 |
07-06-2008, 09:46 AM
|
#1 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
How do i rectify this. [Image Included], Hijackthis log added...
The open and explore options do not show, instead there is some random gibberish.

I've got no idea how this happened, is it a virus or something? HOw do i correct it. Re-installing XP is not an option as i do not have the CD at the moment.
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
Last edited by escape7; 08-06-2008 at 04:01 PM.
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
07-06-2008, 11:58 AM
|
#2 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
Try the usual stuff - Spybot, Ad-Aware, NOD32, HJT.
And this looks like some asian language - you dont have the converter so its displayed as gibberish. What file types is this problem present in? because if its only one or two, you can change it using folder options.
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
07-06-2008, 12:24 PM
|
#3 (permalink)
|
|
The Black Waltz
Join Date: Apr 2008
Location: The Shed
Posts: 1,511
|
Re: How do i rectify this. [Image Included]
as dheeraj mentioned try avast or avg, spybot and all with latest updates. also post hijack this log.
__________________
#krow @ irc.freenode.net
|
|
|
07-06-2008, 02:16 PM
|
#4 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
Re: How do i rectify this. [Image Included]
I've used avg and spbot, there were a few infections but the problem persists. And i feel its not an asian language as they do not open on clicking, an error occurs... I'm typing the name of the drive in the explorer to open it.
How do i get the hijack this log?
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
|
|
|
07-06-2008, 06:47 PM
|
#5 (permalink)
|
|
dá ûnrêäl Kiñg
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
|
Re: How do i rectify this. [Image Included]
do a full system scan with kaspersky, then delete the hidden autorun.inf file in root of every drive to solve the problem.
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
|
|
|
07-06-2008, 07:23 PM
|
#6 (permalink)
|
|
Wise Old Owl
Join Date: Dec 2006
Location: delhi
Posts: 1,429
|
Re: How do i rectify this. [Image Included]
Quote:
Originally Posted by escape7
I've used avg and spbot, there were a few infections but the problem persists. And i feel its not an asian language as they do not open on clicking, an error occurs... I'm typing the name of the drive in the explorer to open it.
How do i get the hijack this log?
|
download hijackthis, http://www.download.com/Trend-Micro-...-10227353.html
and scan it,
then post it here
|
|
|
07-06-2008, 07:37 PM
|
#7 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
And what file types is this problem occuring? And what error do you get upon clicking those options?
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
07-06-2008, 11:01 PM
|
#8 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
Re: How do i rectify this. [Image Included]
Here's the hijackthis log file:
Quote:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:19:31 PM, on 6/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\OfficeScan NT\ntrtscan.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\OfficeScan NT\pccntmon.exe
E:\Tapan\DAEMON Tools Lite\daemon.exe
C:\OfficeScan NT\ofcdog.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\OfficeScan NT\pccntupd.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {487C9905-26A8-42C8-8033-C58AD3D2AEC3} - C:\WINDOWS\system32\fccbYrpN.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\IDM\QUICKF~1\PlugIns\IEHelp.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Tapan\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: fccbYrpN - fccbYrpN.dll (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Unknown owner - C:\OfficeScan NT\tmlisten.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Window Image Worker (windownetpker) - Unknown owner - C:\Program Files\Internet Explorer\svchost.exe (file missing)
--
End of file - 4397 bytes
|
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
|
|
|
07-06-2008, 11:24 PM
|
#9 (permalink)
|
|
God of Mistakes...
Join Date: Dec 2005
Location: Pune, Maharashtra
Posts: 1,923
|
Re: How do i rectify this. [Image Included]
You have to delete autorun.inf file in each drive. It might hidden. So, check for that.
|
|
|
08-06-2008, 01:12 AM
|
#10 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
Yeah, try that. Delete autorun.inf from each drive and restart.
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
08-06-2008, 04:01 PM
|
#11 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
Re: How do i rectify this. [Image Included]
Quote:
Originally Posted by dheeraj_kumar
Yeah, try that. Delete autorun.inf from each drive and restart.
|
I checked the drives, there are no autorun.inf files in them...
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
|
|
|
08-06-2008, 04:06 PM
|
#12 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
They are usually hidden.
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
08-06-2008, 04:12 PM
|
#13 (permalink)
|
|
Debian Gnu/Linux User
Join Date: Jun 2008
Location: Mars
Posts: 556
|
Re: How do i rectify this. [Image Included]
move all the files from root directory.except system files .
__________________
Living for Learning & Learning for Living
|
|
|
08-06-2008, 04:39 PM
|
#14 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
^^ Malware can replicate. So no use.
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
08-06-2008, 08:41 PM
|
#15 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
Re: How do i rectify this. [Image Included]
Quote:
Originally Posted by dheeraj_kumar
They are usually hidden.
|
I know that... can anyone help?
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
|
|
|
08-06-2008, 10:04 PM
|
#16 (permalink)
|
|
Debian Gnu/Linux User
Join Date: Jun 2008
Location: Mars
Posts: 556
|
Re: How do i rectify this. [Image Included]
Try BitDefender Free Edition.. It should remove all threats @ 100$%
but be careful.. it remove all files and registry entry without your intention. even the win system files and registry entres..
But i wil sure Bit Defender engine is the one to remove 100% threats..
Plz try it as final ........
__________________
Living for Learning & Learning for Living
|
|
|
08-06-2008, 10:54 PM
|
#17 (permalink)
|
|
Yalam
Join Date: Jul 2007
Location: Chilgok, South Korea
Posts: 45
|
Re: How do i rectify this. [Image Included]
Use WinRAR to view the drive and it will show all hidden files as well. Delete autorun.inf files from the root of every local and removable drive and restart PC. Else you can also use program like Free Commander and it will show all hidden files. Gud luck!
|
|
|
08-06-2008, 11:34 PM
|
#18 (permalink)
|
|
Legen-wait for it-dary!
Join Date: Dec 2004
Location: Chennai
Posts: 2,471
|
Re: How do i rectify this. [Image Included]
Quote:
Originally Posted by Betruger
Try BitDefender Free Edition.. It should remove all threats @ 100$%
but be careful.. it remove all files and registry entry without your intention. even the win system files and registry entres..
But i wil sure Bit Defender engine is the one to remove 100% threats..
Plz try it as final ........
|
Using different colors make you look like a noob. Not cool.
Bitdefender DOES NOT remove win system files and registry entries. If it does, it means THEY ARE AFFECTED. And if they are affected, you're better off cleaning them rather than working in an affected comp. And BitDefender notifies you and ASKS you what to do, rather than doing it all by itself.
Lol dude, you make it sound like a virus itself
Bitdefender is ranked the best overall antivirus software, and its because it is good, and I choose NOD32 over it only for personal preferences.
__________________
If the Start Windows Restart when Windows starts check box is checked Windows Restart will start automatically every time Windows is started. - Actual excerpt from a windows program help file
|
|
|
09-06-2008, 09:53 AM
|
#19 (permalink)
|
|
Apprentice
Join Date: May 2008
Posts: 64
|
Re: How do i rectify this. [Image Included]
yah! this is due to virus known as CHINESE virus!!
i think ur problem should be solved if u scan it and remove the virus with kaspersky!!
i have seen this problem with people in NEPAL..and if still doesnt..then format it...coz that would be the last option...but however i think if u properly work with it...should solve ur problem!!
good luck
chandal
|
|
|
09-06-2008, 06:33 PM
|
#20 (permalink)
|
|
Wise Old Crow
Join Date: Apr 2005
Location: Inside the Pixel
Posts: 1,227
|
Re: How do i rectify this. [Image Included]
Registry problem i think. If am not wrong some malicious file has added these in Context menu handlers.
Open your Registry Editor and browse through theze keys. See if you can find something.
Quote:
HKEY_CLASSES_ROOT\Folder\shell\
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandle rs
HKEY_CLASSES_ROOT\AllFileSystemObjects\Shellex\Con textMenuHandlers
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
|
or download this free Context Menu Editor.
__________________
http://twitter.com/blueshift155
|
|
|
09-06-2008, 07:41 PM
|
#21 (permalink)
|
|
What? Where? How?
Join Date: Dec 2004
Location: Home
Posts: 402
|
Re: How do i rectify this. [Image Included]
I ran an entire syste scan using AVG, then SysClean, Spybot and a few others and removed all threats, the problem,whatever it was has gone. I just didn't want to format my drive...
Thanks fr all ur help guys, problem solved.
__________________
98% of the people using internet have started or forwarded "chain mails". If you are one of the 98%, Die a horrible death.
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|