Author Topic: Win32:Istdnldr [Trj]  (Read 18628 times)

0 Members and 1 Guest are viewing this topic.

whocares

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #15 on: July 23, 2004, 09:15:37 PM »
Hi,

this seems to be the settings of SPYBOT S&D
Quite a good program, but just the settings won't help much.. ;D ;D

its report/log would be better

even better would be the log from HJT / Hijackthis ;)

whocares

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #16 on: July 23, 2004, 09:21:41 PM »
a direct link to the Hijackthis-program without the need to unzip it is here:

http://tomcoyote.org/hjt/HijackThis.exe


Dreams

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #17 on: July 23, 2004, 11:43:48 PM »
ok, i quit. this is the error i am gettin still:

Internet Explorer was not able to open this internet site.  The requested site is either unavailable or cannot be found.  Well im at the site, duh. lol. bout ready to head to the loony bin. i really need download ability. why me? and you are too kind to be so helpful. can i send you my first born son as a thank you? juuuuust kidding. thanks

Dreams

whocares

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #18 on: July 24, 2004, 01:43:54 AM »
Like I said, download tools on another PC..

e.g.
escan, clrav, AV-Boot-Disks/-CDs




Dreams

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #19 on: July 24, 2004, 11:03:03 PM »
ok, here is the newest hjt log. i was able to get it open in safe mode by copy n pasting into a new folder. i had it analyzed but the very last entry is new and there was no comment regarding it. i even pasted alone and no results. any ideas? you seem to be the only one with any answers lately. thanks again.

dreams


Logfile of HijackThis v1.98.0
Scan saved at 1:48:44 PM, on 7/24/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\HJT\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://yahoo.com/
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O15 - Trusted Zone: http://hoylegames.sierra.com
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O21 - SSODL: AUHook - {BCBCD383-3E06-11D3-91A9-00C04F68105C} - C:\WINDOWS\SYSTEM\AUHOOK.DLL


whocares

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #20 on: July 25, 2004, 02:51:56 PM »
Hi

nothing to account for your problems in the log

- AUHOOK.DLL is unknown to me, but google doesn't show it to be malicious, so leave it

- remove all stuff with sierra/games

IT could of course be a real file-infecting virus:
-->
escan, clrav, AV-Boot-Disks/-CDs

what about those ?

*

did you check all cable connections, fans, temperature,
make  a RAM-test & Scandisk ?
-> could also be hardware problem..

can you restore to an older restore-point in SafeMode ?

or you  might try overinstalling WIN, if you don't just have a WIN-Restore-CD
Make backups first, anyway..

Dreams

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #21 on: July 26, 2004, 08:44:46 PM »
hello,

i keep restore shut off, but im due for a good cleaning and reformatting seems to be the answer. im going to try windows update and if it still wont install, i will start anew. thanks so very much for all of your help. you are fast and precise with the information that you give and i appreciate that so much. hope you get a raise for all your efforts.

dreams

whocares

  • Guest
Re:Win32:Istdnldr [Trj]
« Reply #22 on: July 26, 2004, 09:40:53 PM »

hope you get a raise for all your efforts.


 ;D ;D What about it, pavel ??  ;D ;D :)


dreams, I am neither employed by, nor affiliated with alwil.

Mopst help here is given voluntarily by (more or less experienced) users of avast ;)