Lil concerned w/warning window from explorer

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • dr_ml422
    Lord of Digital Video
    Lord of Digital Video
    • May 2007
    • 1903

    Lil concerned w/warning window from explorer

    ok so twice now I get a message popup window on my pc running xp home that explorer has to close to protect me from potentially harmful viruses etc... Then another window comes up called data execution blah blah blah and the usual if I want to send report to m$.

    Now I ran spybot, avira, mambam and just did a full n quick scan w/microsoft's security essentials for xp which kinda impressed me. No spyware and/or maliscious/viruses were detected. So do i need to run something even more thorogh or is something else going on that's not virus related? Thnx and I do need help on this. I just cloned my xphome drive and have been doing a lot of video and music backing up and storing on hdd's w/my docking station. So if I've been hit I might b sol.

    Here's a hijack This Log just in case.


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:24:32 AM, on 8/7/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
    C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\WINDOWS\explorer.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Hijack This\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
    O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
    O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe -hide
    O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 4401 bytes

    Thnx.
    Last edited by dr_ml422; 7 Aug 2009, 02:36 PM.
    SAMSUNG SH-S203B, SAMSUNG SH-S223F,

    Take the suggestions and follow the directions. The results will speak for themselves.



    Google is definitely our friend.
  • dr_ml422
    Lord of Digital Video
    Lord of Digital Video
    • May 2007
    • 1903

    #2
    Anyone working today. I need help. Turned on my pc and went to ff to check this thread to see any posts and all my contacts were gone. Replaced w/my email address. proceeded to come here and browser went bonkers opening up different windows instead of tabs and locating them on bottom taskbar instead of on top. also would go to different threads here back n forth like crazy.

    Read avira thread by atifsh and followed directions. flash disinfect found nothing. dl'd clamwin to usb flash n when I went to open it on the flashdrive it would select all folders in that window and give me warning that opening up 16 windows might mess me up. my poweruser settings were reconfigured to normal windows directories. I worked around this and finally ran clamwin w/updated files and here's the report.




    Scan Started Fri Aug 07 08:06:39 2009

    -------------------------------------------------------------------------------



    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\avguard.tmp: Permission denied

    C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpSfc.bin: Permission denied

    C:\Documents and Settings\THE DOCTOR\Local Settings\Temp\nsl15.tmp: Permission denied

    C:\pagefile.sys: Permission denied

    C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied

    C:\WINDOWS\system32\config\default: Permission denied

    C:\WINDOWS\system32\config\SAM: Permission denied

    C:\WINDOWS\system32\config\SECURITY: Permission denied

    C:\WINDOWS\system32\config\software: Permission denied

    C:\WINDOWS\system32\config\system: Permission denied

    WARNING: Can't access file D:\



    Scanning aborted...



    ----------- SCAN SUMMARY -----------

    Known viruses: 608000

    Engine version: 0.95.2

    Scanned directories: 1788

    Scanned files: 16479

    Infected files: 0



    Data scanned: 5261.12 MB

    --------------------------------------

    Cancelled

    --------------------------------------

    i cancelled cause it was going to take 4ever to scan my 1tb full of .iso flics which i had plugged in and on in docking station.


    says nothing found. could all this be due to installation of microsoft essentials and when i turned on my pc both that and avira and spybot running? mind you this is my 1st build not the dell. I need a reply w/something to work here. turned off all av's right now and ff back to normal but can't operate w/out protection 4 long. thnx.


    this here was 1st clamwin report that was cutoff cause of crazy mess.


    Scan Started Fri Aug 07 08:06:39 2009
    -------------------------------------------------------------------------------

    C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\avguard.tmp: Permission denied
    C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Scans\History\CacheManager\MpSfc.bin: Permission denied
    C:\Documents and Settings\THE DOCTOR\Local Settings\Temp\nsl15.tmp: Permission denied
    C:\pagefile.sys: Permission denied
    C:\WINDOWS\system32\CatRoot2\tmp.edb: Permission denied
    C:\WINDOWS\system32\config\default: Permission denied
    C:\WINDOWS\system32\config\SAM: Permission denied
    C:\WINDOWS\system32\config\SECURITY: Permission denied
    C:\WINDOWS\system32\config\software: Permission denied
    C:\WINDOWS\system32\config\system: Permission denied
    WARNING: Can't access file D:\

    Scanning aborted...

    ----------- SCAN SUMMARY -----------
    Known viruses: 608000
    Engine version: 0.95.2
    Scanned directories: 1788
    Scanned files: 16479
    Infected files: 0
    Data scanned: 5261.12 MB
    SAMSUNG SH-S203B, SAMSUNG SH-S223F,

    Take the suggestions and follow the directions. The results will speak for themselves.



    Google is definitely our friend.

    Comment

    • rago88
      Digital Video Expert
      Digital Video Expert
      • Aug 2005
      • 566

      #3
      Had a similar problem but not as exstensive as yours.

      I ran Malwarebytes which found a whole slew of problems and quarantined them//

      this program is free and updates almost daily.
      Used by many here..
      good luck.


      Malwarebytes offers real-time antivirus, advanced anti-malware and privacy protection for all your devices. Launched in 2004 as a free virus scan, we still offer a free basic version 20 years later. Learn more.

      Comment

      • dr_ml422
        Lord of Digital Video
        Lord of Digital Video
        • May 2007
        • 1903

        #4
        thnx rago. I have malwarebytes and ran it also. what I ended up doing was going to performance settings advanced and taking explorer off the lit of processes and/or programs using the Data execution nonsense by M$. I have no idea why they keep coming up w/stuff that just won't work properly or in time will not work w/something else they invent. I'll see how it goes from here. I ran 4 almost 5 different av's and all came up zilch.

        The issue w/the browser and the 16 windows wanting to open I think was caused by having Avira and M$ Essentials running simultaneously. If this won't solve it I'll uninstall IE 8 and just put 6 back on. I think 8 is acting up w/certain things as well.
        SAMSUNG SH-S203B, SAMSUNG SH-S223F,

        Take the suggestions and follow the directions. The results will speak for themselves.



        Google is definitely our friend.

        Comment

        • gonwk
          Lord of Digital Video
          Lord of Digital Video
          • Dec 2005
          • 1500

          #5
          Hi dr_ml,

          That happens to me when I go to "funny" sites ... those sites somehow lodge a flash command that continues to open ... in my case something like 50 or 60 web pages ... I just hard disconnect from the web and restart IE7 and then do history cleanup and mark that sites as trouble and report it to WOT, and some other Browser Defender sites.

          G!

          Comment

          • dr_ml422
            Lord of Digital Video
            Lord of Digital Video
            • May 2007
            • 1903

            #6
            Hi gonwk. Thnx for the info. I disabled data execution for explorer and so far ok. I will do a hard disconnect, and now that you've mentioned it prolly go back to either IE6 or install IE7. How stable has IE7 been 4 u, or how stable is it period? I see that even when I use FF which is my default browser that IE8 is running I think. Last cleanup w/Ccleaner had a lil over 401mb's of files to be deleted. I don't even surf that much really except 4 answers to issues like this. This happened in xp home.

            I've googled the results 4 how stable IE 7 is b4 and ttytt I haven't seen anywhere that said it was all that stable or even secure. IE8 has more features, but that even has its own set of bugs/issues. They just can't get it right these guys.
            SAMSUNG SH-S203B, SAMSUNG SH-S223F,

            Take the suggestions and follow the directions. The results will speak for themselves.



            Google is definitely our friend.

            Comment

            • Chewy
              Super Moderator
              • Nov 2003
              • 18971

              #7
              Pass the Robitussin

              Microsoft Security Essentials (codenamed Morro) is free antivirus software created by Microsoft that provides protection against viruses, spyware, rootkits, and trojans for Windows XP, Vista, and 7.[1] Currently in beta testing, it was available for download to the first 75,000 people in the United States, Israel, People's Republic of China and Brazil.
              I do not recommend that you have more than one anti virus product installed and running on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:
              1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't.
              2) System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.
              Therefore please go to add/remove in the control panel and remove either xxxx or xxxx.

              Comment

              • doctorhardware
                Lord of Digital Video
                Lord of Digital Video
                • Dec 2006
                • 1907

                #8
                I always have 1 running, seen other people have so much problems, only to find out that they more then one av running. I have told people this but do they listen nooo.
                Star Baby Girl, Born March,1997 Died June 30th 2007 6:35 PM.

                Comment

                • dr_ml422
                  Lord of Digital Video
                  Lord of Digital Video
                  • May 2007
                  • 1903

                  #9
                  Yes both avira and M$ essentials were on and i know that causes issues. what happened was i had turned off Avira, but i think it went back on prolly through a reboot. The issues w/the Data execution popup window was a 1st. I googled and found how to disable it. So i unticked explorer and hit apply ok. i will see soon if it comes up again. spybot had issues w/IE8 and the Immune function but I haven't experienced any i know of. if something comes up there I think there's a patch for the issue.

                  i'm just getting use to the fact that w/e M$ puts out as a supposedly better product regarding any area is just not tested enough b4 being released. hence so many issues w/much of their stuff. I had become impressed w/the new 7 and IE8, but I now see there's stuff there also that will prolly need ironing out.

                  Would storing executable files whether they install in pc or run as .exe's be better done on cds or flash drive, or it really don't matter security wise to avoid any viruses etc...?
                  SAMSUNG SH-S203B, SAMSUNG SH-S223F,

                  Take the suggestions and follow the directions. The results will speak for themselves.



                  Google is definitely our friend.

                  Comment

                  • Chewy
                    Super Moderator
                    • Nov 2003
                    • 18971

                    #10
                    Having 2 AV's running resident protection actually protects less than one.

                    Comment

                    • dr_ml422
                      Lord of Digital Video
                      Lord of Digital Video
                      • May 2007
                      • 1903

                      #11
                      Hi Chewy. I never had both on my pc. I always just used Avira. I just installed and ran M$ Essentials to see if it would pick up anything that prolly Avira, Mambam and spybot didn't. If in fact there was anything. I just didn't want to uninstall avira to run Essentials. I have no virus as you could prolly see from the Hijack This Log and the Clamwin .exe I also ran after reading your post in atifsh's thread.

                      So only thing left was the Data Execution nonsense. google had solutions going back 2 maybe more years for that issue. I just experienced it now, so I never heard of it.

                      You have any clue why it would start acting up now after all this time w/the 1st build? Only thing new I added was IE8 really so that's why I alluded to it . Also and briefly the only 2 proggies under the Data Execution in performance settings advanced was explorer and Fab.

                      Since this Data thing goes way back is there any new input/suggestion you can give concerning it these days?
                      SAMSUNG SH-S203B, SAMSUNG SH-S223F,

                      Take the suggestions and follow the directions. The results will speak for themselves.



                      Google is definitely our friend.

                      Comment

                      • Chewy
                        Super Moderator
                        • Nov 2003
                        • 18971

                        #12
                        Hi Chewy. I never had both on my pc.
                        You HJT log showed both running?

                        IE8 has caused a lot of people a lot of grief

                        Comment

                        • gonwk
                          Lord of Digital Video
                          Lord of Digital Video
                          • Dec 2005
                          • 1500

                          #13
                          Hi folks,

                          @ dr_ml ... the reason I have Not yet upgraded to IE8 is because I see different posts with problems for IE8 ... so, I figure if my IE7 is working ... just to leave it alone.

                          dr_ml with your permission, since we are already talking AVs I want to ask Chewy few Q's ...

                          @ Chewy ... I have only AVIRA running as my Primary on my Vista Home Prem., SP1, 64-Bit. But of course Vista has it's own Windows Defender ... Oh also I run SpywareBlaster 4.2

                          Q1: So, is this set up considered having 2 AV running on my laptop?

                          I do have MBAM and SAS (SuperAntiSpyware) as my Stand-alone Scanners on-demand.

                          Chewy BTW, I have the following set-up ...

                          Q2: Which ones so I uninstall ... if any!?!?

                          Q3: For Freeware Options ... do you Recommend any changes to my Set-Up? Should I go with something different? Has to work with 64-Bit!

                          - Comodo Firewall Free version (3.10.102363.531) with Defense Plus and I have chosen to run both my Defnse & Firewall in "Safe Mode" which is pretty aggressive setting.
                          - Comodo SafeSurf v1.0.0.7
                          - Comodo BOClean 4.27 (which is the last version and is no longer updated or supported).
                          - Comodo Memory Firewall 2.0.4.20
                          - SUPERAntiSpyware Free Ed (SAS) 4.26.1000
                          - Malwarebytes' Anti-Malware (MBAM) 1.40
                          - SpywareBlaster 4.2

                          Thanks,

                          G!

                          Comment

                          • Chewy
                            Super Moderator
                            • Nov 2003
                            • 18971

                            #14
                            gonwk,

                            Ditch defender



                            Don't even consider Comodo, too many problems

                            64bit Vista is easy to cleanup and rootkit proof to boot

                            but hell to setup and keep running right

                            Comment

                            • gonwk
                              Lord of Digital Video
                              Lord of Digital Video
                              • Dec 2005
                              • 1500

                              #15
                              Hi Chewy,

                              1) Ditch Defender ... so AVIRA will protect me .... RIGHT!?!?

                              2) I ONLY use Firewall PORTION of Comodo. If I ditch Comodo Firewall ... so which Firewall do you Recommend!?!? To work with 64-Bit.

                              3) My laptop came with Vista Home Prem., 64-Bit ... are you recommending I do fresh install with 32-Bit ... I will loose all my GAOTD freebies and may even cause me some problems ... I recall somne folks going from 64-Bit to 32-Bit on my Specific Gateway M-6862 laptop and had nothing but headaches ... stuff NOT working!!!

                              Thanks,

                              G!

                              Comment

                              Working...