Jump to content

<<< 12Oz Computer Tech Support SuperThread >>>


Mainter

Recommended Posts

This forum is supported by the 12ozProphet Shop, so go buy a shirt and help support!
This forum is brought to you by the 12ozProphet Shop.
This forum is brought to you by the 12oz Shop.

There's a scumware plague at the moment. All it takes is a visit to a pushy web site or a "loaded" shareware install and next minute yer Internet Explorer homepage has been changed, yer default search setting altered, unwanted ads pop up on yer screen and worse.

 

If you use Windows 2000 or later my top recommendation for safe browsing is a free program called Sandboxie [1] that creates a special contained "sandbox" environment on yer PC. While browsing within the virtual sandbox provided by Sandboxie you are totally corralled off from other parts of yer PC. So any files you download are isolated to the sandbox. Similarly, any programs that are executed only do so within the sandbox and have no access to yer normal files, the Windows operating system or any other part of yer PC.

 

Usage is remarkably simple. To start a sandboxed browsing session you just click the Sandboxie icon from the Quick Launch tray and this will launch yer default browser in the sandbox. You can then use it in the normal way to browse to sites or download files.

 

If you download a file it will install normally but again will be corralled off from yer real PC as any new processes running in yer computer memory or entries in the Windows startup areas will be sandboxed.

 

After you have finished browsing you can right click the Sandboxie icon and delete all sandboxed files and processes and yer PC will be returned to much the same state it was in before the browsing session. If you want retain particular downloaded files you can save them permanently before clearing the contents of the Sandbox.

 

The advantage is clear: any spyware, trojans, keyloggers or other malware products that infected yer PC while browsing will be eliminated.

 

Sandboxie works fine with all browsers but requires Windows 2000 and later. It can cause problems on some PCs so backup before installing.

 

 

 

http://www.sandboxie.com Free for personal use, Win2K and later

http://www.javacoolsoftware.com/spywareblaster.html Freeware, all Windows version

http://www.javacoolsoftware.com/spywareguard.html Freeware, All Windows versions

Link to comment
Share on other sites

Best Free Anonymous Surfing Service

 

There are lots of reasons folks have for wanting to surf anonymously, ranging from simple paranoia to possibly being murdered by a malevolent foreign government. Whatever the reasons, commercial services that offer anonymity are doing real well. However one of the best services JAP [1], is totally free. In fact JAP is perhaps a little too good. That's why the German Police insisted in 2004 that a backdoor be put into the product to allow interception of child pornographers. This was done but subsequently removed as a result of court action by JAP.

 

An alternative to JAP is a system called Tor It not only allows anonymous browsing but anonymous P2P, email, IM, and IRC chat as well. Given the US Navy origin of Tor, the suspicion arises that this system may indeed have a permanent backdoor. However the source code is now publicly available so that suspicion can perhaps be set aside. More worrying was a raid by German police in September 2006 involving the seizing of some Tor servers in that country. Again, pedophiles were the supposed target but who really knows.

 

Whatever, both JAP and Tor offer a level of secrecy that is better than many commercial systems though not watertight. Do expect your surfing to slow down as you'll be relayed through a chain of servers particularly with Tor which has been ground to a near standstill by BitTorrent users seeking to hide from the RIAA. Note: the latest V5 release of JAP now allows Tor users to use JAP as a software access point.

 

A recent development is the release of the XeroBank Browser previously called TorPark, a special version of the Firefox browser that has been configured to work with the free Tor anonymizing service and run directly from a USB flash drive. It's a neat idea; just plug in your USB stick to any PC with a USB port and Firefox V2 is automatically launched, set up for secure and private surfing.

 

The most obvious application is internet cafes, public terminals or indeed any PC including your own where you don't want to leave any trace of your private surfing activities. However, what attracts me is not so much the privacy side as the security potential. That's because TorPark creates a secure encrypted connection between the PC you are using and the first Tor server. This allows you to safely transmit information without fear of interception. This makes it ideal for surfing on open Wi-Fi networks. Previously, secure surfing on such networks required the use of private VPN networks, an option only available to corporates, the well-heeled and the technically savvy. Now, using XeroBank Browser, any surfer can reap the same security benefits for their browsing.

 

[1] http://anon.inf.tu-dresden.de/index_en.html Freeware, Any Windows system with Java, 5.5MB

[2] http://tor.eff.org/ Free BSD License, All Windows, 6.3MB

[3] http://www.xerobank.com/xB_browser.html Freeware, Windows NT and later, 8.8MB

 

 

written by techsupportalert

Link to comment
Share on other sites

well first off you should have yer media/ most valuable data on a separate hard drive or at least a separate partition

 

if you dont yer fault get the ol cd/dvd -r's and start making backups

 

on how to boot to cd is depenedent on the kind of bios you have on yer computer most common its going to be f2 key when the computer boots up you should see some type of prompt stating press ( ) to enter BIOS when you get into the bios select boot order and select cd exit and save do not touch anything else or you will be fucked and have a brick on yer hands

 

if the f2 key does not work try esc/ del or f1

Link to comment
Share on other sites

i got a couple of viruses that keep popping up after a reboot... i select move to chest in avast and they seem to go away but every time i restart they pop up again???? i select delete and same result....

 

Win32:Zapchast-Dk in C:\WINDOWS\WINDOWS\protection.nrp

 

&

 

Win32:Nuclear-AP in C:\WINDOWS\WINDOWS\install.sys

 

i have run full scans in and out of safe mode... with system restore turned off... any ideas????

 

 

ps. they came with a copy of magic ISO that i dl'ed...

Link to comment
Share on other sites

Best Free Anti-Virus Software

 

If you are looking for the best possible protection my top recommendation is Avira AntiVir Personal Edition Classic [1]. Although its detection rate is outstanding there are some reservations. First it lacks email scanning; this is only available in the paid version. That means that AntiVir won't warn you about any infected emails before you open them. However should you open an infected email then AntiVir will still spring into action, so not having an email scanner doesn't mean you are not protected from email based infections. My second reservation is that AntiVir is quite an intrusive product - you will certainly be well aware of its presence. Finally AntiVir Personal Edition Classic has a time limited license. It is renewable but be aware you will have to periodically go through the hoops.

 

If you not prepared to accept the drawbacks to AntiVir I would suggest either AVG Antivirus 7 Free Edition [2] or the Avast! scanner [3]. Neither is quite as effective in detection as AntiVir however they are both more complete products and less intrusive in use.

 

AVG Free has been continuously refined since it was first released in 1991 and the recently released V7.5 makes further improvements to an already solid product. Additionally, it's relatively small, light on resources, has regular automatic updates and handles email scanning. There is a free and a pro version, the only difference being that the free version has a few non-critical features disabled and has no technical support other than a free user forum .

 

Equally effective is the free Avast! scanner [3] though its funky media player style interface is not to everyone's taste. Avast! also required periodic re-registration while AVG does not. However Avast! does not seem to suffer the signature file update problems that plague some AVG users.

 

AVG and Avast! are excellent free products that will meet the needs of most users. However none of these offer the best malware detection available. That title belongs to commercial products like NOD32, F-Secure, the full versions of AntiVir, Kaspersky AV and others. They are however capable packages that offer the financially challenged a real alternative to the major anti-virus suites.

 

However if you use AVG and Avast! in conjunction with a sandbox for surfing (see section 4) and an anti-spyware product (see section 3) you can achieve a level of protection approaching that offered by the best commercial AV products.

 

Further improvement is possible running regular on-demand scans with a different anti-virus product.

 

On-demand scans should be run regularly, at least weekly, to check for viruses and other malware that may have been missed by your main scanner.

 

A good option for on-demand scanning is the free version of the commercial AV product BitDefender [4]. It's a first class product with excellent detection rates but as the free version lacks an email scanner and a resident virus guard, it's only really suited for use as an on-demand scanner rather than your main AV product. There are some other limitations as well. First it has an annoying habit of detecting malware products that have been quarantined by other security products and you can't exclude these areas from subsequent scans. Secondly, it is only available on a one year non-renewable license.

 

 

http://www.free-av.com (8.7MB)

http://free.grisoft.com/freeweb.php/doc/2/ (16.0MB)

http://www.avast.com/eng/avast_4_home.html (8.8MB)

http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html (13.2MB)

  • Like 1
Link to comment
Share on other sites

johnny: get hijack this!

and google "hijack this log analyzer"

run a scan and save the log, copy/paste to log analyzer

and take care of what it says you need to take care of.

 

i also recommend "a squared free"

 

free and good. all kinds of trojans it kills.

 

 

hydrogen peroxide: www.serialz.to

 

ok im doing that now.....

 

another question: is starwindservice.exe a bad thing? it started when i opened alcohol portable and windows is trying to block it..... google didnt really get me any straight answers...

 

and one more: i have a netopia 4652 sdsl/isdl router thats brand new.... i havve no use for it i dont think... is it any good? does anyone want it? cuz ima throw it out if not..... im trying to clean shit up.... im a fucking pack rat oner,,, i dont throw anything away and the pile of retarded shit is starting to get out of hand....

Link to comment
Share on other sites

Visitor's assessment Analyzerdetails

O4 - HKLM\..\Run: [install] C:\WINDOWS\WINDOWS\install.exe

 

Kind

 

 

Must be fixed! Added by the BANCBAN-HG TROJAN!Visitor's assessment Analyzerdetails

O4 - HKLM\..\Run: [install] C:\WINDOWS\WINDOWS\install.exe

 

Kind

 

 

Must be fixed! Added by the BANCBAN-HG TROJAN!

 

this doesnt help me... how do i fucking fix it?

Link to comment
Share on other sites

seriously... wtf?

 

 

Logfile of HijackThis v1.99.1

Scan saved at 12:13:56 AM, on 10/20/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16544)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Softex\OmniPass\Omniserv.exe

C:\WINDOWS\system32\Tablet.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Softex\OmniPass\OPXPApp.exe

C:\WINDOWS\Explorer.EXE

C:\windows\system\hpsysdrv.exe

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\HP\KBD\KBD.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Messenger\MSMSGS.EXE

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\PeerGuardian2\pg2.exe

C:\WINDOWS\system32\WTablet\TabUserW.exe

C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\BitLord\BitLord.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Owner\Application Data\Thinstall\{E9F81423-211E-46B6-9AE0-38568BC5CF6F}\4000003a00003i\StarWindService.exe

C:\Documents and Settings\Owner\Desktop\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus8.hpwis.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus8.hpwis.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-qus8.hpwis.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://qus8.hpwis.com/

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE

O4 - HKLM\..\Run: [storageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [install] C:\WINDOWS\WINDOWS\install.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe

O4 - HKCU\..\Run: [install] C:\WINDOWS\WINDOWS\install.exe

O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe

O4 - Global Startup: Wireless PCI Card Configuration Utility.lnk = C:\Program Files\Linksys\WMP11 Config Utility\WMP11CFG.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1190275555125

O17 - HKLM\System\CCS\Services\Tcpip\..\{E92FD7B3-8E53-4772-9AC4-2F9B6F7C5543}: NameServer = 68.87.71.226,68.87.73.242

O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll

O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe

O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...