Problems With Imaging Programs; possible virus Whe

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

Post Reply
User avatar
Lord Poe
Sith Apprentice
Posts: 6988
Joined: 2002-07-14 03:15am
Location: Callyfornia
Contact:

Problems With Imaging Programs; possible virus Whe

Post by Lord Poe »

I've been having problem on my computer ever since I installed AOL 9.0

All my image editing programs wouldn't work. If I tried to open an image file, the program would freeze. I uninstalled both and just re-installed Photoshop Elements. So far, it works ok.

However, my Webgraphics Optimizer has the exact same problem. I uninstalled it, then re-installed it, but it still freezes up when I try to open a file. However, it will work if I choose a file in the "history" links it has worked on before.

Recently, I unplugged my scanner for cleaning, and plugged it back in a few days ago. My PE program said it had trouble with the TWAIN drivers or some such. I re-installed the scanner's drivers too.

And, there's this downloadable program in my Windows called "brid.class" that I've sucessfully damaged, but can't get rid of. When I start my computer now, something called "Java Virtual Machine" says it can't load.

There's a program on my HD called Webrebates (by Toprebates.com) that stays in the Add/Remove box because when I try to delete it, that "Java Virtual Machine" box comes up. Suggestions?
Image

"Brian, if I parked a supertanker in Central Park, painted it neon orange, and set it on fire, it would be less obvious than your stupidity." --RedImperator
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Post by General Zod »

run spybot, cwshredder and ad-aware. also do a hijack-this! log scan. the combination of these should be enough to remove whatever's troubling yer system.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
Lord Poe
Sith Apprentice
Posts: 6988
Joined: 2002-07-14 03:15am
Location: Callyfornia
Contact:

Post by Lord Poe »

This is my Hijack This log:

Logfile of HijackThis v1.97.7
Scan saved at 4:46:50 PM, on 6/3/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v5.50 (5.50.4134.0100)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\BCMDMMSG.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\WEBSCANX.EXE
C:\WINDOWS\SYSTEM\HIDSERV.EXE
C:\COMPAQ\CPQINET\CPQINET.EXE
C:\PROGRAM FILES\COMPAQ\DIGITAL DASHBOARD\DEVGULP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\ALOGSERV.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MOZILLAFIREBIRD\MOZILLAFIREBIRD.EXE
C:\AAAAA\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/red ... er&LC=0409
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\BRIDGE.DLL
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [CPQInet] c:\compaq\CPQInet\CpqInet.exe
O4 - HKLM\..\Run: [Digital Dashboard] C:Program Files\Compaq\Digital Dashboard\DevGulp.exe
O4 - HKLM\..\Run: [BCMDMMSG] BCMDMMSG.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [XupiterToolbarLoader] C:\Program Files\Xupiter\XupiterToolbarLoader.exe
O4 - HKLM\..\Run: [SJZQGXNE] C:\WINDOWS\SJZQGXNE.exe
O4 - HKLM\..\Run: [datit] C:\WINDOWS\datit.exe
O4 - HKLM\..\Run: [H.EXE] C:\WINDOWS\TEMP\H.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [RNBOStart] C:\WINDOWS\SYSTEM\RNBOSENT\SENTSTRT.EXE
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [MoneyAgent] "c:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward &Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O9 - Extra button: Translate (HKLM)
O9 - Extra 'Tools' menuitem: AV &Translate (HKLM)
O9 - Extra 'Tools' menuitem: &Find Pages Linking to this URL (HKLM)
O9 - Extra 'Tools' menuitem: Find Other Pages on this &Host (HKLM)
O9 - Extra 'Tools' menuitem: AV Live (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: AOL Instant Messenger (SM) (HKLM)
O9 - Extra button: Microsoft® JavaScript® Console (HKLM)
O9 - Extra 'Tools' menuitem: JavaScript Console (HKLM)
O9 - Extra button: Microsoft® JavaScript® Console (HKCU)
O9 - Extra 'Tools' menuitem: JavaScript Console (HKCU)
O12 - Plugin for .swf: C:\PROGRAM FILES\NETSCAPE\COMMUNICATOR\PROGRAM\PLUGINS\npswf32.dll
O16 - DPF: {E344ADA2-75B6-4E7E-B221-0A04FD5B0165} (MaxisPublishX Control) - http://thesims.ea.com/us/teleport/MaxisPublishX.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/ ... acscom.cab
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://www2.flingstone.com/cab/98ME/CDTInc/bridge.cab
Image

"Brian, if I parked a supertanker in Central Park, painted it neon orange, and set it on fire, it would be less obvious than your stupidity." --RedImperator
darthdavid
Pathetic Attention Whore
Posts: 5470
Joined: 2003-02-17 12:04pm
Location: Bat Country!

Post by darthdavid »

OI GODS!!!! YOU'RE USING ME. :banghead: . Gak, you'd be better off using windows 3.x... Any way, get rid of anything pertaining to xupiter, like this

Code: Select all

 to O4 - HKLM\..\Run: [XupiterToolbarLoader] C:\Program Files\Xupiter\XupiterToolbarLoader.exe 
It's spyware and bad ju ju to boot. I don't know about much else as i'm not the best expert but i can tell you that i'm getting a bad vibe from alot of stuff. And really, i must ask, why are you using aohell? It's t3h sheete and needs to die. You can get dsl for the same price and avoid all their bloated crap.
User avatar
Lord Poe
Sith Apprentice
Posts: 6988
Joined: 2002-07-14 03:15am
Location: Callyfornia
Contact:

Post by Lord Poe »

darthdavid wrote:OI GODS!!!! YOU'RE USING ME.


Ok, ok...calm down with the EVil Microsoft and AOL rant. I use AOL for work, I use ME because everyone screams about how much XP sucks, and wishes they had Win95.
Image

"Brian, if I parked a supertanker in Central Park, painted it neon orange, and set it on fire, it would be less obvious than your stupidity." --RedImperator
darthdavid
Pathetic Attention Whore
Posts: 5470
Joined: 2003-02-17 12:04pm
Location: Bat Country!

Post by darthdavid »

Lord Poe wrote:
darthdavid wrote:OI GODS!!!! YOU'RE USING ME.


Ok, ok...calm down with the EVil Microsoft and AOL rant. I use AOL for work, I use ME because everyone screams about how much XP sucks, and wishes they had Win95.
I'm using 2000 pro. It's better than ME for sure. Hell, if you stuck an AOL 4.0 CD inbetween the halves of a bagel and then rammed an ide cable into said bagel it would act as a better OS than ME. Anyway, i can understand being forced into using a particualr ISP due to ones job. Now i know for sure you need to nuke xuipiter though. Beyond that i'd beg Ein to look over your logs, he's got a spydar like no one's busieness.
User avatar
beyond hope
Jedi Council Member
Posts: 1608
Joined: 2002-08-19 07:08pm

Post by beyond hope »

Aside from Xupiter you also have BlazeFind. It's that "2_0_1browserhelper2.dll " browser help object. I found the info here.
User avatar
The Wookiee
Lex Wookos
Posts: 1650
Joined: 2003-05-29 04:17am
Location: Tearing your arms off

Post by The Wookiee »

Recommend you delete these.
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:\WINDOWS\SYSTEM\NZDD.DLL
O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll
O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\BRIDGE.DLL
O4 - HKLM\..\Run: [XupiterToolbarLoader] C:\Program Files\Xupiter\XupiterToolbarLoader.exe
O4 - HKLM\..\Run: [SJZQGXNE] C:\WINDOWS\SJZQGXNE.exe
O4 - HKLM\..\Run: [datit] C:\WINDOWS\datit.exe
O4 - HKLM\..\Run: [H.EXE] C:\WINDOWS\TEMP\H.EXE
O4 - HKLM\..\RunServices: [RNBOStart] C:\WINDOWS\SYSTEM\RNBOSENT\SENTSTRT.EXE
O16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) - http://www2.flingstone.com/cab/98ME/CDTInc/bridge.cab
Image
"I suggest a new strategy, Artoo: Let The Wookiee win."
SDnet BBS Administrator: Service With A Roar (And A Hydrospanner)
Knight of the Order of the Galactic Empire


Do not taunt The Wookiee.
User avatar
Vertigo1
Defender of the Night
Posts: 4720
Joined: 2002-08-12 12:47am
Location: Tennessee, USA
Contact:

Post by Vertigo1 »

Lord Poe wrote:I use ME because everyone screams about how much XP sucks, and wishes they had Win95.
And those people are fucking morons that don't even know how to properly use a computer. I've been using XP for over two years now and I've yet to have any real major problems with it. Any problems I've had were minor third party software issues at the very start, and haven't been encountered since.
"I once asked Rebecca to sing Happy Birthday to me during sex. That was funny, especially since I timed my thrusts to sync up with the words. And yes, it was my birthday." - Darth Wong

Leader of the SD.Net Gargoyle Clan | Spacebattles Firstone | Twitter
User avatar
Lord Poe
Sith Apprentice
Posts: 6988
Joined: 2002-07-14 03:15am
Location: Callyfornia
Contact:

Post by Lord Poe »

Thanks all, for your help!
Vertigo1 wrote:And those people are fucking morons that don't even know how to properly use a computer. I've been using XP for over two years now and I've yet to have any real major problems with it. Any problems I've had were minor third party software issues at the very start, and haven't been encountered since.
Hmm.. Should I upgrade to XP on a Pentium 3? And would I have to back up my entire HD?
Image

"Brian, if I parked a supertanker in Central Park, painted it neon orange, and set it on fire, it would be less obvious than your stupidity." --RedImperator
User avatar
Vendetta
Emperor's Hand
Posts: 10895
Joined: 2002-07-07 04:57pm
Location: Sheffield, UK

Post by Vendetta »

The baseline for sensibly using XP is about 600MHz (the absolute minimum is 350).

It's basiclaly just 2000 with a sub-Aqua interface overhaul. It's no more or less secure or stable when beaten into shape, and it boots quicker.
darthdavid
Pathetic Attention Whore
Posts: 5470
Joined: 2003-02-17 12:04pm
Location: Bat Country!

Post by darthdavid »

Lord Poe wrote:Thanks all, for your help!
Vertigo1 wrote:And those people are fucking morons that don't even know how to properly use a computer. I've been using XP for over two years now and I've yet to have any real major problems with it. Any problems I've had were minor third party software issues at the very start, and haven't been encountered since.
Hmm.. Should I upgrade to XP on a Pentium 3? And would I have to back up my entire HD?
Yes and yes. You'll be wanting to use NTFS as opposed to the FAT 32 me uses and that would require you send your data somewhere else while you install and get it stable.
Post Reply