A quick google search for each name has returned 0 results for each. Remember however that some viruses can save themselves as random names, so I would run good up to date virus and spyware scanners over the machine. If nothing is found, I would think the machine is clean, especially if they are located in the temp directory as all sorts of stuff gets in there.
You could also do a bootlog and see if there is any information showing there.
Ed Fair
Any advice I give is my best judgement based on my interpretation of the facts you supply. Help increase my knowledge by providing some feedback, good or bad, on any advice I have given.
Download spybot 7.0 and let it run a scan on your machine this also has the ability to inform you of everything that starts up on your machine very useful
The same advice from previous messages in this thread still applied: download and run Spybot or Ad-Aware over your machine.
Those files again don't bring up anything in a google search (apart from a link to this thread). None are standard files supplied with XP (or any other OS) however, so I would see what spybot or ad-aware come up with, also check the file properties of them to see if there are any clues as to what they really are, and finally check msconfig to see if they are set to load at system startup.
Logfile of HijackThis v1.97.3
Scan saved at 7:55:53 PM, on 10/12/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
O8 - Extra context menu item: Coupons - file://C:\Program Files\couponsandoffers\System\Temp\couponsandoffers_script0.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: Yahoo! Spades -
HXDL.EXE
or
HXIUL.EXE
Believed to be spyware - made by a company called Alset . Also known as "HelpExpress". Will install itself if you have previously had Attune by Aveo installed as they're by the same company. Uninstall via Add/Remove programs
click the online tab to search for and download the updates, then shut down and relaunch SpyBot.
Go to the Settings tab > File Sets, and uncheck 'System Internals' and 'Tracks' .
These aren't needed for our present purpose, and you can always experiment with them later on.
Finally, after closing down Internet Explorer, click 'Check for problems', and have SpyBot remove all it finds 'Fix selected problems'
you may have to run spybot more than once to clear everything
I'm having some of the same problems and probably manually removed some cookies last nite that might have been needed. B/C of that I thought I'd see if you might be able to lend me a hand here too. As you can see, my problems are remarkably similar to ScotsLass's.
Here's the Highjackthis output from this morning.
PS: I've been using adAware freeware and have been continually removing morphing ad/popup items.
Thanks in advance for any help you can provide! I'm getting crushed by this stuff!
Logfile of HijackThis v1.97.3
Scan saved at 11:02:54 AM, on 10/14/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
"This is a DLL to enable multiple display monitors on a single computer. It can be a cause of numerous problems on some computers."
If you only have and intend to have 1 monitor - fix this
-------
This line which appears twice, I can find very little information on - but what I have found points to a possible virus
If none of the above resolve the identity of the file, I would also consider fixing these two lines and deleting the file - if you keep it in the bin for a few days and all is well - ditch it.
-----
Also despite running adaware you still have spyware - run spybot as per my above post
I'll do spybot too! It feels good to be making progress! Some of the problems root in Kazaa which never fully uninstalled. Do you see any problem with just deleting the remaining pieces and putting it in the Recycle Bin...
Logfile of HijackThis v1.97.3
Scan saved at 4:04:02 PM, on 10/14/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Some of the problems root in Kazaa which never fully uninstalled when I got rid of it a couple of weeks ago. Do you see any problem with just deleting the remaining pieces and putting it in the Recycle Bin?
Yes delete everything I posted in bold using hijackthis- you can go to Tools/internet options and set your homepage to yahoo.com when you've cleaned up the log.
(Microsoft) Microsoft Office XP Fast Search. Well, well, remember the nightmarish Find Fast of previous versions of Microsoft Office ? MO Search is the Office XP equivalent.
Recommendation :
New name, same problems. Endless trashing of your hard disk when you are not using it, and sometimes when you are, with delays in mouse movements, or downright temporary inability to do anything for a few seconds (while MOSEARCH is updating its indexes). The search speed gains are negligible and yet, as with Find Fast, the constant disk activity and response delays irritate end-users immensely. Try disabling MOSEARCH with Startup Manager. If that is not possible, then you will have to de-install "Support for fast searching" out of Microsoft Office XP, and then rename the program files MOSEARCH.EXE and MOSDMN.EXE by adding .old at the end of their names.
NVIEW ? - see what i said in the post above - it's up to you.
jeired.dll - is a browser hijacker
IEDriver.exe Installed as part of adware (Cydoor) based peer-to-peer file sharing software called URLBlaze
Steamwiz,
I've run hijackthis and can see no obvious problems with the output. I don't want to post the output here for your opinion, as I'm sure you dont want half a million users doing the same. Where can I find some further info for self analysis of the output provided by hijackthis.
Have a star by the way for your consistently clear and helpful advice in this and many other threads.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.