<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0"
 xmlns:blogChannel="http://backend.userland.com/blogChannelModule"
>

<channel>
<title>Topic &#x27;Re: Win98 ZA and AV shutdown&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10402572</link>
<description></description>
<language>en</language>
<pubDate>Sat, 26 Mar 2022 03:28:26 EDT</pubDate>
<lastBuildDate>Sat, 26 Mar 2022 03:28:26 EDT</lastBuildDate>

<item>
<title>Re: Win98 ZA and AV shutdown</title>
<link>http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406567</link>
<description><![CDATA[habya posted : I tried to find the exe file but couldn't seem to locate it, I was going to try and save it to a disk.<br><br>I save a log at least every week, sometimes twice, of HTJ so that if the need arises I'll have a reference point to what is normal and not normal for my system and be able to help pinpoint anything if something goes wrong which is why I deleted that "016".  There were others but all were normal and had the name of what it was and what website it was associated with.  This one however only had the {1111....} so I removed it.  About a week ago I had this in my log<br><br>O16 - DPF: {11111111-1111-1111-1111-111111111124} - ms-its:mhtml:file://C:\foo.mht!&raquo;<A HREF="http://graftymary.netfirms.com/tempdownload//EXPLOIT.CHM::/splitter.exe" >graftymary.netfirms.com/ &middot;&middot;&middot; tter.exe</A><br><br>which I was informed by someone it may be some exploit.  At that time I went ahead and scanned and found nothing so I removed it with HTJ and that was that.  The {111..} is exactly the same so could it have been the same thing?  Possibly used by whatever did this?  I'm going to try to find any backups I may have of my router logs to see what all was going on and what traffic there was.  It's possible that someone else got on here and was downloading junk without me knowing.  I generally keep it with one user on this machine since I'm really the only one that uses it except my mother whom was at work at the time, possible my sister or brother-in-law got on here.  Anyways I'm gonna keep my eye open and make sure there's not anything on the other partitions and if I find any files which may be bad I'll be sure to submit them cause whatever caused this killed me.  Everything ended up just going to hell. <br><br>Thought I was well covered with everything I had installed: AV, AT, Anti-Spyware, Anti-Adware, firewall, router.  Just shows that not everything is 100%.  I sure hope it is completely clean now but I kind of also hope that if in fact it was some malicious program that caused it that there is some reminence of it left that I can get to people so it won't happen to as many other people. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406567</guid>
<pubDate>Wed, 02 Jun 2004 21:41:50 EDT</pubDate>
</item>
<item>
<title>Re: Win98 ZA and AV shutdown</title>
<link>http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406111</link>
<description><![CDATA[CmmTch posted : Info on 016,<br><br>O16 - Download Program Files item<br>ActiveX Controls These are downloaded when you play an online game, use iPix, etc. If it is from a known game site such as Yahoo or Pogo, or the Macromedia site, its legit. Other items you can search for to find out. I usually just do a quick check over these items. Always fix them if they seem to be dialers, adult, or casino software. <br> <br>From this page <A HREF="http://hjt.wizardsofwebsites.com/">HJT Tutorial</A><br><br>Sure sounds like you had something, it would have been interesting to see what exactly it was that was in your machine.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406111</guid>
<pubDate>Wed, 02 Jun 2004 20:45:14 EDT</pubDate>
</item>
<item>
<title>Re: Win98 ZA and AV shutdown</title>
<link>http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406010</link>
<description><![CDATA[keith2468 posted : Hi habya -<br><br>It sounds like you had pretty good security, assuming you kept all those products up-to-date.  If the products was something well known and well understood, it would have been stopped or detected when you ran a scan.<br><br>Whatever got through to your machine, it would have been nice to have had a sample of so counter-measures could be developed.<br><br>Re-formatting was probably the right thing to do to clean your computer, but I agree that it would be nice to know what caused your problems so you/we could ensure there isn't a repeat.<br><br>- Keith<br><SMALL>--<br>(<A HREF="http://www.broadbandreports.com/faq/8428">Virus&Hijacking FAQ</A>+<A HREF="http://www.broadbandreports.com/faq/security/edit/8428#submit">Submit suspected malware</A>+<A HREF="http://www.broadbandreports.com/faq/security">Security FAQ</A>)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10406010</guid>
<pubDate>Wed, 02 Jun 2004 20:30:51 EDT</pubDate>
</item>
<item>
<title>Re: Win98 ZA and AV shutdown</title>
<link>http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10404627</link>
<description><![CDATA[habya posted : Found a note I scribbled down with one of the entried I found a while back in my HTJ log that I was told to delete.  It's the same one that was in the recent one, don't know how it got back, haven't downloaded anything since then.<br><br>O16 - DPF: {11111111-1111-1111-1111-111111111124}<br><SMALL>--<br>HABYA HABYA HABYA TEAR DOWN THE HEM STALKS EAT UP THE OLD MAN AND WOMAN AND CARRY OFF THE LITTLE GIRL MAY YOU DIE ALONE</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-Win98-ZA-and-AV-shutdown-10404627</guid>
<pubDate>Wed, 02 Jun 2004 17:34:48 EDT</pubDate>
</item>
<item>
<title>Win98 ZA and AV shutdown</title>
<link>http://www.dslreports.com/forum/Win98-ZA-and-AV-shutdown-10402572</link>
<description><![CDATA[habya posted : Just spent the past 5 hours trying to repair this computer but finally just gave up and formated it since all the important data is backed up.  I'm not sure whether it was a security issue or not but the way it acted seemed to be.  Anyways it goes like this.<br><br>The system was running just fine for a very long time.  It's running Win98SE and as much security software/hardware as I think was required<br>Panda Platinum<br>eScan on demand<br>A2 AT<br>Spybot<br>Ad-aware<br>Spywareblaster<br>Linksys BEFSR11 router<br>Zone Alarm Free<br>Pest Patrol<br><br>I had the teatimer with Spybot on for a while and nothing went wrong then one day it started giving me errors anytime the screensaver or IE was running for a few minutes, so I turned it off and the problems stopped.  All was well for about 3 days at which point I left my computer to go do some stuff, was in working order when I left and had just gotten done running some programs and what not, nothing was wrong.  I came back and noticed that instant messenger had closed and ZA said it required a reboot.  So I just restarted the computer at whichpoint ZA still would not load and Panda Platinum started causing illegal operations and would not run so just to be safe I unplugged the internet and shutdown everything I could in task manager and ran the eScan on demand scanner which found nothing.  So I reinstalled ZA and rebooted and still would not open, then IE would not open and would crash the computer and so would Firefox, Instant Messenger, PestPatrol and Spybot.  I then started getting some error (unfortunately I don't have the exact) of something like "XXXX caused a fatal error in kernel6836".  Other programs worked just fine but any kind of AV or firewalls I tried to load would just crash, I tried installed Sygate and Panda's firewall all of which would just cause errors and die.  The virus scans (eScan because it was the only one that would load) came up clean.  Also there was one strange entry in my HTJ log which I removed it was a program called "dsrt.exe" unfortunately before I formated I forgot to backup the log so I could post it.  I removed that entry but things still were going crazy and nothing worked.  Last thing, I did try to reinstall Windows which also did no good, still the same thing at which point I just gave up and formated. The reason why I thought it might be a security issue is because of the programs which didn't work, almost all were related to security such as AV and what not.  If it was a problem caused by something my AV wasn't detecting could it still be on here somewhere like on another partition and infect my C: drive again?  I'd hate to have this nice and formatted and running all good again just to have it die.  Any ideas or ponderings would be greatly appreciated.<br><SMALL>--<br>HABYA HABYA HABYA TEAR DOWN THE HEM STALKS EAT UP THE OLD MAN AND WOMAN AND CARRY OFF THE LITTLE GIRL MAY YOU DIE ALONE</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Win98-ZA-and-AV-shutdown-10402572</guid>
<pubDate>Wed, 02 Jun 2004 13:16:31 EDT</pubDate>
</item>
</channel>
</rss>
