Windows Support Forum

Post-Platform User Agent String and IE11 F12 User Agent String Change

Q: Post-Platform User Agent String and IE11 F12 User Agent String Change

Hi
We have a custom User Agent String defined on our clients. When I change IE9 to Compatibility Mode (over F12 Developer Toolbar), the User Agent String changed and the custom definied token stayed.
When I change the User Agent String in IE11 (e.g. to IE9) over F12, the custom definied User Agent String is removed.
Is this by default and is there another way to change the user agent string for troubleshooting but keep the custom definied token?

Regards,
Stephan

Relevancy 100%
Preferred Solution: Post-Platform User Agent String and IE11 F12 User Agent String Change

I recommend downloading and running Reimage. It's a computer repair tool that has been proven to identify and fix many Windows problems with a high level of success.

I've used it in the past to identify and fix everything from blue screens (BSOD's), ActiveX errors, corrupt files and processes, dll/exe/sys errors, recover lost memory, Windows update problems, defragging, malware removal etc.

You can download it direct from this link http://downloadreimage.com/directdownload.php. (This link will automatically start a download of Reimage that you can save to your computer.)

A: Post-Platform User Agent String and IE11 F12 User Agent String Change

Hi,
no.. you have to add the custom token to both the x86 and x64 registry nodes.
Using userAgent sniffing is not Best Practices however. I highly recommend that you do not use it, also your ActiveX controls or plugable protocols should not use version sniffing from either the IE version vector or the iexplore.exe. Your long
term strategy should be towards addons and plugins free browsing wih html5 and native support in the OS.
To detect the presence of an ActiveX control on a client you can user new ActiveXControl ('clsid'). As well Enhanced protected mode IE9 also introduced ActiveX filtering which blocks ActiveX controls from loading (see Tools>ActiveX filtering), so you
have to feature test both for bitness and if new ActiveXcontrol('clsid')... you should distribute both x86 and x64 versions of your ActiveX controls (for public websites). By default EPM is turned off for the Trusted and Intanet zones.
You can determine the bitness of a website frame by typing
navigator.platform
in the Dev tools console or examining the UAS for the win64 token.
Is there any reason why you have not yet upgraded to IE11? Please see
http://blogs.msdn.com/b/ie/archive/2014/04/02/stay-up-to-date-with-enterprise-mode-for-internet-explorer-11.aspx
Post questions about html, css and scripting for website development to
https://social.msdn.microsoft.com/Forums/ie/en-US/home?forum=iewebdevelopment&prof=required
Include with your questions a link to your website or a mashup (jsfiddle) that shows the issue.
If it relates to an intranet site then you may like to arrange a support ticket with a MS Engineer from support.microsoft.com.

Regards.
Questions regarding Internet Explorer 8, 9 and 10 and Internet Explorer 11 for the IT Pro Audience. Topics covered are: Installation, Deployment, Configuration, Security, Group Policy, Management questions. If you are a consumer looking for answers or to
raise a question, it's highly recommended you head on over to http://answers.microsoft.com/en-us
Rob^_^

https://social.technet.microsoft.com/Forums/en-US/263790db-2f57-4aa5-9785-4dd5176567b8/postplatform-user-agent-string-and-ie11-f12-user-agent-string-change?forum=ieitprocurrentver
Relevancy 156.86%

We upgraded all our users to IE11 so they would work with a lot of the newer sites.  We've run into an issue now to where one website will not operate properly.  We've tried adding it to compatibility mode, enterprise mode, etc and it doesn't
change anything.  The only thing that works is using the developer tools and changing the user agent to IE8 and then the site functions properly, but as soon as you close the browser the UA goes back to 11.  Is there a way to specify what UA to use
FOR A SPECIFIC SITE.  I know there are registry entries to change it in IE for every site, but I want to know if there is a way to do this on a per site basis.   Thanks!

https://social.technet.microsoft.com/Forums/en-US/92902ffe-7837-4628-8cf8-7a7ad9ea702c/change-user-agent-string-for-specific-site-ie11?forum=ieitprocurrentver
Relevancy 122.76%

I have IE 8 on my computer but my some website's see it as IE 6 and won't let me access the web site. I understand that I have a corrupted User-Agent String but I don't understand the fix. Microsofts fix for it reads like stereo instructions. Can someone assist me in understanding it and correcting my problem?

A:corrupted User-Agent String

Why not simply repair/reinstall IE 8, if that's the problem?

How to reinstall or repair Internet Explorer and Outlook Express in Windows XP - http://support.microsoft.com/default.aspx?kbid=318378

I would probably try the Fixit tool on that link, first.

Louis

http://www.bleepingcomputer.com/forums/t/399479/corrupted-user-agent-string/
Relevancy 118.73%

Hi all,
tiny netbook running windows 7.
Some massive javascriptey pages take a while to load, and while usable, aren't very smooth.

Anyone have any suggestions for user agent strings so that I get redirected to mobile versions of sites?

My main issue is finding a User Agent that identifies as mobile/tablet but also allows flash (on Youtube) or HTML5 video, as opposed to using the RSTP thing or whatever it is.

I'm using Opera Mobile's one at the moment. Seems to be mostly good!
Opera/12.02 (Android 4.1; Linux; Opera Mobi/ADR-1111101157; U; en-US) Presto/2.9.201 Version/12.02

My actual browser is Firefox, though that's not that important.

Anyone know of a mobile user agent that allows flash?

thanks ~

A:User Agent String spoof suggestion for low bandwidth/resource env?

Well, if you use Firefox on Windows 7 you might consider using such lovely add-on as NoScript. It blocks all scripts out of the box, but you can add needed websites (like youtube) to the white list.

http://www.sevenforums.com/browsers-mail/262148-user-agent-string-spoof-suggestion-low-bandwidth-resource-env.html
Relevancy 112.84%

IE with the latest June patches on Windows Windows and the latest Windows is IE user (after patches) causing June websites incorrectly agent string to reporting display 11 incorrect an 2016 Insider Build reports that it is IE thus causing many websites to display incorrectly As evidence using the site http useragentstring com IE is sending the following string nbsp quot Mozilla compatible MSIE Windows NT WOW Trident NET C NET E NET CLR NET CLR NET CLR InfoPath quot nbsp nbsp This suggests that IE nbsp is telling websites that it is Internet Explorer nbsp I reported this on July st IE 11 is reporting an incorrect user agent string (after June 2016 patches) causing websites to display incorrectly http answers microsoft com en-us windows IE 11 is reporting an incorrect user agent string (after June 2016 patches) causing websites to display incorrectly forum windows -networking when-using-ie- -google-calendar-says df - c - - b - f e b a auth and it doesn't appear to have been taken seriously Our IT folks are asking us to abandon IE and switch to Chrome nbsp Please Make a hotfix available prior to the next Patch Tuesday Make sure this is fixed before the Windows Anniversary Build is completed this month Make sure that a fix is included in the July Patch Tuesday PLEASE TAKE THIS BUG REPORT SERIOUSLY

https://social.technet.microsoft.com/Forums/en-US/85dae816-b7e6-44a2-974c-1845ca5ae280/ie-11-is-reporting-an-incorrect-user-agent-string-after-june-2016-patches-causing-websites-to?forum=ieitprocurrentver
Relevancy 85.87%

I am using windows XP
whenever I try to log in to facebook from any web browser whether it is IE or Chrome or Safari Or firefox it says my browser is incompatible.
My user string reads Mozilla/4.0 (compatible; MSIE 999.1; Unknown)

I have tried everything but of no help

A:User String

You have no problems with other websites?

System manufacturer and model?

Louis

http://www.bleepingcomputer.com/forums/t/414049/user-string/
Relevancy 85.56%

Hey guys. Does anyone know how to change the DEFAULT user agent?

I know about developer tools and how i can change it EVERY time i open a new tab. But i wanna set the default UA to a custom string. So that every time i open the IE9 it defaults to my custom UA.

Thanks!

A:Change IE9 DEFAULT user agent

I don't believe you can change the Default to anything other than IE.

The best way would be to install the other browsers.

http://www.techsupportforum.com/forums/f56/change-ie9-default-user-agent-669500.html
Relevancy 81.22%

So my laptop is a good few years old, has a few issues but generally it still runs ok for what I need. However today, after logging off fine last night I am getting the error 'user profile service service failed to log on'. I'm usually quite happy to have a tinker about with stuff if I have instructions. So I found out about logging into safe mode and ResEdit and looking for the SID key but mine is missing the long string of digits I'm guessing this is not normal, is there a way to fix this and get back in again?I have tried system restore but I only have yesterday evening and that fails.
I apologise for shortness of message I'm on my new iPad and I'm not really use to it, much prefer my laptop ATM!
Thanks in advance
 

A:User profile service failed to log on: SID key missing number string?!

Hi.

Try this:

http://support.microsoft.com/kb/947215

Method 1 usually works.

If as you say, the sid key is missing, then try methods 2 - 3

Hope this helps

Rob
 

https://forums.techguy.org/threads/user-profile-service-failed-to-log-on-sid-key-missing-number-string.1114102/
Relevancy 80.6%

Am trying to create a search/macro that will prompt the user to enter a date for the start of the search.
Just wondering if anyone out there has any ideas.
 

A:Creating a Remedy search string that prompts the user to enter the date

What are you using? Excel?

Try these sites for info and tips

http://www.cpearson.com/Zips/CALENDAR.ZIP
http://www.freevbcode.com/ShowCode.Asp?ID=3471
http://www.fontstuff.com/vba/vbatut07.htm
 

https://forums.techguy.org/threads/creating-a-remedy-search-string-that-prompts-the-user-to-enter-the-date.917057/
Relevancy 107.5%

sorry guys i posted this in web development by accident heres my problem Ok I have a vector quot v quot containing a bunch of strings I have another vector quot v quot that contains keywords I go through this vector v s array/vector string binary ha throug c++ string using values using a simple for loop On each iteration I binary string throug ha string array/vector using c++ want to perform a binary search through vector quot v quot to see how many times that word exists in v My problem is doesnt binary search only return the first position it finds the word in However there are going to be many instances of each word from quot v quot in quot v quot and I need to count how many times each word in quot v quot occurs in quot v quot I have done this succesfully using nested for loop put another for loop through v inside the for loop through v but I will get points off as this is not as efficient as binary search Both vectors are sorted help thanks nbsp

A:binary string throug ha string array/vector using c++

So, for each keyword (v1) you need to find a count of that word's occurrences in ALL of v2?

Given your existing data structures, the only way to do this is by an exhaustive search through ALL of v2 for each keyword - NOT with a binary search.

For a small amount of data, the nested-loop approach would be okay. But
were I programming this problem for a large volume of data, I would parse all of the strings in v2 and store the words in a binary tree, which would look like:

struct b_tree
{
char *word ;
int count ;
struct b_tree *left, *right ;
} ;

OR, an array of

struct
{ char *word ;
int count ;
} ;

Then a binary search would be appropriate.

In each case, *word can point to the first occurrence of that word in v2.

The b-tree approach would make it easier to store the words, while the array approach would make it simpler to search using the library function bsearch().
 

https://forums.techguy.org/threads/binary-string-throug-ha-string-array-vector-using-c.538006/
Relevancy 105.35%

have tried instr and a few other things without success.

most of what I tried returns the wrong result

like sting = "what the shells is going on"
when using str and other functions to find
`hell' it finds `hell' even tho it is not an exact match but part of another word

I have included example of what i need help with in excel file.

Thanking u in anticipation........
 

A:Solved: find exact string within a string using vba

=IF(ISNUMBER(SEARCH(" "&$B$44&" "," "&thecellthathasasentence)),"yes","no")

by adding spaces before and after the cell B44 that contains the word to be searched for it only
gives a yes answer if it finds the whole word. Leaving out the spaces before and after will find
any given occurence. eg "the rat sat on the matter not what it was" Omitting the spaces
and one searches for 'mat' it will give a yes answer which is wrong if a whole word search was required.
 

https://forums.techguy.org/threads/solved-find-exact-string-within-a-string-using-vba.1018513/
Relevancy 98.04%

I use google music to stream music to my tablet since i do not want to clutter up the drive with music files. but unfortunately i have been noticing some flash problems on the CP of windows 8. i would really like to access the HTML5 music player for the ipad from the metro ie browser but i cannot seem to change the user agent to that of the ipad. metro ie just goes to the flash site and says that i do not have flash player installed enven if i change the user agent in internet options (which by the way makes the desktop ie go to the html5 player but not metro). can anyone advise me on how to change metros user agent.
 

https://forums.techguy.org/threads/metro-ie-user-agent.1043909/
Relevancy 98.04%

Does anyone know how to fix a problem with the User Agent information for ie 8?

Relevancy 98.04%

I'm sure this isn't the best way to find out an error. Someone told me that my user agent is erroneous, and says that my IE7 has trouble 'identifying' itself. I think it true since I experienced some web page loading errors which shows errors similar to the first line of the following:

Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; InfoPath.2; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)

If it's really erroneous, how do I fix it?

Edit:
Version: 7.0.5730.13

A:Erroneous user agent (IE7)

A cursory glance at your user agent string doesn't reveal anything unusual. How, exactly, did this person say it was "erroneous?"

http://www.bleepingcomputer.com/forums/t/273592/erroneous-user-agent-ie7/
Relevancy 98.04%

Hi all

I'm having some issues with watching trailers at imdb.com.

I'm using IE10 and have no full screen option.
When using Chrome, there is one.

I've noticed that if I'm going to IE10 dev option (F12) and there I'm changing the user agent to Chrome, I have the full screen option and actually and IE crashes a lot less (I don't understand why, but it does).
Every time I'm closing IE, the option resets the default setting and I have to manually change it to Chrome again.

I'm searching of a way to set the user agent of IE10 (Win8 Pro x64) to be always on "Chrome Mode"

Is there a way to do it?

Thanks

A:IE10 user agent

Originally Posted by nickle20


Hi all
Every time I'm closing IE, the option resets the default setting and I have to manually change it to Chrome again.

I'm searching of a way to set the user agent of IE10 (Win8 Pro x64) to be always on "Chrome Mode"

Is there a way to do it?

Thanks



Hello and welcome to Windows eight forums
got start ,type in defaults ,click open it ,find Chrome and set it to defaults ,next time IE asks to be default ,say no ,and also make sure to check to never ask this again .
good luck

http://www.eightforums.com/browsers-mail/22031-ie10-user-agent.html
Relevancy 97.18%

Where would I get more information about various user-agents? The list of user-agents that one can get for User Agent Switcher has only the user-agent strings filled in, and nothing else. To make a really convincing fake UA, one needs to have App Code Name, App Name, App Version, and Platform filled in correctly as well. The App Version and Platform differ wildly among different browsers and operating systems. Where would I find that for Linux browsers, mobile devices, etc.?

A:User-agent information needed

List of UA :: user-agent-string.info

http://www.techsupportforum.com/forums/f131/user-agent-information-needed-909402.html
Relevancy 97.18%

I want a web site where i can find the user agent of any mobile phone...

Or please send me the file which contains the details of mobile's user agent..

Please reply as soon as possible..
 

A:its very urgent(mobile user agent)

Google will give you what is available, some phones do not appear to be identifiable.

As far as I am aware there is therefore by definition no complete list.
 

https://forums.techguy.org/threads/its-very-urgent-mobile-user-agent.587423/
Relevancy 95.89%

I'm running Firefox 20.0.1 (release channel) and it is 32 bit as reported in task manager, however when I go to whatismybrowser.com it reports Firefox 64. If I go into about:config and search on useragent I see an entry for "general.useragent.override which says "Mozilla/5.0 (Gecko) Firefox/64". I've tried resetting the string and that didn't help. Should I delete it or change the data (what would I change it too)? TIA

A:Firefox user agent is incorrectly reporting 64 bit

unknown <-curent UA string analysis :: user-agent-string.info

Go to above site and see what it shows. It may just be saying you are on a 64 Bit system.
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0

above is what it shows for me and I am using the 32Bit Version of Fx21B5

http://www.sevenforums.com/browsers-mail/287895-firefox-user-agent-incorrectly-reporting-64-bit.html
Relevancy 95.89%

I have an Acer Aspire 5733z laptop. And I would like to change the bios string, if it is possible. Because currently right now at the moment, I do not have a Power section or an Advanced section in my bios. Just so you know I have an Insyde bios setup screen. So please just let me know if this is possbile. Because I really want to try and install a bios update from the Acer Aspire 5742z model laptop. And mine is a Aspire 5733z model. So please just let me know if this is possible. I bet that it is, somehow. Because my Insyde bios setup is very limited in settings, which is not good for me. Well anyway, so please get back to me as soon as possible on this issue. Any kind of help would be greatly appreciated. So thank you very much!

A:I would like to know on how to change my bios string

The BIOS and computer hardware must be very closely matched. Using a BIOS from a different model is almost certain to fail. If you somehow managed to force the update a boot failure is a virtual certainty. In many cases the only recovery is physical replacement of the BIOS chip by a trained technician.

You would be well advised to give up on this before you seriously damage your laptop.

http://www.techsupportforum.com/forums/f217/i-would-like-to-know-on-how-to-change-my-bios-string-689857.html
Relevancy 93.74%

Good day This is user agent browser with mobile forced for portrait UWP browsing solely for touch based portrait browsing on a Windows tablet Edge works how I want in of the cases because a lot of sites are responsive and you just have to zoom to a certain level to get the site to go from desktop adaption to mobile But this does not apply to one single Google related site probably intentional from Google I'll take YouTube as an example On my Android tablet I get this nice mobile oriented layout N B this UWP browser for portrait browsing with forced mobile user agent is NOT the YouTube app but m youtube com in a browser A nice one column structure with no sidescrolling possible at all On my Windows tablet going to m youtube com or the non mobile URL in Edge only gives me the desktop version Even if I zoom to it does not change I do not prefer to watch videos in portrait mode if that's what you think but this applies to anything google related search translate you name it Using these in portrait mode is not a good experience Can Edge or some other UWP browser force a strict mobile user agent If you do feel the urge to let me know how inferior my Windows usage is or how stupid this question is please go ahead if that makes you feel better about yourself but I'll appreciate anything constructive

http://www.tenforums.com/browsers-email/45477-uwp-browser-portrait-browsing-forced-mobile-user-agent.html
Relevancy 93.74%

This intially started when it was noticed and new User account had been created named Nimda and had been appointed the administrator account The computer runs very slow with lots of pop ups I removed the nimda account Ran Search and destroy which found MEDIA PLEX DOUBLE CLICK RIGHT MEDIA VIRTUMONDE WEB TRENDS LIVE AND WIN AGENT P win32.agent.p2 nimda Virtumonde, user creating accounts, I scanned with Ad-aware it found critical objects I also did a panda scan The nimda keeps coming back and I am in need of direr help I would highly appreciate it IM using windows XP professional RSITINFOinfo txt logfile of random's system information tool - - Uninstall list -- C Program Files DivX DivXConverterUninstall exe CONVERTER-- MsiExec exe I EF - B- -BCEF-ECAB C -- rundll exe setupapi dll InstallHinfSection DefaultUninstall C nimda creating user accounts, Virtumonde, win32.agent.p2 WINDOWS INF PCHealth inf Microsoft Office Suite Service Pack nimda creating user accounts, Virtumonde, win32.agent.p2 SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- nimda creating user accounts, Virtumonde, win32.agent.p2 msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - A- - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - B- - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - F- - - FF CE uninstall EC D - B- CD - F-C E Microsoft Office Suite Service Pack SP -- msiexec package - F- C- - FF CE uninstall B -C E- DA- E - C BAB C Microsoft Office Suite Service Pack SP -- msiexec package - F- C A- - FF CE uninstall F A - C - E - A- EC B D BF Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - E- - - FF CE uninstall FAD A E- BAC- - -A D Microsoft Office Suite Service Pack SP -- msiexec package - A - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - BA- - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall FAD A E- BAC- - -A D Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall CA ECC -DBD - - F C-AA AD D E Microsoft Office Suite Service Pack SP -- msiexec package - - - - FF CE uninstall BEE E -DD F- D F-B C- E D ACE Mega CoDecS Pack-- quot C Program Files ACE Mega CoDecS Pack unins exe quot Ad-Aware-- MsiExec exe I DED B B-B C- -AE A-D FD C D EF Adobe Acrobat Professional-- msiexec I AC BA - - - - Adobe Anchor Service CS -- MsiExec exe I - A B- CCC-A D-F A B Adobe Asset Services CS -- MsiExec exe I FF DD A-FE - -B CF- E AF EA A Adobe Bridge CS -- MsiExec exe I C D - - -A A -D E D Adobe Bridge Start Meeting-- MsiExec exe I B - EEF- -AEDA- AB A A Adobe Camera Raw -- MsiExec exe I B BF -A D- D - A - AC ACD FC C Adobe CMaps-- MsiExec exe I A B BD-FF D- - DAA- EABEC C Adobe Color - Photoshop Specific-- MsiExec exe I A D E - A - A -A - B C E Adobe Color Common Settings-- C Program Files Common Files Adobe Installers c e cb fd c a ab e Setup exeAdobe Color Common Settings-- MsiExec exe I D AC A - CF - F - -B B CE BF Adobe Color EU Extra Settings-- MsiExec exe I -E B - - -B F FF B Adobe Color JA Extra Settings-- MsiExec exe I DD DB C - FA - FA - A -C F EB Adobe Color NA Recommended Settings-- MsiExec exe I ED - CA - DF- F- A E Adobe Default Language CS -- MsiExec exe I B B -B E - E C-BF C- BC D Ado... Read more

A:nimda creating user accounts, Virtumonde, win32.agent.p2

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results, click no to the Optional_ScanFollow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERER,K

http://www.bleepingcomputer.com/forums/t/184407/nimda-creating-user-accounts-virtumonde-win32agentp2/
Relevancy 92.88%

Good Morning I dont know How' but the String in Firefox gt Options gt General gt Downloads gt Save To has changed Twice to a Differant Path And it will not let me Edit correct it Nor Alter it to what it should be and allways has been' Nor will it Let me select the Old Path String from the Browse Option lt C Users DazzlingDasha Desktop MMYYDownloaded gt this is the Original Path Then it changed Months ago to This lt C Users DazzlingDasha Contacts Desktop Browse String 8.1 the Cannot By Download Save To to Edit Change Win MMYYDownloaded gt Today it Changed to This lt C Users DazzlingDasha Contacts Desktop Desktop MMYYDownloaded gt Not so Puzzling with Windows I guess it has a Mind of Its Own Roll On Windows Thanks for any help you Can Give Cannot Edit Change By Browse the Save To Download to String Win 8.1 Guys Dasha ---------------------------------------------------------- Computer DELL Inspiron Intel Pentium CPU - GB - Gig amp Meg Ram with Intel Graphics Controller G GL GE PE GV - BENQ Screen MS Wireless Keyboard and Mouse - Running Latest Firefox Gmail Windows I - Firewall is On - File System - NTFS - Capacity - GB - bytes Weston Terabyte HDD - Partitions are - F - G - H - I Malewarebytes -- gt CCleaner -- gt Avast Anti Virus Free All Run Weekly - Genie Time-line Backup Home ON

A:Cannot Edit Change By Browse the Save To Download to String Win 8.1

It just shows you are never too stupid to learn !  I've been using Firefox for 10 or 15 years and until today I thought the choices were 'Downloads' or 'Always ask' ! Since I save different types of files in different places i have always used 'Always ask'.
 
Are you having any other odd behaviour in Firefox - pop-ups, re-directions to unexpected web-sites, failure to go to web-sites ?  Have any of your security products ever suggested something has got in ?  If you try the 'always ask' option, does a downloaded file go where you tell it to ?
 
If it was just that the path was changing from time to time, I would put that down as an oddity in Firefox. It is your statement that you can't change the present path that raises concerns. As a first step I would suggest a full Malwarebytes and Avast system scan to see if they throw up anything.
 
Chris Cosgrove

http://www.bleepingcomputer.com/forums/t/569394/cannot-edit-change-by-browse-the-save-to-download-to-string-win-81/
Relevancy 92.02%

I have a batch file that creates a registry key and a string I want the string value data field to contain a path to a folder on the local machine but have been unsuccessful at doing so My current batch file contains the following This example does create the string but leaves the value data field blank -------------------------------------------------------------------------- echo value data change string file [SOLVED] registry Batch to off REM Add a registry key and values with Regedit exe and a reg file REM s is used to avoid an quot Are you sure quot prompt REM Create the Registry key gt quot temp globalconfig reg quot ECHO Windows Registry Editor Version gt gt quot temp globalconfig reg quot ECHO gt gt quot temp globalconfig reg quot ECHO HKEY LOCAL MACHINE Software iTALC Solutions iTALC path gt gt quot temp globalconfig reg quot ECHO quot globalconfig quot quot quot regedit exe [SOLVED] Batch file to change registry string value data s quot [SOLVED] Batch file to change registry string value data temp globalconfig reg quot -------------------------------------------------------------------------- The new string is globalconfig The value data field of this string needs to contain the following path C Documents and Settings All Users Application Data iTALC [SOLVED] Batch file to change registry string value data globalconfig xml I am new to batch file creation so please give me the for dummies explanation Thanks Kirk

A:[SOLVED] Batch file to change registry string value data

Welcome to TSF!

You've set the globalconfig value equal to nothing:

Code:
"globalconfig"= ""
It should be this

Code:
"globalconfig"= "C:\\Documents and Settings\\All Users\\Application Data\\iTALC\\globalconfig.xml"
The \ must be doubled as the \ is the escape character.

Rather than create a file to merge, be easier to just use reg.exe, only one line needed and no file to delete afterward:

Code:
Reg Add "HKLM\Software\iTALC Solutions\iTALC\path2" /V globalconfig /T REG_SZ /D "C:\Documents and Settings\All Users\Application Data\iTALC\globalconfig.xml" /F
Enter reg /? in a prompt for all the options

http://www.techsupportforum.com/forums/f10/solved-batch-file-to-change-registry-string-value-data-481326.html
Relevancy 91.16%

I have Win XP Media Edition....Today my computer started shutting down by itself. So, I remebered a friend advising me the MSSE was not really up to date on its protections. Not sure...so downloaded Malwarebytes and ran a full scan.

I found SpamTool.Agent, Trojan.Agent, and 2 Rootkit.Agent infections.

My research lead me to this site to get rkille.exe, rkill.com, etc.

How do I find this and then the tdss killer?

Other sites mention this and want you to sign on with them. But, I heard this was a free download from bleeping computer? Where can I find it?
Bill

A:Rootkit.Agent, Trojan.Agent, SpamTool.Agent Removal???????

Please follow the instructions in ==>This Guide<==.Once the proper logs are created, then make a NEW TOPIC and post it ==>HERE<== Please include the link to this topic in your new topic and a description of your computer issues and what you have done to resolve them.If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.Once you have created the new topic, please reply back here with a link to the new topic.

http://www.bleepingcomputer.com/forums/t/358347/rootkitagent-trojanagent-spamtoolagent-removal/
Relevancy 85.14%

Typing this super quick. As I'm sure, the stupid popup will appear again. When trying to access any websites, a message comes up. It isn't an error message or the "unresponsive script" message. It is different. It has lots of code on it. Probably the url of what it's trying to access. This would normally happen in the background, and the user shouldn't see it.
 
I googled part of the message, and it mentioned something about a user agent...whatever that is. I just want the message(s) to stop popping up! Any help is much appreciated.
 
Here is a screenshot of what I'm seeing:

A:Firefox Issue - Constant popup - User agent issue?

User agent info is identifying information about your browser, system, and region plus a unique identifier that your browser sends to websites it visits. I would try resetting your browser if you don't have settings you are worried about losing by doing that.

http://www.bleepingcomputer.com/forums/t/609906/firefox-issue-constant-popup-user-agent-issue/
Relevancy 84.71%

JAVA Dldr Agent W JAVA Agent M JAVA Agent AN HTML Infected WebPage Gen by JAVA/Agent.M.1; JAVA/Agent.AN; detected JAVA/Dldr.Agent.W; AntiAvira HTML/Infected.WebPage.Gen were detected separately between scans from Anti Avira however Malwarebyte scans have shown nothing Thanks for the helpDDS Ver - - - NTFSx Run by user at on WedInternet Explorer BrowserJavaVersion Microsoft Windows Home Premium GMT - Running Processes C Windows system wininit JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen detected by AntiAvira exeC Windows system lsm exeC Windows system svchost exe -k DcomLaunchC Windows system nvvsvc exeC Windows system svchost exe -k RPCSSC JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen detected by AntiAvira Windows System svchost exe -k LocalServiceNetworkRestrictedC Windows System svchost exe -k LocalSystemNetworkRestrictedC Windows system svchost exe -k netsvcsC Windows system svchost exe -k LocalServiceC Windows system svchost exe -k NetworkServiceC Windows System spoolsv exeC JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen detected by AntiAvira Program Files Avira AntiVir Desktop sched exeC Windows system svchost exe -k LocalServiceNoNetworkC Windows system nvvsvc exeC Program Files Avira AntiVir Desktop avguard exeC Program Files Microsoft Small Business Business Contact Manager BcmSqlStartupSvc exeC Program Files Lenovo Bluetooth Software btwdins exeC Program Files Lenovo ReadyComm common IGRS exec PROGRA mcafee SITEAD mcsacore exeC Program Files Common Files Motive McciCMService exeC Windows system rundll exeC Windows System svchost exe -k HPZ C Windows System svchost exe -k HPZ C Windows system svchost exe -k imgsvcC Program Files Lenovo OneKey App System Repair UpdateMonitor exeC Windows system wbem wmiprvse exeC Windows system svchost exe -k bthsvcsC Windows system svchost exe -k LocalServiceAndNoImpersonationC Windows system Dwm exeC Windows system taskhost exeC Windows Explorer EXEC Program Files Apoint K Apoint exeC Program Files Lenovo Energy Management Energy Management exeC Program Files Lenovo Energy Management utility exeC Program Files Microsoft Office Office GrooveMonitor exeC Program Files Apoint K ApMsgFwd exeC Program Files Lenovo VeriFace PManage exeC Program Files Avira AntiVir Desktop avgnt exeC Program Files Apoint K Apntex exeC Program Files Common Files Adobe ARM AdobeARM exeC Windows system conhost exeC Program Files Common Files Java Java Update jusched exeC Program Files Windows Sidebar sidebar exeC Program Files Siber Systems AI RoboForm robotaskbaricon exeC Windows System StikyNot exeC Program Files Lenovo Bluetooth Software BTTray exeC Program Files Olympus DeviceDetector DevDtct exeC Windows system SearchIndexer exeC Program Files Windows Media Player wmpnetwk exeC Windows System svchost exe -k secsvcsC Program Files Mozilla Firefox firefox exeC Program Files VideoLAN VLC vlc exeC Windows system SearchProtocolHost exeC Windows system SearchFilterHost exeC Users user Documents dds scrC Windows system conhost exeC Windows system wbem wmiprvse exe Pseudo HJT Report uStart Page hxxp lenovo live com uSearch Bar PreservemDefault Page URL hxxp www lenovo commStart Page hxxp lenovo live com uInternet Settings ProxyServer hkclproxy hkpl gov hk uURLSearchHooks McAfee SiteAdvisor Toolbar ebbbe -bad - b c- e a- abecae - c progra mcafee sitead mcieplg dllBHO Adobe PDF Link Helper df c-e ad- -a -fa c ebdc - c program files common files adobe acrobat activex AcroIEHelperShim dllBHO RoboForm d a - d - d - - e a - c program files siber systems ai roboform roboform dllBHO Groove GFS Browser Helper - c - d -b f - bbc d a e - c progra micros office GR A DLLBHO McAfee SiteAdvisor BHO b e -a b - a -b - cd e a ff - c progra mcafee sitead mcieplg dllBHO Windows Live Toolbar Helper bdbd dad-c - a -adc - b b ff d - c program files windows live toolbar msntb dllBHO x - No FileBHO Java Plug-In SSV Helper dbc -a - b-bc - c c c a - c ... Read more

A:JAVA/Dldr.Agent.W; JAVA/Agent.M.1; JAVA/Agent.AN; HTML/Infected.WebPage.Gen detected by AntiAvira

Hello and Welcome to the forums! My name is Gringo and I'll be glad to help you with your computer problems. Somethings to remember while we are working together.Do not run any other tool untill instructed to do so!Please Do not Attach logs or put in code boxes.Tell me about any problems that have occurred during the fix.Tell me of any other symptoms you may be having as these can help also.Do not run anything while running a fix.In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.In order for me to see the status of the infection I will need a new set of logs to start with.Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.DeFogger: Please download DeFogger to your desktop.Double click DeFogger to run the tool. The application window will appear Click the Disable button to disable your CD Emulation drivers Click Yes to continue A 'Finished!' message will appear Click OKDeFogger may ask you to reboot the machine, if it does - click OKDo not re-enable these drivers until otherwise instructed.Download DDS:Please download DDS by sUBs from one of the links below and save it to your desktop:Download DDS and save it to your desktopLink1Link2Link3Please disable any anti-malware program that will block scripts from running before running DDS.Double-Click on dds.scr and a command window will appear. This is normal.Shortly after two logs will appear: DDS.txt Attach.txtA window will open instructing you save & post the logsSave the logs to a convenient place such as your desktopCopy the contents of both logs & post in your next replyScan With RKUnHookerPlease Download Rootkit Unhooker Save it to your desktop.Now double-click on RKUnhookerLE.exe to run it.Click the Report tab, then click Scan.Check (Tick) Drivers, Stealth,. Uncheck the rest. then Click OK.Wait till the scanner has finished and then click File, Save Report.Save the report somewhere where you can find it. Click Close.Copy the entire contents of the report and paste it in a reply here.Note** you may get this warning it is ok, just ignore"Rootkit Unhooker has detected a parasite inside itself!It is recommended to remove parasite, okay?"information and logs:In your next post I need the following1.logs from DDS2.log from RKUnHooker3.let me know of any problems you may have hadGringo

http://www.bleepingcomputer.com/forums/t/344398/javadldragentw;-javaagentm1;-javaagentan;-htmlinfectedwebpagegen-detected-by-antiavira/
Relevancy 83.85%

(reposted from Customization)

Having just learned from an OLD post here that renaming a user account apparently doesn't change the order in which the corresponding logon icons appear at startup -- due to the order being apparently determined by when each folder was originally created, which was when this computer was first opened back in 2011 -- I want to be able, after creating a new user account, to migrate data from the account whose name I changed. I'd been previously suggested to try User Profile Wizard from Forensit.com... would this be a good idea, or can you suggest something different?

HP/Compaq CQ2014, AMD E-300, Radeon HD graphics, Win7 Home Premium 64-bit custom SP1, 3MB RAM, 500GB disk

Bob

http://www.sevenforums.com/performance-maintenance/392449-create-new-user-migrate-old-users-data-change-logon-icon-order.html
Relevancy 83.85%

Having just learned from an OLD post here that renaming a user account apparently doesn't change the order in which the corresponding logon icons appear at startup -- due to the order being apparently determined by when each folder was originally created, which was when this computer was first opened back in 2011 -- I want to be able, after creating a new user account, to migrate data from the account whose name I changed. I'd been previously suggested to try User Profile Wizard from Forensit.com... would this be a good idea, or can you suggest something different?

HP/Compaq CQ2014, AMD E-300, Radeon HD graphics, Win7 Home Premium 64-bit custom SP1, 3MB RAM, 500GB disk

Bob

http://www.sevenforums.com/customization/392313-create-new-user-migrate-old-users-data-change-logon-icon-order.html
Relevancy 81.27%

Hi i recently reinstalled windows se when i did so i put a password on it for when it boots up after this i created another user because someone multi user platform keeps getting diallers on my computer i want them to have their own seperate area where i can limit there access to the internet where they can have their games etc my desktop is used for business and i dont really want the mixed as multi user platform i work hours a day on my computer and my stuffs hard enough to find as it is lol anyway when i created a new user the password for the main account just seemed to become inactive so if the person i m trying to stop getting onto my area can just press cancel and they are on it also i want to set seperate powers ie basically i d like it like windows xp where I can have an admin account and i can make other user accounts with limited rights Is this possible on windows if not is there a program i can download that would make this possible ie i ve seen many internet cafes with something simular to what i require preferably free tho shareware nbsp

A:multi user platform

I don't believe that it's possible within Win98,the 95/98/ME's were based on ease of use,not security.I don't think that you can do that without setting up an active directory on another server.It'd obviously be easier to upgrade to NT/2000/XP
 

https://forums.techguy.org/threads/multi-user-platform.144035/
Relevancy 81.27%

I installed Win x with a user name quot user quot a long time ago At some point I changed the User's name to quot Karen quot to make it easier to spot on the home network etc The Computer Name quot Dell quot has not changed Today I wanted to connect to the computer quot Karen quot using my workgroup not a homegroup All of my other computers now share with workgroup However the computer quot I Name user the and user's the Can remove old change completely name? Karen quot does not Can I change the user's Name and completely remove the old user name? require a password to logon so when I tried to connect via the workgroup I got a popup box asking for the Credentials to Connect I need to enter the User Name and Password to connect to quot Dell quot And I and wife don't know the password Anyways I reset the password using the quot Reset Forgotten Password quot tutorial going into registry etc That worked but I still could not access the computer Karen - windows would not accept the password Running quot net users Can I change the user's Name and completely remove the old user name? quot I see that I don't have a User quot Karen quot I have a user quot user quot So i used that user name with the new password and I'm connected All is good But how do I get rid of quot user quot and replace with quot Karen quot Can this be done

A:Can I change the user's Name and completely remove the old user name?

  
Quote: Originally Posted by CountryBumkin


But how do I get rid of "user1" and replace with "Karen"? Can this be done?


When a new user is created in Windows, either the first user when Windows is installed or any user later on, and the new user has signed in to Windows first time, the user profile is created and named. Any later username change does not change the name of the user profile.

An example, if my ex-wife had created a user account for me on a Windows computer she had most probably named it as "Idiot". If I then later on changed my username on that computer from "Idiot" to "Kari", my profile had remained as "Idiot".

Basically, the easiest way to change this is to create a new user account and profile with the preferred name, copy the personal files and folders from C:\Users\Wrong_Username folder to C:\Users\New_Username, and delete the user Wrong_Username completely.

In your case now you can try the method told in this tutorial: User Profile Folder - Change User Account Folder Name

Kari

http://www.sevenforums.com/general-discussion/372135-can-i-change-users-name-completely-remove-old-user-name.html
Relevancy 81.27%

Hi there,

In Win-7, as an admin-user, it was easy to change the picture from another user. In Win-8 I'm only able to find where I can change my own picture. Can't I set it anymore for other users?

Cheers.

http://www.eightforums.com/user-accounts-family-safety/11409-change-user-account-picture-another-user.html
Relevancy 80.84%

Hi Boopme Are you here Do I need to post everything that I have already posted to you here http www bleepingcomputer com forums forum html or is someone else going to help me if so please let me know and I will give details to them By the way - this morning before work - I deleted my quarentine folders from SuperAntiSpyware and the logs from my desktop and ran a scan and it didn t pick anything up But my Malwarbytes will not load again from the task bar when I with Trojan.Agent/Gen-IExplorer[Fake] &Trojan.Agent/Gen-PEC Trojan.Agent/Gen-IEFake, Infected click on it - it would not let me stop it by right clicking either so hoping it wasn t running a script for the DDS scan - so I m afraid my trojans might be back I was going to run the Rkill one more time - but I didn t I couldn t run GMER - I have Windows bit and it would run but it didn t give me any options to check mark I was using the bit explorer does that matter Also the defogger - I m not sure it worked as it didn t come up for me to click the finish button - it just went back to Infected with Trojan.Agent/Gen-IEFake, Trojan.Agent/Gen-IExplorer[Fake] &Trojan.Agent/Gen-PEC the little box that says disable But I did get the DDS logs Here is my DDS Log DDS Ver - - - NTFS AMD Run by tamhbrih at on Mon Internet Explorer Microsoft Windows Home Premium GMT Infected with Trojan.Agent/Gen-IEFake, Trojan.Agent/Gen-IExplorer[Fake] &Trojan.Agent/Gen-PEC - AV AntiVir Desktop Disabled Updated F C - CE- C F- C- B A B SP Windows Defender Disabled Updated D DDC A- F- fae- E -DA C ACF SP AntiVir Desktop Disabled Updated B E DCD- F - E - D C- CF DCF A FW ZoneAlarm Firewall Enabled D DF -CFF -F -D C -FCD DFE D E Running Processes C Windows system wininit exe C Windows system lsm exe C Windows system svchost exe -k DcomLaunch C Windows system svchost exe -k RPCSS C Windows system atiesrxx exe C Windows System svchost exe -k LocalServiceNetworkRestricted C Windows System svchost exe -k LocalSystemNetworkRestricted C Windows system svchost exe -k netsvcs C Windows System DriverStore FileRepository stwrt inf amd neutral ccf dd cb af STacSV exe C Windows system svchost exe -k LocalService C Windows system atieclxx exe C Windows system svchost exe -k NetworkService C Windows SysWOW ZoneLabs vsmon exe C Windows system WLANExt exe C Windows system conhost exe C Program Files CheckPoint ZAForceField IswSvc exe C Windows System spoolsv exe C Program Files x Avira AntiVir Desktop sched exe C Windows system svchost exe -k LocalServiceNoNetwork C Program Files SUPERAntiSpyware SASCORE EXE C Windows System DriverStore FileRepository stwrt inf amd neutral ccf dd cb af AESTSr exe C Program Files LSI SoftModem agr svc exe C Program Files x Avira AntiVir Desktop avguard exe C Program Files x Common Files LightScribe LSSrvc exe C Program Files x CyberLink Shared files RichVideo exe C Program Files x Common Files supportsoft bin sprtlisten exe C Program Files x Avira AntiVir Desktop avshadow exe C Windows system conhost exe C Program Files Common Files Microsoft Shared Windows Live WLIDSVC EXE C Program Files Common Files Microsoft Shared Windows Live WLIDSvcM exe C Windows system taskhost exe C Windows system Dwm exe C Windows Explorer EXE C Windows system svchost exe -k NetworkServiceNetworkRestricted C Program Files Synaptics SynTP SynTPEnh exe C Program Files IDT WDM sttray exe C Program Files x Common Files LightScribe LightScribeControlPanel exe C Program Files x Hewlett-Packard HP Advisor HPAdvisor exe C Windows system SearchIndexer exe C Program Files x HP HP Software Update hpwuschd exe C Program Files Synaptics SynTP SynTPHelper exe C Program Files x Hewlett-Packard HP Wireless Assistant HPWAMain exe C Windows Microsoft Net Framework v WPF PresentationFontCache exe C Program Files x Qwest Desktop QwestTouchPointAgent exe C Program Files x Hewlett-Packard Shared hpqwmiex exe C Program Files x Avira AntiVir Desktop avgnt exe C Program Files x Zone Labs ZoneAlarm zlclient exe C Program Files... Read more

A:Infected with Trojan.Agent/Gen-IEFake, Trojan.Agent/Gen-IExplorer[Fake] &Trojan.Agent/Gen-PEC

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.Please take note:If you have since resolved the original problem you were having, we would appreciate you letting us know. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
If you are unsure about any of these characteristics just post what you can and we will guide you.Please tell us if you have your original Windows CD/DVD available.If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information.If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review your topic an do their best to resolve your issues.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.We need to see some information about what is happening in your machine. Please perform the following scan again:Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explanation about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HEREWe also need a new log from the GMER anti-rootkit Scanner. Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step.Please first disable any CD emulation programs using the steps found in this topic:Why we request you disable CD Emulation when receiving Malware Removal AdviceThen create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here:How to create a GMER logThanks and again sorry for the delay.Casey

http://www.bleepingcomputer.com/forums/t/379605/infected-with-trojanagentgen-iefake-trojanagentgen-iexplorerfake-trojanagentgen-pec/
Relevancy 79.98%

old sony laptop with windows xp pro sp intel pentium with MB rami've got some nasty bugs on my laptop i can remove them with spybot or malwarebytes but they come back Laptop infected with and Trojan.Agent Spyware.Agent.H, win32.delf.uc, every time i restart the pc they are able to turn off windows firewall and symantec anti-virus autoprotect my laptop got infected after my desktop so both are only in safemode and off the network for now any help Laptop infected with win32.delf.uc, Spyware.Agent.H, and Trojan.Agent would be Laptop infected with win32.delf.uc, Spyware.Agent.H, and Trojan.Agent greatly appreciated from spybot win delf ucfrom malwarebytes HKEY LOCAL MACHINE SOFTWARE Microsoft Windows NT CurrentVersion Windows llpinit dlls Spyware Agent H - gt Quarantined and deleted successfully C WINDOWS system nvtpm dll Spyware Agent H - gt Delete on reboot C WINDOWS system D tmp Trojan Agent - gt Quarantined and deleted successfully C WINDOWS system E tmp Trojan Agent - gt Quarantined and deleted successfully C WINDOWS system F tmp Trojan Agent - Laptop infected with win32.delf.uc, Spyware.Agent.H, and Trojan.Agent gt Quarantined and deleted successfully C WINDOWS system azton mt Trojan Agent - gt Quarantined and deleted successfully Here is my log from HijackThis Logfile of Trend Micro HijackThis v Scan saved at AM on Platform Windows XP SP WinNT MSIE Internet Explorer v Boot mode NormalRunning processes C WINDOWS System smss exeC WINDOWS system winlogon exeC WINDOWS system services exeC WINDOWS system lsass exeC WINDOWS system svchost exeC WINDOWS System svchost exeC Program Files Juniper NetScreen-Remote IPSecMon exeC Program Files Juniper NetScreen-Remote IreIKE exeC Program Files Common Files Symantec Shared ccSetMgr exeC WINDOWS system spoolsv exeC Program Files Symantec AntiVirus DefWatch exeC Program Files Timbuktu Pro tb launch exeC Program Files Google Update GoogleUpdate exeC WINDOWS Explorer EXEC Program Files Timbuktu Pro TimbuktuRemoteConsole exeC WINDOWS system igfxtray exeC WINDOWS system hkcmd exeC Program Files NETGEAR WG Utility WG WLU exeC Program Files Timbuktu Pro minitb exeC Program Files Common Files Symantec Shared ccApp exeC PROGRA SYMANT VPTray exeC Program Files Java jre bin jusched exeC Program Files Common Files Real Update OB realsched exeC Program Files Adobe Reader Reader Reader sl exeC WINDOWS system ctfmon exeC Program Files Spybot - Search amp Destroy TeaTimer exeC Program Files palmOne Hotsync exeC Program Files Juniper NetScreen-Remote SafeCfg exeC WINDOWS system wuauclt exeC Program Files Trend Micro HijackThis HijackThis exeR - HKCU Software Microsoft Internet Explorer Main Search Page http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Default Page URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Default Search URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Search Page http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Start Page http go microsoft com fwlink LinkId R - HKCU Software Microsoft Internet Connection Wizard ShellNext http go microsoft com fwlink LinkId O - BHO Adobe PDF Reader Link Helper - E F-C D - D -B D- B D BE B - C Program Files Common Files Adobe Acrobat ActiveX AcroIEHelper dllO - BHO Spybot-S amp D IE Protection - - F - D - - D F - C PROGRA SPYBOT SDHelper dllO - BHO SSVHelper Class - BB-D F - C-B EB-D DAF D D - C Program Files Java jre bin ssv dllO - BHO Google Gears Helper - E FEFE -FBF - AE-BA - CA E FB - C Program Files Google Google Gears Internet Explorer gears dllO - HKLM Run IgfxTray C WINDOWS system igfxtray exeO - HKLM Run HotKeysCmds C WINDOWS system hkcmd exeO - HKLM Run WG WLU C Program Files NETGEAR WG Utility WG WLU exe -hideO - HKLM Run TLogonPath quot C Program Files Timbuktu Pro minitb exe quot O - HKLM Run ccApp quot C Program Files Common Files Symantec Shared ccApp exe quot O - HKLM Run vptra... Read more

A:Laptop infected with win32.delf.uc, Spyware.Agent.H, and Trojan.Agent

you can close this out as i actually just did a clean reinstall of the OS. however, if anyone can help me with my other PC i'd prefer to not reinstall it as well:http://www.bleepingcomputer.com/forums/t/207842/desktop-infected-with-trojanagent-more/it has:trojan.agentadware.cometadware.starwaretrojan.dnschangerthanks!

http://www.bleepingcomputer.com/forums/t/207843/laptop-infected-with-win32delfuc-spywareagenth-and-trojanagent/
Relevancy 79.98%

When I restarted my Vista bit Gateway Desktop PC days ago I recieved a BSOD stating Driver Power State Failure Viruses & Need Help! Trojan.Agent/Gen-Autorun Rogue.Agent/Gen-Nullo Detected x F Ever since I have rebooted I am getting constant freeze ups and extremely slow start ups rendering the function of most programs useless I have tried running normal Avast scans in Rogue.Agent/Gen-Nullo & Trojan.Agent/Gen-Autorun Viruses Detected Need Help! regular mode without success but in safe mode I was able to run a complete Avast scan in safe mode which no major results and after running Superantispyware free edition scan it located and quarantined Rogue Agent Gen-Nullo dll Trojan Agent Gen-Autorun Heur Agent Gen-whitebox I then proceeded to run a Malwarebytes Full Scan but the scan always gets stuck on File C windows syswow sql srv rll wid dll woa dll I have run these scans for over hours Rogue.Agent/Gen-Nullo & Trojan.Agent/Gen-Autorun Viruses Detected Need Help! but most of the time it freezes up at hrs mins There are infected files detected but I cannot fix them since the scan never finishes I also had a 'not a genuine windows' issue pop up in the bottom right corner which cant be correct because this desktop has not been modified in anyway and it came with a certified Vista bit OS pre-installed by Gateway I seemed to have remedied the pop up from appearing but I suspect this has something to do with the other issues I am having I have tried using an earlier system restore point but it did not remedy the problem I've also recieved a pop-up in the middle of the screen a few times now that states Host process for windows services stopped working and was closed Safe mode works but scans still don't complete and program features like print and so on are not functional but I can access the internet through safe mode still Please see the attached Rkill txt log that I attached there seems to be a number of possibly patched files windows service integrity issues and a whole bunch of files missing their digital signatures I successfully ran the Rkill program hoping it would this time allow me to then run a COMPLETE Malwarebytes Threat Scan after but once again it stopped near the end of the scan with items detected on a C windows syswow sql file Please help my drawings and software for a garage that I am building for my father in law are on this computer and I cant access them Many thanks in advance Scott

A:Rogue.Agent/Gen-Nullo & Trojan.Agent/Gen-Autorun Viruses Detected Need Help!

Hi there,my name is Marius and I will assist you with your malware related problems.Before we move on, please read the following points carefully.First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.Perform everything in the correct order. Sometimes one step requires the previous one.If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.Important: To help me reviewing your logs, please post them in code boxes. You can create them by clicking on the <>-symbol on top of the reply window.    HijackThis is not the preferred initial scanning tool in this forum. With today's malware, a more comprehensive set of logs is required to determine the presence of malware.    Scan with FRST in normal modePlease download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties) Run FRST.Don´t change one of the checkboxes and hit Scan.Logfiles are created on your desktop.Poste the FRST.txt and (after the first scan only!) the Addition.txt.     Scan with aswMBRPlease download aswMBR ( 4.5MB ) to your desktop.Double click the aswMBR.exe icon, and click Run.There will be a short delay before the next dialog box comes up. Please just wait a minute or two.When asked if you'd like to "download the latest Avast! virus definitions", click Yes.Typically this is about a 100MB download so depending on your connection speed it can take a short while to download and become ready.Click the Scan button to start the scan once the update has finished downloadingOn completion of the scan, click the save log button, save it to your desktop, then copy and paste it in your next reply.Note: There will also be a file on your desktop named MBR.dat do not delete this for now. It is an actual backup of the MBR (master boot record).

http://www.bleepingcomputer.com/forums/t/548968/rogueagentgen-nullo-trojanagentgen-autorun-viruses-detected-need-help/
Relevancy 79.98%

This virus was unknowingly attached / Virus: With Win32.agent.gvu Trojan.downlader.agent.aejp Trouble to a game that was downloaded on my pc I am Trouble With Virus: Win32.agent.gvu / Trojan.downlader.agent.aejp using a different pc to post here as the virus prevents me from launching websites that offer support for its removal Other posts that I have read recommend running an online scanner from eset Unfortunately for me this would be one of the many sites the virus prohibits me from accessing If I attempt to locate a help site from a search engine I am redirected to other random sites If I Trouble With Virus: Win32.agent.gvu / Trojan.downlader.agent.aejp manually type the URL of a help site in the address bar the site is blocked I was able to run HijackThis and am providing this log Any assistance that you can offer will be greatly appreciated Logfile of Trend Micro HijackThis v Scan saved at PM on Platform Windows XP SP WinNT MSIE Internet Explorer v Boot mode NormalRunning processes C WINNT System smss exeC WINNT system winlogon exeC WINNT system services exeC WINNT system lsass exeC WINNT system svchost exeC WINNT System svchost exeC WINNT system svchost exeC WINNT system spoolsv exeC WINNT system basfipm exeC Program Files Common Files Symantec Shared ccSetMgr exeC Program Files Cisco Systems VPN Client cvpnd exeC WINNT Explorer EXEC Program Files Symantec AntiVirus DefWatch exeC Program Files Symantec AntiVirus SavRoam exeC Program Files Spyware Terminator sp rsser exeC Program Files Symantec AntiVirus Rtvscan exec WINNT system ZuneBusEnum exeC Program Files Common Files Symantec Shared ccEvtMgr exeC WINNT system hkcmd exeC WINNT system dla tfswctrl exeC Program Files Microsoft IntelliType Pro type exeC Program Files Microsoft IntelliPoint point exeC Program Files Common Files Symantec Shared Trouble With Virus: Win32.agent.gvu / Trojan.downlader.agent.aejp ccApp exeC PROGRA SYMANT VPTray exeC WINNT system rundll exeC Program Files Spyware Terminator SpywareTerminatorShield exeC Program Files Common Files InstallShield UpdateService isuspm exeC Program Files Java jre bin jusched exeC WINNT system ctfmon exeC Program Files Mozilla Firefox firefox exeC Program Files Trend Micro HijackThis HijackThis exeC Program Files Internet Explorer Iexplore exeR - HKCU Software Microsoft Internet Explorer Main Default Page URL http www dell comR - HKLM Software Microsoft Internet Explorer Main Default Page URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Default Search URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Search Page http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Start Page http go microsoft com fwlink LinkId O - BHO Adobe PDF Reader Link Helper - E F-C D - D -B D- B D BE B - C Program Files Common Files Adobe Acrobat ActiveX AcroIEHelper dllO - BHO Spybot-S amp D IE Protection - - F - D - - D F - C PROGRA SPYBOT SDHelper dllO - BHO DriveLetterAccess - CA D E- - CF- E - - C WINNT system dla tfswshx dllO - BHO SSVHelper Class - BB-D F - C-B EB-D DAF D D - C Program Files Java jre bin ssv dllO - BHO no name - E D - A- EC-A -BA D E E - no file O - BHO AcroIEToolbarHelper Class - AE CD -E - f- - EE - C Program Files Adobe Acrobat Acrobat AcroIEFavClient dllO - Toolbar Adobe PDF - -D C - - FA - E EAAC - C Program Files Adobe Acrobat Acrobat AcroIEFavClient dllO - HKLM Run Synchronization Manager SystemRoot system mobsync exe logonO - HKLM Run IgfxTray C WINNT system igfxtray exeO - HKLM Run HotKeysCmds C WINNT system hkcmd exeO - HKLM Run dla C WINNT system dla tfswctrl exeO - HKLM Run UpdateManager quot C Program Files Common Files Sonic Update Manager sgtray exe quot rO - HKLM Run type quot C Program Files Microsoft IntelliType Pro type exe quot O - HKLM Run IntelliPoint quot C Program Files Microsoft IntelliPoint point exe quot O - HKLM Run ccApp quot C Program Files Common Files Symantec Shared ccApp e... Read more

A:Trouble With Virus: Win32.agent.gvu / Trojan.downlader.agent.aejp

I apologize for the very long delay. We have a huge backlog of HijackThis Logs to handle and it has been taking us greater time than normal to get caught up. If you are still having a problem, and want us to analyze your information, please reply to this topic stating that you still need help and I will work with you on resolving your computer problems. If your problem has been resolved, please post a reply letting us know so we can close your topic.

Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, feel free to create a new one.

Once again, I apologize for the delay in responding to this topic.

http://www.bleepingcomputer.com/forums/t/168417/trouble-with-virus-win32agentgvu-trojandownladeragentaejp/
Relevancy 79.98%

My computer runs slow at times so I started a boot scan with Avast Free Home Edition Scan results showed Java Agent-TB and Java Agent-WY Boot Scan didn t complete due to a brownout in our neighborhood I had to use System Restore to reboot computer I m running Jave: and Java: found Agent-TB Scan Agent-WY Boot Avast Windows Home Edition on a Toshiba A -S -bit laptops Avast Free Edition version Update Engine and Virus Definitions version - Avast Boot Scan found Java: Agent-TB and Jave: Agent-WY COMODO Firewall Free Edition version Malwarebytes Anti-Malware Database version SuperAntiSpyware Free Edition Database Definition Version Core Trace Ad-Aware Free Edition Glary Utilities Free Edition Database - - I primarily use Firefox and Opera Ad-Aware and CCleaner don t seem to complete there scans recently DDS Log File DDS Ver - - - NTFSAMD Internet Explorer BrowserJavaVersion Run by bondzephyr at on - - Microsoft Windows Home Premium GMT - AV Lavasoft Ad-Watch Live Anti-Virus Disabled Updated FF - D -CE B- ECB-E A A AV avast Antivirus Enabled Updated B D - B-D C - E- FE FC C SP avast Antivirus Enabled Updated Avast Boot Scan found Java: Agent-TB and Jave: Agent-WY CF - -DA - FCE-A D DFB SP Windows Defender Disabled Updated D DDC A- F- fae- E -DA C ACF SP Lavasoft Ad-Watch Live Disabled Updated - EE-C E - B-DC BDD BAB SP COMODO Defense Enabled Updated CE - FA- -BB -B A A CA EC FW COMODO Firewall Enabled D F E - AF- E E-AACD- CDCF AA A Running Processes C windows system wininit exe C windows system lsm exe C windows system svchost exe -k DcomLaunch C windows system svchost exe -k RPCSS C Program Files COMODO COMODO Internet Security cmdagent exe C windows system svchost exe -k NetworkService C windows System svchost exe -k LocalServiceNetworkRestricted C windows System svchost exe -k LocalSystemNetworkRestricted C windows system svchost exe -k netsvcs C windows system svchost exe -k LocalService C Program Files Alwil Software Avast AvastSvc exe C windows system svchost exe -k LocalServiceNoNetwork C windows system taskhost exe C Program Files x Hotspot Shield bin openvpnas exe C Program Files x Hotspot Shield HssWPR hsssrv exe C Program Files x Hotspot Shield bin hsswd exe C Program Files x Intel Intel reg Management Engine Components LMS LMS exe C Program Files x Common Files Protexis License Service PsiService exe C windows system Dwm exe C windows system ThpSrv exe C Program Files x ThreatFire TFService exe C Windows system TODDSrv exe C Program Files TOSHIBA Power Saver TosCoSrv exe C windows system SearchIndexer exe C windows system svchost exe -k LocalServiceAndNoImpersonation C Program Files TOSHIBA TECO TecoService exe C windows SysWOW vsnapvss exe C windows Explorer EXE C windows system wbem wmiprvse exe C Windows System igfxtray exe C Windows System hkcmd exe C Windows System igfxpers exe C Program Files Realtek Audio HDA RAVCpl exe C Program Files Realtek Audio HDA RAVBg exe C Program Files Synaptics SynTP SynTPEnh exe C Windows System ThpSrv exe C Program Files TOSHIBA Power Saver TPwrMain exe C Program Files TOSHIBA SmoothView SmoothView exe C Program Files TOSHIBA FlashCards TCrdMain exe C Program Files TOSHIBA TECO Teco exe C Program Files TOSHIBA BulletinBoard TosNcCore exe C Program Files TOSHIBA ReelTime TosReelTimeMonitor exe C Program Files COMODO COMODO Internet Security cfp exe C Program Files x SUPERAntiSpyware SUPERAntiSpyware exe C Program Files Synaptics SynTP SynTPHelper exe C Program Files x TOSHIBA Utilities KeNotify exe C Program Files x TOSHIBA TOSHIBA Service Station ToshibaServiceStation exe C Program Files x ThreatFire TFTray exe C Program Files x Common Files Java Java Update jusched exe C Program Files TOSHIBA FlashCards Hotkey TcrdKBB exe C Program Files x Malwarebytes Anti-Malware mbamgui exe C Program Files Alwil Software Avast AvastUI exe C Windows System taskmgr exe C Program Files x Hotspot Shield bin openvpntray exe C windows System svchost exe -k LocalServicePeerNet C Program Files x TOSHIBA ... Read more

A:Avast Boot Scan found Java: Agent-TB and Jave: Agent-WY

Hello, Welcome to BleepingComputer.I'm nasdaq and will be helping you.If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.===Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: http://www.bleepingcomputer.com/combofix/how-to-use-combofixLink 1Link 2* IMPORTANT !!! Save ComboFix.exe to your DesktopIMPORTANT....1. Close any open browsers.2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.3. Do not install any other programs until this if fixed.How to : Disable Anti-virus and Firewall...http://www.bleepingcomputer.com/forums/topic114351.htmlDouble click on ComboFix.exe & follow the prompts. When finished, it will produce a report for you. Please post the C:\ComboFix.txt Note:Do not mouse click ComboFix's window while it's running. That may cause it to stallNote: If you have difficulty properly disabling your protective programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html===Third party programs if not up to date can be the cause infiltration of an infection.Please run this security check for my review.Download Security Check by screen317 from here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document.===

http://www.bleepingcomputer.com/forums/t/423818/avast-boot-scan-found-java-agent-tb-and-jave-agent-wy/
Relevancy 79.98%

I think i see the culprits on here but i don't dare hit fix without some help Logfile of Trend Micro HijackThis v Scan saved at Otherforum See Please In Cc.agent.cz, Post PM on Platform Windows XP SP WinNT MSIE Internet Explorer v SP Boot mode NormalRunning processes C WINDOWS Cc.agent.cz, See Post In Otherforum Please System smss exeC WINDOWS system winlogon exeC WINDOWS system services exeC WINDOWS system lsass exeC WINDOWS system svchost exeC Program Files Windows Defender MsMpEng exeC WINDOWS Cc.agent.cz, See Post In Otherforum Please System svchost exeC WINDOWS Explorer EXEC WINDOWS system spoolsv exeC Program Files AntiVir PersonalEdition Classic sched exeC Program Files AntiVir PersonalEdition Classic avguard exeC WINDOWS system CTsvcCDA EXEC WINDOWS System svchost exeC Program Files Viewpoint Common ViewpointService exeC WINDOWS system hkcmd exeC WINDOWS system dla tfswctrl exeC Program Files AntiVir PersonalEdition Classic avgnt exeC Program Files Windows Defender MSASCui exeC Program Files PeerGuardian pg exeC Program Files Spybot - Search amp Destroy TeaTimer exeC Program Files SpywareGuard sgmain exeC WINDOWS System svchost exeC Program Files SpywareGuard sgbhp exeC Program Files AntiVir PersonalEdition Classic avscan exeC Program Files MSN Messenger msnmsgr exeC Documents and Settings Yurei Desktop HiJackThis exeR - HKCU Software Microsoft Internet Explorer Main Default Page URL http www dell me com mywayR - HKCU Software Microsoft Internet Explorer Main Start Page http www metalmachinemusic com forums index php act idxR - HKLM Software Microsoft Internet Explorer Main Default Page URL http www dell me com mywayR - HKLM Software Microsoft Internet Explorer Main Start Page http www dell me com mywayF - win ini run C WESTWOOD REDALERT INSTICON EXEO - BHO SpywareGuard Download Protection - A E - F- - B - B DDD DB - C Program Files SpywareGuard dlprotect dllO - BHO Spybot-S amp D IE Protection - - F - D - - D F - C PROGRA SPYBOT SDHelper dllO - BHO DriveLetterAccess - CA D E- - CF- E - - C WINDOWS system dla tfswshx dllO - Toolbar no name - BA B -B - c -B - F F - no file O - HKLM Run IgfxTray C WINDOWS system igfxtray exeO - HKLM Run HotKeysCmds C WINDOWS system hkcmd exeO - HKLM Run dla C WINDOWS system dla tfswctrl exeO - HKLM Run KernelFaultCheck systemroot system dumprep -kO - HKLM Run avgnt quot C Program Files AntiVir PersonalEdition Classic avgnt exe quot minO - HKLM Run Windows Defender quot C Program Files Windows Defender MSASCui exe quot -hideO - HKLM RunOnce InnoSetupRegFile quot C WINDOWS is-B EM exe quot REGO - HKCU Run PeerGuardian C Program Files PeerGuardian pg exeO - HKCU Run SpybotSD TeaTimer C Program Files Spybot - Search amp Destroy TeaTimer exeO - HKUS S- - - Run DWQueuedReporting quot C PROGRA COMMON MICROS DW dwtrig exe quot -t User 'SYSTEM' O - HKUS DEFAULT Run DWQueuedReporting quot C PROGRA COMMON MICROS DW dwtrig exe quot -t User 'Default user' O - Startup SpywareGuard lnk C Program Files SpywareGuard sgmain exeO - Extra button no name - B E C - FCB- CF-AAA - C - C Program Files Java jre bin npjpi dllO - Extra 'Tools' menuitem Sun Java Console - B E C - FCB- CF-AAA - C - C Program Files Java jre bin npjpi dllO - Extra button AIM - AC E - - d -BC D- B D A DE - C Program Files AIM aim exeO - Extra button no name - CD F -D E - d - FE- C F AFE - no file O - Extra button no name - DFB A - F - C -A - CAB FD A - C PROGRA SPYBOT SDHelper dllO - Extra 'Tools' menuitem Spybot - Search amp Destroy Configuration - DFB A - F - C -A - CAB FD A - C PROGRA SPYBOT SDHelper dllO - Extra button Messenger - FB F -F - d -BB E- C F - C Program Files Messenger msmsgs exeO - Extra 'Tools' menuitem Windows Messenger - FB F -F - d -BB E- C F - C Program Files Messenger msmsgs exeO - DPF B CFB- - -A -C A C Checkers Class - http messenger zone msn com binary msgrchkr cab cabO - DPF B - E - EA - B - F A BC MessengerStatsClient Class - http messenger zone msn com binary Messe nt cab cabO - DPF -C A- E-A -C C BBF Window... Read more

A:Cc.agent.cz, See Post In Otherforum Please

I apologize for the very long delay. We have a huge backlog of HijackThis Logs to handle and it has been taking us greater time than normal to get caught up. If you are still having a problem, and want us to analyze your information, please post a brand new hijackthis log. If we do not hear back from you within a couple of days we will need to close your topic.When posting your logs please post them directly into the reply. Do not attach them.Also make sure you have already followed the steps outlined below:Preparation Guide For Use Before Posting A Hijackthis LogThank you for your patience.

http://www.bleepingcomputer.com/forums/t/134070/ccagentcz-see-post-in-otherforum-please/
Relevancy 79.55%

Hi My Neighbour has asked me to have and Cant Trojan remove Agent.gen-pec Trjan Agent.gen/iexplorer[fake] a look at her laptop as all her Cant remove Trjan Agent.gen/iexplorer[fake] and Trojan Agent.gen-pec programs desktop icons and desktop background have disappeared and I have exhausted all avenues to try and fix it for her Below is a list of what i have done and found Acer Aspire series Laptop running windows home premium bit operating sysytem Mc affee full scan found nothing Ran Rkill then maleware bytes and it found infections and removed them Ran Rkill then SAS and SAS found tracking cookies and two trojans which are Trojan Agent Gen-IExplorer Fake and Trojan Agent Gen-PEC SAS managed to delete all the tracking cookies however these aforementioned trojans are persistent and SAS reports as removing them but on a re scan with SAS the are still there I can see from the logs that It is IExplorer exe that is the issue here but i am now at a loss as to what to do Ran unhide exe which brought back most of the files however the program files from the start menu still show as being empty I think that the problem is the fake Iexplorer starts and runs at startup and cant be stopped by rkill but am unsure as I am a hardware diagnostic engineer with limited experience on software issues and people keep asking me to have a look at there computers for them and i like to try and help people as much as i can but am stumped on this one Any assistance that you can give me would be greatly appreciated Many thanks

http://www.bleepingcomputer.com/forums/t/403147/cant-remove-trjan-agentgeniexplorerfake-and-trojan-agentgen-pec/
Relevancy 79.12%

I want to start by saying this is my third time here and you guys have been absolutely FABULOUS the other two times I say that not by way of pressure but appreciation for all you all do I have run McAfee Adaware Malwarebytes and superantispyware and got the above items quarantined but am still having non-stop popups and I can spyware.banker, and .vundo, .agent, and adware.popcap .downloader; .fake-alert, trojans: .bho, rogue.agent/gen-nullo[dll], type in a URL but if I click a link who knows where I ll end up Looks like most of the required stats are in the dds file so here it is If you need anything else just let me know Oh and I m attaching my attach txt but can t attach the ark file as gmer gives me a BSOD every time I try to run it No error codes just quot your computer has encountered blah blah and has to shut down quot If you need the precise text of that I ll recreate it for you Also the date on these trojans: .fake-alert, .agent, .vundo, .bho, and .downloader; spyware.banker, adware.popcap and rogue.agent/gen-nullo[dll], files is but they should still be current since the PC s been sitting turned off and disconnected from the internet since then but if I should run updated files again just let me know Thanks in advance LynnDDS Ver - - - NTFSx Run by Lynn Springle at on Sat Internet Explorer Microsoft Windows XP Home Edition GMT - AV McAfee VirusScan On-access scanning enabled Updated B EE - - CDE-A A-DD BA FAD FW McAfee Personal Firewall enabled B - C F- -BDA - CA DA E Running Processes C WINDOWS system svchost -k DcomLaunchsvchost exeC WINDOWS System svchost exe -k netsvcsC WINDOWS system svchost exe -k WudfServiceGroupsvchost exesvchost exeC WINDOWS system spoolsv exesvchost exeC Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exeC Program Files Bonjour mDNSResponder exeC Program Files Dell Network Assistant hnm svc exeC Program Files Java jre bin jqs exeC Program Files McAfee SiteAdvisor McSACore exeC PROGRA McAfee MSC mcmscsvc exec PROGRA COMMON mcafee mna mcnasvc exec PROGRA COMMON mcafee mcproxy mcproxy exeC PROGRA McAfee VIRUSS mcshield exeC Program Files McAfee MPF MPFSrv exeC Program Files Microsoft Search Enhancement Pack SeaPort SeaPort exeC Program Files Comcast Desktop Doctor bin sprtsvc exeC Program Files Dell Support Center bin sprtsvc exeC WINDOWS system svchost exe -k imgsvcC Program Files Viewpoint Common ViewpointService exeC Program Files Zoom Zoom Phone Adaptor VServ exeC Program Files Common Files Microsoft Shared Windows Live WLIDSVC EXEC WINDOWS system SearchIndexer exeC Program Files Common Files Pure Networks Shared Platform nmsrvc exeC Program Files Common Files Microsoft Shared Windows Live WLIDSvcM exeC WINDOWS Explorer EXEC WINDOWS system rundll exec PROGRA mcafee com agent mcagent exeC Program Files Trend Micro TrendSecure TSCFPlatformCOMSvr exeC Program Files Viewpoint Viewpoint Manager ViewMgr exeC WINDOWS system ctfmon exeC PROGRA McAfee VIRUSS mcsysmon exeC PROGRA MI AA rapimgr exeC Program Files Pure Networks Network Magic nmapp exeC Program Files Microsoft Search Enhancement Pack SCServer SCServer exeC Program Files QuickTime qttask exeC Program Files Microsoft ActiveSync wcescomm exeC Program Files NewTech Infosystems Backup Now EZ BackupNowEZSvr exeC Program Files NewTech Infosystems Backup Now EZ BackupNowEZtray exeC WINDOWS System vssvc exeC WINDOWS system dllhost exeC WINDOWS system dllhost exeC Program Files Microsoft IntelliType Pro itype exeC Program Files MSN Toolbar Platform mswinext exeC Program Files Skype Toolbars Shared SkypeNames exeC WINDOWS explorer exeC Documents and Settings All Users Application Data ogRlGTXd exeC Program Files Mozilla Firefox firefox exeC Program Files Microsoft Search Enhancement Pack Default Manager DefMgr exeC Program Files QuickTime qttask exeC WINDOWS system taskmgr exeC Program Files Internet Explorer IEXPLORE EXEC WINDOWS system wuauclt exeC Program Files Internet Explorer IEXPLORE EXEC Program Files ... Read more

A:trojans: .fake-alert, .agent, .vundo, .bho, and .downloader; spyware.banker, adware.popcap and rogue.agent/gen-nullo[dll],

Hello , And to the Bleeping Computer Malware Removal Forum. My name is Elise and I'll be glad to help you with your computer problems.I will be working on your malware issues, this may or may not solve other issues you may have with your machine.Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.The cleaning process is not instant. Logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen. Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.-----------------------------------------------------------If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.If you have already posted a log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.We need to see some information about what is happening in your machine. Please perform the following scan:Please download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" checkbox.Push the Quick Scan button.Two reports will open, copy and paste them in a reply here:OTListIt.txt <-- Will be openedExtra.txt <-- Will be minimizedPlease download Rootkit Unhooker and save it to your DesktopDouble-click on RKUnhookerLE to run itClick the Report tab, then click ScanCheck Drivers, Stealth and uncheck the restClick OKWait until it's finished and then go to File > Save ReportSave the report to your DesktopCopy the entire contents of the report and paste it in a reply here.Note - you may get this warning it is ok, just ignore: "Rootkit Unhooker has detected a parasite inside itself!It is recommended to remove parasite, okay?"-------------------------------------------------------------In the meantime please, do NOT install any new programs or update anything unless told to do so while we are fixing your problemIf you still need help, please include the following in your next replyA detailed description of your problemsA new OTL log (don't forget extra.txt)RKU logThanks and again sorry for the delay.

http://www.bleepingcomputer.com/forums/t/342585/trojans-fake-alert-agent-vundo-bho-and-downloader;-spywarebanker-adwarepopcap-and-rogueagentgen-nullodll/
Relevancy 78.69%

Hi Thanks in advance for your assistance I'm new to this forum any forum Below I've listed what procedures I performed and selected resulting logs Let me know what additional information I can provide to assist I received repeated pop-up Windows Security Alert warning of a potential spyware operation I performed the following NOTE I do not have access to the control panel I believe I have my system set to show hidden files but can t confirm since I don t have access to the control panel Perhaps there is another way I downloaded and ran the following recommended software from MISEC NET forum and or BEEPINGCOMPUTER a Spybot-S amp D b Ad-Aware c A-Squared d CCleaner safe modee TrojanHunter safe modef SuperAntiSpyware errors resulted in regular mode and safe mode do you need the log Where is it saved g Could NOT load F-Secure Blacklight with AVG running disabled Would not uninstall h BitDefender not remote i Could NOT load run REMOTE scan with BitDefender could not change to administrator since I don t have access to the control panel Perhaps there Trojan.agent.afhf; Possibly Pop-up; Recurring Agent.100 is Recurring Pop-up; Trojan.agent.afhf; Possibly Agent.100 another way I ran in regular mode Could not determine how to copy paste log Advise if needed and steps to take Made HijackThis log NOTE I just found another list of suggested procedures that include a few different antivirus spyware programs to be run If needed just let me know and I will download and run not run Housecall anti virus panda anti virus and mcaffee avert stinger I m not sure which list of suggested procedures is more current Since I ve spent so much time following the first list I thought I would send on to see if it is adequate HIJACKTHIS LOG Logfile of Trend Micro HijackThis v Scan saved at AM on Platform Windows XP SP WinNT MSIE Internet Explorer v Boot mode NormalRunning processes C WINDOWS System smss exeC WINDOWS system csrss exeC WINDOWS system winlogon exeC WINDOWS system services exeC WINDOWS system lsass exeC WINDOWS system svchost exeC WINDOWS system svchost exeC WINDOWS System svchost exeC WINDOWS system svchost exeC WINDOWS system svchost exeC WINDOWS Explorer exeC WINDOWS system spoolsv exeC Program Files Analog Devices SoundMAX SMax PNP exeC Program Files Dell Media Experience PCMService exeC WINDOWS system dla tfswctrl exeC Program Files Adobe Photoshop Album Starter Edition Apps apdproxy exeC WINDOWS system hkcmd exeC WINDOWS system igfxpers exeC Program Files Musicmatch Musicmatch Jukebox mmtask exeC Program Files ScanSoft OmniPageSE OpwareSE exeC Program Files iTunes iTunesHelper exeC Program Files TrojanHunter THGuard exeC Program Files a-squared Anti-Malware a guard exeC Program Files a-squared Anti-Malware a service exeC Program Files BitDefender BitDefender bdagent exeC Program Files Messenger msmsgs exeC WINDOWS system ctfmon exeC Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exeC Program Files Symantec LiveUpdate ALUSchedulerSvc exeC Program Files SUPERAntiSpyware SUPERAntiSpyware exeC Program Files Common Files Intuit QuickBooks QBUpdate qbupdate exeC Program Files Red Chair Software Anapod Explorer anamgr exeC PROGRA Grisoft AVG avgamsvr exeC PROGRA Grisoft AVG avgupsvc exeC Program Files Common Files Microsoft Shared VS DEBUG MDM EXEC WINDOWS system svchost exeC WINDOWS system wdfmgr exeC Program Files Common Files BitDefender BitDefender Communicator xcommsvr exeC PROGRA Grisoft AVG avgfwsrv exeC Program Files Common Files BitDefender BitDefender Update Service livesrv exeC Program Files BitDefender BitDefender vsserv exeC Program Files iPod bin iPodService exeC WINDOWS System svchost exeC Program Files Grisoft AVG avgcc exeC Program Files Microsoft Office OFFICE WINWORD EXEC Program Files Internet Explorer iexplore exeC DOCUME TINKER LOCALS Temp Temporary Directory for hijackthis zip HijackThis exeR - HKCU Software Microsoft Internet Explorer Main Default Page URL http www dell me com mywaybiz... Read more

A:Recurring Pop-up; Trojan.agent.afhf; Possibly Agent.100

Hello TPayne,Sorry for the long delay, we are really swamped with logs right now. NOTE: If you have downloaded SmitfraudFix previously please delete that version and download it again! Please download SmitfraudFix Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of the SmitfraudFix report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm

http://www.bleepingcomputer.com/forums/t/109792/recurring-pop-up;-trojanagentafhf;-possibly-agent100/
Relevancy 78.69%

Hello I have been directed to post an SSD log on this forum board for diagnosis From this topic http www bleepingcomputer others Backdoor.bot, Comp and on Rootkit.agent, Trojan.agent, my com forums t systemexe-problems OB About midway through January my computer caught a very strange virus causing my desktop Backdoor.bot, Trojan.agent, Rootkit.agent, and others on my Comp background to be changed to some Warning Your computer is infected with PassCaptures many viruses blah blah I remember seeing the exact same background that I had on my desktop on the Home section But after running MBAM my computer seemed to work normally Now everytime I scan my computer with MBAM the same Malwares show up I am stuck on what to do next At the moment my computer is only exhibiting minor symptoms such as when I open my Firefox Browser Shortcut on my Desktop a box titled Malformed File pops up and reads Firefox could not install this item because install rdf provided by the item is not well-formed or does not Backdoor.bot, Trojan.agent, Rootkit.agent, and others on my Comp exist Please contact the author about this problem But as soon as I press OK Firefox opens up Some sites appear different though I also have several iexplore exe that are in the Processes tab of the Task Manager Finally my computer will beat periodically and randomly every - minutes All right here is the SDD scan and its attachment DDS Ver - - - NTFSx Run by Akaash Prasad at on - - Internet Explorer BrowserJavaVersion Microsoft Windows XP Home Edition GMT - AV AVG Anti-Virus Free On-access scanning enabled Updated Running Processes C WINDOWS system svchost -k DcomLaunchsvchost exeC WINDOWS System svchost exe -k netsvcssvchost exesvchost exeC Program Files Lavasoft Ad-Aware AAWService exeC WINDOWS system spoolsv exeC Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exeC Program Files Bonjour mDNSResponder exeC Program Files Viewpoint Common ViewpointService exeC Program Files Lavasoft Ad-Aware AAWTray exeC WINDOWS Explorer EXEC WINDOWS SOUNDMAN EXEC Program Files CyberLink PowerDVD PDVDServ exeC Program Files Microsoft Office Office GrooveMonitor exeC Program Files Adobe Reader Reader Reader sl exeC Program Files Java jre bin jusched exeC Program Files iTunes iTunesHelper exeC WINDOWS system ctfmon exeC Program Files Microsoft Office Office FINDFAST EXEC Program Files TRENDnet TEW- UB WlanCU exeC Program Files Microsoft Office Office ONENOTEM EXEC Program Files iPod bin iPodService exeC WINDOWS System svchost exeC WINDOWS System svchost exeC WINDOWS System svchost exeC WINDOWS System svchost exeC WINDOWS TEMP BN tmpC WINDOWS System svchost exesvchost exe C WINDOWS TEMP VRT tmpC WINDOWS System svchost exeC Documents and Settings Akaash Prasad Desktop dds scr Pseudo HJT Report uLocal Page blank htmuStart Page hxxp www help go com forum spyware-help -cant-open-cmd-exe htmluInternet Settings ProxyOverride localTB AVG Security Toolbar a a -bacc- d - - a e e - c progra avg avg AVGTOO DLLuRun ctfmon exe c windows system ctfmon exeuRun Aim mRun IMJPMIG c windows ime imjp IMJPMIG EXE Spoil RemAdvDef Migration mRun PHIME ASync c windows system ime tintlgnt TINTSETP EXE SYNCmRun PHIME A c windows system ime tintlgnt TINTSETP EXE IMENamemRun SoundMan SOUNDMAN EXEmRun RemoteControl c program files cyberlink powerdvd PDVDServ exe mRun NeroFilterCheck c windows system NeroCheck exemRun AppleSyncNotifier c program files common files apple mobile device support bin AppleSyncNotifier exemRun GrooveMonitor c program files microsoft office office GrooveMonitor exe mRun Adobe Reader Speed Launcher c program files adobe reader reader Reader sl exe mRun SunJavaUpdateSched c program files java jre bin jusched exe mRun QuickTime Task c program files quicktime QTTask exe -atboottimemRun iTunesHelper c program files itunes iTunesHelper exe mRun Ad-Watch c program files lavasoft ad-aware AAWTray exedRun reader s c documents and settings akaash prasad reader s exedRun ser... Read more

A:Backdoor.bot, Trojan.agent, Rootkit.agent, and others on my Comp

Hello aNimosity1 and welcome to Bleeping Computer,I'm afraid I have bad news for you I see you're dealing with Virut on top of the other nasty malware on your system. In that case, it's unfortunately a lost cause - Game over situation and a format and reinstall is the fastest and especially the safest solution.You may want to read this why:Virut and other File infectors - Throwing in the Towel? So, I suggest you to start backup all of your valuable data/documents/pictures/movies/songs/etc.. Do NOT backup any applications/installers and Do NOT backup any .exe/.scr/.htm/.html/.xml/.zip/.rar files...This because these files may be infected as well. If you back them up and replace them afterwards, it will infect your computer again.Read here for instructions how to format and reinstall Windows: http://web.mit.edu/ist/products/winxp/adva...all-format.htmlGreetings,Thunder

http://www.bleepingcomputer.com/forums/t/207132/backdoorbot-trojanagent-rootkitagent-and-others-on-my-comp/
Relevancy 78.69%

Hello,

I am new to the forum and just learning my way around. What a great resource! Thanks.

I am running AVG, and it informs me (threat detected!) that I have some trojan horses:
tojan horse agent.AABY and trojan horse agent.AACL

I have tried to heal the files to no avail. I have tried deleting the files and nothing.

I downloaded and ran Malwarebytes Anti-Malware and it found 6 affected files which I deleted, and I am still getting the message from AVG...

I appreciate your help!

-Cynthia

A:Trojan Horse Agent.aaby And Agent.aacl

Did AVG provide a specific file name associated with this malware threat and if so, where is it located (full file path) at on your system?

http://www.bleepingcomputer.com/forums/t/165252/trojan-horse-agentaaby-and-agentaacl/
Relevancy 78.69%

Hi I'm brand new any sort of forum - so don't really know the form What I know is that my daughter's laptop has the above Backdoor.agent.pta Horse Trojan Dropper.agent.git & Trojan Horse viruses that have knocked out the AVG control centre any internet connection and the C drive probably lots more as well So I'm doing this on my PC The HijackThis log file follows - very grateful for your help to recover things Logfile of Trend Micro HijackThis v Scan saved at on Platform Windows XP SP WinNT MSIE Internet Explorer v SP Boot mode NormalRunning processes C WINDOWS System smss exeC WINDOWS system winlogon exeC WINDOWS system services Trojan Horse Dropper.agent.git & Backdoor.agent.pta exeC WINDOWS system lsass exeC WINDOWS system svchost exeC WINDOWS System Trojan Horse Dropper.agent.git & Backdoor.agent.pta svchost exeC WINDOWS system spoolsv exeC Program Files Lavasoft Ad-Aware aawservice exeC PROGRA Grisoft AVG avgamsvr exeC PROGRA Grisoft AVG avgupsvc exeC PROGRA Grisoft AVG avgemc exeC Program Files WIDCOMM Bluetooth Software bin btwdins exeC Program Files Network Associates Common Framework FrameworkService exeC Program Files Network Associates VirusScan Mcshield exeC Program Files Network Associates VirusScan VsTskMgr exeC WINDOWS SYSTEM SPOOL DRIVERS W X HPZipm exeC WINDOWS system svchost exeC Program Files UPHClean uphclean exeC Trojan Horse Dropper.agent.git & Backdoor.agent.pta Program Files Hewlett-Packard Shared hpqwmiex exeC WINDOWS Explorer EXEC WINDOWS system userinit exeC Program Files Hewlett-Packard HP Quick Launch Buttons QlbCtrl exeC Program Files Network Associates VirusScan SHSTAT EXEC Program Files Com Com OfficeConnect Wireless Utility Com Wireless g PC Card Monitor exeC Program Files Belkin Belkin g Wireless Card Configuration Utility Belkinwcui exeC Program Files WIDCOMM Bluetooth Software BTTray exeC Program Files Trend Micro HijackThis HijackThis exeR - HKCU Software Microsoft Internet Explorer Main Search Bar http g msn co uk SEENGB SAOS FORM TOOLBRR - HKCU Software Microsoft Internet Explorer Main Search Page http g msn co uk SEENGB SAOS FORM TOOLBRR - HKCU Software Microsoft Internet Explorer Main Start Page http www google co uk R - HKCU Software Microsoft Internet Explorer SearchURL Default http g msn co uk SEENGB SAOS FORM TOOLBRF - REG win ini load C WINDOWS system jkkjh exeO - Toolbar amp Google - C B - - d - B - A CD F - c program files google googletoolbar dllO - Toolbar Windows Live Toolbar - BDAD DAD-C - A -ADC - B B FF D - C Program Files Windows Live Toolbar msntb dllO - HKLM Run SoundMAX quot C Program Files Analog Devices SoundMAX Smax exe quot trayO - HKLM Run QlbCtrl ProgramFiles Hewlett-Packard HP Quick Launch Buttons QlbCtrl exe StartO - HKLM Run WatchDog C Program Files InterVideo DVD Check DVDCheck exeO - HKLM Run ShStatEXE quot C Program Files Network Associates VirusScan SHSTAT EXE quot STANDALONEO - HKLM Run McAfeeUpdaterUI quot C Program Files Network Associates Common Framework UpdaterUI exe quot StartedFromRunKeyO - HKLM Run Network Associates Error Reporting Service quot C Program Files Common Files Network Associates TalkBack TBMon exe quot O - HKLM Run Synchronization Manager SystemRoot system mobsync exe logonO - HKLM Run PRISMSVR EXE quot C Program Files Com Com OfficeConnect Wireless Utility Com Wireless g PC Card PRISMSVR EXE quot APPLYO - HKLM Run AVG CC C PROGRA Grisoft AVG avgcc exe STARTUPO - HKLM Run QuickTime Task quot C Program Files QuickTime qttask exe quot -atboottimeO - HKLM Run iTunesHelper quot C Program Files iTunes iTunesHelper exe quot O - HKUS S- - - Run CTFMON EXE C WINDOWS system CTFMON EXE User 'LOCAL SERVICE' O - HKUS S- - - Run AVG Run C PROGRA Grisoft AVG avgw exe RUNONCE User 'LOCAL SERVICE' O - HKUS S- - - Run CTFMON EXE C WINDOWS system CTFMON EXE User 'NETWORK SERVICE' O - HKUS S- - - Run CTFMON EXE C WINDOWS system CTFMON EXE User 'SYSTEM' O - HKUS DEFAULT Run CTFMON EXE C WINDOWS system CTFMON EXE User 'Default user' O - Gl... Read more

A:Trojan Horse Dropper.agent.git & Backdoor.agent.pta

Welcome to the BleepingComputer HijackThis Logs and Analysis forum. My name is Richie and i'll be helping you to fix your problems.Apologies for the late response,as i'm sure you can appreciate we are extremely busy.If you've already recieved help at another forum and your issues have been resolved,or you're presently recieving help elsewhere then please let us know.If you have not followed the info in the link below prior to posting your log then please do so now:Preparation Guide for use before posting a HijackThis Log:http://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/If you still require help,please post a new Hijackthis log into this topic in your next reply.Also post a detailed description of the issues you're experiencing.*Note*Post all reports/logs directly into this topic,not as attachments,thanks.

http://www.bleepingcomputer.com/forums/t/126982/trojan-horse-dropperagentgit-backdooragentpta/
Relevancy 78.69%

I am working on my fiance s laptop She gave it to me after seeing AVG Resident with Trojan Infected & PSW.Agent.AGLY Rootkit-Agent.EG Shield warnings last night AVG scan free identified Trojan PSW Agent AGLY and AVG Resident Shield identified Rootkit-Agent EG Virus BAT Deleter amp Infected with Trojan PSW.Agent.AGLY & Rootkit-Agent.EG Exploit AVG could not clean or heal the infections saying object is inaccessible The Resident Shield found the Trojan horse Rootkit-Agent EG under C Windows system drivers asyncmac sys and said quot Object is white-listed critical system file that should not be removed I do not get a dialog Open box to attach the attach txt and ark txt files Please let me know if these can be pasted or why I possibly cannot get the box to open It appears the Browse button is depressing but I do not get a dialog box to select the files Please help DDS txt DDS Ver - - - FAT x Run by Suzanne at on Fri Internet Explorer Microsoft Windows XP Professional GMT - AV AVG Anti-Virus Free On-access scanning enabled Updated DDD - FF- F- E B- D D BF Running Processes C WINDOWS System Ati evxx exeC WINDOWS system svchost -k DcomLaunchC WINDOWS system svchost -k rpcssC WINDOWS System svchost exe -k netsvcsC WINDOWS System S EvMon exeC Program Files AVG AVG avgchsvx exeC Program Files AVG AVG avgrsx exeC WINDOWS System svchost exe -k NetworkServiceC WINDOWS system ZCfgSvc exeC WINDOWS system Ati evxx exeC WINDOWS System svchost exe -k LocalServiceC WINDOWS Explorer EXEC Program Files AVG AVG avgcsrvx exeC WINDOWS system LEXBCES EXEC WINDOWS system spoolsv exeC WINDOWS system LEXPPS EXEC WINDOWS System SCardSvr exeC WINDOWS System svchost exe -k LocalServiceC Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exeC Program Files AVG AVG avgwdsvc exeC Program Files Bonjour mDNSResponder exeC Program Files Dell NICCONFIGSVC NICCONFIGSVC exeC WINDOWS System RegSrvc exeC WINDOWS System svchost exe -k imgsvcC Program Files AVG AVG avgnsx exeC WINDOWS system wbem wmiprvse exeC WINDOWS System alg exeC WINDOWS System XConfig exeC Program Files ATI Technologies ATI Control Panel atiptaxx exeC Program Files CyberLink PowerDVD DVDLauncher exeC Program Files Common Files Microsoft Shared Works Shared WkUFind exeC Program Files Java jre bin jusched exeC Program Files QuickTime QTTask exeC Program Files iTunes iTunesHelper exeC Program Files Lexmark X Series lxbfbmgr exeC Program Files Lexmark X Series lxbfbmon exeC PROGRA AVG AVG avgtray exeC WINDOWS system ctfmon exeC Program Files HP Digital Imaging bin hpqtra exeC Program Files iPod bin iPodService exeC Program Files HP Digital Imaging bin hpqgalry exeC Program Files Microsoft Office OFFICE WINWORD EXEC Program Files Microsoft Works WkDStore exeC Program Files Internet Explorer iexplore exeC Program Files Microsoft Office OFFICE MSTORDB EXEC Program Files Common Files Microsoft Shared Works Shared wkcalrem exeC WINDOWS msagent AgentSvr exeC Program Files Internet Explorer iexplore exeC Program Files Common Files Adobe Updater AdobeUpdater exeC Program Files Internet Explorer iexplore exeC Program Files Internet Explorer IEXPLORE EXEC WINDOWS system rundll exeC WINDOWS System dllhost exeC WINDOWS System msdtc exeC Program Files Internet Explorer iexplore exeC Documents and Settings Suzanne Desktop Jason dds scrC WINDOWS system wbem wmiprvse exe Pseudo HJT Report uStart Page hxxp www google com uSearch Page hxxp www google comuSearch Bar hxxp www google com ieuSearchMigratedDefaultURL hxxp www google com search q searchTerms amp sourceid ie amp rls com microsoft en-US amp ie utf amp oe utf mSearch Bar hxxp red clientapps yahoo com customize ie defaults sb ymsgr http www yahoo com ext search search htmluInternet Connection Wizard ShellNext iexploreuInternet Settings ProxyOverride localuSearchAssistant hxxp www google com ieuSearchURL Default hxxp www google com search q smSearchAssistant hxxp www google com ieuURLSearchHooks AVG Security Toolbar BHO a b... Read more

A:Infected with Trojan PSW.Agent.AGLY & Rootkit-Agent.EG

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HEREPlease download GMER from one of the following locations and save it to your desktop:Main MirrorThis version will download a randomly named file (Recommended)Zipped MirrorThis version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.Disconnect from the Internet and close all running programs.Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.Now click the Scan button. If you see a rootkit warning window, click OK.When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.Click the Copy button and paste the results into your next reply.Exit GMER and re-enable all active protection when done.-- If you encounter any problems, try running GMER in Safe Mode.

http://www.bleepingcomputer.com/forums/t/318212/infected-with-trojan-pswagentagly-rootkit-agenteg/
Relevancy 78.69%

I was getting popup windows saying quot MSVideo dll is not a valid Windows image quot See previous discussion in link Norton Internet Security and Malbyteware found nothing SuperAntiSpyware found the above viruses and removed them I continued to see popup windows after doing this To see if everything is gone I was instructed to create log files with and Rogue windows Agent Trojan Agent/Popup DDS and GMER The dds txt file is pasted below The attach txt and ark txt files are attached I just Rogue Agent and Trojan Agent/Popup windows tried to run SuperAntiSpyware and got the same error page about msvideo see attached image So something is still wrong DDS Ver - - - NTFSx Run by Les at on Fri Internet Explorer Microsoft Windows XP Professional GMT - Running Processes C WINDOWS system svchost -k DcomLaunchsvchost exeC WINDOWS System Rogue Agent and Trojan Agent/Popup windows svchost exe -k netsvcssvchost exesvchost exeC WINDOWS system spoolsv exesvchost exeC Program Files Symantec LiveUpdate AluSchedulerSvc exeC Program Files Verizon IHA MessageCenter Bin Verizon IHAMessageCenter exeC WINDOWS Explorer EXEC Program Files Nero Nero InCD InCDsrv exeC Program Files Java jre bin jqs exeC Program Files Common Files LightScribe LSSrvc exeC Program Files Common Files Motive McciCMService exeC Program Files Norton Internet Security Engine ccSvcHst exeC PROGRA NORTON NORTON NPROTECT EXEC Program Files Nuance PaperPort PDFProFiltSrvPP exeC WINDOWS System snmp exeC PROGRA NORTON NORTON SPEEDD NOPDB EXEC WINDOWS system svchost exe -k imgsvcC Program Files Common Files Microsoft Shared Windows Live WLIDSVC EXEC WINDOWS system SearchIndexer exeC Program Files Iomega AutoDisk ADService exeC Program Files Common Files Microsoft Shared Windows Live WLIDSvcM exeC Program Files Canon CAL CALMAIN exeC Program Files Norton Internet Security Engine ccSvcHst exeC Program Files Nero Nero InCD NBHGui exeC WINDOWS RTHDCPL EXEC WINDOWS system igfxpers exeC WINDOWS system igfxsrvc exeC Program Files Microsoft IntelliPoint ipoint exeC Program Files Nero Nero InCD InCD exeC Program Files Iomega AutoDisk ADUserMon exeC Program Files Google Gmail Notifier gnotify exeC Program Files Nuance PDFViewerPlus pdfpro hook exeC Program Files Verizon McciTrayApp exeC WINDOWS system ctfmon exeC Program Files Google GoogleToolbarNotifier GoogleToolbarNotifier exeC Documents and Settings All Users Application Data FLEXnet Connect ISUSPM exeC Program Files Windows Desktop Search WindowsSearch exeC Program Files Wiley Webster s New World HKML SRV exeC Documents and Settings Les Desktop dds scr Pseudo HJT Report uStart Page hxxp finance yahoo com p v amp k pf uSearch Bar mSearch Bar hxxp home netscape com home winsearch htmluSearchURL Default hxxp keyword netscape com keyword sBHO Adobe PDF Link Helper df c-e ad- -a -fa c ebdc - c program files common files adobe acrobat activex AcroIEHelperShim dllBHO RealPlayer Download and Record Plugin for Internet Explorer c e -b - bc - - c ca - c documents and settings all users application data real realplayer browserrecordplugin ie rpbrowserrecordplugin dllBHO PlusIEEventHelper Class a f- a - a - c -afbec a d - c program files nuance pdfviewerplus bin PlusIEContextMenu dllBHO Symantec NCO BHO adb e- aff- - aa - dac dfa - c program files norton internet security engine coIEPlg dllBHO Symantec Intrusion Prevention d ec - aae- -aeee-f f c - c program files norton internet security engine ips IPSBHO DLLBHO Windows Live ID Sign-in Helper d - c - abf- ecc- c - c program files common files microsoft shared windows live WindowsLiveLogin dllBHO Adobe PDF Conversion Toolbar Helper ae cd -e - f- - ee - c program files common files adobe acrobat activex AcroIEFavClient dllBHO Google Toolbar Notifier BHO af de - d - -b fa-ce b ad d - c program files google googletoolbarnotifier swg dllBHO ZeonIEEventHelper Class da d d-ccaf- b - fe-bfa bebf - c program files nuance pdfviewerplus bin ZeonIEFavClient dllBHO Java Plug-In SSV Helper dbc -a - b-bc - c c c a... Read more

A:Rogue Agent and Trojan Agent/Popup windows

Hi,Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.Please subscribe to this topic, if you haven't already. Click the Watch This Topic button at the top on the right.

Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

Please reply to this post so I know you are there.The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.Once I receive a reply then I will return with your first instructions.Thanks

http://www.bleepingcomputer.com/forums/t/381615/rogue-agent-and-trojan-agentpopup-windows/
Relevancy 78.69%

I had found & online Agent.nbs Agent.nbl scanner eset noticed recently that my pc hard drive would by spinning up nad my hd activity light would be on like constant flickering red even when i wasnt using it at all I did an online scan with eset online scanner found Agent.nbl & Agent.nbs eset online scanner just to see if i could tarck down the problem Unfortunately for whatever reason when i looked at the log it was supposed to save of the scan it had not saved anything that would describe what it found and removed I do know it was something about Agent nbl amp Agent nbs And to do with possible java something or other I am including the logs from Hijack This and other reqested items Although as I have bit system i cannot use Gmer Logfile of Trend Micro HijackThis v Scan saved at on Platform Windows SP WinNT MSIE Internet Explorer v Boot mode Normal Running processes C Program Files x Common Files Acronis Schedule schedhlp exe C Windows vVX exe C Program Files x Samsung Kies KiesTrayAgent exe C Program Files x Vtune TBPANEL exe C Program Files x Samsung Kies External FirmwareUpdate KiesPDLR exe C Program Files x eset online scanner found Agent.nbl & Agent.nbs Common Files Apple Internet Services ubd exe C Users user AppData Roaming Spotify Data SpotifyWebHelper exe C Program Files x Samsung Kies Kies exe C Program Files x Renesas Electronics USB Host Controller Driver Application nusb mon exe C Program Files x Acronis TrueImageHome TrueImageMonitor exe C Program Files x D-Link DWA- revB AirNCFG exe C Program Files x Razer Naga RazerNagaSysTray exe C Program Files x Common Files Apple Apple Application Support distnoted exe C Users user AppData Roaming Spotify spotify exe C Program Files x Internet Explorer iexplore exe C Program Files x Internet Explorer iexplore exe C Program Files eset online scanner found Agent.nbl & Agent.nbs x Windows Live Messenger msnmsgr exe C Program Files x Windows Live Contacts wlcomm exe C Users Public Games World of Warcraft Wow exe c PROGRA mcafee SITEAD saui exe C Program Files x Internet Explorer iexplore exe C Program Files x Internet Explorer iexplore exe C Program Files x ESET ESET Online Scanner OnlineScannerApp exe C Program Files x Trend Micro HiJackThis HiJackThis exe R - HKLM Software Microsoft Internet Explorer Main Default Page URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Default Search URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Search Page http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Start Page http go microsoft com fwlink LinkId R - HKCU Software Microsoft Windows CurrentVersion Internet Settings ProxyOverride local R - HKCU Software Microsoft Internet Explorer Toolbar LinksFolderName R - URLSearchHook McAfee SiteAdvisor Toolbar - EBBBE -BAD - B C- E A- ABECAE - c PROGRA mcafee SITEAD mcieplg dll O - BHO AcroIEHelperStub - DF C-E AD- -A -FA C EBDC - C Program Files x Common Files Adobe Acrobat ActiveX AcroIEHelperShim dll O - BHO McAfee Phishing Filter - B A- - A -B -BE AFE AB - c progra mcafee msk mskapbho dll file missing O - BHO Java tm Plug-In SSV Helper - BB-D F - C-B EB-D DAF D D - C Program Files x Java jre bin ssv dll O - BHO scriptproxy - DB D A - - E -B D- F C - C Program Files x Common Files McAfee SystemCore ScriptSn dll O - BHO IESpeakDoc - D F C - E - BD - - AC FDF - C Program Files x Bluetooth Suite IEPlugIn dll O - BHO Windows Live ID Sign-in Helper - D - C - ABF- ECC- C - C Program Files x Common Files Microsoft Shared Windows Live WindowsLiveLogin dll O - BHO McAfee SiteAdvisor BHO - B E -A B - A -B - CD E A FF - c PROGRA mcafee SITEAD mcieplg dll O - BHO Java tm Plug-In SSV Helper - DBC -A - b-BC - C C C A - C Program Files x Java jre bin jp ssv dll O - Toolbar McAfee SiteAdvisor Toolbar - EBBBE -BAD - B C- E A- ABECAE - c PROGRA mcafee SITEAD mcieplg dll O - HKLM Run mcui exe quot C Program Files McAfee com Agent m... Read more

Relevancy 78.69%

Hello- My Malwarebytes Antimalware scan shows these infections HKEY LOCAL MACHINE SOFTWARE Microsoft Windows CurrentVersion Explorer Browser Settings bf Trojan Agent HKEY LOCAL MACHINE SOFTWARE Microsoft Windows CurrentVersion Explorer Browser Settings bk and Rootkit.Agent with Infected Trash.gen Trojan.Agent, Trojan Agent HKEY LOCAL MACHINE SOFTWARE Microsoft Windows CurrentVersion Explorer Browser Settings iu Trojan Agent HKEY LOCAL MACHINE SOFTWARE Microsoft Windows CurrentVersion Explorer Browser Settings mu Trojan Agent C Documents and Settings MH Local Settings Temp dgankqeo dat Rootkit Agent My Avira scan shows Trash gen Both programs say that these infections are locked and will be removed when I restart the computer but they are still there when I recheck I've tried turning off system restore but this doesn't seem to make a difference I've run SuperAntispyware Adaware SpywareBlaster and CCcleaner Infected with Trojan.Agent, Trash.gen and Rootkit.Agent but nothing gets rid of them Please help Here's the DDS txt DDS Ver - - - NTFSx Run by MH at on Sun Internet Explorer BrowserJavaVersion Microsoft Windows XP Home Edition Infected with Trojan.Agent, Trash.gen and Rootkit.Agent GMT - AV AntiVir Desktop On-access scanning enabled Updated FW Online Armor Firewall enabled Running Processes C WINDOWS system svchost -k DcomLaunch C WINDOWS system svchost -k rpcss C Program Files TuneUp Utilities WinStylerThemeSvc exe C WINDOWS System svchost exe -k netsvcs C WINDOWS System svchost exe -k NetworkService C WINDOWS system svchost exe -k LocalService C Program Files Tall Emu Online Armor oasrv exe C Program Files Lavasoft Ad-Aware AAWService exe C WINDOWS system spoolsv exe C Program Files Avira AntiVir Desktop sched exe C WINDOWS System svchost exe -k LocalService C WINDOWS Nhksrv exe C Program Files Avira AntiVir Desktop avguard exe C Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exe C Program Files Bonjour mDNSResponder exe C WINDOWS system CTsvcCDA EXE C Program Files Java jre bin jqs exe C WINDOWS system nvsvc exe C Program Files Tall Emu Online Armor oacat exe C WINDOWS System svchost exe -k imgsvc C WINDOWS system MsPMSPSv exe C WINDOWS System wbem unsecapp exe C WINDOWS system wbem wmiprvse exe C WINDOWS Explorer EXE C WINDOWS System alg exe C WINDOWS DELLMMKB EXE C Program Files Vista Drive Icon DrvIcon exe C Program Files Common Files Real Update OB realsched exe C Program Files Netropa OSD exe C Program Files iTunes iTunesHelper exe C Program Files Avira AntiVir Desktop avgnt exe C Program Files Java jre bin jusched exe C Program Files Tall Emu Online Armor oaui exe C Program Files Lavasoft Ad-Aware AAWTray exe C WINDOWS system tbctray exe C Program Files Siber Systems AI RoboForm RoboTaskBarIcon exe C Program Files RamBooster Rambooster exe C Program Files Tall Emu Online Armor oahlp exe C Program Files PeerGuardian pg exe C Program Files DAEMON Tools Lite daemon exe C Program Files iPod bin iPodService exe C Program Files Logitech SetPoint SetPoint exe C Program Files Jetico BestCrypt BCResident exe C Program Files Microsoft SQL Server Tools Binn sqlmangr exe C Program Files Common Files Logitech KHAL KHALMNPR EXE C Program Files WinZip WZQKPICK EXE C Program Files Mozilla Firefox firefox exe C Documents and Settings MH Desktop dds scr C WINDOWS system wbem wmiprvse exe Pseudo HJT Report uStart Page hxxp www google com uInternet Settings ProxyOverride local BHO Adobe PDF Reader Link Helper e f-c d - d -b d- b d be b - c program files adobe acrobat activex AcroIEHelper dll BHO - f - d - - d f - c progra spybot SDHelper dll BHO d a - d - d - - e a - c program files siber systems ai roboform roboform dll BHO c a de - - - d - f - c windows system BORLNDM dll BHO Java Plug-In SSV Helper dbc -a - b-bc - c c c a - c program files java jre bin jp ssv dll BHO JQSIEStartDetectorImpl Class e e f - ce- c -bc -eabfe f c - c program files java jre lib deploy jqs ie jqs plugin dll TB amp RoboFor... Read more

A:Infected with Trojan.Agent, Trash.gen and Rootkit.Agent

Hello and welcome to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.If you have already posted a DDS log, please do so again, as your situation may have changed.Use the 'Add Reply' and add the new log to this thread.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results.Follow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERER,K

http://www.bleepingcomputer.com/forums/t/220640/infected-with-trojanagent-trashgen-and-rootkitagent/
Relevancy 78.69%

I believe it is time to find the perfect accomplice Analyst to get me out of a gap between the rock and a hard place you see not only the agent trojan infected my computer Agent Help!!! et.al (jspygone007) trapped this secret Trojan agent but several others No popups after I have remove the infection with ewido and tried to uninstall MyWaySearch Toolbar but it has been set to where my mouse is acting strangely like a keylogger has been lurking on my system Here is my log Are you in for the challenge Logfile of HijackThis v Scan saved at AM on Platform Windows XP SP WinNT MSIE Internet Explorer v SP Running processes C WINDOWS System smss exe C WINDOWS system winlogon exe C WINDOWS system services exe C WINDOWS system lsass exe C WINDOWS system svchost exe Help!!! Agent Trojan et.al trapped this secret agent (jspygone007) C WINDOWS system svchost exe C WINDOWS system svchost exe C WINDOWS Explorer EXE C Program Files Sunbelt Software CounterSpy Consumer SunServer exe C WINDOWS system taskmgr exe C Program Files Internet Explorer iexplore exe C Documents and Settings aarons Desktop Misc HijackThis exe R - HKCU Software Microsoft Internet Explorer Main Default Page URL http www dell me com mywaybiz R - HKCU Software Microsoft Internet Explorer Main Start Page http securityresponse symantec com fix homepage R - HKLM Software Microsoft Internet Explorer Main Start Page http home verizon yahoo com R - HKCU Software Microsoft Internet Connection Wizard ShellNext http www dell com O - BHO Yahoo Toolbar Helper - D -C F - EFB- B - ECA - C Program Files Yahoo Companion Installs cpn yt dll O - BHO Adobe PDF Reader Link Helper - E F-C D - D -B D- B D BE B - C Program Files Adobe Acrobat ActiveX AcroIEHelper dll O - BHO UberButton Class - BAB B B- BC- B - D - FC DE A - C Program Files Yahoo Common yiesrvc dll O - BHO DriveLetterAccess - CA D E- - CF- E - - C WINDOWS system dla tfswshx dll O - BHO YahooTaggedBM Class - D A - CA - B-BB - D EFB A - C Program Files Yahoo Common YIeTagBm dll O - BHO SSVHelper Class - BB-D F - C-B EB-D DAF D D - C Program Files Java jre bin ssv dll O - BHO CNisExtBho Class - ECB - F - bbc- D- DDF E - C Program Files Common Files Symantec Shared AdBlocking NISShExt dll O - BHO SidebarAutoLaunch Class - F AA - - -B C -A CCDF CBF D - C Program Files Yahoo browser YSidebarIEBHO dll O - Toolbar Norton Internet Security - B EAC - D - b e- B -A C A A - C Program Files Common Files Symantec Shared AdBlocking NISShExt dll O - Toolbar Yahoo Toolbar - EF BD -C FB- D - F- D F - C Program Files Yahoo Companion Installs cpn yt dll O - HKLM Run LXCCCATS rundll C WINDOWS System spool DRIVERS W X LXCCtime dll RunDLLEntry O - HKLM Run MSConfig C WINDOWS PCHealth HelpCtr Binaries MSConfig exe auto O - HKLM Run SunServer C Program Files Sunbelt Software CounterSpy Consumer sunserver exe O - HKCU RunOnce CounterSpyCleaner C Program Files Sunbelt Software CounterSpy Consumer sunASCleaner exe O - Extra button no name - B E C - FCB- CF-AAA - C - C Program Files Java jre bin npjpi dll O - Extra 'Tools' menuitem Sun Java Console - B E C - FCB- CF-AAA - C - C Program Files Java jre bin npjpi dll O - Extra button Create Mobile Favorite - EAF BB - F- D - - C FAE D F - C Program Files Microsoft ActiveSync inetrepl dll O - Extra button no name - EAF BB - F- D - - C FAE D F - C Program Files Microsoft ActiveSync inetrepl dll O - Extra 'Tools' menuitem Create Mobile Favorite - EAF BB - F- D - - C FAE D F - C Program Files Microsoft ActiveSync inetrepl dll O - Extra button Verizon Yahoo Services - BAB B B- BC- B - D - FC DE A - C Program Files Yahoo Common yiesrvc dll O - Extra button Real com - CD F -D E - d - FE- C F AFE - C WINDOWS system Shdocvw dll O - Extra button Messenger - FB F -F - d -BB E- C F - C Program Files Messenger msmsgs exe O - Extra 'Tools' menuitem Windows Messenger - FB F -F - d -BB E- C F - C Program Files Messenger msmsgs exe O - DPF BC F - A - D -BEB - AA B AE Symantec AntiVirus scanner - http security symantec com sscv S... Read more

A:Help!!! Agent Trojan et.al trapped this secret agent (jspygone007)

New log... IN NORMAL MODE!!!

Logfile of HijackThis v1.99.1
Scan saved at 11:14:55 AM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Yahoo!\Yahoo! Music Engine\ymetray.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\lxcccoms.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\aarons\Desktop\Misc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.verizon.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.verizon.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Norto... Read more

http://www.techsupportforum.com/forums/f284/help-agent-trojan-et-al-trapped-this-secret-agent-jspygone007-110352.html
Relevancy 78.69%

KASPERSKY ONLINE SCANNER REPORTSaturday November Operating System Microsoft Windows XP Professional Service Pack build Kaspersky Online Scanner version Program database last update Friday November Records in database Scan settingsScan using the following database extendedScan archives yesScan mail databases yesScan area My ComputerC D E F Scan statisticsFiles scanned Threat name Infected objects Suspicious objects Duration of the scan File name Threat name Threats countC Documents and Settings All Users Application Data FreeApp exe Infected Infected: Backdoor.Win32.Agent.ubx IRC-Worm.Win32.Small.x, Trojan-Proxy.Win32.Agent.bcw, Trojan.Win32.Agent.arng, Trojan Win Agent arng C Qoobox Quarantine C Program Infected: Trojan.Win32.Agent.arng, Trojan-Proxy.Win32.Agent.bcw, IRC-Worm.Win32.Small.x, Backdoor.Win32.Agent.ubx Files tinyproxy tinyproxy exe vir Infected Trojan-Proxy Win Agent bcw C RECYCLER S- - - - - - - winse exe Infected IRC-Worm Win Small x C WINDOWS bolivar exe Infected Backdoor Win Agent ubx The selected area was Infected: Trojan.Win32.Agent.arng, Trojan-Proxy.Win32.Agent.bcw, IRC-Worm.Win32.Small.x, Backdoor.Win32.Agent.ubx scanned Infected: Trojan.Win32.Agent.arng, Trojan-Proxy.Win32.Agent.bcw, IRC-Worm.Win32.Small.x, Backdoor.Win32.Agent.ubx ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Logfile of random's system information tool written by random random Run by William Junior at - - Microsoft Windows XP Professional Service Pack System drive C has GB free of GBTotal RAM MB free Logfile of Trend Micro HijackThis v Scan saved at on Platform Windows XP SP WinNT MSIE Internet Explorer v Boot mode NormalRunning processes C WINDOWS System smss exeC WINDOWS system winlogon exeC WINDOWS system services exeC WINDOWS system lsass exeC WINDOWS system svchost exeC WINDOWS System svchost exeC Program Files Intel Wireless Bin EvtEng exeC Program Files Intel Wireless Bin S EvMon exeC Program Files Lavasoft Ad-Aware aawservice exeC WINDOWS Explorer EXEC Program Files TortoiseSVN bin TSVNCache exeC WINDOWS system spoolsv exeC Program Files Apoint Apoint exeC WINDOWS RTHDCPL EXEC Program Files Java jre bin jusched exeC Program Files COMODO COMODO Internet Security cfp exeC Program Files iTunes iTunesHelper exeC WINDOWS system ctfmon exeC Program Files Spybot - Search amp Destroy TeaTimer exeC Program Files Internet Download Manager IDMan exeC Program Files Apoint Apntex exeC Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exeC Program Files Bonjour mDNSResponder exeC Program Files COMODO COMODO Internet Security cmdagent exeC Program Files Java jre bin jqs exeC WINDOWS system nvsvc exeC Program Files Intel Wireless Bin RegSrvc exeC WINDOWS system svchost exeC Program Files iPod bin iPodService exeC Program Files Internet Download Manager IEMonitor exeC Program Files Mozilla Firefox firefox exeC WINDOWS system winlogon exeC WINDOWS system wuauclt exeC Documents and Settings William Junior My Documents Downloads Programs RSIT exeC Program Files trend micro William Junior exeR - HKCU Software Microsoft Internet Explorer Main Start Page http www google ie R - HKLM Software Microsoft Internet Explorer Main Default Page URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Default Search URL http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Search Page http go microsoft com fwlink LinkId R - HKLM Software Microsoft Internet Explorer Main Start Page http go microsoft com fwlink LinkId F - REG win ini load F - REG win ini run O - BHO IDM Helper - C - - B-A BF- B C A A - C Program Files Internet Download Manager IDMIECC ... Read more

A:Infected: Trojan.Win32.Agent.arng, Trojan-Proxy.Win32.Agent.bcw, IRC-Worm.Win32.Small.x, Backdoor.Win32.Agent.ubx

Hello and to Bleeping ComputerWe apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.Thanks and again sorry for the delay.We need to see some information about what is happening in your machine. Please perform the following scan:Download DDS by sUBs from one of the following links. Save it to your desktop.DDS.comDDS.scrDDS.pifDouble click on the DDS icon, allow it to run.A small box will open, with an explaination about the tool. No input is needed, the scan is running.Notepad will open with the results, click no to the Optional_ScanFollow the instructions that pop up for posting the results.Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

http://www.bleepingcomputer.com/forums/t/182650/infected-trojanwin32agentarng-trojan-proxywin32agentbcw-irc-wormwin32smallx-backdoorwin32agentubx/
Relevancy 77.83%

I have an Acer Aspire z laptop And I was just wondering if I can change my bios ID if this even exists or to change my bios string But I am not so sure on how to do this Because I have an Insyde bios unfortunetly And my bios is very limited in bios change on to string how to I id bios would like know or my settings which has no quot Power quot tab and no quot Advanced quot tab And I am very upset about this But I really want these Power and Advanced tabs to show up in my Insyde bios So please help I would like to know on how to change my bios string or bios id me out here I am asking you Because I was thinking of like I would like to know on how to change my bios string or bios id downloading another Insyde bios from like an Acer Aspire z model laptop or an HP laptop Insyde bios but I do not know I would like to know on how to change my bios string or bios id if that is possible So any kind of help will be greatly appreciated That is all I want from you So please get back to me as soon as you can on this I would really like my Insyde bios to have a Power and Advanced tab a lot And also just let me know if I can change my bios ID and or my bios string so I can upgrade to a different bios for Insyde I have a Insyde bios chip so any bios should work But it has to match with my Pentium dual-core processor I am assuming Which is what I have So please get back to me soon with answers Thank you very much

A:I would like to know on how to change my bios string or bios id

Please do not create multiple threads for the same issue.
Stick to your other thread:
http://www.techsupportforum.com/forums/f217/i-would-like-to-know-on-how-to-change-my-bios-string-689857.html

Thread closed

http://www.techsupportforum.com/forums/f217/i-would-like-to-know-on-how-to-change-my-bios-string-or-bios-id-690685.html
Relevancy 77.83%

I'm setting up Win for the st time on a Lenovo Win laptop It had to do a ton of upgrades before all the features would work like the touch screen amp task bar Once all the updates were completed I started to set it up Somehow I missed the part where you put a name to the quot USER quot in the C drive On my Asus it says This USER? This to edit/change "USER" How > user > in: C: PC> PC gt C gt user gt johnf But on the Lenovo is says This PC gt C gt user gt USER I went in amp changed the Local Account Admin to a Name I wanted hoping that would change quot USER quot to quot rocco quot but it didn't I know that all programs installed in the future will have a path that looks like This How to edit/change "USER" in: This PC> C: > user > USER? PC gt How to edit/change "USER" in: This PC> C: > user > USER? C gt user gt USER gt Dropbox unless I can change it I'm not very far into setting the laptop up so I want to make sure I don't keep moving forward in case I have to reset or roll back anything How can I fix this problem Also why do I have a C drive GB amp a D drive GB after I did the Win update it had Win on it but needed to upgrade to a newer version amp now I have a D drive that i did not create Thanks

http://www.techsupportforum.com/forums/f338/how-to-edit-change-user-in-this-pc-c-user-user-1145193.html
Relevancy 77.83%

I can't Backdoor.Agent.CHGen, & Backdoor.Agent.E Trojan.Agent, post a log because when I run MalwareBytes and Copy the log to Trojan.Agent, Backdoor.Agent.CHGen, & Backdoor.Agent.E clipboard it comes Trojan.Agent, Backdoor.Agent.CHGen, & Backdoor.Agent.E up empty But Malwarebytes keeps finding three persistent malware that it keeps saying it quarantined and I try to delete but Trojan.Agent, Backdoor.Agent.CHGen, & Backdoor.Agent.E they show up after every single scan I've posted the image above and attached it to this post Help me get rid of these please Trojan Agent Malwarebytes Anti-Malware www malwarebytes org Scan Date Scan Time PM Logfile Administrator Yes Version Malware Database v Rootkit Database v License Trial Malware Protection Enabled Malicious Website Protection Enabled Self-protection Disabled OS Windows CPU x File System NTFS User SillyTilly Scan Type Threat Scan Result Completed Objects Scanned Time Elapsed min sec Memory Enabled Startup Enabled Filesystem Enabled Archives Enabled Rootkits Disabled Heuristics Enabled PUP Enabled PUM Enabled Processes No malicious items detected Modules No malicious items detected Registry Keys No malicious items detected Registry Values No malicious items detected Registry Data No malicious items detected Folders No malicious items detected Files No malicious items detected Physical Sectors No malicious items detected end

A:Trojan.Agent, Backdoor.Agent.CHGen, & Backdoor.Agent.E

Hi & to Bleeping Computer Forums!My name is Jürgen and I will be assisting you with your Malware related problems. Before we move on, please read the following points carefully: My native language isn't English. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.Please read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.Perform everything in the correct order. Sometimes one step requires the previous one.If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.If I don't hear from you within 5 days from this initial or any subsequent post, then this thread will be closed.If I don't reply within 24 hours please PM me!Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.Step 1Please run a FRST scan. This will help us diagnose your problem.Please download Farbar Recovery Scan Tool and save it to your Desktop.(If you are not sure which version (32-/64-bit) applies to your system, download and try to start both of them as just the right one will run.)Start FRST with administator privileges.Make sure the option Addition.txt is checked and press the Scan button.When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.Please copy and paste these logs in your next reply.Temporary disable your AntiVirus and AntiSpyware protection - instructions here.Step 2Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)Right-click on icon and select Run as Administrator to start the tool.Wait patiently until the main console will appear, it may take a minute or two.In the main box please paste in the following script:process;
services-list;
systemspecs;
startupall;
filesrcm;
Make sure that Scan All Users option is checked.Push Run Script and wait patiently. The scan may take a couple of minutes.When the scan completes, a zoek-results logfile should open in notepad.If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)Post its content into your next reply.

http://www.bleepingcomputer.com/forums/t/565870/trojanagent-backdooragentchgen-backdooragente/
Relevancy 77.4%

I am running Windows -bit I use AVG and Spybot S amp D as antivirus and haven't had an issue in over years that I wasn't able to clear up myself with these antivirus programs and by reading through these forums My computer has been running very slow for several months but I haven't bothered to mess with it much With the introduction of smartphones and tablets my family doesn't use our desktop as often Long story short I haven't kept up on updating and scanning my computer I finally decided to look into it and I seem to have something that is being extremely deceptive that I have exploit:js/axpergle Trojan.Agent/Gen-Agent and never dealt with before I Trojan.Agent/Gen-Agent and exploit:js/axpergle ran my normal antivirus and was told on top of several PUPS I had Trojan Agent Gen-Agent and exploit js axpergle These were found by different antivirus software I cannot tell you which ones as I've run so many since then I can't remember Anyway the programs say they've taken care of the issue but clearly I am still harboring a Trojan Problems I've encountered since removing these Trojans unable to start command prompt - I received an error Unable to turn on Windows Defender - error Unable to update other Trojan.Agent/Gen-Agent and exploit:js/axpergle antivirus programs - error With some antivirus programs I Trojan.Agent/Gen-Agent and exploit:js/axpergle get an error saying it can't update then it says it was updated Then I run it it finds issues it says it has deleted them but it hasn't done anything I have run all of these things in safe mode once running in regular mode didn't seem to work I finally gave up and tried a system restore and near the end I received an error saying it couldn't be done but then when it restarted it said that the system restore had been completed and it appears that my system has in fact been reset to the date I chose I've run the two antivirus programs listed above plus SuperAnti Spyware TDSSkiller ESETPoweliks cleaner Kapersky Malwarebytes FRST and all after running iexplore exe in safe mode first I've also tried ESET online time scanner and get an error saying the database can't be downloaded is the proxy configured I am at my wits end and am asking for the infinite wisdom of Bleeping Computer professional to help me out I've dealt with Trojans that hide everything on the desktop completely blocked antivirus and the internet but never one that pretends my legit antivirus does its job so it can go undetected Any assistance with my BLEEPING computer is very much appreciated

A:Trojan.Agent/Gen-Agent and exploit:js/axpergle

Greetings kls_01 and to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.If you would allow me to call you by your first name I would prefer to do that. ===================================================Ground Rules:First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.When you post your reply, use the button instead.In the upper right hand corner of the topic you will see the button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.I would like to remind you to make no further changes to your computer unless I direct you to do so.Now let's get started ===================================================Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.Thank you for your patience thus far. Please do this.===================================================Farbar Recovery Scan Tool (FRST)--------------------Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop <<< ImportantIf you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one shouldDouble click the iconClick Yes to the disclaimerMake sure the Addition.txt box is checkedClick Scan and allow the program to runClick OK on the Scan complete screen, then OK on the Addition.txt pop up screen2 Notepad documents should now be open on your desktop.Please copy and paste the contents of both in your reply===================================================System Summary Information--------------------Press the windows key + r on your keyboard at the same timeType msinfo32 and press EnterLeft click on System SummaryClick File, Save, and name the file SummaryZip and attach the file to your reply===================================================Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. FRST resultsAddition logSystem Summary Information

http://www.bleepingcomputer.com/forums/t/585467/trojanagentgen-agent-and-exploitjsaxpergle/
Relevancy 77.4%

Like everyone else who writes, I need HELP. Last week I ended up with Trojan.Agent on my computer but was able to get rid of it with Malwarebytes and several other programs. A couple of days ago I noticed I have no sound on my computer. I ran Malwarebytes again and it found and quarantined CrackTool.Agent. I went ahead and deleted it thinking that would solve my problem. Nope. I have read other fixes for this on your site but am not savvy enough to feel comfortable just executing without some hand holding. Can you help?

A:Trojan.Agent last week, now CrackTool.agent

Hello, Welcome to BleepingComputer.I'm nasdaq and will be helping you.If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.===Please download AdwCleaner by Xplode onto your Desktop.Close all open programs and internet browsers.Double click on AdwCleaner.exe to run the tool.Click the Scan button and wait for the process to complete.Click the LogFile button and the report will open in Notepad.IMPORTANTIf you click the Clean button all items listed in the report will be removed.If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.Close all open programs and internet browsers.Double click on AdwCleaner.exe to run the tool.Click the Scan button and wait for the process to complete.Check off the element(s) you wish to keep.Click on the Clean button follow the prompts.A log file will automatically open after the scan has finished.Please post the content of that log file with your next answer.You can find the log file at C:\AdwCleanerCx.txt (x is a number).===Download the version of this tool for your operating system.Farbar Recovery Scan Tool (64 bit)Farbar Recovery Scan Tool (32 bit)and save it to a folder on your computer's Desktop.Double-click to run it. When the tool opens click Yes to disclaimer.Press Scan button.It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.How to attach a file to your reply:In the Reply section in the bottom of the topic Click the "more reply Options" button.Attach the file.Select the "Choose a File" navigate to the location of the File.Click the file you wish to Attach.Click the Add reply button.Let me know what problem persists

http://www.bleepingcomputer.com/forums/t/595973/trojanagent-last-week-now-cracktoolagent/
Relevancy 77.4%

Trojan appears to be gone but computer doesnt function normally I have tried several malware removal tools forum solutions of somilar issues and restore to a previous time with no luck DDS Ver trogjan.agent/Gen-PEC trojan.agent/Gen-iefake - - - NTFS AMD Run by carol at on Fri Internet Explorer Microsoft Windows Home Premium GMT - SP Windows Defender Enabled Updated D DDC A- F- fae- E -DA C ACF Running Processes C Windows system trojan.agent/Gen-iefake trogjan.agent/Gen-PEC wininit trojan.agent/Gen-iefake trogjan.agent/Gen-PEC exe C Windows system lsm exe C Windows system svchost exe -k DcomLaunch C Windows system svchost exe -k RPCSS C Windows System svchost exe -k LocalServiceNetworkRestricted C Windows System svchost exe -k LocalSystemNetworkRestricted C Windows system svchost exe -k netsvcs C Windows System DriverStore FileRepository stwrt inf amd neutral afc f cfedd STacSV exe C Windows system svchost exe -k LocalService C Program Files Dell DellDock DockLogin exe C Windows system svchost exe -k NetworkService C Program Files Dell Dell Wireless WLAN Card WLTRYSVC EXE C Windows system WLANExt exe C Windows system conhost exe C Program Files Dell Dell Wireless WLAN Card bcmwltry exe C Windows System spoolsv exe C Windows system svchost exe -k LocalServiceNoNetwork C Program Files SUPERAntiSpyware SASCORE EXE C Program Files x Common Files Apple Mobile Device Support AppleMobileDeviceService exe C Program Files x Bonjour mDNSResponder exe C Program Files x Microsoft Search Enhancement Pack SeaPort SeaPort exe C Program Files x Dell DataSafe Local Backup sftservice EXE C Windows system svchost exe -k imgsvc C Windows System svchost exe -k secsvcs C Program Files Common Files Microsoft Shared Windows Live WLIDSVC EXE C Program Files x Intel Intel Matrix Storage Manager IAANTMon exe C Windows system SearchIndexer exe C Program Files Common Files Microsoft Shared Windows Live WLIDSvcM exe C Windows system wbem wmiprvse exe C Windows system svchost exe -k LocalServiceAndNoImpersonation C Program Files Windows Media Player wmpnetwk exe C Windows system taskhost exe C Windows system Dwm exe C Windows Explorer EXE C Program Files DellTPad Apoint exe C Program Files IDT WDM sttray exe C Windows System igfxtray exe C Windows System igfxpers exe C Program Files Dell Dell Wireless WLAN Card WLTRAY EXE C Program Files Dell QuickSet quickset exe C Program Files x Intel Intel Matrix Storage Manager IAAnotif exe C Program Files SUPERAntiSpyware SUPERAntiSpyware exe C Windows system igfxsrvc exe C Program Files Dell DellDock DellDock exe C Users carol AppData Roaming Dropbox bin Dropbox exe C Program Files x Dell DataSafe Online DataSafeOnline exe C Program Files x CyberLink PowerDVD DX PDVDDXSrv exe C Program Files x Dell Webcam Dell Webcam Central WebcamDell exe C Program Files x Roxio Roxio Burn RoxioBurnLauncher exe C Program Files x Common Files Nikon Monitor NkMonitor exe C Program Files x MSN Toolbar Platform mswinext exe C Program Files x iTunes iTunesHelper exe C Program Files DellTPad ApMsgFwd exe C Program Files DellTPad Apntex exe C Windows system conhost exe C Program Files DellTPad HidFind exe C Program Files iPod bin iPodService exe C Windows system svchost exe -k NetworkServiceNetworkRestricted C Windows system taskhost exe C Program Files x internet explorer iexplore exe C Program Files x internet explorer iexplore exe C Program Files x Windows Live Toolbar wltuser exe C Program Files x Microsoft Search Enhancement Pack SCServer SCServer exe C Windows system SearchFilterHost exe C Program Files x internet explorer iexplore exe C Windows system SearchProtocolHost exe C Windows system DllHost exe C Windows system DllHost exe C Users carol Desktop dds scr C Windows system conhost exe C Windows system wbem wmiprvse exe Pseudo HJT Report uStart Page hxxp www google com uInternet Settings ProxyOverride local mWinlogon Userinit userinit exe BHO Adobe PDF Link Helper df c-e ad- -a -fa c ebdc - C Program Files x Common Files Adobe ... Read more

A:trojan.agent/Gen-iefake trogjan.agent/Gen-PEC

Hello and welcome to Bleeping Computer We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here. Please take note: If you have since resolved the original problem you were having, we would appreciate you letting us know. If you are unable to create a log because your computer cannot start up successfully please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
If you are unsure about any of these characteristics just post what you can and we will guide you.Please tell us if you have your original Windows CD/DVD available. If you are unable to perform the steps we have recommended please try one more time and if unsuccessful alert us of such and we will design an alternate means of obtaining the necessary information. If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far. Upon completing the steps below another staff member will review your topic and do their best to resolve your issues. If you have already posted a DDS log, please do so again, as your situation may have changed. Use the 'Add Reply' and add the new log to this thread. We need to see some information about what is happening in your machine. Please perform the following scan again: Download DDS by sUBs from one of the following links if you no longer have it available. Save it to your desktop.DDS.scr DDS.pifDouble click on the DDS icon, allow it to run. A small box will open, with an explanation about the tool. No input is needed, the scan is running. Notepad will open with the results. Follow the instructions that pop up for posting the results. Close the program window, and delete the program from your desktop.Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE We also need a new log from the GMER anti-rootkit Scanner. Please note that if you are running a 64-bit version of Windows you will not be able to run GMER and you may skip this step. Please first disable any CD emulation programs using the steps found in this topic: Why we request you disable CD Emulation when receiving Malware Removal Advice Then create another GMER log and post it as an attachment to the reply where you post your new DDS log. Instructions on how to properly create a GMER log can be found here: How to create a GMER log Thanks and again sorry for the delay.

http://www.bleepingcomputer.com/forums/t/385814/trojanagentgen-iefake-trogjanagentgen-pec/
Relevancy 77.4%

Hi,

I currently am running windows xp and performed a virus scan using avira antivirus. The scan came back with two different viruses showing up. One was TR/agent.66048.153 and the other was adware/agent.180224.a. These both showed as being unppc.exe and ppal3ppc.exe. I have people pc files still on my computer but i thought i had deleted the program and the files ages ago. Am i infected with viruses?

Thanks.

A:TR/agent.66048.153 and adware/agent.180224.a

Hello, unppc.exe is a process from PeoplePC. It can be found in the location of C:\. It is a potential security risk which can be modified maliciously by virus. unppc.exe virus should be disabled and removed.Lets scan further.MiniToolBoxPlease download MiniToolBox, save it to your desktop and run it.Checkmark the following checkboxes:Flush DNSReport IE Proxy SettingsReset IE Proxy SettingsReport FF Proxy SettingsReset FF Proxy SettingsList content of HostsList IP configurationList Winsock EntriesList last 10 Event Viewer logList Installed ProgramsList Users, Partitions and Memory size.Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.>>>ADW CleanerPlease download AdwCleaner by Xplode onto your desktop.Close all open programs and internet browsers.Double click on adwcleaner.exe to run the tool.Click on Delete.Confirm each time with Ok.You will be prompted to restart your computer. A text file will open after the restart.Please post the contents of that logfile with your next reply.You can find the logfile at C:\AdwCleaner[S1].txt as well.>>>>I'd like us to scan your machine with ESET OnlineScanHold down Control and click on this link to open ESET OnlineScan in a new window.Click the button.For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.Double click on the
icon on your desktop.Check "YES, I accept the Terms of Use."Click the Start button.Accept any security warnings from your browser.Under scan settings, check "Scan Archives" and "Remove found threats" Click Advanced settings and select the following:Scan potentially unwanted applicationsScan for potentially unsafe applicationsEnable Anti-Stealth technologyESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.When the scan completes, click List ThreatsClick Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.Click the Back button.Click the Finish button.NOTE:Sometimes if ESET finds no infections it will not create a log.

http://www.bleepingcomputer.com/forums/t/484212/tragent66048153-and-adwareagent180224a/
Relevancy 77.4%

I can't get rid of those trojans here is the hjt log plus the files emplacements PLEASE HELP.
 

Relevancy 76.97%

OS Windows XP v Professional SP I restored the computer system as I had lost everything stored in the old user profile A NEW USER PROFILE mlinda quot is created with the correct domain attached to it eg CAA MAU and is fully restored The OLD USER PROFILE quot m linda quot remains in the documents and settings BUT - the domain is of a local computer eg SPARXX and it no longer works with the eg CAA MAU domain The original quot m linda quot user profile contains almost nothing in it no documents etc m linda is still listed in the userlist in computer management BUT 2 (fully name user user restored) new profile old ? Urgent-How profile change to back NOT THE NEW mlinda In administrator mode I dont t see ALL the contents of the newly restored profile Questions How do I change user profile quot mlinda Urgent-How 2 change new user profile (fully restored) back to old user profile name ? quot that has successfully retored everthing back to quot m linda quot since the new profile has everything intact How do I safely delete the newly restored quot mlinda quot and ensure everything is back to normal with the OLD USER PROFILE m linda How to ensure that the correct domain name is attached to the profile by transferring all the data from THE NEW mlinda eg domain CAA MAU to THE OLD m linda that currently has a local computer domain SPARXX User profile m linda has to be attched to domain CAA MAU Should I be backing up before eventhough the new mlinda is in super condition I read in forums that the links to desktop can be lost by transfering How do I retain it Do I have to change anything in the registry value Should I do it with Administrator account in normal mode or safe mode When I log on as an Administrator both mlinda and m linda is as brand new and none of the exisiting files in it When I log in as mlinda new I still see m linda local computer domain in the user list but not mlinda the new But when I right click properties of c documents and setting mlinda under security I see that mlinda is listed with the correct domain name My biggeest fear is not to lose the domain ouutlook etc while changing mlinda to m linda B Rather than going through a process of copying mlinda to m linda Is it possible just delete THE OLD USER PROFILE m linda and rename the THE NEW USER PROFILE mlinda since this is fully restored to m linda If yes what are the best steps And how can I make the adjustments to user list since when wondows starts there is only THE NEW PROFILE mlinda popping up I need it back to m linda I read in a forum that I can go to registry HKLM SOFTWARE Microsoft Windows NT CurrentVer Profilelist and change but I don t want to mess with it In my case in the registry i should I delete m linda first and rename mlinda to m linda This is rather urgent and need to fix today All your help are truly appreciated Thank you nbsp

https://forums.techguy.org/threads/urgent-how-2-change-new-user-profile-fully-restored-back-to-old-user-profile-name.1004093/
Relevancy 76.97%

Howdy All -
I'm thinking I'm not the first nor the last to have MS trick me into changing my User Name from Local to (in my case) an outlook.com email account. Now I'm forced to sign in every time I log on. And FWIW, I prefer to be fully in charge of my devices.
-
I surely would appreciate some guidance on the proper way to switch back to a Local User and disassociate my computer from outlook.com. Many thanks in advance for reading this and all replies.

Best,
/jdU

A:Proper (Safe) way to change from "Microsoft.com" User to Local User

Settings>>Accounts>>Under your Microsoft Account listing, click on "Change to a Local account instead".

Local Account - Switch to in Windows 10

http://www.tenforums.com/user-accounts-family-safety/49640-proper-safe-way-change-microsoft-com-user-local-user.html
Relevancy 76.54%

Hi was redirected from http www techsupportforum com f ml post Recently had antimalware virus which successfully removed using malware bytes infected files removed on a fresh scan no infected files Yet ive recieved BSOD in space on hrs with the comment DRIVE IRQL NOT LESS EQUAL or something along these lines I then ran malware bytes again and it comes up with infected file rootkit agent u delete then reboot run scan again same thing comes back a further BSODs in past few hrs with same message DDS files obtained fine however using GMER exe it would crash when doing the first suggested scan so did it just antimalware rootkit.agent doctor post virus and BSOD for sections and C here are the results attached regards and much respect for the effort you guys put in DDS Ver - - - NTFSx Run by Roberto at on Internet Explorer BrowserJavaVersion Microsoft Windows Vista Home Premium GMT AV AVG Anti-Virus Free On-access scanning enabled Updated DDD - FF- F- E B- D D BF AV BitDefender Antivirus On-access scanning disabled Updated C BB C-B ED- F -A C- BB SP BitDefender Antispyware disabled BSOD post antimalware doctor virus and rootkit.agent Updated B EC- D - F-BC - DB BDF SP AVG Anti-Virus Free enabled Updated DDD - FF- F- E B- D D BF SP Windows Defender disabled Updated D DDC A- F- FAE- E -DA C ACF FW BitDefender Firewall disabled F- E - A -A - D B F Running Processes C Windows system wininit exe C Windows system lsm exe C Windows system svchost exe -k DcomLaunch C Windows system nvvsvc exe C Windows system svchost exe -k rpcss C Windows System svchost exe -k secsvcs C Windows System svchost exe -k LocalServiceNetworkRestricted C Windows System svchost exe -k LocalSystemNetworkRestricted C Windows system svchost exe -k netsvcs C Windows system svchost exe -k GPSvcGroup C Windows system SLsvc exe C Windows system svchost exe -k LocalService C Windows system nvvsvc exe C Windows system svchost exe -k NetworkService C Windows System spoolsv exe C Windows system svchost exe -k LocalServiceNoNetwork C Windows System svchost exe -k Akamai C Program Files Common Files Apple Mobile Device Support bin AppleMobileDeviceService exe C PROGRA AVG AVG avgwdsvc exe C Program Files Bonjour mDNSResponder exe C Program Files Creative Shared Files CTDevSrv exe C Program Files Canon IJPLM IJPLMSVC EXE C Windows system PnkBstrA exe C Windows system PnkBstrB exe C Windows system svchost exe -k NetworkServiceNetworkRestricted C PROGRA AVG AVG avgrsx exe C Windows system STacSV exe C Windows system svchost exe -k imgsvc C Windows System svchost exe -k WerSvcGroup C Windows system SearchIndexer exe C PROGRA AVG AVG avgemc exe C Program Files AVG AVG avgcsrvx exe C Windows System alg exe quot C Windows System svchost exe quot C Windows system taskeng exe C Windows system Dwm exe C Windows system taskeng exe C Windows Explorer EXE C Program Files Windows Defender MSASCui exe C Program Files Common Files InstallShield UpdateService issch exe C Program Files Common Files Roxio Shared SharedCOM RoxWatchTray exe C Program Files Canon MyPrinter BJMYPRT EXE C Program Files ScanSoft OmniPageSE OpWareSE exe C Program Files AVG AVG avgtray exe C Windows OEM Mon exe C Program Files iTunes iTunesHelper exe C Program Files SigmaTel C-Major Audio WDM sttray exe C Program Files Java jre bin jusched exe C Windows System rundll exe C Program Files Windows Media Player wmpnscfg exe C Program Files Windows Sidebar sidebar exe C Program Files Windows Media Player wmpnetwk exe C Windows system wbem unsecapp exe C Windows system wbem wmiprvse exe C Program Files Creative Creative Media Lite CTZDetec exe C Windows ehome ehtray exe C Windows ehome ehmsas exe C Program Files Common Files Roxio Shared SharedCOM CPSHelpRunner exe C Program Files iPod bin iPodService exe C Program Files Internet Explorer ieuser exe C Program Files Internet Explorer iexplore exe C Windows system Macromed Flash FlashUtil d exe C PROGRA AVG AVG avgnsx exe C Windows system taskeng exe C Windows system conime exe ... Read more

A:BSOD post antimalware doctor virus and rootkit.agent

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

http://www.techsupportforum.com/forums/f100/bsod-post-antimalware-doctor-virus-and-rootkit-agent-516827.html
Relevancy 76.11%

I run windows 7 premium 64 and all of the sudden I stated to get this popup after windows loads that says
"C:\User\Lori-Bee\AppData\Local\Temp\032150Log.iniis lost"
How can I fix this?...I tried check disk running CCleaner ....No difference

A:C:\User\User -User\AppData\Local\Temp\032150Log.iniis lost

Hi there ... Read the Link below and follow the Instructions ..
ASUSTeK Computer Inc.-Forum- Error 182418Log.iniis lost

http://www.sevenforums.com/general-discussion/325334-c-user-user-user-appdata-local-temp-032150log-iniis-lost.html
Relevancy 76.11%

Posted here because I don't see a separate IE forum and since IE is part of Windows I view it as a Windows problem I've been having a problem with one of the One Hangs for User Frequent Only IE11 PCs where IE11 Frequent Hangs for Only One User IE frequently hangs spin spin spin and sometimes gets a stopped working error but not always It was specific to one of the six users on the machine I first deleted the user and created a new user in case it was a corrupt IE install Now the new user is experiencing the same problems It doesn't always give the stopped working error and most often just hangs along Fixes upon reboot but will end up happening eventually Turned off all add-ons including run without permission etc but couldn't determine which add-on might be the culprit on cycling them back on Also ran Malware Bytes and ESET NOD and don't come up with malware or Trojans etc in latest scan I'm flummoxed Thoughts and guidance appreciated for this one Here's the latest hang report Problem Event Name AppHangXProcB Application Name iexplore exe Application Version Application Timestamp fe bb Hang Signature e Hang Type Waiting on Application Name taskhost exe Waiting on Application Version OS Version Locale ID Additional Hang Signature e d cc ef b d e Additional Hang Signature e Additional Hang Signature e bcd e d cf f Additional Hang Signature f Additional Hang Signature f f f e aed e ec cbb Additional Hang Signature Additional Hang Signature e bf f ffc bd f Again thoughts Thanks in advance Richard

A:IE11 Frequent Hangs for Only One User

Have you tried running system file checker and or a clean boot with the particular user account? Do you happen to also transfer the user profile on the new account?

http://www.bleepingcomputer.com/forums/t/580666/ie11-frequent-hangs-for-only-one-user/
Relevancy 76.11%

I have the latest IE11 on win7 with all updates. After being sufficiently scared by ransomware reports, I decided to run IE isolated as a different user from my main desktop (standard UAC settings). The idea is whatever nasty comes in through the back door
will only harm a fake normal user's "documents" and leave mine in peace!
I can see in the task manager that there are a number of IE running processes all correctly set to that different user
However, IE loses login information. For example, when I login to my yahoo account or a phpBB forum with the option "remember me and login automatically", it doesn't. If I keep the same tab active it is ok, but if I browse away to say google, and
come back to the phpBB page, I have to login again. Which is a pain
what can be wrong and is there any solution? thanks

https://social.technet.microsoft.com/Forums/en-US/5b27e8ef-4648-45d3-b5ad-19336c9277f7/ie11-loses-login-when-run-as-different-user?forum=ieitprocurrentver
Relevancy 76.11%

Hi,
After the IE 11 is upgraded, If the internet explore opened where home page is set, it prompts for user name and password. If it is canceled it opens the home page.
But need to know why User Name and Password Prompts.

Regards,
Boopathi

https://social.technet.microsoft.com/Forums/en-US/71ef991b-d7fe-4e14-82ce-7f54adee7252/ie11-prompts-for-user-name-and-password?forum=ieitprocurrentver
Relevancy 76.11%

I work in IT and I have a user with a problem where they cannot send webpages Be send I mean they go into IE gt File gt send gt page by e-mail When they do this for the first time after they open IE and they go to the webpage they send User webpages can't IE11 need to send they can send that one just fine It will open up outlook give a description of the page in the subject line and in the main part it will show the page just fine Now if they go to the next page IE11 User can't send webpages they need to send they will do file gt send and then outlook will pop up the description will show correctly but the page that shows up in the main part is the one they first sent It does not match the second page they are trying to send nbsp Explained in IE11 User can't send webpages a different way they have page and page they need to send the pages are different parts of the same website The user IE11 User can't send webpages will send page and it describes page in the subject line and shows page in the main part When they go to send page it describes page in the subject line but in the main part it shows page nbsp I have found that this problem is only happening with website if they go to google for instance and send that page it shows google in the description and shows the google page in the main part Also if the users sends page and then closes IE re-opens it and goes to page it will be described as page in the subject line and show page in the main part Sorry for the long post but I wanted to give you guys as much info as possible to save time Any assistance would be great thanks

https://social.technet.microsoft.com/Forums/en-US/0fd74d9b-4f82-4bd8-9b5f-94646111a90d/ie11-user-cant-send-webpages?forum=ieitprocurrentver
Relevancy 75.68%

I was trying to work through making a project in C NET and the code I was looking off of from Microsoft used the notation String What does the carrot mean I am including the entire code in here so you can see it but it doesn t seem specific to Strings but C++ String^ .NET other than that I can t find any mention of it anywhere What does it mean C++ .NET String^ and should I be worried about it Thanks text read cpp compile with clr using lt system dll gt using namespace System using namespace System IO int main String fileName quot textfile txt quot try Console WriteLine quot trying to open file quot fileName StreamReader din File OpenText fileName String C++ .NET String^ str int count while str din- gt ReadLine nullptr count Console WriteLine quot line quot count str catch Exception e if dynamic cast lt FileNotFoundException gt e Console WriteLine quot file not found quot fileName else Console WriteLine quot problem reading file quot fileName return nbsp

A:C++ .NET String^

In C++/CLI the only type of pointer is the normal C++ pointer, and the .NET reference types are accessed through a "handle", with the new syntax ClassName^ instead of ClassName*. This new construct is especially helpful when managed and unmanaged code is mixed; it clarifies which objects are under .NET automatic garbage collection and which must be destroyed.Click to expand...

From http://en.wikipedia.org/wiki/C++/CLI
 

https://forums.techguy.org/threads/c-net-string.681474/
Relevancy 75.68%

Okay, quick question.
I have a text file with a list of words. I need each word to become a variable. So for example, I have in the text file: word1, word2, word3. Now I import them into a vector<string>. Now is there any way for me to overload that vector so as to make each word that I imported become a variable?

I could then say something like
word1 + word2 * word3. where each of these words is of type double.

Okay, thanks for your time and effort
Sincerely,
Ronald
 

A:C++, String

Im pretty sure you can't do this but something similar that you could do is import them into a map, where the key is the string you import and the value is a double (you didnt say if this was an imported value or otherwise but it shouldnt matter).

example:
Code:
map<string, double> myMap;
myMap["Word1"] = 5.03;
myMap["Word2"] = 2.0;
myMap["Word3"] = myMap["Word1"] * myMap["Word2"];
cout<<myMap["Word3"]<<endl;

hope this helps
 

https://forums.techguy.org/threads/c-string.164035/
Relevancy 75.25%

Suddenly today, IE11 stops working at load for just the Administrator user ID. The message says there is problem with the web page its trying to load. The web page is "cnn.com/#" and is the home page for this user in IE11. IE11 loads fine for the regular user which does not have admin privileges and will load the same URL with no problems. No addons for the admin user in IE11 and I can't get to the home page edit since the program won't load. Does anyone know where the start page for IE11 in W7 is stored? I've searched here and found no location. Thanks.

A:W7 IE11 stops working on load for one user

  
Quote: Originally Posted by jamis


...and I can't get to the home page edit since the program won't load. Does anyone know where the start page for IE11 in W7 is stored? I've searched here and found no location. Thanks.


You can open IE's settings/options using the control panel (without starting IE).

But to answer your question:

http://www.sevenforums.com/browsers-mail/375212-w7-ie11-stops-working-load-one-user.html
Relevancy 74.82%

Hello everyone.

I just want to ask how can i get/dsiplay the reverse value of a string (e.g. "string" will be "gnirts") in c++. ?
 

A:Reverse a string

Code:
#include <iostream>
using namespace std;
int main()
{
const int max = 80;
char str[max];
int count = 0;
int i = 0;

cout << "Enter a string:\n";
cin.getline(str,max,'\n');

while(str[count] != '\0')
count++;

for(i = count; i >=0; i--)
{
cout << str[i];
}
return 0;
}

 

https://forums.techguy.org/threads/reverse-a-string.375398/
Relevancy 74.82%

I have a new computer with Windows XP I run -Adobe Photoshop CS -My Music -Mozilla Firefox -iTunes -The Core Codec Media Player -MSN messenger -AIM messenger -StyleXP I have all these programs open at one time of A string problems... but with GB of RAM it's never slowed the processing speed I only mention it because one of the above might be contributing to the problem I sent it to a computer store to have the mirror harddrive fixed A string of problems... It was installed backwards and I wanted to have it installed correctly When my computer was returned to me it came with the software -Avast Antivirus -E-Z backup -ASUS WiFi-AP Solo -ASUS DH Remote V A string of problems... -Catalyst Control Center -Windows Defender -PrintMe Internet Printing -Microsoft Office Tools I tried to uninstall Avast because it was clogging up all my processes I don't like freeware on my machine but that was the only one that was really getting in my way I'm not sure it's completely uninstalled it directed me to a website that would lead A string of problems... me through the uninstallation process but that seemed hokey to me Now the computer is being funky My problems are It won't screenshot anything My printscrn button won't take desktop screencaptures It's like the image isn't being saved to the clipboard It will cut off my tablet I have a x Wacom tablet and when I try to draw in Photoshop it will stop working after one keystroke The tablet pen and the tablet mouse both stop functioning I installed all the software that came with the tablet I can't open Limewire It doesn't do anything when I double-click the desktop icon I can't open java chats I've tried to get into java chatrooms several times but after it loads it closes down all the windows I've tried using both Firefox and Internet Explorer This is super frustrating as I bought this computer for graphics purposes and I can't even use my tablet Does anyone know what could be causing it

A:A string of problems...

Quote:





Originally Posted by Nawni


3. I can't open Limewire.




This would be my best guess. You need to get rid of that P2P program and leave it off your computer. These P2P programs (especially Limeware) will give you viruses, Malware, trojans, etc., and mess up your computer so badly that you have to do everything over from scratch and lose all your programs.

My suggestion, remove that program and any like it and then post a log in the HiJackThis area and ask our security team to help you clean up your computer. If interested, here is what you need to do:

MicroBell?s 5 step process

http://www.techsupportforum.com/showthread.php?t=15968

http://www.techsupportforum.com/forums/f10/a-string-of-problems-169095.html
Relevancy 74.82%

Forgive me if this is the wrong section I have a mixture of problems that don t fit in any one area although I do have Windows Also I don t know for sure if of the things here are related so bear String of Whole A Issues with me A month or two back Windows Update was bugging me to update A Whole String of Issues Internet Explorer As much as I tried to I kept getting error code c always making my update fail Not a big deal since I would never use IE anyway but It was annoying Today I turned on my A Whole String of Issues computer and it wasn t bugging me anymore I could tell because the shut down button in the start menu actually said shut down instead of shut down to install updates Instead I got a notification in the system tray saying quot Xfire exe - Corrupt file The file or directory C users name appdata local microsoft windows temporary internet files content ie BZ CHO is corrupt and unreadable Please run the Chkdsk utility quot Xfire is a chat programs that I ve had for years and I have no idea why it would be in the title of that notification Anyways before I did the chkdsk I did some searching Some people said there may be a problem with a quot icudt dll quot or Spybot Search amp Destroy I have Spybot and it helps protects Internet Explorer from changes or malware which I suppose might explain some things Someone also suggested scanning with Spybot and Malyware Bytes Anti Malware which I had to download and install Neither one had any results I also noticed that I can t access the Internet Options in control panel or Internet Explorer I click on it but nothing happens After that I ran chkdsk like the error told me to It did its thing deleting index records or whatever it says it does Now I can t start Firefox no message or anything I can t open Google Chrome getting an error message about missing that icudt dll mentioned earlier Still can t access Internet options Also AVG my normal antivirus was turned off according to Windows Message Center I m not sure if this is because I just installed Malware Bytes and Windows is confused or because of whatever is wrong with my computer Sorry for the wall of text I ve got a real mess going on here nbsp

A:A Whole String of Issues

Deleting index records is never a good sign. If it went on for some time, it bodes even less well.

Try running chkdsk /r on that drive. If you have the Windows DVD, it would be best to boot from that and run chkdsk /r from a command prompt since you could then read the results at the end.

But if you need to run it from Windows and don't see the results, you can find them in the Event Viewer or in the Chkdsk folder inside SystemVolumeInformation at the root of your drive.

Make sure you have a recent, full system backup that includes Windows and your programs, as well as all personal files..
 

https://forums.techguy.org/threads/a-whole-string-of-issues.1056975/
Relevancy 74.82%

I ran an sfc/scannow and it revealed corrupted files that could not be fixed. I tried to run a dmis but could not get the source correct. I upgraded to windows 10 and don'y know what the correct string is. Please help!
Thanks,
Harvey Stobezki

A:dmis string

Originally Posted by paterson0461


I ran an sfc/scannow and it revealed corrupted files that could not be fixed. I tried to run a dmis but could not get the source correct. I upgraded to windows 10 and don'y know what the correct string is. Please help!
Thanks,
Harvey Stobezki



Welcome to TenForums, Harvey.

Have you had a look at this TenForums tutorial on how to do DISM repair? Follow this link: DISM - Repair Windows 10 Image

http://www.tenforums.com/antivirus-firewalls-system-security/42323-dmis-string.html
Relevancy 74.82%

Hello everyone.

I'm using Windows 7 and I get an error when trying to connect to my modem, 'Error 651'. So I found a solution online that involves replacing a file in my Drivers folder.

My problem is that I can't edit my drivers folder in any way. When I try to edit the ownership I simply get 'Access Denied'. Why wont my computer let me access these files? How do I get access?

Thanks for reading.
 

Relevancy 74.82%

hi all, i'm getting text from a text file, reading it into a string, and displaying it onto a text field. all this is done using perl/xml/html. what i need to do is, i'm supposed to check for any valid url (ie. strings starting with http or www) and change them into hyperlinks. how do i check for it? for example in the following string: this is just a test www.yahoo.com end test
www.yahoo.com is supposed to appear as a hyperlink, but not any words before or after www.yahoo.com. can anyone help? thanks!!
 

A:finding a url in a string.......

use a perl regex (regular expression)
Read up on them, they are confusing, but oh so powerful
http://demo.freshwater.com/SiteScope/docs/regexp.htm
 

https://forums.techguy.org/threads/finding-a-url-in-a-string.279164/
Relevancy 74.82%

Using the system() command with WS_FTP:

system("C:\\PROGRA~1\\WS_FTP\\ws_ftp95 -p Cross -s local:c:\\Docume~1\\User\\Desktop\\file.txt -d Cross:/public_html/ -ascii");

What if the file I wanted uploaded changed every time I ran the program? The file will always be 3 letters, plus .jpg:

swp.jpg
llf.jpg
etc.

If I had a char[3] into which I input three letters every time I run the program, how will I perform the system command?

system("C:\\PROGRA~1\\WS_FTP\\ws_ftp95 -p Cross -s local:c:\\Docume~1\\User\\Desktop\\this_is_where_the_char_variable_will_go.jpg -d Cross:/public_html/ -binary"

So how do I get the variable in there? (does this make sense?)
 

A:C++: string concatenation maybe?

Here's a basis that should help.
Code:

#include <iostream>
#include <string>
#include <cstdlib>

using namespace std;

int main() {
string file; //path to file
getline(cin,file);
string beginning = "C:\\PROGRA~1\\WS_FTP\\ws_ftp95 -p Cross -s local:";
string end = " -d Cross:/public_html/ -binary";
string command = beginning + file + end ;
system(command.c_str());
}

You will of course need to customize it to your exact needs.

If you would rather be able drag n drop the file you want to upload onto the binary, we can show you that too.

note: You don't have to store the beginning part and end part in variables. You can just put it with the command declaration.
 

https://forums.techguy.org/threads/c-string-concatenation-maybe.225630/
Relevancy 74.82%

Hello there,

I am a JSP beginner by the way.
I need to use a unique variable within a tag, so for experimentation I used the following code:

<%! String theVariable = "andy"; %>
<jade:useAgent
id="<%=theVariable%>"
container="moncontainer"
classname="umist.dricnip4jsp.NegDemoServer"
scope="application"/>
I get the two main errors upon compilation:
org.apache.jasper.JasperException: Unable to compile class for JSP
java.lang.ClassCastException: java.lang.Object

the code is otherwise fine, Is there anyway I can get round this problem?

Thanks, Andy
 

https://forums.techguy.org/threads/using-string-variable-in-jsp-tag.152465/
Relevancy 74.82%

The error says "String PRODUCT_NAME was not found in string table." I 'm not sure how this problem occured. I'm not sure how to fix it though.

A:String Error

This most likely refers to a program that was recently installed. What products have you installed recently?

http://www.techsupportforum.com/forums/f217/string-error-399892.html
Relevancy 74.82%

when i start my computer, the first message displayed is string.dat got couurpted..

pls send me a tip of solution for the problem...

my mail id is [email protected]

http://www.techsupportforum.com/forums/f10/string-dat-corrupted-318962.html
Relevancy 74.82%

Hi! when I open my computer I get this message.
Ready Key [email protected]@@[email protected]@[email protected]

A key is missing in my Sys tray
I hope I wrote the right sentence.
Thank you!
 

Relevancy 74.82%

Occasionally, when browsing to websites using IE9 (9.0.8112.16421), a curious web address will appear in the status bar.

http://mail.live.com/?rru=compose, which might otherwise indicate the cursor is hovering over something like a mailto link, except for the fact that within those pages there are no such hyperlinks. 
This string always includes the title of the current page along with the current site's web address.
I?ve noticed this more often appears whenever a page is first loaded. 
Refreshing the page or hovering over an actual hyperlink causes this information to be replaced.

A:Odd status bar string in IE9

I think you misunderstand.  I have no problems accessing and using Windows Live Mail.
I work as a web developer so I make use of a number of different browsers. 
I?ve used Live Mail with IE8, IE9, Firefox 6-10, most later versions of Chrome, Safari, Opera and Maxthon and the only browser I?ve experienced any issues in accessing and using Live Mail has been Maxthon.
IE9 is the only web browser I have installed on this particular desktop computer. 
I use it as basically my personal computer and not one of my development systems.
For the past several weeks I?ve noticed a Windows Live Mail link appearing in the IE9 browser?s status bar. 
This seems to occur more often following a new tab being opened and then only once or twice a day.
I was curious as to why this was happening so I posted a question within the IE forum looking for an answer. 
For now I don?t seek to change this behavior, only to understand it.
This problem is not related to any desire to use Windows Live Mail or as the result of some inability to do so.
I?ve scanned with a number of different anti-malware tools and none have shown any detection that the system has in any way been compromised.
This was simply a curiosity and at this point I do not wish to pursue the matter any further.

https://social.technet.microsoft.com/Forums/en-US/31969887-6b64-43dd-8f5a-225be3be2c12/odd-status-bar-string-in-ie9?forum=ieitprocurrentver
Relevancy 74.82%

Hello,
Okay, I have another question for yall. I am having a little problem going from double to string.

I am currently saving to a text file then reading it back, but I don't line this away at all. Could you show me an easier way please.

Okay thanks for the help.
~Ronald
 

A:string to double

by the way this is C++
 

https://forums.techguy.org/threads/string-to-double.165677/
Relevancy 74.82%

Hi
I have the following question
Write a function conundrum that takes a sting as input. The function must then return the letters of the​ word in random order e.g. apple might be pelpa.

Write a function ​scramble that takes a string as input. The function must return the following * letters of the message in random order * a vector that contains the order of the positions of the scrambled letters​ that will give the original message.​ Hi there
-> i eHreth
Write a function ​descramble that will construct the original message from the scrambled string and vector of the previous question.
 

Relevancy 74.82%

Whenever I try to install the NTI CD Maker 6.0 software, I get a string error.

ERROR_MOVEDATA
ERROR_COMPONENT
ERROR_FILEGROUP
ERROR_FILE
Is there anything I can do to fix this? Thanks.
 

Relevancy 74.82%

undefinedundefined HELP, I messed up bad. I did something and I don't know how to fix it. I am running Windows XP Pro and when I turn on my computer it asks for my user name and password. I don't have either. I get a message String error_ADMIN wasn't found in string tab. Does anyone know how I can fix this mess? I don't want a administrator on my computer. undefined
 

A:String Error

A System Restore may fix your problem, for details how see: http://support.microsoft.com/?kbid=304449
 

https://forums.techguy.org/threads/string-error.219384/
Relevancy 74.82%

I am running XP professional with service pack About a month ago after daylight savings time my time and date was off I corrected it and it happened again about two weeks ago So far it has not chnaged The computer has been running weirdness of String a bit slow lately also Just recently I have tried to start iTunes and String of weirdness I am not able too I have tried to install over it and I keep getting an error message that says it can t write to a certain file verify you have access to that file I couldn t uninstall it either In my attempt to solve this based on advice from another website I treid to do disk repair using the windows utility It wouldn t run -- I mean nothing would happen Then I tried a disk defrag and it could complete the analysis of disk I got an error message I tried again to do disk repair in safe mode and the same thing happened Is this malware I run Spyware Doctor Spybot and AdAware regularly Any ideas on how to resolve

A:String of weirdness

Can you maybe run both of these if only to exclude an infection?First this Please download and scan with SUPERAntiSpyware FreeDouble-click SUPERAntiSypware.exe and use the default settings for installation.An icon will be created on your Desktop. Double-click that icon to launch the program.If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates".

(If you encounter any problems while downloading the updates, manually download them from here and unzip into the program's folder.)
In the Main Menu, click the Preferences... button.Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all others unchecked):Close browsers before scanning.Scan for tracking cookies.Terminate memory threats before quarantining.Click the "Close" button to leave the control center screen and exit the program.Do not run a scan just yet.Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".Scan with SUPERAntiSpyware as follows:Launch the program and back on the main screen, under "Scan for Harmful Software" click Scan your computer.On the left, make sure you check C:\Fixed Drive.On the right, under "Complete Scan", choose Perform Complete Scan and click "Next".After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".Make sure everything has a checkmark next to it and click "Next".A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.If asked if you want to reboot, click "Yes" and reboot normally.To retrieve the removal information after reboot, launch SUPERAntispyware again.Click Preferences, then click the Statistics/Logs tab.Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.Please copy and paste the Scan Log results in your next reply.Click Close to exit the program.then try this Please download Malwarebytes Anti-Malware and save it to your Desktop.Make sure you are connected to the Internet.Double-click on mbam-setup.exe to install the application.When the installation begins, follow the prompts and do not make any changes to default settings.When installation has finished, make sure you leave both of these checked:Update Malwarebytes' Anti-MalwareLaunch Malwarebytes' Anti-MalwareThen click Finish.MBAM will automatically start and you will be asked to update the program before performing a scan.

If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.On the Scanner tab:Make sure the "Perform Quick Scan" option is selected.Then click on the Scan button.If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.

The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found... Read more

http://www.bleepingcomputer.com/forums/t/181428/string-of-weirdness/
Relevancy 74.82%

I am trying to put a faster cpu in my computer, so what i have to do is get my bios string so I can identify the chipset and mother board. I have done this but I cant find a match for it. I have tried WIMS bios page. Can someone help me. This is my bois string 07/08/98 82430HX-P155TZP4C-00.

THANX
 

A:bios string

Ask the friendly people @ www.houseofhelp.com they helped me.

Macky
 

https://forums.techguy.org/threads/bios-string.33770/
Relevancy 74.82%

I wanna pass the following string to recordset:
strSQL = "SELECT Contractor, Add_D, Chores.Type, Code, Reserved, Finished, Engineer"
strSQL = strSQL & " FROM (Chores INNER JOIN Projects ON Chores.Project=Projects.Code) "
strSQL = strSQL & "INNER JOIN Engineers ON Chores.Engineer=Engineers.Number"
strSQL = strSQL & " WHERE (((Chores.Reserved)=Yes) AND ((Chores.Finished) Is Null) AND "
strSQL = strSQL & "((Chores.Engineer)=" & Me.frm_Engineer.Value & "));"

but strSQl can hold it until "((Chores.Finished)" in 4th line, when I increase the string like "Dim strSQL as String * 2000" it only saves the first like!!! what should I do?
I tried to save rest of the string in strSQL1 and concatenate them in openrecordset(strSQL & strSQL1) but that does not work either, what is the solution?
 

A:Long string for SQL

You only need to Dim strSQL as a String.
Then use this kind of Format to construct the SQL String
Dim rs As Object, SQL As String
SQL = "SELECT Inventory.* " & _
"FROM Inventory " & _
"WHERE TagNumber = '" & Me.TagNumber & "' "

Note the "& _" to continue on the next line.
 

https://forums.techguy.org/threads/long-string-for-sql.992085/
Relevancy 74.82%

Hello,
here is my question. I am new to VC++, but not C++.
I would like to pass a variable of type CString (VC++) to a string in (C++).
I currently am saving the variable of type CString in a file. Then in my C++ code open the file and read it out as type string.
Is there just some short conversion.

CString s1;
s1="hello";
string s2;
s2=s1;

could you do this? If not then what?

Thanks for the help,
Ronald

(oh, by the way, how do you put your pic in the site?)
 

https://forums.techguy.org/threads/cstring-to-string.167369/
Relevancy 74.82%

my computer contain xp sp2.when I convert pdf to word this was the error.The error message was shown below.

"STRING WAS NOT RECOGNIZED AS A VALID DATE TIME FORMAT DD/MM/YY"

A:string was not recognized

What program are you using to convert a PDF to Word?

http://www.techsupportforum.com/forums/f10/string-was-not-recognized-670001.html
Relevancy 74.82%

Can anyone help with the "Set Up String" for a Ham Ambient Modem, V90, 56K, Voice, Fax, Data. Friend told me it can be forced to connect at highest speed if this is inserted.
 

A:Modem Set Up String

Couldnt answer any questions about it, but is this what you are looking for?

http://808hi.com/56k/cirrus.htm
 

https://forums.techguy.org/threads/modem-set-up-string.64337/