans with both


A few things I saw that may need some cleaning out, this mostly spyware and other problematic junk:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = Play Games, Free Online Games at AddictingGames
O2 - BHO: SDWin32 Class - {31822611-3879-4A74-A9AA-416B6AB0F09A} - C:\WINDOWS\System32\dpylg.dll (file missing)
O2 - BHO: (no name) - {D80C4E21-C346-4E21-8E64-20746AA20AEB} - (no file)

O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML

O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)







Thanks HL and Corsair!

My opinions are my own and not representative of this site or its members.

screwballl is offline   Reply With Quote
Old July 3rd, 2007   #10
SB4L!! Oh..and um..C4L...
 
duckingzebra's Avatar
 
Join Date: Nov 2006
Location: Las Vegas, Nevada
Posts: 230
Default Re: ok i got a question

ok i ran hijackthis again and selected and fixed the problems u mentioned, rescanned and they didnt come up again, so no more trojans? i also dloaded and installed antivir and deleted etrust and when a-squared is done dloading im gonna reboot in safe mode and scan my comp with antivir, a-squared, sb search and destrtoy, and adaware se. so that might take a while, so when i can get rebooted again in normal mode, cause it wont let me access the internet in safe mode, ill report back and have u walk me through getting rid of those to programs on my desktop, cause there still there. nice catch on those trojans though screwball. ok so ill talk to you guys in a little while, which will probably be a lot while cause my comp is slow...lol

Updade:
ok i rebooted in safe mode and ran antivir, a-squared, sb s&d, and adaware se, and got rid of a lot of crap including a couple of trojans. and i had hijackthis delete those programs on a reboot and there gone, so i think problem solved.



Intel Celeron CPU 2.8GHz
MS-6714 Mainboard
Intel 845G Chipset
Intel Integrated 82845G Graphics
40GB UltraDMA Hard Drive
Sony DVD/CD RW
Steady-state 200 watts PSU

Last edited by duckingzebra; July 4th, 2007 at 08:08.
duckingzebra is offline   Reply With Quote
Reply

  HardwareLogic > General Discussions > General Computing

Tags
question


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Question Jokerswild HL Lounge 9 June 24th, 2008 15:20
Question? jayzer General Computing 5 February 14th, 2008 16:23
An odd question Mysterio Internet/Networking 3 March 16th, 2007 17:27
Ask me a Question.... Kiwi2022 HL Lounge 66 March 14th, 2007 16:36
IE7 Question garetjax Software & OSs 18 December 16th, 2006 08:18


All times are GMT -8. The time now is 04:18.


Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
© HardwareLogic 2005 - 2008. All Rights Reserved


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49