User User name Password  
   
Thursday 6.3.2025 / 20:05
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > guyz help me out, frrom this ntndis.exe thing!!
Show topics
 
Forums
Forums
guyz help me out, frrom this ntndis.exe thing!!
  Jump to:
 
Posted Message
jeynash
Junior Member
_
4. December 2007 @ 02:48 _ Link to this message    Send private message to this user   
O my god!! i know what that means. its the windows security center icon.
the icon about which i mention is also like that.( except that it is an animated one. it changes to icon with a cross mark and with a "?" mark.
U gettin me?
Advertisement
_
__
jeynash
Junior Member
_
4. December 2007 @ 02:54 _ Link to this message    Send private message to this user   
And if you dont mind telling me, which time zone are you in??
coz u been solving my problems for almost 5 hrs in continuous....
Senior Member
_
4. December 2007 @ 02:59 _ Link to this message    Send private message to this user   
I'm in the S.F.Bay area, California, US
Yeah, that means your Internet Security Suite, ain't doing it's thing. Get you Internet Security working. Ran a complete virus scan and remove the crap.

This message has been edited since posting. Last time this message was edited on 4. December 2007 @ 03:02

jeynash
Junior Member
_
4. December 2007 @ 03:05 _ Link to this message    Send private message to this user   
me from Kerala, India....
anywayz it was nice to be with you....
Signing off for now!! maybe next time i login, ill find the right solution from you for the problem...rite?
Senior Member
_
4. December 2007 @ 03:11 _ Link to this message    Send private message to this user   
Or from another member. Bye now.
Member
_
4. December 2007 @ 06:04 _ Link to this message    Send private message to this user   
thats no windows security icon. you are trying manually to clean up a smitfraud variant.

look here:
http://www.virusvault.us/smitfraud_trojan_downloaders.htm

there is a automated fix. oddly enough its called smitfraudfix

regards,

echoreply

Senior Member
_
4. December 2007 @ 06:24 _ Link to this message    Send private message to this user   
jeynash,
This red icon in system tray is a Windows Firewall warning. YOUR PC IS NOT PROTECTED: TURN ON WINDOWS FIREWALL. However, please note if your OS is fully updated to Service Pack 2(SP2)and you are already using a Internet Security Suite, such as, McAfee or Norton. You do not need this Windows firewall. Once an Internet Security Suite is fully installed and protecting, the Windows Firewall warning will turn off. After the security software is working go the Windows Security Center and make sure the Windows Firewall is turned off. You will not need two Firewalls. This should correct the problem, unless you have viruses which required a manual removal. Be sure to run a Disk Clean and Disc Defragmenter afterwards. Let me know what happens.

This message has been edited since posting. Last time this message was edited on 4. December 2007 @ 06:26

Member
_
4. December 2007 @ 12:05 _ Link to this message    Send private message to this user   
jeynash,

iam referring to the question mark like icon in your tray, with the ballon msg about being infected-- from the image you posted-- this is the classic sign of a smitfraud infection. it prompts/directs you to download worthless security software.

you said it here:

Quote:
"There is an icon in the task bar, just like the windows security alert,
which cant be found in the "process" in the task manager and i also cant exit the program. when i click it, it opens the internet explorer, and guides to "http://www.antivirgear.com/?aff=1012", which does not exist."


jeynash
Junior Member
_
5. December 2007 @ 06:53 _ Link to this message    Send private message to this user   
i had tried smitfraudfix even days before, but without any success. and for quikdraw, its not the windows security centre icon, it is "like" windows security centre icon.
Senior Member
_
5. December 2007 @ 13:33 _ Link to this message    Send private message to this user   
jeynash
Junior Member
_
5. December 2007 @ 13:50 _ Link to this message    Send private message to this user   
thanx QD, the problem that they described in the page( of the link above) is exactly the same as mine. But the Smitfraud isnt working for me.

Maybe can you check this. this is the log file of the "system scan" using "hijackthis":




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:16:25 AM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\BitTorrent\bittorrent.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=488
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinPatrol] D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\RunServices: [SystemTray Monitor] SysTraymon.exe
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O8 - Extra context menu item: Download all links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{74AC2C92-D280-4080-9A45-42845F903AC2}: NameServer = 218.248.255.145 61.1.96.69
O20 - AppInit_DLLs:
O22 - SharedTaskScheduler: exegeses - {1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f} - D:\WINDOWS\system32\bubbj.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3502 bytes
jeynash
Junior Member
_
5. December 2007 @ 13:54 _ Link to this message    Send private message to this user   
or would this be the problem

i have got

NAME: {438755C2-A8BA-11D1-B96B-00A0C90312E1}
DATA: Browseui preloader

in [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
Senior Member
_
5. December 2007 @ 14:11 _ Link to this message    Send private message to this user   
All you have to do is Google it. Here's the results. http://www.google.com/search?hl=en&q=NAM...G=Google+Search
Member
_
5. December 2007 @ 17:48 _ Link to this message    Send private message to this user   
smitfraud is often updated. delete your copy and run the first step (search) and post the log in next reply:

Download SmitfraudFix (by S!Ri) to your Desktop.

http://siri.urz.free.fr/Fix/SmitfraudFix.exe

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. post log in next reply.

echoreply

jeynash
Junior Member
_
5. December 2007 @ 20:26 _ Link to this message    Send private message to this user   
SmitFraudFix v2.257

Scan done at 6:55:17.56, Thu 12/06/2007
Run from D:\Documents and Settings\anandakrishnan\Desktop\BAjar ARchivos\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

127.0.0.1 legal-at-spybot.info
127.0.0.1 www.legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» D:\


»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32

D:\WINDOWS\system32\bubbj.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\anandakrishnan


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\anandakrishnan\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

D:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
D:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\ANANDA~1\FAVORI~1

D:\DOCUME~1\ANANDA~1\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}"="exegeses"

[HKEY_CLASSES_ROOT\CLSID\{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}\InProcServer32]
@="D:\WINDOWS\system32\bubbj.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}\InProcServer32]
@="D:\WINDOWS\system32\bubbj.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=dword:00000001
"AppInit_DLLs"=" "


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 218.248.255.145
DNS Server Search Order: 61.1.96.69

Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.1.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{74AC2C92-D280-4080-9A45-42845F903AC2}: NameServer=218.248.255.145 61.1.96.69
HKLM\SYSTEM\CCS\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{74AC2C92-D280-4080-9A45-42845F903AC2}: NameServer=218.248.255.145 61.1.96.69
HKLM\SYSTEM\CS2\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
Member
_
5. December 2007 @ 20:33 _ Link to this message    Send private message to this user   
ok. time to run the 2nd step, which has to be done in SAFE MODE.

to reach safe mode you would tap the f8 key during a computer restart
chose the first option from the list: safe mode.
once at the safe mode desktop

you should copy/paste the rest into notepad and save it somewhere so you can read it in safe mode;

locate the smitfraud icon on the desktop and double click it to start.
from the main option menu, chose the second option (clean). after smitfraud runs-- disk clean will run, last when asked if you want to clean the registry, select y (yes) then enter. computer will reboot and after the restart produce a log. please save the log somewhere.
post that log and a new hjt log in next reply.

jeynash
Junior Member
_
5. December 2007 @ 21:04 _ Link to this message    Send private message to this user   
SMITFRAUDFIX LOG AFTER CLEANING

SmitFraudFix v2.257

Scan done at 7:18:22.51, Thu 12/06/2007
Run from D:\Documents and Settings\anandakrishnan\Desktop\BAjar ARchivos\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}"="exegeses"

[HKEY_CLASSES_ROOT\CLSID\{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}\InProcServer32]
@="D:\WINDOWS\system32\bubbj.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1817ab5d-25bf-4d5e-ba90-6e5fe658fc5f}\InProcServer32]
@="D:\WINDOWS\system32\bubbj.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri

D:\WINDOWS\system32\bubbj.dll -> Hoax.Win32.Renos.gen.o
D:\WINDOWS\system32\bubbj.dll -> Deleted


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

D:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
D:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
D:\DOCUME~1\ANANDA~1\FAVORI~1\Online Security Test.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CS1\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{8EFB045B-B454-41EE-91BF-36C22AE0E79A}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
jeynash
Junior Member
_
5. December 2007 @ 21:08 _ Link to this message    Send private message to this user   
HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:20:40 AM, on 12/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Ahead\InCD\InCDsrv.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\userinit.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
D:\Program Files\Internet Download Manager\IDMan.exe
D:\Program Files\Internet Download Manager\IEMonitor.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=488
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinPatrol] D:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\RunServices: [SystemTray Monitor] SysTraymon.exe
O4 - HKCU\..\Run: [IDMan] D:\Program Files\Internet Download Manager\IDMan.exe /onboot
O8 - Extra context menu item: Download all links with IDM - D:\Program Files\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - D:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - D:\Program Files\Internet Download Manager\IEExt.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs:
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3002 bytes
Senior Member
_
5. December 2007 @ 21:37 _ Link to this message    Send private message to this user   
Here check these freeware programs, too.
http://www.majorgeeks.com/download506.html
http://www.safer-networking.org/en/download/
http://www.javacoolsoftware.com/spywareblaster.html
In the log report are a few (BHO) Browser Helper Object, and ActiveX. These may be or may not be considered spyware. All depends on the program.

This message has been edited since posting. Last time this message was edited on 5. December 2007 @ 21:44

jeynash
Junior Member
_
5. December 2007 @ 22:21 _ Link to this message    Send private message to this user   
Thumbs up for echoreply and QuikDraw. I eliminated the malware. Thanks 2 Smitfraud n HijackThis n etc. etc...
A great support from the afterdawn team once again. Hurray!! guyz! u rock.
Senior Member
_
5. December 2007 @ 23:02 _ Link to this message    Send private message to this user   
jeynash
Junior Member
_
6. December 2007 @ 00:45 _ Link to this message    Send private message to this user   
gr8! dat one was one of ma favorites!!!
Senior Member
_
6. December 2007 @ 01:08 _ Link to this message    Send private message to this user   
dun dah dah dah dun dun dun dun... wahoo! LOL
Goes something like that.
Hey, now that the bugs are out.
RESET your browser
Configure your startups
Run Disk Cleanup &
Disk Defragmenter.
You can run a registry cleaner, if you know what to remove.

THEN BOB'S YOUR UNCLE!
jeynash
Junior Member
_
6. December 2007 @ 01:21 _ Link to this message    Send private message to this user   
that was pretty clean and complete!
may i have your email.... mail me at jeynash@hotmail.com
Advertisement
_
__
 
_
Senior Member
_
6. December 2007 @ 01:39 _ Link to this message    Send private message to this user   
I can give you an alternate email on a PM. Did you know adbots are on chats and help sites? Waiting for some dummy to post their main email address. Next thing ya got is 20 to 50 SPAMS per day! Ever seen the movie, Cool Hand Luke? Come men you just can't...

This message has been edited since posting. Last time this message was edited on 6. December 2007 @ 01:46

 
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > guyz help me out, frrom this ntndis.exe thing!!
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork