Help - Search - Members - Calendar
Full Version: Opera browser changing color
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Andrew_&*(
Dear Moderator,

Can you please help. Thank you very much

I am having problems with my browser "Opera," which seems to have contracted a virus or something. Also I completely uninstalled it and re-installed and still have the same problem, so I think I have a virus somewhere on my computer. The shell and the web page I am on all of the sudden changes color to reds, orange and yellow and some greens colors. This happens at various times. Sometimes when I am surfing on the net or if I open Microsoft Windows. Can you look at my Hijack thread. Thank you. Also all files are visible and I have run the suggested virus software. Are Spybot and Adware SE still the programs of choice? Thanx.

Logfile of HijackThis v1.99.1
Scan saved at 3:17:23 PM, on 12/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\ZONELABS\ISAFE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\SECURITY TASK MANAGER\SPYPROTECTOR.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\PORT EXPLORER\PORTEXPLORER.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SBC Yahoo! DSL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE"
O4 - HKLM\..\Run: [Spy Protector] C:\PROGRAM FILES\SECURITY TASK MANAGER\SPYPROTECTOR.EXE /autostart
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\Windows\SYSTEM\E_SRCV03.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab

Again thank you,

Andrew OMG.gif
hayc59
Andrew, Welcome to the forum
I moved your post to "HELP! Think you are Infected?" section
be patient read the Guidelines for this section
someone should be around shortly
Gordon
Andrew_&*(
Thank You Gordon.

I also was wondering if someone can tell me if it would be a good idea or not to delete the isafe program that is running with ZoneAlarm. Do you know "exactly" what it does? Is it necessary? If you don't know I can accept that answer also.

Also what is the latest, best anivirus, anti trojan, or necessary security programs? In other words what do I need to do to protect my computer online.

Thanks Again,

Andrew :)
Autodad
Hi Andrew,

I don't use ZoneAlarm, so I'm not sure what isafe does, but at this point I would keep it.
I also don't see any problems in your HJT log.


click Start | Run | (type) cleanmgr | then "OK"
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Click "OK" to remove them.
Click "Yes" to confirm the deletion.


Please download and run a Free Trial of Trojan Hunter
If any infected files are found, delete them.

Next, take a free Online Virus scan at HouseCall and Panda ActiveScan
If any infected files are found, delete them.
Then please post the log from them.

And let us know if you still have any concerns....
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.