BlackHawk66
November 13th, 2003, 11:02 AM
Hi again.
Only been here long enough for a couple of posts, but I've learned alot just lurking. ;D
As I said in my first or second post, I've just recently (9, November 2003) reformated and reinstalled windows 98se. After installing SpywareGuard it found this:
NEW BHO DETECTION ALERT
On 08:47:08 11/12/2003 a new BHO installation attempt was detected.
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
ProgramID: AcroIEHelper.AcroIEHlprObj.1
File Location: C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
User Action Taken: REMOVE BHO
I'm not quite sure what yet what a BHO is but, as I didn't ask Adobe for it, I took the above action.
Coincidentally, the night I installed Adobe (before learning of Spyware Guard) my wife complained that her Slimbrowser was acting up.....badly. Refusing to minimize and generally locking up the system to the point of requiring a manual shutdown. She hasn't tried it since I removed the BHO.
I personally have started having problems with my preferred browser, Opera 7.2. Mostly "has performed an illegal operation and will now shutdown". This seems to be happening more and more at the same time I'm noticing the computer does not want to shutdown properly.
Not knowing what I'm looking at in the following log ???, I can only say that my wife does run Yahoo! Messenger while browsing to notify her of e-mails and keep in touch with friends. She also does a bit of selling on E-bay if that helps explain some of the entries.
Any help would be much appreciated.
Logfile of HijackThis v1.97.6
Scan saved at 10:51:49 AM, on 11/13/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
C:\DOWNLOADEDPROGRAMS\SECURITY\HIJACK THIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi1.ebay.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://mail.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
[EDITED to take out ebay users account] Unzy
Only been here long enough for a couple of posts, but I've learned alot just lurking. ;D
As I said in my first or second post, I've just recently (9, November 2003) reformated and reinstalled windows 98se. After installing SpywareGuard it found this:
NEW BHO DETECTION ALERT
On 08:47:08 11/12/2003 a new BHO installation attempt was detected.
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
ProgramID: AcroIEHelper.AcroIEHlprObj.1
File Location: C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
User Action Taken: REMOVE BHO
I'm not quite sure what yet what a BHO is but, as I didn't ask Adobe for it, I took the above action.
Coincidentally, the night I installed Adobe (before learning of Spyware Guard) my wife complained that her Slimbrowser was acting up.....badly. Refusing to minimize and generally locking up the system to the point of requiring a manual shutdown. She hasn't tried it since I removed the BHO.
I personally have started having problems with my preferred browser, Opera 7.2. Mostly "has performed an illegal operation and will now shutdown". This seems to be happening more and more at the same time I'm noticing the computer does not want to shutdown properly.
Not knowing what I'm looking at in the following log ???, I can only say that my wife does run Yahoo! Messenger while browsing to notify her of e-mails and keep in touch with friends. She also does a bit of selling on E-bay if that helps explain some of the entries.
Any help would be much appreciated.
Logfile of HijackThis v1.97.6
Scan saved at 10:51:49 AM, on 11/13/03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2614.3500)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\OPERA7\OPERA.EXE
C:\DOWNLOADEDPROGRAMS\SECURITY\HIJACK THIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://cgi1.ebay.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://mail.yahoo.com/
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
[EDITED to take out ebay users account] Unzy